Transporter Zone

Privacy Policy

Version 2026-09-15 · Terms of Service · Cookie Policy

What we collect

  • Account data — name, email, phone, password (stored only as a salted hash), avatar, appearance preferences, and the organizations you belong to.
  • Organization data — company details (MC/DOT/SCAC/EIN, address), members and roles, loads, stops, rates, documents, equipment, compliance records, incidents, fuel and mileage records, invoices, bills, settlements and payments — everything your organization enters to run its business.
  • Driver data — where an organization records it: CDL details, medical card and other credential expiry dates, pay plan, location check-ins and stop timestamps submitted from the mobile app.
  • Technical data — session cookies, API token usage timestamps, registered devices (platform, push token), IP addresses in audit logs, and server logs kept for security and debugging.

How we use it

To provide the Service to you and your organization; to show loads and documents to the other organizations you tender or share them with; to send notifications you or your organization have triggered (invitations, tender offers, document-expiry alerts) in-app and, when configured, by email; to keep an audit trail of organization-level changes; and to secure and improve the Service. We do not sell personal data and we do not use your data for advertising.

Who can see what

Inside an organization, access is governed by roles set by its owners and admins. Across organizations, a load is visible only to its owner and the parties on it (customer, broker, carrier, shipper, receiver) or to organizations it is explicitly shared with; each organization sees only the rates it pays or receives. Public tracking links expose stop status and ETA only. Platform administrators (the Operator) can access organization data to operate and support the Service.

Third parties

Data is processed by the infrastructure the Operator uses to host the Service (servers, database, file storage, email delivery). If your organization enables AI extraction, the specific document you submit is sent to the configured AI provider (for example Anthropic or OpenAI) under that provider’s API terms; those providers do not train on API data by default. Google Fonts may be loaded for the display font you choose. Optional map services (for example Mapbox) receive addresses for geocoding and mileage.

Retention and deletion

Organization records are retained while the organization is active because they form the business record of the loads it moved. Uploaded documents are stored in the Operator’s file storage and can be deleted by users with the appropriate role. You can change or delete your profile data in Settings; to delete your account or an organization entirely, contact the Operator. Audit logs and backups may persist for a limited period after deletion.

Security

Passwords are hashed with bcrypt; sessions use sealed, HTTP-only cookies; API keys stored for AI providers are encrypted at rest; file downloads re-check access on every request. No system is perfectly secure — please use a strong password and revoke API tokens and devices you no longer use.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, or to object to certain processing. Requests can be made to the Operator of this installation. Where an organization controls the data (for example driver records entered by an employer), we will refer your request to that organization.

Changes

We may update this policy; the version date above will change and material changes will be announced in the Service.