Privacy Policy

Last updated: 8 September 2026

Who we are

BorderLens is a cross-border duty and tax intelligence platform for ecommerce businesses. BorderLens is the trading name and product brand of Chapter 4 Intelligence Limited (company number 17436781), a company registered in England and Wales. Our registered office is 82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE. If you have any questions about this policy or how we handle your data, contact us at [email protected].

Who this policy covers

BorderLens is a business-to-business (B2B) service. Our customers are ecommerce businesses ("Merchants"), not individual consumers. This policy explains how we handle data in two distinct contexts:

  • Platform data — information about your business account (contact details, usage, and support). For this data, BorderLens is the data controller.
  • Merchant trade data — carrier invoices, order data, and customs declarations that you upload or connect to the platform. For the personal data of your end-customers contained within this data, you are the data controller and BorderLens acts as your data processor, processing it only on your instructions to provide the service.

If you are an individual whose personal data appears in a carrier invoice or order uploaded by a BorderLens merchant, you should contact that merchant directly to exercise your data rights. We will assist merchants in responding to such requests.

Our merchant Data Processing Agreement explains the controller and processor terms that apply when we process merchant customer data.

What we collect and why

Account data

When you sign up we collect your name, email address, company name, and account contact details. We use this to provide and administer your account. Legal basis: performance of contract.

Carrier invoice data

You upload carrier invoices (DHL, FedEx, UPS, and others) containing shipment charge records, airway bill (AWB) numbers, consignee/consignor names, and limited address signals such as country and postcode. We process this data to perform duty and tax reconciliation — the core function of the service. Legal basis: performance of contract.

Order data from Shopify

When you connect your Shopify store, we ingest order values, destination countries, line items, and customer name fingerprints. Customer names are normalised and hashed using SHA-256 for matching; BorderLens does not store readable Shopify customer names as order identifiers. We do not ingest full Shopify delivery addresses for reconciliation. Legal basis: performance of contract.

HMRC CDS declaration data

Where you authorise us to connect to HMRC's Customs Declaration Service (CDS) via OAuth, we retrieve customs entry numbers, duty amounts, and declaration metadata to support reconciliation and C285 claim identification. This connection is optional and initiated only at your request. Legal basis: performance of contract.

Usage and analytics

Inside the authenticated BorderLens service, we collect a deliberately limited activity trail: when the app is opened and which top-level screens are viewed. These records are tied to the merchant account but do not contain user names or email addresses, order or shipment identifiers, uploaded document contents, search terms, or filter values. We use them to understand adoption, provide support, and improve the service. Google Analytics is not used inside the authenticated app. Legal basis: our legitimate interest in operating and improving the service.

On our public website, Cloudflare Web Analytics provides aggregate page-view, referral, country, device, browser, and performance reporting without using cookies, local storage, cross-site tracking, or fingerprinting. Cloudflare states that this service does not collect or use visitors' personal data. We use it to understand whether the website is being visited and whether it performs reliably. Legal basis: our legitimate interest in operating and improving the website.

On our public website, Google Analytics is loaded only after you accept analytics cookies. It records information such as page views, referring sites, campaign parameters, approximate location, and browser or device type. We have disabled Google advertising signals and do not intentionally send names, email addresses, merchant trade data, or other direct identifiers to Google Analytics. Legal basis: consent. You can withdraw or change your choice at any time using the "Cookie settings" link in the website footer.

How we handle end-customer personal data

Carrier invoices for business-to-consumer shipments may contain personal names. Our ingestion pipeline is designed to minimise exposure of this data:

  • Unconfirmed uploads waiting for shipper confirmation have a 30-day retention limit and are removed through our operational retention review.
  • Access to source carrier invoice files needed for evidence review expires after a limited operational window, currently up to 6 months; file deletion is completed through the same retention review.
  • When a shipment is classified as a customer order or customer return, readable customer-name fields on the shipment are hashed (SHA-256) and nulled.
  • A restricted raw extraction payload may retain parsed names for classification replay and audit while the merchant account is active.
  • Full street addresses are not displayed in merchant-facing views; address handling is limited to the route and matching signals needed for reconciliation.
  • Stored files and database records are encrypted at rest by the hosting/storage provider.

Data retention

Data type Retention period
Unconfirmed upload files 30-day limit; deletion is currently enforced through operational retention review
Source carrier invoice files retained for evidence review Access for up to 6 months; file deletion is currently enforced through operational retention review or earlier account closure
Carrier invoice charge records, shipment, order, and reconciliation data Duration of the active account, then deleted on account closure unless legal retention is required
Account data Duration of the active account, then deleted on closure unless legal retention is required
Authenticated app activity events Duration of the active account, then deleted on closure unless legal retention is required
All merchant data on account closure Deleted within 30 days of closure request, subject to backups and legal retention obligations

Subprocessors

We use a small number of third-party service providers to deliver the platform — covering areas such as authentication, encrypted file storage, document processing, and AI-assisted analysis. Each is bound by appropriate data processing agreements. All file storage and core processing is intended to be hosted within the UK or EU where available. Where providers outside the UK or EU are used, transfers are covered by appropriate safeguards such as Standard Contractual Clauses or UK International Data Transfer Addenda.

Cloudflare provides our cookieless aggregate public-website analytics and website hosting. Google provides our optional, more detailed public-website analytics service. Google Analytics is not loaded unless you accept analytics cookies, and is not used inside the authenticated BorderLens app.

You may request our full subprocessor list at any time by emailing [email protected]. We will notify you by email at least 30 days before adding a new subprocessor that processes your trade data.

Your rights

As a business customer (and as an individual whose data we control as part of your account), you have the following rights under UK GDPR:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Data portability — request a copy of all data we hold about you, provided in a structured, machine-readable format. Email [email protected] and we will prepare a full export of your account data.
  • Erasure (right to be forgotten) — request deletion of your account and all associated data. Email [email protected] and we will permanently delete your account and the data we hold about you, subject to any legal retention obligations.
  • Restriction — ask us to restrict processing in certain circumstances
  • Objection — object to processing based on legitimate interests

To exercise any of these rights — including a full data export or account deletion — email [email protected]. These requests are currently handled manually, and we will complete them within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.

Cookies

This website uses functional browser storage for preferences such as dark mode and your analytics-consent choice. If you accept analytics, Google Analytics may set cookies such as _ga to distinguish visits and measure website and campaign performance. Google Analytics remains blocked if you reject analytics. We do not use advertising cookies or enable Google advertising signals. You can reopen "Cookie settings" from the footer to change your choice. Cloudflare's aggregate Web Analytics does not use cookies or browser storage and therefore is not controlled by the analytics-cookie choice.

Changes to this policy

We may update this policy as the platform evolves. For material changes we will notify you by email at least 14 days before the change takes effect. The "last updated" date at the top of this page always reflects the current version.

Contact

For privacy questions, data subject requests, or to report a concern: [email protected].