Skip to main content
PSTCargo & Postal Management System

Legal document

Privacy policy

How PST collects, stores, uses, shares, and safeguards your personal data — in compliance with Iran’s e-commerce law, data protection rules, and CRA directives.

Our privacy commitment

This document explains which user data we collect, why, how it is stored, with whom it is shared, and what rights users have over their data. PST (national ID 14009039475, postal license 1416-93-100) complies with Iran’s E-Commerce Act, Freedom of Information Act, Cyber Crimes Act, and CRA directives. Last updated in 1404 (2025). Substantive changes are published here with the revision date and announced via the news feed.

  1. 1

    1 — Data we collect

    Registration & service use: name, mobile, national ID, postal address, IP address, browser metadata. Shipment registration: sender & recipient names and contacts, origin & destination addresses, item details (weight, dimensions, value, HS Code, content type), parcel photos, and customs documents where needed. Online payments: card data is processed exclusively by gateways (Zarinpal, Saman, …) and never stored by PST; we only receive the transaction reference and status.

  2. 2

    2 — Identity verification via Shahkar

    To prevent abuse and meet regulator requirements, at activation we match the user’s name, national ID and mobile via the CRA Shahkar system. Only matching is performed — no ID image, face image, or biometric data is stored by PST.

  3. 3

    3 — Purpose of collection

    Data is used solely for: (a) postal, customs, and cargo services; (b) official invoicing and tax reports; (c) tracking and SMS/email notifications; (d) complaints and compensation; (e) mandatory periodic reports to the CRA; (f) anonymous quality and trend analytics; (g) responding to judicial and security authorities’ lawful orders. Personal data is never sold or rented for third-party advertising.

  4. 4

    4 — Cookies & tracking technologies

    The PST website uses functional cookies (session, security), preference cookies (language, theme), and analytics cookies (traffic). Third-party marketing cookies (Google Ads, Facebook Pixel) are not enabled. Users may disable cookies in browser settings but this may impair login and shipment tracking.

  5. 5

    5 — Data storage location & security

    All data is stored on in-country servers in licensed data centers. Sensitive fields (national ID, passwords) are encrypted; sessions are secured via JWT and HTTPS; staff access is limited via role-based access control (RBAC). Every access to customer data is recorded in our Audit Log and is reviewable.

  6. 6

    6 — Retention periods

    Shipment & tracking data: minimum 3 years post-delivery for claims and reports. Financial data & invoices: 10 years per Direct Taxes Act. User profile data: while the account is active, plus 12 months after deactivation, then archived or erased. Security & audit logs: 24 months.

  7. 7

    7 — Sharing with third parties

    For international services we share necessary data (name, address, declared contents, HS Code) with foreign carriers, destination customs, and UPU systems. For domestic customs we exchange data with NTSW and Iran’s customs (EPL). In legal cases, data is provided to authorities on judicial order. PST will provide the list of data partners on formal user request.

  8. 8

    8 — User rights over data

    Users may: (a) access their personal data and receive an electronic copy; (b) correct inaccurate data; (c) request deletion within legal limits after the mandatory retention period; (d) withdraw consent for marketing messages; (e) escalate privacy complaints to the CRA portal (195.cra.ir). Requests via privacy@pstcargo.com are answered within 10 business days.

  9. 9

    9 — Children’s privacy

    PST services are intended for users 18+. Registration of minors requires legal guardian approval and ID documents. If we discover a minor account without guardian consent, it is deactivated immediately and the data deleted.

  10. 10

    10 — Security incidents & breach disclosure

    In case of any security incident leading to unauthorized data disclosure, PST will report to the CRA within 72 hours, notify affected users, and post a public notice. Our infosec team monitors infrastructure 24/7.

  11. 11

    11 — Contact our data protection officer

    For privacy questions, rights requests, incident reports, or complaints, contact our Data Protection Officer at privacy@pstcargo.com, 021-79308 (legal extension), or the HQ address (Tehran, Palestine Sq., Taleghani St., Baradaran Mozaffar St., No. 133, Ground Floor, Unit 2, Postal code 1416793182).