+44 (0)121 256 8702 | support@globord.co.uk | WhatsApp
GLOBORD.
  • How It Works
  • Services
  • Shipping Routes
  • FAQ
  • About
  • Guide me?
Login Sign Up Free
Home / Privacy Policy
UK GDPR & DPA 2018 Compliant

Privacy Policy

We take your privacy seriously. This policy explains exactly what personal data we collect, why we collect it, how it is used, and your full rights as a data subject under UK law.

Effective date: 21 June 2026   |   Data Controller: Globord Customs and Trade Ltd t/a GLOBORD   |   Terms of Service
Contents
1Who We Are 2Data We Collect 3How We Use Your Data 4Third Parties & Sharing 5International Transfers 6Data Retention 7Cookies & Tracking 8Your Rights 9Children's Privacy 10Marketing 11Security 12Policy Changes 13Contact & Complaints
Read Terms of Service
Last updated: 21 June 2026. If you have questions about this policy, contact our privacy team at privacy@globord.co.uk.
Section 1

Who We Are

Globord Customs and Trade Ltd (trading as GLOBORD) ("GLOBORD", "we", "us", "our") is registered in England and Wales (Company No. 7222404), with its registered office at Izabella House, 24-26 Regent Pl, Birmingham, B1 3NJ, Great Britain.

GLOBORD is the data controller for all personal data collected in connection with the use of our website (globord.co.uk) and our package forwarding and international shipping services.

As a data controller, we are registered with the UK Information Commissioner's Office (ICO) under registration number C1964024.

For all privacy matters, our designated contact is:

Privacy Team — Globord Customs and Trade Ltd t/a GLOBORD
Izabella House, 24-26 Regent Pl, Birmingham, B1 3NJ
privacy@globord.co.uk

This Privacy Policy is written in compliance with the UK General Data Protection Regulation (UK GDPR) as retained under the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018. These are the primary laws governing how organisations must handle personal data in the United Kingdom.

Section 2

Personal Data We Collect

We collect the minimum personal data necessary to provide our services ("data minimisation" — UK GDPR Article 5(1)(c)). The categories of personal data we hold are:

2.1 Identity & Contact Data

  • Full legal name
  • Email address
  • Country of residence
  • Phone number (optional)
  • Delivery destination address (provided when requesting a shipment)

2.2 Account Data

  • Hashed password (we never store your password in plain text; it is irreversibly hashed using bcrypt)
  • Account creation date
  • Assigned suite code(s)
  • Email verification status

2.3 Transactional & Operational Data

  • Package tracking numbers, courier names, weights, and arrival dates
  • Item descriptions and categories (as provided by you for customs purposes)
  • Declared customs values of goods
  • Shipment destinations and references
  • Shipment and payment status history

2.4 Financial Data

  • Payment method type (card or PayPal — we do not store card numbers)
  • Transaction IDs and payment confirmation references
  • Payment amounts and dates

Card security: Full credit and debit card details are processed exclusively by Stripe and are never transmitted to or stored on GLOBORD systems. Stripe is PCI DSS Level 1 compliant. Similarly, PayPal payments are handled entirely within PayPal's environment.

2.5 Communications Data

  • Messages sent to our support team (email content, subject lines)
  • Records of notifications we have sent you (emails, SMS)

2.6 Technical & Usage Data

  • IP address at the time of account registration or login
  • Browser type and version
  • Device type
  • Pages visited and time spent (via server logs and analytics)

2.7 What We Do Not Collect

We do not collect any special category personal data (UK GDPR Article 9) such as health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, or trade union membership. We do not collect criminal offence data (UK GDPR Article 10), except where required to comply with our legal anti-money laundering obligations.

Section 3

How We Use Your Personal Data

We only process your personal data where we have a valid lawful basis under UK GDPR Article 6. The table below sets out each purpose, the data used, and the lawful basis:

Purpose Data Used Lawful Basis
Creating and managing your account Identity, account data Contract
Assigning and managing your suite address Identity, account data Contract
Receiving, logging, and storing your packages Transactional data, identity Contract
Processing and dispatching shipments Transactional data, customs data, delivery address Contract
Processing payments Financial data, identity Contract
Sending service notifications (package received, dispatched, delivered) Identity, contact, transactional Contract
Email & SMS shipping updates Contact, transactional Contract
Customs documentation & export declarations Identity, transactional, customs data Legal Obligation
HMRC record-keeping (financial records — 6 years) Financial, transactional, identity Legal Obligation
Anti-money laundering & KYC checks Identity, financial Legal Obligation
Fraud prevention and account security Identity, technical, financial Legitimate Interests
Improving our services and platform analytics Technical, usage data (anonymised where possible) Legitimate Interests
Responding to support enquiries Identity, communications data Legitimate Interests
Sending marketing emails and promotional offers Contact data Consent
Non-essential cookies and analytics tracking Technical, usage Consent

3.1 Legitimate Interests Assessment

Where we rely on Legitimate Interests as a lawful basis, we have conducted a balancing test to confirm that our interests are not overridden by your rights and interests. We would be happy to provide a summary of our Legitimate Interests Assessment for any specific processing purpose on request.

