Legal
Privacy Policy
Effective date: July 7, 2026
This Privacy Policy explains how Flutter Freight LLC (“Flutter Freight,” “we,” or “us”) collects, uses, and protects information when you use the Flutter Freight platform and websites (the “Service”). It applies primarily to the personal information of our account users. Where a business customer uploads personal information about third parties (such as consignee or bill‑to parties), we act as that customer’s service provider, as described in the “How We Share Information” section below and in our Data Processing Addendum. If you are a California resident, please also review the California‑specific sections below.
1. Information We Collect
- Account information — your name, business name, email, an optional phone number, and password. Account login passwords are stored hashed, never in plain text.
- Carrier credentials — the API keys, tokens, account numbers, and carrier account passwords you connect. The sensitive secrets among these — API keys, tokens, and passwords — are encrypted at rest (AES-256-GCM) and are used only to make requests to the carriers on your behalf.
- Shipment data — origin/destination addresses, weights, dimensions, freight classes, quotes, bills of lading, labels, and tracking events you create or retrieve, including the consignee and bill-to details you enter.
- Usage & device data — log data, IP address, browser type, and actions taken in the Service, used to operate, secure, and improve the product.
2. Categories of Personal Information We Collect (California disclosure)
For California residents, this section maps the information we handle to the categories of personal information defined under the California Consumer Privacy Act, as amended by the CPRA (Cal. Civ. Code § 1798.140). For each category we describe the information, where we get it, why we use it, and the categories of recipients we may disclose it to. We collect this information directly from you when you register for and use the Service, automatically from your device and browser as you use the Service, and from the carrier accounts you choose to connect.
Identifiers and California customer‑records information (§ 1798.140(v)(1)(A)–(B)). Examples: your real name, business or company name, postal address, email address, telephone number, account username, a unique account identifier, and online identifiers such as IP address. Sources: you, and automatically from your device. Business purpose: to create, authenticate, and secure your account, provide and operate the Service, and communicate with you. Recipients: our service providers (hosting, database, email); the carriers you connect, where an identifier forms part of a shipment; and legal, safety, or corporate‑transaction recipients as described in this Policy.
Commercial information (§ 1798.140(v)(1)(D)). Examples: your subscription plan and status, billing and transaction records, and records of the quotes, bookings, shipments, bills of lading, and labels you create through the Service. Sources: you, and generated by your use of the Service; billing records via our payment processor once paid billing is live. Business purpose: to provide the Service, process transactions, maintain records, and support you. Recipients: our payment processor (for billing), hosting and database providers, and the carriers you transact with.
Internet or other electronic network activity information (§ 1798.140(v)(1)(F)). Examples: log data, IP address, browser and device type, pages and features viewed, and actions you take in the Service. Sources: automatically, from your device and our servers. Business purpose: to operate, secure, debug, and improve the Service and to detect and prevent abuse. Recipients: our hosting and infrastructure providers.
Geolocation data (§ 1798.140(v)(1)(G)). Examples: approximate location inferred from IP address, and the geocoding of postal addresses you type (for example, origin and destination addresses on a shipment), performed in your browser by our mapping provider. We do not collect precise (GPS‑level) geolocation about you. Sources: automatically (IP), and from addresses you enter. Business purpose: security and fraud prevention (IP), and address lookup and validation to build shipments (typed addresses). Recipients: our mapping provider (Mapbox), which receives typed addresses to return address suggestions.
Professional or employment‑related information (§ 1798.140(v)(1)(I)). Examples: your job title or role and your business contact details, and the business‑contact details of the consignee and bill‑to parties contained in the shipments you create. Sources: you. Business purpose: to operate your account and to prepare shipping documents and transmit shipment details to carriers. Recipients: the carriers you select. Where consignee or bill‑to details identify a California resident, we handle that information as a service provider on behalf of the customer who uploaded it.
Sensitive personal information (§ 1798.140(ae)). See the dedicated section below. In summary, the carrier account credentials you connect (API keys, tokens, and account numbers used to access your carrier accounts) are treated as sensitive personal information. We use them only to make requests to the carriers on your behalf.
