1. Introduction
CargoGauge ("we", "us", or "our") is a Danish company that sells logistics software to haulage operators. This Privacy Policy explains what personal data the platform holds, who decides what happens to it, how it is protected and what you can do about it. It is written to meet the General Data Protection Regulation (GDPR) and the Danish law that sits alongside it.
Read section 2 before anything else. For most of the data in the platform, we are not the party that decides what happens to it: the haulage company is. That single fact changes where you send a request and who has to answer it, and section 8 explains what it means in practice.
2. Who We Are, and Who Decides
Company Name: CargoGauge
CVR: 42423432
Address: Thomas Laubs Gade 23, 2100 Copenhagen, Denmark
Email: privacy@cargogauge.com
CargoGauge is sold to haulage operators. The operator decides which drivers exist in their account, which trips are planned and tracked, and what is recorded against them. We supply the software, run the servers and hold the data for them. GDPR calls the party that decides the controller, and the party that acts on the controller's instructions the processor. We are one or the other depending on which data you mean, and this section says which.
2.1 Where the operator is the controller and we are the processor
Everything a haulage company puts into the platform about its own business and its own people:
- Drivers, their profiles, their documents and their photographs
- Vehicles, trailers, routes and schedules
- Trips, stops, arrival and departure times and delivery records
- The GPS trail recorded while a trip is running
- Subcontractor companies and their contact details
The operator is the controller of all of it. They chose to use the platform, they decide who is entered into it and what is tracked, and they answer for that choice. We hold and process it on their documented instructions, under the data processing agreement described in section 2.3. We do not use it for our own purposes, and we do not sell it.
2.2 Where we are the controller
- Accounts on the platform. A login is held once for a person, not once per employer, so that the same person can work for more than one company in the platform without a second password. The account record itself, its email address, its credentials and when it was last used, is ours to run and therefore ours to answer for. What that person then does inside an operator's account is the operator's data, under 2.1.
- The driver sign-in register. Drivers sign in to the mobile app with a phone number and a PIN. Those credentials are held once per person, keyed on the phone number and belonging to no company, for the same reason: a driver who works for two operators has one login, not two. That register is ours.
- Security records. Sign-in attempts, the record of what our own staff did in the administration tools, and the IP addresses and browser identifiers in those records. We keep them to protect the platform, which is our own interest as well as our customers'.
- This website, and people who contact us. Enquiries, demo requests and the correspondence that follows. If you accept the measurement question on this website, also the counting of your visits and the campaign that brought you, described in section 12.2.
2.3 The agreement behind the processing
Where an operator is the controller, GDPR Art. 28 requires a written agreement between them and us setting out what we may do with the data, how it is protected, who else touches it and what happens at the end of the contract. Ours is published in full, so it can be read before anybody signs anything: Databehandleraftale. Its annexes carry the current list of sub-processors, which is the same list as section 10 of this notice.
3. What Data We Collect
Each heading says who the controller of that data is, using the split in section 2.
3.1 Account Information (operator is controller, except the login itself)
- Operators/Users: Email address, first name, last name, phone number, company affiliation
- Drivers: Name, email, phone number, driver license number and expiry date, and a photograph where one has been uploaded
- Subcontractors: Company name, contact email and phone, VAT number and country
The credentials behind a login, the email address and password for a dashboard user, and the phone number and PIN for a driver, are held once per person across the whole platform and we are the controller of those. See section 2.2.
3.2 Location Data (operator is controller)
- GPS Coordinates: Latitude, longitude, accuracy, altitude
- Route Information: Planned routes, actual routes taken, timestamps
- Stop Data: Arrival times, departure times, delivery confirmations
- Speed and Heading: Vehicle speed and direction during active assignments
3.3 Usage and Security Data (we are controller)
- Login times, sign-in attempts and IP addresses
- Browser and device identifiers sent with a request (the user agent)
- Actions taken by our own staff in the administration tools, recorded against the company they touched
- System interactions and errors
3.4 Operational Data (operator is controller)
- Assignment details and schedules
- Route templates and configurations
- Customer location information
- Proof of delivery records
4. Legal Basis for Processing (GDPR Article 6)
4.1 Where the operator is the controller
The legal basis for tracking a driver and recording a trip is the operator's to choose and the operator's to defend, because they are the controller (section 2.1). We process it for them on the basis of our contract with them, and we do not add a purpose of our own. Operators in road haulage typically rely on the performance of the employment or transport contract (Art. 6(1)(b)) and on their legitimate interest in running and evidencing the work (Art. 6(1)(f)). If you want to know which basis your employer relies on, ask your employer. They are the ones who must be able to tell you, and it may differ between companies.
