Skip to content

Security is part of the product

Data security: how we handle your Nova Poshta API key and personal data

Is it safe to give a Nova Poshta API key to a third-party service? A Nova Poshta key has no read-only mode, so it’s the right question. That is why data protection is built into the design of Rampo: the key only after a data processing agreement, only two read methods, encryption, short retention periods and no personal data in Telegram.

  • The audit needs no key at all
  • Delete the key with one click
  • EU servers: Germany or Finland

How we protect your Nova Poshta API key

Six rules that never change.

  • Agreement first

    We accept a key only after you accept the public offer and sign a data processing agreement. Never before.

  • A separate key

    You create a key just for Rampo — not the one your CRM uses. We show you how.

  • Only 2 read methods

    We call only the shipment list and shipment statuses. All other API methods are blocked in our code and covered by tests.

  • Encryption

    The key is stored in the database only in encrypted form, with a dedicated encryption key.

  • One-click removal

    Delete the key in your Rampo account or in Nova Poshta and the service simply stops. No calls, no emails.

  • Tenant isolation

    Users of one shop never see another shop’s parcels, lists or reports — not through the interface, not via a direct link.

Protecting buyers’ personal data

Phone numbers, names and even tracking numbers are your buyers’ personal data. You, the shop, are the data owner; Rampo processes the data only on your behalf and for one purpose: reminding the buyer to collect the parcel and measuring the effect.

So we sign a data processing agreement with you under the Law of Ukraine “On Personal Data Protection”. You can sign electronically or upload a signed PDF if you need paper. For EU shops: a DPA with Standard Contractual Clauses (later, when we launch in the EU).

  • Processing only on your instructions
  • Data minimisation — only what a reminder needs
  • No personal data in logs

How long we keep data

The shorter we keep data, the lower the risk. So retention periods are strict, and clean-up runs automatically and is logged.

Data Retention Purpose
Free audit file Deleted right after the calculation Only to calculate pickup rate and losses
File with extra columns Deleted immediately, never processed We don’t accept personal data for the audit
Call list 2 days So managers can make their calls
Parcel data (status, amount, buyer phone) 90 days To calculate outcomes and the effect

Call lists are available only inside the shop’s authenticated account. Links to them carry an unguessable token and expire within 2 days.

Where data is stored

On Hetzner servers in the EU — in a data centre in Germany or Finland. They are unaffected by power outages in Ukraine, and data processing there is subject to the GDPR.

Telegram gets numbers only

Shop owners like seeing the essentials in Telegram. But Telegram is no place for personal data. So Rampo messages contain only aggregates: how many parcels are waiting at branches, their total value, how many will enter paid storage tomorrow, and a link to the account.

No names, phone numbers or tracking numbers. This rule is enforced by automated tests: a message containing personal data simply fails the check.

  • Parcel count and total value
  • How many parcels enter paid storage tomorrow
  • A link to the secure account

How to connect Nova Poshta safely

  1. 1. Audit without a key

    Start with a free audit from a 4-column export. No key and no personal data needed.

  2. 2. Agreement

    If you decide to run a pilot, you accept the offer and sign the data processing agreement. We record the document version, date and time.

  3. 3. A separate key

    Create a separate API key in your Nova Poshta business account and paste it into your Rampo account. We verify it right away.

  4. 4. You stay in control

    In the Security section of your account, delete the key with one click whenever you want.

Data security questions

Is it safe to share a Nova Poshta API key?

A Nova Poshta key grants broad access, so we accept only a separate key and only after an agreement, call only two read methods, store the key encrypted, and you can delete it with one click.

Why a data processing agreement?

Buyers’ personal data belongs to your shop. The agreement states that Rampo processes it only on your instructions, for a defined purpose and for agreed periods.

Can you create or change shipments with my key?

Our code calls only two read methods — the shipment list and statuses. All other methods are blocked, and automated tests verify this.

What happens if I delete the key?

The service stops receiving statuses and no new call lists appear. Parcel data is deleted automatically on the normal schedule.

Where is the data physically stored?

On Hetzner servers in the EU — in Germany or Finland. They are unaffected by power outages.

Does the audit need personal data?

No. The audit works with 4 columns without names, phone numbers or tracking numbers. Files with other columns are not processed and are deleted. See the audit page.

Start with no key and no risk

The free audit needs neither an API key nor personal data. Report within 1 business day.