We do not collect the following CCPA categories: characteristics of protected classifications (§ 1798.140(v)(1)(C)); biometric information (E); audio, electronic, visual, thermal, olfactory, or similar information (H); education information (J); or inferences drawn to create a profile about you (K).
3. Sensitive Personal Information
Some of the information you provide is treated as “sensitive personal information” under the CPRA. Specifically, when you connect a carrier account, you provide account log‑in credentials, API keys, tokens, and account numbers that allow access to your account with that carrier. Under Cal. Civ. Code § 1798.140(ae), credentials that allow access to an account are sensitive personal information, and we treat them accordingly.
We collect these credentials for one reason: so the Service can authenticate to the carriers you choose and, at your direction, retrieve rates, generate documents, book shipments, and pull tracking. We do not use your carrier credentials to infer any characteristics about you, we do not use them for advertising or profiling, and we do not sell or share them. They are encrypted at rest (AES-256-GCM), access is restricted, and each organization’s credentials are isolated from every other organization’s.
Because we use sensitive personal information only as necessary to perform the Service you have requested, and not to infer characteristics about you, the CPRA’s “right to limit the use and disclosure of sensitive personal information” does not apply to our use, and we are not required to offer a “Limit the Use of My Sensitive Personal Information” choice. You can remove any connected carrier credential at any time from your account settings, which stops all further use of that credential.
We do not collect any other categories of sensitive personal information (such as government identifiers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, the contents of your mail, email, or text messages, genetic or biometric data, or information about your health, sex life, or sexual orientation).
4. How We Use Information
- To provide the Service — connect carriers, return quotes, generate documents, book, and track shipments;
- To secure the platform, detect abuse, and troubleshoot errors;
- To communicate with you about your account, support requests, and service updates;
- To improve features and performance, and to comply with legal obligations.
5. How We Share Information
We do not sell your personal information. We share information only as needed to run the Service:
- Carriers — we transmit shipment details and your connected credentials to the carriers you choose, to obtain rates, documents, and tracking.
- Service providers / subprocessors — vendors that process data on our behalf under contract: Supabase (database), Vercel (application hosting), Mapbox (address lookup / geocoding), our email providers (Microsoft 365 and Resend) for account and transactional email, and, for paid plans, our payment processor (Stripe).
- Legal & safety — when required by law, or to protect the rights, safety, and property of Flutter Freight, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
Our role for uploaded shipment data. When a business customer uploads personal information about third parties (for example, consignee or bill‑to names and addresses), Flutter Freight acts as that customer’s service provider and processes the data only on the customer’s behalf and instructions. For business customers, our Data Processing Addendum sets out these service‑provider commitments and is available for our business customers on request.
6. Do We “Sell” or “Share” Your Personal Information?
We do not sell your personal information, and we do not share it for cross‑context behavioral advertising. Under California law, a “sale” means disclosing personal information to a third party for monetary or other valuable consideration, and “sharing” means disclosing it to a third party for cross‑context behavioral advertising (targeted advertising across different businesses’ sites or services). We do neither. We do not use your personal information, or the third‑party personal information you upload, to serve you or anyone else targeted advertising, and we have no advertising business.
We also do not knowingly sell or share the personal information of consumers we know to be under 16 years of age. The Service is intended for business use and is not directed to minors.
Twelve‑month statement. In the preceding 12 months, we collected the categories of personal information described in the “Categories of Personal Information We Collect” section above, and we did not sell or share (as those terms are defined under the CCPA/CPRA) any personal information, and we did not use or disclose sensitive personal information for any purpose that would give rise to a right to limit. In that same period, for a business purpose, we disclosed personal information only to our service providers and to the carriers you direct us to transact with. The categories we disclosed for a business purpose were:
- Identifiers and California customer-records information;
- Commercial information;
- Internet or other electronic network activity information;
- Geolocation data;
- Professional or employment-related information; and
- To your chosen carriers only, the sensitive personal information (carrier credentials) needed to act on your behalf.