4.2 Where we are the controller
These we decide, so these we account for:
| What | Legal Basis | Purpose |
|---|---|---|
| Platform logins and the driver sign-in register | Contract Performance (Art. 6(1)(b)) | Letting the right person into the right company's data, once per person rather than once per employer |
| Security and administration records | Legitimate Interest (Art. 6(1)(f)) | Protecting accounts against abuse, and being able to show afterwards what our own staff did |
| Enquiries from this website | Legitimate Interest and pre-contractual steps (Art. 6(1)(f), 6(1)(b)) | Answering the person who wrote to us |
| Measuring visits to this website, and the campaign behind an enquiry | Consent (Art. 6(1)(a)), which also covers the access to your browser that ePrivacy Art. 5(3) requires consent for | Knowing which pages and campaigns bring visitors and enquiries, only if you accepted |
| Marketing Communications | Consent (Art. 6(1)(a)) | Product updates and promotional content (opt-in only) |
5. How We Use Your Data
Where the operator is the controller, this list is what the platform does for them. We add no purpose of our own to their data beyond running, supporting and securing the service, and the aggregated road statistics described in section 7.
- Service Delivery: Provide real-time tracking, ETA calculations, route optimization
- Communication: Send assignment notifications, system alerts, support responses
- Analytics: Improve arrival times and service quality. Statistics that outlive an individual trip are aggregated first, so they describe a stretch of road rather than a driver; section 7 sets out what that means and why they are kept
- Security: Detect and prevent fraud, unauthorized access, system abuse
- Compliance: Meet legal obligations, respond to lawful requests from authorities
- Customer Support: Respond to inquiries, troubleshoot issues, provide assistance
6. Data Storage & Location
Your platform data is stored in the European Union. The single exception is push notification delivery, set out in section 11.
- Primary Location: Hetzner data centre in Helsinki, Finland
- Backups: Taken nightly and encrypted, so that a copy is unreadable without a key that is not kept on the server. We undertake to keep every backup copy inside the EU. Where a copy is held is a setting on the server rather than something this page can demonstrate, so ask us and we will tell you what is configured.
- Data Transfer: Within the EU/EEA, apart from push delivery (section 11)
7. Data Retention Periods
We retain your data only for as long as necessary to fulfill the purposes outlined in this policy:
| Data Category | Retention Period | Reason |
|---|---|---|
| GPS Location Data | 13 months from the time the position was recorded | Evidence for claims. CMR sets a one-year limitation period for claims arising from carriage by road; 13 months covers it with room for a late filing. |
| Photographs in delay reports | 13 months from the date the photograph was taken | The same basis as GPS data above: a photograph of a hold-up is evidence for the same kind of carriage claim, so it is kept for the same period. The measured lateness it supports remains on the assignment record. |
| Driver and company photographs | Until 30 days after the driver or the haulier leaves | A profile picture serves no purpose once the person no longer drives for anyone on the platform. The thirty days exist only so that a deactivation made in error can be undone. A driver may delete their own picture at any time, and an erasure request is acted on immediately rather than after this period. |
| Assignment Records | 5 years | The delivery records are the accounting material behind an invoice, and Danish bookkeeping law requires that to be kept for five years from the end of the financial year it belongs to. |
| User Accounts (Active) | Until account deletion requested | Service provision |
| User Accounts (Inactive) | 3 years after last login | Reactivation possibility |
| Audit Logs | 2 years | Security, compliance |
| Website Enquiries | 2 years after we last worked on the enquiry. The copy in our sales mailbox has no automatic deletion and is reviewed by hand. | Replying to your enquiry |
| Website Analytics | 90 days for each recorded page view. Daily totals per page and source, which hold no visitor code, are kept. | Measuring visits, only if you accepted (section 12.2) |
| Financial Records | 7 years | Tax and accounting regulations |
When we erase a person at their request but the record around them must be kept, we remove the things that identify them, their name, contact details and licence number, and keep the operational record of the journey itself. A trip that was driven still happened, and both the haulier and we may need to evidence it.