3.2 No Automated Decision-Making

GLOBORD does not make any solely automated decisions (including profiling) that produce legal or similarly significant effects on you, as described in UK GDPR Article 22.

Relevant legislation: UK GDPR Articles 5, 6, 9, 22 | Data Protection Act 2018
Section 4

Who We Share Your Data With

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share data only where necessary for the delivery of our services, fulfilment of legal obligations, or with your consent.

4.1 Service Providers (Data Processors)

The following third parties process personal data on our behalf, under written data processing agreements compliant with UK GDPR Article 28:

Provider Purpose Location
Resend Transactional email delivery (account verification, shipping notifications, receipts) USA (SCCs in place)
Twilio SMS and WhatsApp shipping notifications USA (SCCs in place)
Stripe Payment processing and card data handling (PCI DSS Level 1) UK / EU / USA
PayPal Alternative payment processing UK / EU / USA
Railway Cloud hosting and PostgreSQL database (all application data) USA (SCCs in place)
Vercel Website hosting and content delivery USA (SCCs in place)
Google (Analytics) Website analytics — anonymised traffic and session data (GA4). Only active with your consent. USA (SCCs in place)
Meta Platforms (Facebook Pixel) Ad performance measurement and remarketing for Facebook/Instagram campaigns. Only active with your consent. USA (SCCs in place)

4.2 Customs & Regulatory Authorities

When your goods are exported from the UK or imported into your destination country, we are required by law to share relevant personal data (your name, delivery address, and goods details) with HMRC, UK Border Force, and the customs authorities of the destination country. This sharing is required under the Customs and Excise Management Act 1979 and equivalent legislation in destination jurisdictions.

4.3 Shipping Partners & Carriers

We share your name, delivery address, and shipment details with the freight carriers and courier companies we use to transport your goods. These carriers are independently subject to GDPR-equivalent or locally applicable data protection laws.

4.4 Law Enforcement & Regulatory Bodies

We may disclose personal data to law enforcement agencies, regulatory bodies (including the NCA under our AML obligations), or courts where required by law, a court order, or where we have a good-faith belief that disclosure is necessary to prevent fraud, criminal activity, or harm. We will notify you of such disclosures where we are legally permitted to do so.

4.5 Business Transfers

If GLOBORD is involved in a merger, acquisition, or asset sale, your personal data may be transferred to the acquiring entity, subject to the same privacy protections set out in this policy. We will notify you before your personal data becomes subject to a materially different privacy policy.

Section 5

International Data Transfers

Several of our service providers (Section 4.1) are based in the United States, which is not currently covered by a UK adequacy decision under UK GDPR. When we transfer your data to such providers, we ensure appropriate safeguards are in place, specifically:

  • UK International Data Transfer Agreements (IDTAs) — the UK's post-Brexit equivalent of EU Standard Contractual Clauses, approved by the ICO
  • Standard Contractual Clauses (SCCs) — EU Commission-approved clauses, recognised by the ICO as an appropriate transfer mechanism under the UK GDPR transitional provisions

Data transfers to destination countries for customs purposes (e.g., Nigeria, Ghana, Kenya) are made under legal obligation and are subject to the applicable laws of those jurisdictions. GLOBORD cannot control how customs authorities in other countries use data once it has been legally disclosed.

You may request a copy of the transfer mechanisms in place for any specific processor by emailing privacy@globord.co.uk.

Relevant legislation: UK GDPR Articles 44–49 | UK-US Data Bridge (where applicable)
Section 6

How Long We Keep Your Data

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law ("storage limitation" — UK GDPR Article 5(1)(e)).

Data Category Retention Period Reason
Active account data (identity, suite address) For the lifetime of your account + 12 months after closure Contract performance; wind-down period
Financial records (payments, invoices, shipment charges) 6 years from end of the tax year of the transaction HMRC legal requirement (Finance Act / Companies Act 2006)
Customs declaration records 6 years HMRC / Customs legal requirement
Package and shipment records 6 years Legal obligation; contract claims limitation period
AML / KYC verification records 5 years from the end of the business relationship Money Laundering Regulations 2017
Customer support communications 3 years from last contact Legitimate interests (dispute resolution)
Marketing consent records 3 years from last interaction or withdrawal of consent PECR / UK GDPR consent record-keeping
Website server logs (IP, access logs) 90 days Security monitoring; fraud detection

When the retention period expires, personal data is securely deleted or anonymised. Anonymised or aggregated data (from which you cannot be identified) may be retained indefinitely for statistical and business analysis purposes.

