Privacy Policy
Last updated July 6, 2026
This Privacy Policy explains how [Company Legal Name](“we”) processes personal data in connection with eWall TMS(the “Service”).
1. Our role
For personal data about our direct users and account administrators (for example, name, email, and login activity), we act as a controller. For personal data a Carrier submits into the Service about its own drivers, customers, and contacts, the Carrier is the controller and we act as a processoron the Carrier’s behalf — those arrangements are governed by our Data Processing Agreement.
2. Data we process
Account and profile data
- Name and email address;
- a hashed password (we never store passwords in plain text);
- if you enable two-factor authentication, an encrypted authenticator secret and hashed recovery codes;
- sign-in timestamps.
Usage and security data
- IP address and browser user-agent associated with sessions and security events;
- audit log entries recording significant actions (who did what and when) for security and accountability.
Operational data submitted by Carriers
Carriers use the Service to manage their operations, which may include personal data such as:
- Driver data — name, contact details, employee identifier, date of birth, hire/termination dates, and qualification records including CDL number, class, state, and issue/expiry dates, endorsements, restrictions, medical-card expiry, MVR and drug-test dates, and Clearinghouse status;
- Business-contact data — names and contact details of customers, shippers, receivers, and brokers;
- Operational records — loads, stops and addresses, equipment, invoices, and driver settlements;
- Uploaded documents — compliance files (such as licenses and medical cards) stored in cloud object storage; and
- Vehicle location data— where a Carrier connects Motive, GPS positions and related telematics for the Carrier’s vehicles and drivers.
Payment data
When a customer pays an invoice online, payment is processed by Stripe. We receive the payment amount, status, and a payment reference; we do not receive or store full card numbers.
3. How we use data
- to provide, maintain, and secure the Service;
- to authenticate users and prevent fraud and abuse;
- to send transactional communications (invitations, password resets, notifications);
- to provide support and respond to requests; and
- to comply with legal obligations and enforce our terms.
4. Legal bases
Where the GDPR or similar laws apply, we rely on: performance of a contract (to provide the Service); our legitimate interests (to secure and improve the Service); compliance with legal obligations; and consent where required. For operational data processed on a Carrier’s behalf, the Carrier is responsible for establishing the legal basis.
5. Sharing and sub-processors
We do not sell personal data. We share it with service providers that process it on our behalf, under contract and only as needed to run the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Motive (Keep Truckin, Inc.) | ELD / GPS vehicle location & driver data import for live tracking | United States |
| FMCSA QCMobile — U.S. Department of Transportation | Carrier lookup by USDOT/MC number | United States |
| Google Maps Platform (Google LLC) | Address autocomplete and mapping | United States |
| Microsoft Azure Communication Services | Transactional email delivery (invitations, password resets, notifications) | United States / European Union |
| Microsoft Azure Blob Storage | Storage of uploaded compliance documents | United States / European Union |
| Stripe, Inc. | Online invoice payment processing (card data handled entirely by Stripe) | United States |
We may also disclose data where required by law or to protect rights, safety, and the integrity of the Service.
6. International transfers
Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
7. Retention
We retain personal data for as long as an account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period, unless a longer retention is required by law. Carriers control the retention of the operational data they submit.
8. Security
We use technical and organizational measures appropriate to the risk, including password hashing, encryption of authenticator secrets, hashing of session and reset tokens, role-based access control scoped per Carrier, audit logging, and encryption in transit. No method of transmission or storage is completely secure.
9. Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. To exercise these rights, contact us at privacy@example.com. If your data was provided by a Carrier (for example, as one of its drivers), we will refer your request to that Carrier, who is the controller of that data.
10. Children
The Service is intended for business use and is not directed to children.
11. Changes
We may update this Policy; we will revise the “last updated” date and, where appropriate, provide additional notice.
12. Contact
Privacy questions or requests: privacy@example.com.