detentioniq

Legal

Privacy Policy

What detentioniq collects from your ELD, your load documents, and your messaging — why we hold it, who else touches it, and how long it stays.

Last updated: August 23, 2026

Pending legal review

This policy accurately describes how the product works today and was written by the team that built it. We deliberately claim no security certifications here — see the security section. Questions or corrections: support@detentioniq.com.

  1. 1.Who this policy covers

    detentioniq (“detentioniq,” “we,” “us”) provides software that motor carriers and their dispatch teams use to detect driver detention, assemble supporting evidence, and bill and track accessorial charges. This policy describes how we handle information across the detentioniq website, the detentioniq application, and the SMS and email messages we send on a carrier's behalf.

    We are a business-to-business service. Most of the information we process is submitted by, or generated on behalf of, a carrier that has an account with us (the “customer”). For that information we act as a service provider or processor: we handle it on the customer's instructions and for the purposes described below, not for our own independent purposes. If you are a driver, dispatcher, shipper contact, or broker contact and your information reached us through a carrier, that carrier decides what data is sent to us and how long its account keeps it.

    The service is not directed to children and is not intended for personal, family, or household use.

  2. 2.Information we collect

    Account and business contact information. Name, work email address, work phone number, role, company name, and motor carrier identifiers such as USDOT or MC number. These are entered by the carrier customer — by the person who opens the account, or by a workspace administrator who invites a colleague. Passwords are handled by our authentication provider and stored as hashes, never in readable form.

    Telematics and vehicle data. When a customer connects an ELD or GPS provider, we ingest the records that provider exposes for that customer's fleet, under that customer's own authorization with the provider. Depending on the provider and configuration, this can include:

    • Vehicle, tractor, trailer, and asset identifiers
    • GPS coordinates with timestamps, including precise location while a vehicle is at or near a facility
    • Ignition, engine, movement, odometer, and similar vehicle status events
    • Hours-of-service and duty-status events, and the driver identifier the ELD associates with them
    • Geofence arrival and departure events derived from the above

    Driver-shared location. Separately from ELD ingestion, we may text a driver a location link. A driver's position is captured only when the driver opens that link and chooses to share it from their device. Each link carries its own single-purpose token tied to one location request, and the token expires — a link stops working 72 hours after it is created, and can be revoked before then. Declining, ignoring, or closing the link shares nothing.

    Operational business records. Load and shipment details, stop and facility information, appointment and arrival times, rate confirmations, bills of lading, proofs of delivery, lumper and scale receipts, invoices, accessorial charges, and the shipper, broker, and consignee identifiers attached to them. Where a customer connects a mailbox, we ingest the messages and attachments in scope for that connection so load documents can be matched to trips.

    Documents and evidence. Files that a customer, its staff, or its drivers upload or forward to us, together with the text we extract from those files so they can be searched and attached to a detention event.

    Messaging data. The content, sender and recipient phone numbers or email addresses, timestamps, and delivery status of SMS and email we send or receive on a customer's behalf, including replies from drivers. We also keep SMS consent and opt-out records: which numbers have replied STOP, when, and the resulting suppression, so a number that opts out is not texted again. We use automated classification on inbound driver replies so a reply can be routed to the right load or event.

    Website and product usage data. Server and application logs, IP address, browser and device characteristics, features used, and error diagnostics. If you submit the contact form on our website, we receive what you type into it.

  3. 3.How we use information

    • Detecting dwell and detention events from telematics and matching them to loads
    • Assembling the evidence timeline behind an event and storing the supporting documents
    • Generating detention and accessorial invoices and tracking billed-versus-paid outcomes
    • Producing facility and customer scorecards for the carrier whose data it is
    • Sending operational SMS and email to drivers, dispatchers, and the contacts a customer designates
    • Maintaining SMS opt-out suppression so a driver who replied STOP stops receiving messages
    • Providing support, troubleshooting, and account administration
    • Billing and collections for our own subscription
    • Securing the service: authentication, abuse and fraud prevention, audit logging, and incident response
    • Meeting legal obligations and establishing, exercising, or defending legal claims
    • Maintaining and improving the service, including debugging detection accuracy against real events

    We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use driver location data for advertising or for any purpose beyond delivering the service to the carrier that supplied it. We may produce aggregated or de-identified statistics — for example, typical dwell times at a facility — provided the output cannot reasonably be used to identify an individual, a specific vehicle, or an individual customer's confidential data, and we will not attempt to re-identify it.

