CarrierClear

Privacy Notice

Last updated: 2026-06-21

Draft for review — not yet reviewed by an attorney.

This notice explains what personal information CarrierClear collects and how we use it. It applies to everyone who uses CarrierClear, including business contacts (under California law, business-contact information has the same privacy rights as any other personal information).

What we collect

Account information for paid users — the name, email, and company you provide (identifiers and commercial information). Billing is handled by Stripe; card numbers are never stored on our servers.

Usage data — the carriers you look up, features you use, and records you generate (commercial information / internet activity).

Technical data — standard server logs, a hashed form of your IP address, and privacy-friendly, cookieless usage analytics about how pages are viewed (internet activity). Free-tier lookups are counted by a hashed IP address, without an account.

Marketing email address — if you voluntarily submit your email address to receive a discount code or similar offer, we store that address (together with a hashed form of your IP address and the offer it relates to) and use it to send you the code and occasional messages about CarrierClear. You are never required to provide it in order to use the free lookup tool. Every marketing message includes a one-click unsubscribe link, and unsubscribing takes effect immediately; it does not affect account, billing, or carrier-monitoring email, which are separate and necessary to provide the service.

We do not intentionally collect sensitive personal information, and the service is not directed to anyone under 18.

Where it comes from

Directly from you (account details, inputs, attestations); automatically from your use of the service (usage and technical data); from our service providers (for example, billing status from Stripe); and from public data sources we surface, namely the Federal Motor Carrier Safety Administration / U.S. Department of Transportation (carrier records) and the U.S. Treasury Office of Foreign Assets Control (the publicly published Specially Designated Nationals list, used for sanctions screening). These public sources concern commercial carriers and listed parties, not you.

How we use it

To provide and operate the service, generate your records, send alerts you request, bill your subscription, prevent abuse, maintain and improve the service (including creating aggregated, de-identified data as described below), and comply with law.

Hashed IP addresses

We hash IP addresses used for free-tier rate limiting and abuse prevention. Hashing reduces — but does not by itself eliminate — the possibility that data could be linked to a person, so we treat a hashed IP as personal information and keep it only as needed for those purposes.

Usage analytics

We use Vercel Web Analytics to understand how the site is used in aggregate — for example, which pages are visited and overall traffic patterns — so we can improve the product. It is designed to be privacy-friendly: it is cookieless, does not use persistent device identifiers, does not track you across other sites, and derives page-view counts without storing data that identifies you. Any IP-derived information is hashed by the provider and not retained in a form tied to you. Vercel acts as our processor for this analytics and may use the data only to provide the analytics service to us.

Because we do not track users across third-party websites over time, we do not respond to browser “Do Not Track” signals. We do not sell or share your personal information, and we honor the Global Privacy Control (GPC) signal as a valid opt-out where it applies.

Service providers & sub-processors

We share personal information with service providers who run the product under contract and may use it only to provide their service to us. As of the date above, our sub-processors are: Supabase (database, authentication, and hosting of application data — United States); Stripe (payment processing — United States); Resend (email delivery — transactional messages such as account confirmation, password reset, alerts and digests, and any marketing message you opted into — United States); Vercel (application hosting, content delivery, and privacy-friendly usage analytics — United States); Twilio (phone-line analysis used to generate paid-tier carrier risk signals — United States); and Smarty (address validation used to generate paid-tier carrier risk signals — United States). Twilio and Smarty receive a carrier's public FMCSA contact information (such as a business phone number or physical address), not your account or personal information.

We require these providers, by contract, to handle personal information only on our instructions and to protect it (the CCPA “service provider” terms). We will update this list when our sub-processors change. We may also disclose information to authorities where legally required, and to a successor in connection with a merger, acquisition, or sale of the business. Business customers who need CCPA service-provider terms or a data processing addendum can request them by contacting us.

We do not sell your personal information

We do not sell or share your personal information for cross-context behavioral advertising, and we do not sell or disclose which specific carriers you personally looked up in any identifiable way. Anything we license or sell is aggregated and de-identified only, as described below.

Aggregated & de-identified data

To build this aggregated intelligence we keep a record of carrier lookups and periodic carrier-status snapshots over time (for example, the carrier looked up, its public FMCSA status on a given date, and how that status changes). This history is keyed to carriers — which are commercial businesses, not consumers — and lets us produce carrier-level trends that public FMCSA data, which shows only the current state, does not capture. When we derive statistics from this for any aggregated or licensed product, we use de-identification techniques such as aggregation and k-anonymity (only reporting figures across a large enough group of users or carriers that no individual user can be singled out), so the output describes groups, not any identifiable person.

We may create aggregated and de-identified information derived from how the service is used — for example, carrier-level risk and demand statistics and industry trends. This information relates to groups or categories of users and carriers and is not linked, and cannot reasonably be linked, to any individual consumer or household.

We take reasonable technical and organizational measures to ensure this information cannot be re-associated with an individual, and we publicly commit to maintain and use it only in aggregated or de-identified form and to NOT attempt to re-identify it, except solely to test whether our de-identification meets legal requirements. We contractually require any recipient of such information to comply with the same restrictions — including the prohibition on re-identification — and to impose those restrictions on any further recipient.

What we may license or sell is limited to this aggregated, carrier-level, de-identified intelligence. We will NEVER sell or expose the raw lookup or monitoring records, anything tied to your account or IP address, or which specific carriers a particular customer looked up. Because aggregated and de-identified information is not “personal information” and is subject to these commitments, its use, sharing, license, or sale is not a “sale” or “sharing” of personal information under laws such as the California CCPA/CPRA (Cal. Civ. Code §1798.140(b), (m), (v); §1798.145(a)(1)(F)).

Data products & data-broker status

Because the data products we may offer consist solely of aggregated and de-identified information (not the personal information of consumers with whom we have no direct relationship), we do not believe CarrierClear is a “data broker” required to register under California's Delete Act or comparable state laws. If we ever sell information that constitutes personal information of such consumers, we will register as required, honor opt-out and deletion rights (including through California's DROP platform), and update this notice.

Cookies

We use essential cookies to keep you signed in and operate the site. We do not use advertising cookies. For product analytics we use Vercel Web Analytics, which is privacy-friendly and cookieless — it does not set advertising or tracking cookies and does not build a cross-site profile of you. Free-tier rate limiting is handled by a hashed IP address rather than a cookie.

How long we keep it

Account information: while your account is active and for a reasonable period afterward to meet legal, tax, and record-keeping needs (some billing records are retained longer where law requires).

Usage and lookup records: while needed to provide the service and your saved history.

Hashed IP addresses (free tier): only as long as needed for rate limiting and abuse prevention.

Aggregated/de-identified data: may be retained indefinitely, because it no longer identifies you.

Security

We use reasonable administrative and technical safeguards to protect personal information, including access controls and database row-level security so each account can reach only its own data.

Your California privacy rights

Depending on where you live (for example, California under the CCPA/CPRA), you may have the right to know and access the personal information we hold about you, to correct it, to delete it, to opt out of any sale or sharing of personal information, to data portability, and to not be discriminated against for exercising these rights.

To exercise a right, email us at the address below. Because CarrierClear operates exclusively online and has a direct relationship with you, email is our designated request method. We may need to verify your identity before acting on a request.

Changes to this notice

We may update this notice and will post the new version with an updated “last updated” date above.

Contact

Privacy questions: info@getcarrierclear.com.