Legal
Privacy Policy
What detentioniq collects from your ELD, your load documents, and your messaging — why we hold it, who else touches it, and how long it stays.
Last updated: July 27, 2026
Pending legal review
This policy accurately describes how the product works today and was written by the team that built it. It has not yet been reviewed by outside counsel, so treat it as a good-faith operational disclosure rather than settled legal advice. We deliberately claim no security certifications here — see the security section. Questions or corrections: support@detentioniq.com.
1.Who this policy covers
detentioniq (“detentioniq,” “we,” “us”) provides software that motor carriers and their dispatch teams use to detect driver detention, assemble supporting evidence, and bill and track accessorial charges. This policy describes how we handle information across the detentioniq website, the detentioniq application, and the SMS and email messages we send on a carrier's behalf.
We are a business-to-business service. Most of the information we process is submitted by, or generated on behalf of, a carrier that has an account with us (the “customer”). For that information we act as a service provider or processor: we handle it on the customer's instructions and for the purposes described below, not for our own independent purposes. If you are a driver, dispatcher, shipper contact, or broker contact and your information reached us through a carrier, that carrier decides what data is sent to us and how long its account keeps it.
The service is not directed to children and is not intended for personal, family, or household use.
2.Information we collect
Account and business contact information. Name, work email address, work phone number, role, company name, and motor carrier identifiers such as USDOT or MC number. Passwords are handled by our authentication provider and stored as hashes, never in readable form.
Telematics and vehicle data. When a customer connects an ELD or GPS provider, we ingest the records that provider exposes for that customer's fleet. Depending on the provider and configuration, this can include:
- Vehicle, tractor, trailer, and asset identifiers
- GPS coordinates with timestamps, including precise location while a vehicle is at or near a facility
- Ignition, engine, movement, odometer, and similar vehicle status events
- Hours-of-service and duty-status events, and the driver identifier the ELD associates with them
- Geofence arrival and departure events derived from the above
Operational business records. Load and shipment details, stop and facility information, appointment and arrival times, rate confirmations, bills of lading, proofs of delivery, lumper and scale receipts, invoices, accessorial charges, and the shipper, broker, and consignee identifiers attached to them. Where a customer connects a mailbox, we ingest the messages and attachments in scope for that connection so load documents can be matched to trips.
Documents and evidence. Files that a customer, its staff, or its drivers upload or forward to us, together with the text we extract from those files so they can be searched and attached to a detention event.
Messaging data. The content, sender and recipient phone numbers or email addresses, timestamps, and delivery status of SMS and email we send or receive on a customer's behalf, including replies from drivers. We use automated classification on inbound driver replies so a reply can be routed to the right load or event.
Website and product usage data. Server and application logs, IP address, browser and device characteristics, features used, and error diagnostics. If you submit the contact form on our website, we receive what you type into it.
3.How we use information
- Detecting dwell and detention events from telematics and matching them to loads
- Assembling the evidence timeline behind an event and storing the supporting documents
- Generating detention and accessorial invoices and tracking billed-versus-paid outcomes
- Producing facility and customer scorecards for the carrier whose data it is
- Sending operational SMS and email to drivers, dispatchers, and the contacts a customer designates
- Providing support, troubleshooting, and account administration
- Billing and collections for our own subscription
- Securing the service: authentication, abuse and fraud prevention, audit logging, and incident response
- Meeting legal obligations and establishing, exercising, or defending legal claims
- Maintaining and improving the service, including debugging detection accuracy against real events
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use driver location data for advertising or for any purpose beyond delivering the service to the carrier that supplied it. We may produce aggregated or de-identified statistics — for example, typical dwell times at a facility — provided the output cannot reasonably be used to identify an individual, a specific vehicle, or an individual customer's confidential data, and we will not attempt to re-identify it.
4.Driver location and telematics data
Telematics records reach us because a carrier connected its own ELD or GPS account and directed us to read it. The carrier, not detentioniq, decides which vehicles and drivers are in scope. The carrier is responsible for giving its drivers whatever notice, and obtaining whatever consent or bargaining-unit agreement, applicable law or its own agreements require for that monitoring. We process location data only to detect, evidence, and bill detention and related accessorials for that carrier.
Precise location data is retained on the schedule in the retention section below, because detention disputes are frequently raised months after the event and the location trail is the evidence that resolves them.
If you are a driver and want to know what is held about you, start with your carrier's dispatch or safety team — they control the account. We will help a customer respond to such a request, and we will respond directly where the law requires us to.
5.SMS messaging
We send operational SMS through Twilio using messaging campaigns registered under the industry 10DLC framework. Messages are transactional and relate to loads, detention events, evidence requests, and account activity. We do not send marketing SMS.
Message frequency varies with load activity. Message and data rates may apply. Reply STOP to any message to opt out and HELP for assistance, or contact us at the address below. Mobile carriers are not liable for delayed or undelivered messages.