  4. 4.SMS and text messaging

    Our SMS program is transactional and operational. It exists to move a specific load or a specific account forward, and it sends exactly two kinds of message:

    • Driver location links — a text asking a driver to share their current location for a load they are running, so their carrier can evidence arrival, departure, and detention time. The driver taps the link and decides whether to share.
    • Team account invitations — a text containing a sign-in link, sent when a workspace administrator at a carrier invites a colleague to that carrier's detentioniq account.

    We do not send marketing, promotional, advertising, or political text messages of any kind, and we do not operate a consumer sign-up or keyword-join campaign.

    How we get your number. Mobile numbers are entered into the product by our customer — the carrier or dispatcher you drive for, or the administrator of your company's workspace — in the course of dispatching a load or adding a teammate. detentioniq does not buy, rent, scrape, or otherwise acquire phone numbers, and one customer's numbers are never used to message on behalf of another.

    Message frequency varies. Message and data rates may apply.

    Reply STOP to any message to cancel and stop receiving texts from us; you will receive a single confirmation and no further messages. Reply HELP for help, or email support@detentioniq.com. Carriers are not liable for delayed or undelivered messages.

    No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.

    Mobile numbers and SMS consent and opt-out records are disclosed only to the messaging providers that transmit the message for us — Twilio, and the mobile carriers that terminate it — and only so the message you or your employer asked for is delivered. They are never sold, never used for our own marketing, and never disclosed to anyone for their marketing.

    The corresponding SMS Terms, including the full program disclosures, are in our Terms of Service at https://www.detentioniq.com/terms.

  5. 5.Driver location and telematics data

    Telematics records reach us because a carrier connected its own ELD or GPS account and directed us to read it. The carrier, not detentioniq, decides which vehicles and drivers are in scope. The carrier is responsible for giving its drivers whatever notice, and obtaining whatever consent or bargaining-unit agreement, applicable law or its own agreements require for that monitoring. We process location data only to detect, evidence, and bill detention and related accessorials for that carrier.

    Location shared from a link is different: nothing is captured unless the driver opens the link and shares. The link's token is scoped to that one location request and expires 72 hours after it is issued, so an old text cannot be used to locate a driver later.

    Precise location data is retained on the schedule in the retention section below, because detention disputes are frequently raised months after the event and the location trail is the evidence that resolves them.

    If you are a driver and want to know what is held about you, start with your carrier's dispatch or safety team — they control the account. We will help a customer respond to such a request, and we will respond directly where the law requires us to.

  6. 6.Cookies and similar technologies

    The application uses cookies that are strictly necessary to run it: session and authentication cookies, and cookies supporting security controls such as request verification. Without them you cannot stay signed in.

    We do not run third-party advertising networks, ad-retargeting pixels, or cross-site tracking cookies on this website or in the application. Any usage measurement we perform is first-party and is used to operate and improve the service.

  7. 7.How we share information

    We share information with service providers (subprocessors) that run parts of the service under contract, and only as needed for them to perform that function. As of the date above, these are:

    • Vercel — application and website hosting, edge delivery, and request logs (United States)
    • Supabase — managed Postgres database, authentication, authentication email, and document storage (United States)
    • Inngest — background job orchestration for ingestion, detection, and messaging workflows
    • Twilio — SMS delivery, inbound message receipt, opt-out handling, and 10DLC campaign registration
    • Resend — email delivery for our website contact form and transactional email
    • Reducto — parsing and text extraction from uploaded documents such as rate confirmations and receipts
    • Anthropic — model-based classification of inbound driver SMS replies so they reach the right load; content sent for classification is not used to train third-party models
    • Microsoft — the Microsoft Graph API, used only where a customer connects a Microsoft 365 mailbox so load email and attachments can be ingested
    • The ELD, GPS, or TMS provider a customer connects (for example Samsara, Motive, or Alvys) — the source of telematics and load data, accessed under that customer's own credentials or authorization

    None of these providers is permitted to use what we send them for their own marketing or promotional purposes, and none receives mobile opt-in or consent data for any purpose other than delivering the messages described above.