Transmitting your shipment details and your connected credentials to the carriers you select, and to our service providers who process data on our behalf under contract, is not a “sale” or “share”: carriers receive the data at your direction to perform the service you requested, and our service providers are contractually restricted to processing the data only to provide services to us.
7. How We Protect Your Data
We apply industry‑standard safeguards. Data is encrypted in transit (TLS). The connected carrier credentials you provide — API keys, tokens, and passwords — are encrypted at rest using AES‑256‑GCM, and account login passwords are stored hashed. We do not encrypt every field: for example, your account email and carrier account numbers are stored in standard form and protected by access controls and tenant isolation, so that each organization can access only its own data. No system is perfectly secure, but we work to protect your information and to respond promptly to incidents.
8. Data Retention
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, and no longer than permitted by law. The retention period, or the criteria we use to set it, for each category is:
- Account and profile information (identifiers, professional and business-contact information): retained for the life of your account and deleted, or de-identified, within approximately 30 to 90 days after your account is closed, except where a longer period is required by law or to resolve disputes.
- Carrier credentials (sensitive personal information): retained only while the carrier connection is active, and deleted promptly — within approximately 30 days — after you disconnect the carrier or close your account.
- Shipment records, bills of lading, labels, and tracking (commercial and professional information): retained for the life of the account and for a period afterward to support recordkeeping, disputes, and legal compliance; the criteria include applicable transportation-recordkeeping norms and any legal hold.
- Billing and transaction records (commercial information): retained for the period required by tax, accounting, and audit obligations, typically up to seven years.
- Usage, log, and security data (internet/network activity, IP-based geolocation): retained for a limited period for security, debugging, and abuse prevention, typically 12 to 24 months, then deleted or aggregated.
Where information is retained in encrypted backups, it is deleted on our regular backup‑expiration cycle after it is deleted from active systems. Some records may be retained longer where necessary to comply with a legal obligation, establish or defend legal claims, or enforce our agreements.
9. Your California Privacy Rights
If you are a California resident, you have the following rights regarding the personal information we hold about you as an account user. To exercise any of these rights, see “How to Submit a Privacy Request” below.
- Right to know / access: request the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties to whom we disclose it.
- Right to a portable copy: receive the personal information you have provided to us in a portable and, to the extent technically feasible, readily usable format.
- Right to delete: request that we delete personal information we have collected from you, subject to legal exceptions (for example, information we must keep to complete a transaction, comply with a legal obligation, secure the Service, or exercise or defend legal claims).
- Right to correct: request that we correct inaccurate personal information we maintain about you.
- Right to opt out of sale or sharing: direct us not to sell or share your personal information. As explained above, we do not sell or share personal information, so there is nothing to opt out of; we honor Global Privacy Control signals as an opt-out preference regardless.
- Right to limit use of sensitive personal information: as explained in the Sensitive Personal Information section, we use sensitive personal information only to provide the Service you requested and not to infer characteristics, so this right does not apply to our use.
- Right to non-discrimination: you will not receive discriminatory treatment for exercising any of these rights (see the Non-Discrimination section below).
Requests about shipment data you upload. If your request concerns personal information contained in shipments a Flutter Freight customer uploaded about you (for example, if you are a consignee named on a shipment), we act as a service provider to that customer. Please direct your request to the customer that arranged the shipment; we will assist that customer in responding as required by law.
10. How to Submit a Privacy Request
How to submit. You may submit a privacy request by emailing us at privacy@flutterfreight.com. Because we operate exclusively online and interact with you directly through your account, email is a designated method for submitting requests.
What happens next. We will confirm receipt of your request within 10 business days and explain how we will process it. We will respond to a verifiable request within 45 calendar days of receiving it. If we need more time, we may extend our response by up to an additional 45 days (90 days total) and will notify you of the extension and the reason before the initial 45‑day period ends. There is no fee to submit a request, unless it is manifestly unfounded or excessive, in which case we will tell you why and, where permitted, may charge a reasonable fee or decline the request.
