Goshen Seven Staff App

Privacy Policy

How Goshen Seven collects, uses, shares and protects personal data across the staff operations platform, the Staff and CarryAll Android apps, our websites and kiosks.

Version 2026-09-28 · Effective 28 September 2026

What personal data Goshen Seven collects across its websites, apps and kiosks, why, who it is shared with, where it is stored, how long it is kept, and the rights you have over it.

1. Who is responsible for your data

  • CarryAll customers (deliveries, moves, forwarding, shopping): Goshen Seven CarryAll & Delivery LLC is the data controller.
  • Staff: the Goshen Seven company or Business that employs or engages you is the controller of your employment data.
  • Customers and patients of a Business that uses Goshen Seven Business (for example a restaurant, shop, clinic or laboratory): that Business is the controller of the records it keeps about you, and Goshen Seven processes them on its behalf and on its instructions.
  • Privacy contact for all of the above: hello@goshenseven.com.

2. What this policy covers

carryall.goshenseven.com, business.goshenseven.com, the Goshen Seven CarryAll Android app, the Goshen Seven Staff Android app, restaurant self-order kiosks and order-status screens, and the services provided through them.

3. The personal data we collect

  • Account and identity: name, email address, phone number, country, profile photo, and your password (held by our sign-in provider in hashed form — we never see it). Staff also have a role, branch, department, employee number and a PIN, which we store only in hashed form.
  • Orders: pickup and delivery addresses and map coordinates, contact details for each end, package descriptions, weights, dimensions, declared values, package photos, moving inventories, schedules, notes for the driver, delivery signatures and proof-of-delivery photos, ratings and support tickets.
  • Payments: amount, currency, card brand or wallet (e.g. "Visa", "PayPal"), the payment provider's transaction reference, status, and the time you accepted the Payment & Refund Policy. Card numbers are entered on our payment providers' secure pages; we never receive or store them.
  • Communications: order-chat and team-chat messages and attachments, support tickets, contact-form messages, call records (who called whom, when, and for how long) and, where a call is recorded, the recording. The call screen tells you that calls may be recorded.
  • Job applications: when you apply for a role on our careers page, your name, email, phone number, location, the covering message you write, the CV you upload, and our notes on the application.
  • Location: your device location, only when you allow it — to set a pickup point, to show a driver's position to the customer during a trip, and for staff attendance where a Business turns that on.
  • Workforce records (staff): schedules, time-clock entries, leave, payroll, training, compliance and disciplinary records, skills, and documents HR uploads.
  • Health information (healthcare Businesses only): patient registration, appointments, clinical, laboratory and pharmacy records that a clinic or laboratory records about its patients. This is sensitive personal data and is handled under section 9.
  • AI inputs: messages you send to the AI assistant, documents you upload to draft a form, and package photos checked for clarity.
  • Device and security data: IP address, browser and device type, app version, push-notification token, sign-in and authenticator events, and audit logs of actions taken in the platform.
  • Consent records: which version of these policies you accepted, when, and from which app.

4. Why we use it, and our legal basis

  • To create and run your account and provide the Services you book — performance of our contract with you.
  • To take payments, issue receipts and refunds, and keep accounting records — contract and legal obligation.
  • To contact you about your orders, calls and account, by in-app notification, push, email or phone — contract.
  • To keep the Services secure, prevent fraud and abuse, and investigate incidents — legitimate interests and legal obligation.
  • To run staff employment, attendance and payroll — employment contract and legal obligation.
  • To check package photos for clarity and to answer AI-assistant questions — contract (and, for the assistant, your choice to use it).
  • To train our staff and improve the Services and the system, using chat messages and call recordings — legitimate interests. They are used for nothing else.
  • To consider you for a role you applied for — steps you asked us to take before a possible employment contract.
  • To send offers and news — only with your consent, which you can withdraw at any time.
  • To process health information — the explicit consent of the patient or another condition the law allows for healthcare, as determined by the clinic or laboratory.

5. Artificial intelligence

  • The AI assistant sends your messages to our AI provider to generate replies. Package photos are sent to the same provider to check that the whole package is visible and well lit. Documents uploaded to draft a form are sent to generate the draft.
  • Everything AI generates or modifies is labelled AI-generated or AI-assisted wherever it appears, including messages a person drafted with AI.
  • We do not use your data to train AI models, and our providers' business terms do not allow them to use it for training.
  • AI never makes a decision with legal or similarly significant effect about you on its own. A photo the AI flags can still be accepted by a person, and you can ask for any AI result to be reviewed by a person.

6. Who we share it with

We do not sell personal data and do not share it for cross-context behavioural advertising. We share it only with:

  • the driver, crew or staff assigned to your order, and the Business you are dealing with;
  • our cloud providers for sign-in, the database, push notifications and website hosting — United States;
  • our file-storage provider, for photos, documents and other uploads — United States;
  • our payment providers — they act as independent controllers for the card and wallet data you give them;
  • our AI provider, for AI features — United States;
  • our email provider (transactional email such as sign-in, receipts and notices);
  • mapping and routing services, which receive the addresses and coordinates you search for and map, so we can show maps and calculate distances;
  • a call-connection provider, which sees the network addresses of the two devices on a call so they can connect — never the call's content, which is encrypted end to end;
  • courts, police and regulators, when the law requires it or to protect someone's safety; and a buyer of our business, under the same protections, if the business is sold.