    We also disclose information at a customer's direction — including when the customer sends an invoice, evidence packet, or message to its own shipper, broker, or factoring partner through the service; to professional advisors such as auditors, accountants, and lawyers under confidentiality obligations; when required by law, subpoena, or other valid legal process, or to protect the rights, safety, or property of detentioniq, our customers, or the public; and in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor commitments consistent with this policy and will notify affected customers.

    This list may change as the service evolves, and we will update this page when it does. Customers whose written agreement requires advance notice of subprocessor changes will receive it on the terms of that agreement.

  8. 8.How long we keep it

    The periods below are our operating defaults. A customer's written agreement may set different periods, and a customer can ask us to shorten or extend them for its own account.

    • Detention events, telematics-derived timelines, and the underlying location and duty-status records: for the life of the account and 24 months after the event, because detention disputes, audits, and collections routinely run past a year
    • Documents and evidence files: for the life of the account, plus 90 days after account closure to allow export
    • SMS and email records, including message content and delivery status: 18 months
    • SMS opt-out records: kept indefinitely, because forgetting that a number replied STOP would mean texting it again
    • Account, billing, and invoice records: as long as needed for tax, accounting, and legal-claim purposes, typically 7 years
    • Application and security logs: 12 months
    • Encrypted backups: a rolling window, deleted within 35 days of the backup date

    When a retention period ends we delete the data or de-identify it so it can no longer be tied to an individual, a vehicle, or a customer.

  9. 9.Security

    We encrypt data in transit using TLS and rely on our infrastructure providers' encryption at rest. Access to customer data in the application is enforced per tenant at the database layer, so one carrier's account cannot read another's. Internal access to production data is limited to the people who need it to operate or support the service, requires multi-factor authentication, and is logged.

    We do not currently hold, and this page does not claim, a SOC 2 report, ISO 27001 certification, HIPAA compliance, PCI DSS attestation, or any other third-party security certification. We will say so plainly here if that changes. If your procurement process requires a specific attestation, ask us before assuming one exists.

    No system is perfectly secure. If we become aware of a breach affecting your information, we will notify affected customers and, where required, regulators and individuals, within the timeframes the applicable law sets.

  10. 10.Your rights and choices

    Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, obtain a portable copy, or opt out of certain processing. Because we do not sell personal information and do not use it for cross-context behavioral advertising, there is nothing to opt out of in those categories. We will not discriminate against you for exercising a right.

    If your information reached us through a carrier's account, that carrier controls it. Send your request to the carrier, or send it to us and we will route it to them and assist with the response. If you are one of our own account holders, or you contacted us directly, write to the address in the contact section and we will verify your identity before acting.

    An authorized agent may submit a request on your behalf where the law allows, with proof of authorization. If we decline a request we will tell you why, and how to appeal.

  11. 11.Where data is processed

    detentioniq is operated from the United States, and the service and its subprocessors store and process data in the United States. If you access the service from outside the United States, your information is transferred to and processed there.

    We do not currently offer regional data residency, and we do not claim any specific cross-border transfer mechanism, adequacy decision, or certification for transfers into the United States. If your organization requires one, raise it with us before sending data to the service.

  12. 12.Changes to this policy

    We will update this page when our practices change and revise the “last updated” date at the top. For changes that materially reduce your rights or materially expand how we use information, we will give account holders advance notice by email or in the application before the change takes effect.

  13. 13.Contact us

    Questions about this policy, a privacy request, a message you received, or a security concern: email support@detentioniq.com. We aim to acknowledge privacy requests within 10 business days and to resolve them within the period the applicable law allows.

This document was prepared without legal counsel review.