Section 7

Cookies & Tracking Technologies

We use cookies and similar technologies on our website in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR). PECR requires your consent for non-essential cookies.

7.1 Essential Cookies (No Consent Required)

CookiePurposeDuration
globord_auth Stores your authentication JWT token to keep you logged in Session / 7 days
googtrans Stores your language preference for Google Translate (functional) Session

7.2 Functional Cookies (Your Preference)

Cookie / StoragePurposeDuration
globord_lang (localStorage) Remembers your chosen language to avoid re-prompting Persistent
globord_lang_dismissed (localStorage) Records that you dismissed the language suggestion prompt Persistent

7.3 Google Translate

Our website uses Google Translate to offer multilingual content. When you use this feature, Google may set cookies and collect usage data in accordance with Google's Privacy Policy. GLOBORD does not control Google's data collection. You can reset the translation at any time using the "← EN" button in the top bar.

7.4 Analytics & Advertising (Consent Required)

With your consent, we load Google Analytics 4 (GA4) to understand site usage — pages viewed, session duration, and traffic sources — and Meta Pixel to measure the effectiveness of our Facebook and Instagram advertising. Neither service loads unless you choose "Accept All" on the cookie banner. You can withdraw consent at any time via Cookie Settings in the footer.

CookieProviderPurposeDuration
_ga, _ga_* Google Analytics Anonymised visitor and session tracking 2 years
_fbp Meta Pixel Ad measurement and remarketing 3 months

7.5 Managing Your Cookie Preferences

You can manage or withdraw your cookie consent at any time by:

  • Clicking Cookie Settings in the footer of any page
  • Adjusting your browser settings to block or delete cookies
  • Clearing localStorage via your browser's developer tools
  • Contacting us at privacy@globord.co.uk

Disabling essential cookies will prevent you from logging into your account. Disabling functional cookies will mean your language preference is not remembered.

Section 8

Your Rights Under UK GDPR

The UK GDPR grants you the following rights in relation to your personal data. We will respond to all requests within one calendar month, free of charge, unless your request is manifestly unfounded or excessive.

Right of Access (Art. 15)

Request a copy of all personal data we hold about you (a "Subject Access Request"). We will provide this in a commonly used electronic format.

Right to Rectification (Art. 16)

Ask us to correct inaccurate or incomplete personal data. You can update most information directly in your account settings.

Right to Erasure (Art. 17)

Request deletion of your personal data ("right to be forgotten"). This right may be limited where we are required to retain data by law (e.g., HMRC 6-year rule).

Right to Restriction (Art. 18)

Ask us to restrict processing of your data in certain circumstances — for example, while you contest its accuracy or the lawfulness of our processing.

Right to Portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) and transfer it to another controller. Applies to data you provided to us processed on a contractual or consent basis.

Right to Object (Art. 21)

Object to processing based on legitimate interests (including profiling) or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds that override your interests.

Automated Decision-Making (Art. 22)

GLOBORD does not currently make solely automated decisions that have significant legal effects on you. If this changes, we will update this policy and provide you with the right to human review.

Right to Withdraw Consent (Art. 7)

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.

8.1 How to Exercise Your Rights

To exercise any of the above rights, please email privacy@globord.co.uk with the subject line "Data Subject Request", specifying which right(s) you wish to exercise. We may ask you to verify your identity before processing the request.

You may also update your name, email, and contact details directly in your account profile at any time.

Section 9

Children's Privacy

GLOBORD's services are not directed at persons under the age of 18. We do not knowingly collect personal data from children.

Under the Data Protection Act 2018 (Section 9), the age of consent for data processing in the context of online services in the UK is 13 years. However, our Terms of Service require users to be 18 or over to enter into a contract. Accordingly, we treat all users as adults and will not permit use by minors.

If you believe a child under 18 has provided us with personal data without appropriate consent, please contact us immediately at privacy@globord.co.uk and we will take steps to delete that information promptly.

Section 10

Marketing Communications

We will only send you marketing emails, newsletters, or promotional messages where you have given us your explicit consent in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and UK GDPR.