7. Where your data is stored, and international transfers

Our database, file storage, website and API are hosted by our cloud providers in the United States. If you use the Services from Zambia or any other country, your personal data is therefore transferred to and stored in the United States.

We protect it there with encryption in transit (TLS) and at rest, strict access controls, and contracts with each provider that require them to protect it. We keep a register of these providers, which we make available to the data protection authority. By accepting this policy you consent to this transfer. If you do not consent, do not create an account; if you withdraw consent, you can delete your account at any time.

8. How long we keep it

  • Your account, orders, messages, payment history, uploads and support tickets: for as long as your account exists. When you delete your account they are erased (section 10).
  • Call signalling data (the technical data used to connect a call): deleted when the call ends. The call record itself (who, when, how long) is kept with your account.
  • Call recordings, where a call is recorded: 12 months, then deleted.
  • Job applications, including the CV: 12 months after you apply, then deleted automatically. If you are hired, what HR needs moves to your staff record.
  • Notifications and automatic-message logs: 12 months, then deleted automatically.
  • Security and audit logs: 24 months, then deleted automatically, unless needed for an ongoing investigation. They are kept for that period even after an account is deleted, but no longer link to a profile.
  • Deletion requests made through our website: 12 months after they are closed.
  • Staff sign-in records (when a sign-in started and ended, and why): 90 days after it ends. The sign-in and sign-out events themselves are part of the security log above.
  • Accounting totals: when an account is deleted, only amount, currency, date and payment reference are kept, with nothing that identifies you, for the period tax law requires.
  • Staff employment and payroll records: for the period employment and tax laws require after employment ends.
  • Health records: for the period required by the health-records laws that apply to the clinic or laboratory, which decides this as controller.
  • Backups: our providers keep encrypted backups for disaster recovery; deleted data disappears from them as the backups expire.

9. Sensitive data and health information

  • Health information is visible only to staff of the clinic or laboratory that recorded it, and within that Business only to roles that need it — reception does not see clinical notes, and billing staff do not see clinical records.
  • Each Business's records are isolated from every other Business on the platform: staff of one Business cannot see another Business's data. Goshen Seven's company administrators can view every Business in order to oversee its operations — but not health records, which stay with the clinic or laboratory that recorded them unless that Business grants access.
  • Access to records is logged, and staff are bound by confidentiality obligations.

10. Your rights

  • Access and portability: download a copy of your data from your profile ("Download my data"), or ask us for it.
  • Correction: edit your details in your profile, or ask us to correct them.
  • Deletion: customers can delete their account themselves from their profile — it takes effect immediately and erases their orders, messages, payment history, uploads, support tickets, notifications and sign-in sessions. Staff ask from their profile and an administrator completes it. Anyone can also ask at /data-deletion. You cannot delete an account while goods are in our care; finish or cancel that order first.
  • Objection and restriction: ask us to stop or limit a use of your data.
  • Withdrawing consent: stop marketing at any time; withdraw consent to processing by deleting your account.
  • Complaints: you can complain to the Office of the Data Protection Commissioner of Zambia, or to the privacy regulator or Attorney General where you live.
  • We answer requests within 30 days. We may need to verify your identity first. We will not treat you differently for exercising your rights.

11. Security

  • All traffic is encrypted with TLS; stored data is encrypted at rest by our providers.
  • Secure sign-in, hashed staff PINs, optional authenticator-app two-factor sign-in, and automatic sign-out after inactivity. Staff sign-ins are recorded on our servers, so signing out — or being signed out automatically — ends the sign-in on both of our websites and in every tab of that browser at once.
  • Role-based permissions, checked by the server, and isolation of each Business's data.
  • Payments handled only by PCI-DSS certified providers.
  • Audit logs of sensitive actions, and least-privilege access for our own personnel.

12. Personal-data breaches

If a breach puts your personal data at risk, we will contain it, investigate it, notify the Office of the Data Protection Commissioner and any other regulator within the time the law requires, and tell you without undue delay what happened, what data was involved, and what you can do to protect yourself.

13. Cookies and similar technology

We use only what the Services need to work: a session cookie that keeps you signed in; for staff, a security cookie that identifies the browser (a random code, not you) so that signing out ends every sign-in that browser holds, and a cookie recording when the screen was last used so that an unattended screen is signed out; and your device's local storage for preferences such as theme, units, the selected branch and unsent chat drafts. These are strictly necessary and are shared only between our own websites. We do not use advertising or analytics cookies, and we do not track you across other websites.

14. Children

The Services are not intended for anyone under 18, and we do not knowingly collect personal data from children. A clinic may record a child's health information with a parent or guardian's consent, under that clinic's responsibility.

15. Changes to this policy

When we change this policy materially we will show you the new version and ask you to accept it before you continue. The version and effective date appear at the top.

16. Contact and privacy requests

Email hello@goshenseven.com, use Support in the app, or submit a request at /data-deletion. Staff may also contact their administrator.

Also see the Terms of Use, Payment & Refund Policy and data deletion.