Verifying your identity. To protect your information, we must verify your identity before acting on a request to know, delete, or correct. We will match the information in your request against the information in your account and may ask for additional information to confirm you are the person the data is about. We use any information you provide for verification only, and delete it afterward. If we cannot verify your identity, we may be unable to fulfill the request, and we will explain why.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof that you gave them signed permission to act for you (or a valid power of attorney), and we may still require you to verify your own identity directly with us and to confirm that you authorized the agent.
11. Your Right to Non‑Discrimination
We will not discriminate against you for exercising any of your privacy rights. This means we will not deny you the Service, charge you a different price or rate (including through discounts or penalties), provide you a different level or quality of Service, or suggest that you will receive any of these, because you exercised a privacy right.
We may not be able to complete a transaction or provide a feature if the personal information at issue is necessary to do so; for example, if you ask us to delete, or you disconnect, the carrier credentials required to obtain rates, we will no longer be able to return rates for that carrier. That is a direct consequence of the request, not discrimination. We do not offer financial incentives in exchange for the collection, sale, or retention of personal information; if that ever changes, we will describe the incentive and its material terms here and obtain your opt‑in consent.
12. Automated Decision‑Making
We do not use your personal information for automated decision‑making or profiling that produces legal or similarly significant effects about you. If we introduce any such processing in the future, we will update this Policy and provide any notice and choices required by law before doing so.
13. Data Breach Notification
We maintain safeguards designed to protect your information, and we maintain an incident‑response process. If we discover a breach of the security of the system that compromises unencrypted (or encrypted‑with‑compromised‑key) personal information we own or license, we will notify affected individuals in the most expedient time possible and without unreasonable delay, and in any event within 30 days after discovery, consistent with Washington’s data‑breach notification law (RCW 19.255). Where a single breach requires us to notify more than 500 Washington residents, we will also notify the Washington State Attorney General within 30 days, as required by that law. Notification may be delayed only as needed for the legitimate needs of law enforcement, or to determine the scope of the breach and restore the integrity of our systems.
Where the affected data is personal information that a customer uploaded to the Service and that we hold on the customer’s behalf but do not own (for example, consignee or bill‑to details), we will notify that customer of the breach immediately following discovery so that the customer, as the owner of the data, can notify the affected individuals; we will cooperate with and support the customer in doing so.
14. Where Your Data Is Stored, and Changes to Our Subprocessors
Data residency. We host and store personal information in the United States, using the service providers listed below. When you type an address into the Service, that address is sent from your browser to our mapping provider (Mapbox) to return address suggestions; this happens in your browser and is limited to the address text you enter. We do not currently transfer personal information outside the United States.
Subprocessors. We use the following categories of service providers (subprocessors) to operate the Service, each under a contract that restricts them to processing data only to provide services to us: database (Supabase), application hosting (Vercel), address lookup and geocoding (Mapbox), transactional and account email (Microsoft 365 and Resend), and, for paid plans, our payment processor (Stripe). We maintain a current list of subprocessors and will make a materially updated list available on request.
Changes to subprocessors. Before we add or replace a subprocessor that processes your personal information, we will update our subprocessor list and, where we have committed to do so in a customer agreement, provide advance notice and a reasonable opportunity to object. If you have a signed Data Processing Addendum with us, its notice and objection terms control.
15. Cookies
We use a single essential cookie — an httpOnly session cookie — to keep you signed in and operate the Service. We do not set third‑party analytics or advertising cookies, and we do not use your information for targeted advertising. Because the session cookie is httpOnly, it cannot be read by client‑side scripts. You can control cookies through your browser settings, but disabling this essential cookie will break core functionality such as authentication.
16. Children’s Privacy
The Service is for business use and is not directed to children under 18, and we do not knowingly collect their data.
17. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated via email or in‑app, and the “Effective date” above will be updated.
18. Contact
Privacy questions or requests? Contact us at privacy@flutterfreight.com.