Privacy Policy

Last updated: February 28, 2026

1. Introduction

TrackLTL ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our white-label LTL freight tracking platform ("Service").

2. Information We Collect

Account Information (Merchants)

  • Company name, email address, and password
  • Brand assets (logo, accent color)
  • Carrier API credentials (encrypted at rest)
  • Shopify store domain and access token (encrypted at rest)
  • Contact information (support email, phone number)
  • Billing information (processed by Stripe — we do not store card numbers)

Tracking Page Visitors (End Users)

  • PRO numbers, order numbers, or invoice numbers entered for tracking lookups
  • Basic analytics data (page views, browser type, country) via Cloudflare Web Analytics — no cookies, no personal identifiers

Automatically Collected

  • IP address (for rate limiting and security)
  • Browser user agent (for compatibility)
  • Timestamps of requests

3. How We Use Your Information

  • Providing the Service: Authenticating accounts, rendering branded tracking pages, querying carrier APIs
  • Billing: Processing subscription payments through Stripe
  • Communication: Sending transactional emails (password resets, billing receipts, service alerts)
  • Security: Detecting and preventing unauthorized access, fraud, and abuse
  • Improvement: Understanding how the Service is used to improve features and performance

4. Third-Party Services

We share data with the following third-party services as necessary to operate:

Stripe

Payment processing. Receives billing information. Stripe Privacy Policy

Cloudflare

Infrastructure, CDN, DNS, analytics. Processes requests. Cloudflare Privacy Policy

LTL Carriers (TForce, Estes, XPO, SAIA, Old Dominion)

Tracking data retrieval. We send PRO numbers to query shipment status. Carrier terms apply.

Shopify

Order lookup integration (when connected by merchant). We query order data using merchant-provided credentials.

5. Data Storage and Security

Your data is stored on Cloudflare's global edge network using Cloudflare D1 (database) and R2 (file storage). All data is transmitted over HTTPS.

  • Passwords are hashed using bcrypt (never stored in plain text)
  • Carrier API credentials and Shopify tokens are encrypted at rest using AES-256-GCM
  • Authentication uses signed JWT tokens transmitted via secure HTTP-only cookies

6. Cookies

We use minimal cookies:

  • Authentication cookie: A secure, HTTP-only session cookie for logged-in merchants. Required for the Service to function.
  • Cloudflare security cookies: Used by Cloudflare for bot protection and security.

We use Cloudflare Web Analytics for tracking page visitor analytics, which does not use cookies and does not collect personally identifiable information.

7. Data Retention

  • Active accounts: Data is retained for the duration of your subscription
  • Cancelled accounts: Data is retained for 30 days after cancellation, then permanently deleted
  • Tracking lookup logs: Retained for 90 days for analytics and debugging
  • You may request immediate deletion of your data at any time by contacting us

8. Your Rights

You have the right to:

  • Access: Request a copy of the data we hold about you
  • Correction: Update or correct inaccurate data
  • Deletion: Request deletion of your data
  • Export: Request a machine-readable export of your data
  • Objection: Object to certain processing of your data

To exercise any of these rights, contact us at privacy@trackltl.com.

9. California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete your data, and the right to opt out of the sale of personal information. We do not sell personal information.

10. International Users (GDPR)

If you are located in the European Economic Area (EEA), we process your personal data on the basis of legitimate interest (providing the Service you signed up for) and contractual necessity. You have the right to lodge a complaint with your local data protection authority.

11. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect.

13. Contact

For privacy-related inquiries:

Email: privacy@trackltl.com

General: hello@trackltl.com