We will never:

  • Sell or share your contact details with third parties for their marketing purposes
  • send marketing texts or WhatsApp messages without your prior consent
  • Add you to a mailing list without a clear opt-in action on your part

Every marketing email we send includes an unsubscribe link. You can also withdraw your marketing consent at any time by:

  • Clicking "Unsubscribe" in any marketing email
  • Updating your notification preferences in your account settings
  • Emailing privacy@globord.co.uk

Withdrawing marketing consent will not affect service-critical communications (such as shipment notifications, payment receipts, and security alerts), which we will continue to send as they are necessary for the performance of your contract with us.

Relevant legislation: Privacy and Electronic Communications Regulations 2003 (PECR) | UK GDPR Article 6(1)(a) | Data Protection Act 2018
Section 11

Security of Your Data

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, consistent with UK GDPR Article 32.

11.1 Technical Measures

  • Passwords — hashed using bcrypt with a high work factor; never stored in plain text
  • Data in transit — all communications between your browser and our servers are encrypted using TLS 1.2 or higher (HTTPS)
  • Authentication — JSON Web Tokens (JWT) with defined expiry; role-based access controls
  • Database access — restricted to authorised application services only; not publicly accessible
  • Payment processing — delegated entirely to PCI DSS-compliant providers (Stripe, PayPal)

11.2 Organisational Measures

  • Access to personal data is limited to staff who need it to perform their role ("need-to-know" principle)
  • Staff with access to personal data are bound by confidentiality obligations
  • We conduct periodic reviews of our security practices

11.3 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, as required by UK GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (UK GDPR Article 34).

11.4 Your Role in Security

You play an important role in keeping your data safe. Please use a strong, unique password for your GLOBORD account, do not share your login details, and notify us immediately if you suspect your account has been compromised.

No method of data transmission over the internet is 100% secure. While we implement strong security measures, we cannot guarantee the absolute security of data transmitted to us. You provide data at your own risk, and by using our services you acknowledge this inherent risk.

Section 12

Changes to This Privacy Policy

We review and may update this Privacy Policy periodically to reflect changes in our services, applicable law, or regulatory guidance from the ICO. The "Effective Date" at the top of this page indicates when the current version came into force.

For material changes — those that significantly affect how we process your data or your rights — we will provide at least 30 days' prior notice by email to your registered address and by posting a prominent notice on our website.

For non-material changes (such as clarifications, formatting, or contact details), we may update the policy without individual notice. Continued use of our services after any update constitutes acceptance of the revised policy.

We encourage you to review this policy periodically to stay informed about how we protect your personal data.

Section 13

Contact Us & How to Complain

13.1 Privacy Enquiries

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:

privacy@globord.co.uk
Privacy Team, Globord Customs and Trade Ltd t/a GLOBORD, Izabella House, 24-26 Regent Pl, Birmingham, B1 3NJ

We aim to respond to all privacy-related enquiries within 5 working days, and all formal data subject rights requests within one calendar month.

13.2 Right to Complain to the ICO

If you are not satisfied with how we have handled your personal data or responded to your request, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)

Website: ico.org.uk
Report a concern: ico.org.uk/make-a-complaint
Helpline: 0303 123 1113 (Monday–Friday, 9am–4:30pm)
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF

The ICO recommends contacting the organisation first before filing a formal complaint. We encourage you to contact us at privacy@globord.co.uk in the first instance so we have the opportunity to address your concern directly.

GLOBORD.

Your trusted UK-based package forwarding and international shipping partner. Connecting the world one parcel at a time.

Services
  • Assisted Purchasing
  • Package Consolidation
  • Repackaging
  • Air Freight
  • Sea Freight
  • Customs Support
  • Door-to-Door Delivery
  • Real-Time Tracking
Shipping Routes
  • 🇬🇧 UK → 🇳🇬 Nigeria
  • 🇬🇧 UK → 🇺🇸 USA
  • 🇬🇧 UK → 🇨🇦 Canada
  • 🇨🇳 China → 🇳🇬 Nigeria
  • 🇨🇳 China → 🇬🇧 UK
  • 🇳🇬 Nigeria → 🇬🇧 UK
  • 🇳🇬 Nigeria → 🇺🇸 USA
  • 🇳🇬 Nigeria → 🇨🇳 China
Company
  • About GLOBORD
  • How It Works
  • Customer Guide
  • FAQ
  • Contact Us
  • Terms of Service
  • Privacy Policy
  • Cookie Policy

+44 (0)121 256 8702

support@globord.co.uk

+44 7438 445212

© 2026 Globord Customs and Trade Ltd t/a GLOBORD. Registered in England & Wales. Company No. 7222404

Registered Office: Izabella House, 24-26 Regent Pl, Birmingham, B1 3NJ, Great Britain