Mobile phone numbers and SMS opt-in or consent information are never sold, and are never shared with third parties for their own marketing purposes. They are shared only with the messaging providers listed below, for the sole purpose of delivering the messages you or your carrier asked us to send.
6.Cookies and similar technologies
The application uses cookies that are strictly necessary to run it: session and authentication cookies, and cookies supporting security controls such as request verification. Without them you cannot stay signed in.
We do not run third-party advertising networks, ad-retargeting pixels, or cross-site tracking cookies on this website or in the application. Any usage measurement we perform is first-party and is used to operate and improve the service.
7.How we share information
We share information with service providers (subprocessors) that run parts of the service under contract, and only as needed for them to perform that function. As of the date above, these are:
- Vercel — application hosting, edge delivery, and request logs (United States)
- Supabase — managed Postgres database, authentication, and document storage (United States)
- Inngest — background job orchestration for ingestion, detection, and messaging workflows
- Twilio — SMS delivery, inbound message receipt, and 10DLC campaign registration
- Resend — transactional and website email delivery
- Reducto — parsing and text extraction from uploaded documents such as rate confirmations and receipts
- Anthropic — model-based classification of inbound driver SMS replies so they reach the right load; content sent for classification is not used to train third-party models
- Microsoft — the Microsoft Graph API, used only where a customer connects a Microsoft 365 mailbox so load email and attachments can be ingested
- The ELD or GPS provider a customer connects (for example Samsara or Motive) — the source of telematics data, accessed under that customer's own credentials or authorization
We also disclose information at a customer's direction — including when the customer sends an invoice, evidence packet, or message to its own shipper, broker, or factoring partner through the service; to professional advisors such as auditors, accountants, and lawyers under confidentiality obligations; when required by law, subpoena, or other valid legal process, or to protect the rights, safety, or property of detentioniq, our customers, or the public; and in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor commitments consistent with this policy and will notify affected customers.
This list may change as the service evolves, and we will update this page when it does. Customers whose written agreement requires advance notice of subprocessor changes will receive it on the terms of that agreement.
8.How long we keep it
The periods below are our operating defaults. A customer's written agreement may set different periods, and a customer can ask us to shorten or extend them for its own account.
- Detention events, telematics-derived timelines, and the underlying location and duty-status records: for the life of the account and 24 months after the event, because detention disputes, audits, and collections routinely run past a year
- Documents and evidence files: for the life of the account, plus 90 days after account closure to allow export
- SMS and email records, including message content and delivery status: 18 months
- Account, billing, and invoice records: as long as needed for tax, accounting, and legal-claim purposes, typically 7 years
- Application and security logs: 12 months
- Encrypted backups: a rolling window, deleted within 35 days of the backup date
When a retention period ends we delete the data or de-identify it so it can no longer be tied to an individual, a vehicle, or a customer.
9.Security
We encrypt data in transit using TLS and rely on our infrastructure providers' encryption at rest. Access to customer data in the application is enforced per tenant at the database layer, so one carrier's account cannot read another's. Internal access to production data is limited to the people who need it to operate or support the service, requires multi-factor authentication, and is logged.
We do not currently hold, and this page does not claim, a SOC 2 report, ISO 27001 certification, HIPAA compliance, PCI DSS attestation, or any other third-party security certification. We will say so plainly here if that changes. If your procurement process requires a specific attestation, ask us before assuming one exists.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify affected customers and, where required, regulators and individuals, within the timeframes the applicable law sets.
10.Your rights and choices
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, obtain a portable copy, or opt out of certain processing. Because we do not sell personal information and do not use it for cross-context behavioral advertising, there is nothing to opt out of in those categories. We will not discriminate against you for exercising a right.
If your information reached us through a carrier's account, that carrier controls it. Send your request to the carrier, or send it to us and we will route it to them and assist with the response. If you are one of our own account holders, or you contacted us directly, write to the address in the contact section and we will verify your identity before acting.
An authorized agent may submit a request on your behalf where the law allows, with proof of authorization. If we decline a request we will tell you why, and how to appeal.
11.Where data is processed
detentioniq is operated from the United States, and the service and its subprocessors store and process data in the United States. If you access the service from outside the United States, your information is transferred to and processed there.
We do not currently offer regional data residency, and we do not claim any specific cross-border transfer mechanism, adequacy decision, or certification for transfers into the United States. If your organization requires one, raise it with us before sending data to the service.
12.Changes to this policy
We will update this page when our practices change and revise the “last updated” date at the top. For changes that materially reduce your rights or materially expand how we use information, we will give account holders advance notice by email or in the application before the change takes effect.
13.Contact us
Questions about this policy, a privacy request, or a security concern: email support@detentioniq.com. We aim to acknowledge privacy requests within 10 business days and to resolve them within the period the applicable law allows.