Back to blog Privacy

How Trampay Handles Your Delivery Data: Read-Only, Yours to Delete

Data privacy and security approach at Trampay

When we were building the connection layer between Trampay and delivery platforms, the question we came back to repeatedly was: what is the minimum we need to read in order to give couriers an accurate income forecast and a useful credit profile? Not what would be convenient to have, or what might be useful someday. What do we actually need right now, and nothing more.

That question shaped a design principle we have not deviated from: read-only access, explicit data categories, no password storage. This post explains exactly how it works and what your rights are under Brazilian data law.

Read-Only API Access: What It Means in Practice

When you connect a delivery platform to Trampay, we access your delivery history through a read-only API connection. Read-only means exactly that. Trampay can retrieve information from your platform account. Trampay cannot take any action on your account: cannot accept orders, cannot change your profile, cannot modify your settings, cannot withdraw funds, cannot contact customers. The connection is one-directional.

We never ask for your platform password, and we never store it. The connection works through a token-based authorization mechanism, similar to how other financial apps connect to bank accounts in Brazil under the Open Finance framework. You authorize the connection inside the platform's own interface or through a secure redirect. The authorization token that allows Trampay to read your data is stored on our systems in encrypted form and can be revoked by you at any time from within the Trampay app. Revoking it removes our ability to read new data from your account going forward.

What Data We Actually Read

The data categories we pull from connected delivery platforms are:

  • Delivery completion records: date, time, duration, and earnings amount for each completed delivery. We do not read customer names, delivery addresses, or order contents.
  • Platform activity status: when you were online and accepting orders, aggregated to hour-level resolution. We do not track your physical location.
  • Aggregate earnings summaries: weekly and monthly totals as reported by the platform.
  • Account status and tenure: how long your platform account has been active and your current account standing. We do not read private account details or payment method information.

We do not read delivery destination addresses. We do not read customer information. We do not read chat messages or communications within the platform. We do not read payment card or banking details stored on the platform. The data we pull is limited to earnings history and activity patterns.

Why We Need Each Data Category

Every data category we read serves a specific function in either the income forecast or the credit profile. If a data point does not contribute to those outputs, we do not pull it.

Delivery completion records with timestamps and earnings are the core input to the forecast model. Without the individual delivery records, we cannot identify the time-of-day and day-of-week patterns that are the strongest predictors of future income. The aggregated weekly totals alone are not sufficient for accurate forecasting at the daily resolution we provide.

Activity status data lets the model distinguish between a courier who was active but had a slow shift and one who did not work at all. Those are different signals for forecasting and for the credit profile. A week of low earnings from consistent activity reads differently than a week of no activity.

Account tenure contributes to the credit profile as a stability signal. A courier with 24 months on iFood has a longer track record than one with three months, and that distinction is relevant to lenders evaluating the consistency of the income source.

Your Rights Under LGPD

The Lei Geral de Protecao de Dados (LGPD), Brazil's data protection law, gives you a set of rights over the personal data that any company holds about you. These apply to your data at Trampay.

Right of access: You can request a copy of all personal data Trampay holds about you at any time. We will provide this in a readable format within the timeframe required by LGPD.

Right of correction: If any personal data we hold about you is inaccurate, you can request correction. For delivery earnings data, the source of record is the platform, not us, so corrections would need to originate there. For other personal data (name, contact details), we correct them directly on request.

Right to deletion: You can request deletion of your Trampay account and all associated data. This removes your delivery history from our systems, your income forecast history, and your credit profile data. After deletion, we retain only the minimum records required for legal and compliance purposes, for the period specified in our privacy policy.

Right to data portability: You can request your data in a machine-readable format for transfer to another service. We support this through a data export function in the app settings.

Right to revoke consent: The legal basis for processing your delivery data is your explicit consent, given at the point of platform connection. You can revoke this consent at any time by disconnecting the platform in the Trampay app. Revocation stops new data from being collected. It does not automatically delete historical data already collected unless you also submit a deletion request.

To exercise any of these rights, contact us at [email protected] with the subject line "LGPD Request." We respond within the statutory timeframe. Our full privacy policy is at legal/privacy.html.

What Happens to Your Data When We Share It

With your explicit consent, Trampay may share your credit profile data with partner lenders as part of the credit access feature on the Plus plan. This sharing is limited to the credit profile summary: earnings consistency, tenure, and derived score signals. We do not share individual delivery records with lenders. We do not share your delivery platform login credentials under any circumstances, because we do not hold them.

We do not sell your data to third parties. We do not share your data with advertisers. The data you share with Trampay is used to provide you with the income forecasting and credit profile services, and for the credit access connection you explicitly opt into.

A Direct Statement on What We Are Not Doing

We are not building behavioral profiles for advertising. We are not selling courier location or activity patterns to logistics companies, platform operators, or any other commercial party. We are not using your data to identify you to your delivery platforms in ways that could affect your standing as a worker on those platforms. Our business depends on couriers trusting us with their data. We know that, and it shapes every decision we make about what to collect and what to share.

If you have questions about any aspect of how we handle your data that this article does not address, email us at [email protected]. We are a small team and we respond to every real question directly.

More from Trampay Blog

Your data stays yours

Read-only access. No passwords stored. LGPD rights built in from day one.