Legal

Data Processing Addendum

Effective date: July 7, 2026

This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the Flutter Freight Terms of Service (the “Agreement”) between Flutter Freight LLC (“Flutter Freight,” “we,” or “us”) and the customer that accepts the Agreement (“Customer,” “you”). It governs our processing of personal information about third parties — such as the names and physical addresses of consignees, shippers, and bill‑to parties — that you upload to, or generate within, the Flutter Freight platform (the “Service”). If there is a conflict between this DPA and the rest of the Agreement regarding the processing of such personal information, this DPA controls.

1. Definitions

  • “CCPA” means the California Consumer Privacy Act of 2018 (Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act, and its implementing regulations (Cal. Code Regs. tit. 11, § 7000 et seq.).
  • “Applicable Privacy Law” means all U.S. federal and state privacy and data-protection laws that apply to our processing of Customer Personal Information, including the CCPA.
  • “Customer Personal Information” means personal information, as defined by Applicable Privacy Law, that Flutter Freight processes on Customer’s behalf under the Agreement — including consignee, shipper, and bill‑to names, physical addresses, contact details, and the shipment records you submit or generate.
  • “Business,” “Service Provider,” “Sell,” “Share,” “Consumer,” “Process/Processing,” and “Personal Information” have the meanings given in the CCPA.
  • “Subprocessor” means a third party we engage to process Customer Personal Information on our behalf.

2. Roles of the Parties

For Customer Personal Information, Customer is the Business (and, where a controller/processor framework applies, the controller), and Flutter Freight is the Service Provider (and, where applicable, the processor). We process Customer Personal Information only on Customer’s documented instructions; the Agreement, this DPA, and your configuration and use of the Service constitute those instructions.

The carriers you select are not our Service Providers or Subprocessors. When you direct us to obtain a rate, generate documents, or book a shipment, and we transmit the necessary shipment details (including consignee and bill‑to names and addresses) to your selected carrier, that carrier receives the information as a separate, independent business/controller and processes it for its own transportation, tariff, and legal-compliance purposes under its own agreement with you.

3. Scope and Purpose Limitation

We will process Customer Personal Information only for the following limited and specified business purposes, and for no other purpose:

  • Obtaining multi-carrier rate quotes for the shipments you create;
  • Generating bills of lading, shipping labels, and related shipping documents;
  • Booking shipments with, and transmitting the necessary shipment details to, the carriers you select, at your direction;
  • Validating and completing typed addresses through browser-side geocoding;
  • Storing and displaying your shipment records within your account;
  • Providing support, securing the Service, preventing fraud and abuse, debugging, error-logging, and maintaining and improving the Service; and
  • Complying with our legal obligations.

We will not use Customer Personal Information to train machine-learning or artificial-intelligence models for our own purposes.

4. CCPA Service-Provider Commitments

Flutter Freight certifies that it understands the restrictions in this Section 4 and will comply with them. With respect to Customer Personal Information, we will not:

  • Sell or share it;
  • Retain, use, or disclose it for any purpose other than the specified business purposes in Section 3, including any commercial purpose;
  • Retain, use, or disclose it outside the direct business relationship between Flutter Freight and Customer; or
  • Combine it with personal information we receive from, or on behalf of, any other person, or that we collect from our own interactions with consumers, except as expressly permitted by the CCPA.

We will:

  • Comply with all applicable CCPA obligations and provide the same level of privacy protection for Customer Personal Information as the CCPA requires of a Business;
  • Notify Customer promptly after we determine that we can no longer meet our obligations under the CCPA; and
  • Grant Customer the right to take reasonable and appropriate steps to help ensure we use Customer Personal Information consistent with Customer's CCPA obligations, and to stop and remediate any unauthorized use.

5. Security Measures

We maintain technical and organizational measures designed to protect Customer Personal Information, including:

  • Encryption in transit (TLS), and encryption at rest (AES-256-GCM) of sensitive credential fields, including connected carrier API keys, tokens, and account passwords;
  • Tenant isolation so each organization can access only its own data;
  • Role-based access controls and least-privilege access for personnel;
  • Hashed account passwords, and access logging and monitoring;
  • Confidentiality obligations for personnel with access to Customer Personal Information; and
  • Security due diligence on Subprocessors.

6. Subprocessors and Carriers

We engage the following Subprocessors to help provide the Service. We impose data-protection obligations on each Subprocessor that are at least as protective as this DPA, and we remain responsible for their performance of those obligations.

  • Supabase, Inc. — database hosting and storage (United States);
  • Vercel Inc. — application hosting (United States);
  • Mapbox, Inc. — browser-side geocoding of typed addresses (United States);
  • Microsoft Corporation (Microsoft 365) — email and productivity (United States);
  • Resend, Inc. — transactional email (United States); and
  • Stripe, Inc. — payment processing (applies only once paid billing is enabled; Stripe processes Customer's own billing information, not third-party consignee/bill-to data).

As explained in Section 2, the carriers you select are recipients that act as independent businesses/controllers and are not Subprocessors.

7. Subprocessor Change Notice

We keep the current Subprocessor list here and in our Privacy Policy. Before we add or replace a Subprocessor that processes Customer Personal Information, we will give at least 30 days’ notice by email or in‑app. You may object on reasonable data-protection grounds within the notice period; we will work with you in good faith to address the concern, and if we cannot, you may terminate the affected part of the Service.

8. Assistance with Consumer and Data-Subject Requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures in responding to verified consumer requests to know or access, delete, correct, or opt out of the processing of Customer Personal Information. Where the Service provides self-serve tools (for example, editing or deleting shipment records and addresses), you may use those directly; otherwise, we will act on your documented instructions within a reasonable time. We will not respond directly to a third-party data subject except to refer them to you, unless legally required to respond.

9. Security Incident Notification

We will notify you without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Information, and we will provide information reasonably available to us to help you meet your own notification obligations.

10. Deletion or Return on Termination

On termination or expiration of the Agreement, or on your written request, we will delete or return Customer Personal Information within 30 days and delete existing copies, except to the extent retention is required by law or permitted by the CCPA for a limited, specified purpose and duration (for example, legal compliance or security). We will certify deletion on request. You may also export or delete your shipment data from within the Service before termination.

11. Data Location

We process Customer Personal Information in the United States. Address geocoding occurs in your browser via Mapbox. We do not currently transfer Customer Personal Information outside the United States.

12. Demonstrating Compliance

We will make available to you information reasonably necessary to demonstrate our compliance with this DPA and, on reasonable prior notice and no more than once per year (absent a security incident or a regulator’s requirement), will allow for reasonable review of that compliance, which we may satisfy by providing documentation of our security and privacy practices.

13. General

This DPA is incorporated into and governed by the Agreement, including its governing-law and jurisdiction terms (the State of Washington; courts located in Yakima County, Washington). Except as amended by this DPA, the Agreement remains in full force. Questions about this DPA can be sent to privacy@flutterfreight.com.

Data Processing Addendum — Flutter Freight