What we collect and what we do with it. Last updated 12 May 2026.
The Short Version
We collect only what we need to run the product: your email, your name, and the shipment data you upload. We use it to show you analysis of your own freight portfolio.
We don't sell your data. We don't share it with advertisers. We don't train AI models on it. We don't use third-party analytics or tracking pixels. Email [email protected] and we'll delete your account and all data within 30 days.
What We Collect
Account info
Email address, name, and a hashed password. Used to identify you across sessions and to send you operational emails (password resets, billing if/when we charge).
Uploaded CSV data
Shipment records you upload — origin, destination, dates, revenue, cost, etc. Stored on our server (Postgres) and processed to compute the dashboard you see.
Geocoded addresses
As we resolve origin/destination addresses to coordinates, we cache the results in a shared geocode table so future uploads are faster. The cache contains addresses; it doesn't link those addresses to specific accounts.
Basic request logs
Standard web server logs: timestamps, IP addresses, paths visited. Used for security/abuse detection. Rotated out after 30 days.
What We Don't Collect
No third-party analytics
No Google Analytics, no Segment, no Mixpanel, no Posthog, no Hotjar. The only telemetry is server-side request logs we run ourselves.
No ad-network tracking
No pixels, no cookies sold to advertisers. The cookies we set are first-party session cookies used only to keep you signed in.
No AI training on your data
Your CSV data is not used to train any model, ours or anyone else's. If we ever offer an opt-in 'help improve the product' option in the future, it'll be opt-in and clearly disclosed.
How We Use It
Show you your data
Compute the portfolio diagnosis, synergy candidates, and lane analytics that appear on your dashboard.
Operate the service
Authenticate you on sign-in, route uploads through the ETL pipeline, store backups for disaster recovery.
Talk to you
Send transactional emails (password resets, important service notices). We don't run a marketing newsletter.
Security and abuse prevention
Use logs and rate limits to detect compromise attempts, brute force, scraping. Anonymized data may be used to improve security signals.
Who We Share It With
We share data only with infrastructure providers strictly needed to operate the service. As of this writing:
- Cloudflare — DNS, TLS, DDoS protection. Sees request metadata; does not see decrypted application data once the tunnel terminates.
- Hosting hardware — physically located in the United States, operated by Nap Factory LLC.
- OpenStreetMap Nominatim (geocoding) — receives address strings (city, state, ZIP, optionally street). Self-hosted; addresses never leave our network unless you explicitly enable external Nominatim via the admin settings.
We do not sell or rent your data to anyone for any purpose. We'll only disclose data in response to a valid legal process, and where possible we'll notify you first.
Your Rights
Access and export
Email us and we'll send you a copy of all data we have on you, in JSON or CSV form.
Deletion
Email us and we'll delete your account and all associated data within 30 days. We may keep minimal records (e.g. that an account with your email previously existed) to enforce abuse policies.
Correction
If anything we have on you is wrong, tell us and we'll fix it.
Complaint
If you think we've mishandled your data, email us first. If you're in the EU/UK, you can also file a complaint with your local data protection authority.
Contact
Privacy questions or requests: [email protected].
Nap Factory LLC — data controller for CarryNet.