Pre-launch preview — pending final legal review
Privacy Policy
Last Updated: 09/03/2026 · Version 2026-09-03-draft.1
Scope and responsibility
This pre-launch preview describes the data flows implemented in ExpressGo. Companies enter information about their operations, staff and customers and control user access. Contact your company administrator about company-managed records. Final legal identity, privacy contacts and jurisdiction-specific notices must be approved before launch.
Information processed
Account and security information: email, authentication credentials handled through Supabase Auth, verification and MFA/session records, company memberships, roles and account preferences.
Company operations: company identity, drivers and customers entered by the company, contact information, Truck and Equipment records, VINs, serial numbers, plates and private notes where provided; assignments, maintenance and compliance history.
Loads and Routes: pickup, delivery, depot and stop addresses, ticket/reference information, routing coordinates and mileage, operational history, revenue, expenses, planning assumptions and profitability snapshots.
Documents: uploaded route screenshots, maintenance invoices, compliance documents and archived reports where those upload workflows are used. Screenshots can contain customer names, addresses and delivery details.
Billing and audit information: provider customer/subscription references, purchased capacity, subscription status, invoice/payment summaries, security/rate-limit records, and support-session activity and reasons.
Why information is used
Information is used to authenticate accounts, enforce company and role access, run transportation workflows, calculate and review results, provide reports and exports, manage subscriptions, investigate errors and security events, and support authorized users. You should provide only information needed for these purposes.
Service providers and feature-based sharing
Supabase provides the database, authentication and private file storage used by the application. Account verification and recovery messages use the configured Supabase Auth email-delivery service; the production email provider is not identified in this preview.
Stripe hosts payment checkout and subscription management. ExpressGo stores subscription and billing metadata and reads invoice summaries and links; it does not store raw payment-card numbers or security codes. Payment details are entered on Stripe-hosted pages.
Trimble / PC*Miler receives addresses for geocoding and locations and supplied Truck dimensions/weight for requested routes. An optional Google Routes integration can process locations when configured. Route calculation is requested explicitly, rather than geocoding each typed character.
When you request AI screenshot extraction, ExpressGo sends the submitted image content to OpenAI to extract route information. Images may contain names, addresses and ticket details. Review results and avoid submitting unnecessary personal information. This processing is not required for manual route entry.
Map tiles load directly from MapTiler in production, which receives network information such as IP address and tile requests corresponding to the viewed area. Local development may use public OpenStreetMap tiles as a fallback.
Hosting and email delivery also involve the providers configured for deployment. This preview does not claim particular provider retention, training, residency or transfer practices; deployment contracts and notices must be verified before launch.
Company access and support
Company membership and roles limit access. Financial and private Truck/Equipment details are restricted to permitted Admin/Manager workflows. Support sessions are time-limited and audited and do not automatically receive company financial, billing or sensitive document access. Company administrators can manage members; do not share individual login credentials.
Cookies, browser processing and network data
Cookies support authentication, verification, recovery and trial-plan selection. The public calculator computes its inputs in your browser and does not save them as company Loads. Visiting a page still creates ordinary network requests. Maps request tiles when displayed. This preview does not assert that hosting or third-party services collect no technical logs or use no cookies.
Retention, corrections and deletion
Operational and financial history, corrections, snapshots and audit records can remain after a record is deactivated or a subscription ends. Canceling a subscription does not erase company data. After trial or paid access expires, existing records remain readable/exportable within role permissions; this is not a promise of indefinite storage.
No fixed retention or deletion deadline is established in this preview. Requests must account for company authority, financial/history integrity, backups, security records and applicable legal obligations. Contact your company administrator for corrections or exports; the public privacy-request process must be finalized before launch.
Security and your choices
The architecture uses authenticated access, company-scoped database policies, role-restricted private fields, private storage and short-lived authorized download links. These controls do not guarantee that every incident can be prevented. Protect your credentials and avoid uploading unrelated sensitive data.
Available access, correction, deletion or other rights depend on applicable law and the company’s role in managing the data. This preview makes no claim of certification or compliance with a particular privacy regime. It is a business service, not a service intended for children.
Updates and contact
The version and last-updated date identify this notice. Material practice changes require review and appropriate notice before launch or rollout.
For company account or data requests, contact your company administrator. ExpressGo’s public legal contact details will be published before launch.