8. Your Rights Under GDPR
You have the following rights regarding your personal data. They are exercised against the controller, so read section 2 first: for driver and trip data that is your employer, and for your login and our security records it is us. Section 8.8 says where to write in either case. Where we rely on your consent you can withdraw it at any time, which does not affect what was done before (Article 7(3)). For measuring visits on this website, use Cookie settings at the bottom of any page (section 12.2).
8.1 Right of Access (Article 15)
Request a copy of the personal data held about you, in a commonly used electronic format, within 30 days. Where we are the controller we provide it ourselves; where an operator is, we produce the file and they provide it.
8.2 Right to Rectification (Article 16)
Request correction of inaccurate or incomplete data. We will update your information within 30 days.
8.3 Right to Erasure / "Right to be Forgotten" (Article 17)
Request deletion of your personal data. It is carried out within 30 days, unless there is a legal obligation to keep the record. Section 7 sets out what stays behind when that applies, and why.
8.4 Right to Restriction of Processing (Article 18)
Request temporary restriction of data processing while we verify accuracy or assess legitimate grounds for processing.
8.5 Right to Data Portability (Article 20)
Receive your data in a structured, machine-readable format, and have it transferred to another service provider. What the platform produces is JSON.
8.6 Right to Object (Article 21)
Object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds.
8.7 Automated Decision-Making (Article 22)
We do not use automated decision-making or profiling that produces legal effects or significantly affects you.
8.8 Where to Send a Request
Email privacy@cargogauge.com. We answer within 30 days, whoever the controller turns out to be, and we confirm in writing what was done.
- If the data is ours (your login, the driver sign-in register, our security records, an enquiry you sent us) we deal with it ourselves.
- If the data belongs to a haulage company (your driver profile, your trips, your GPS trail) we are the processor and cannot decide it for them. We identify the controller, forward your request to them, tell you that we have done so and who it went to, and then act on their instruction. We will not simply drop it.
- If you drive for more than one company each of them is a separate controller of their own trips, and each has to answer separately. We will say which companies hold data about you so you know who to ask; we will not hand one operator's records to another.
Before we act we have to be satisfied that you are who you say you are. Sending a driver's records to the wrong person would itself be a breach, so expect us to verify the request rather than take it at face value.
Erasure does not remove the journeys themselves. What that means, and why transport records survive the removal of the person, is set out in the deletion note in section 7.
9. Data Security Measures
What follows is what is actually in place, and the box at the end of this section says what is not. Where a customer is the controller, this section is also the description of measures annexed to the Databehandleraftale, so it is maintained here and nowhere else.
9.1 Technical Measures
- Encryption in Transit: HTTPS/TLS for every connection, to the platform and between our own services
- Authentication: JSON Web Tokens, with every API endpoint requiring authentication unless it is explicitly marked public. The default is closed, so a new endpoint is protected by the fact that nobody opened it
- Two-Factor Authentication: time-based one-time codes on our own staff administration accounts, which are the accounts that can reach more than one customer. It is not currently offered on operator dashboard accounts
- Access Controls: role-based access control, with each company's data separated at the query level. Tenant records are keyed by the company they belong to, so a row cannot be addressed from another company's session even by guessing its identifier
- Brute-Force Protection: rate limiting on sign-in attempts, and a lockout after repeated wrong PINs in the driver app
- Database Integrity: PostgreSQL 17 with data checksums switched on, so corruption on disk is detected rather than served back as if it were your data
- Least Privilege: the application connects to the database as a role that may read and write data and nothing else. It cannot create, alter or drop anything, so a flaw in the application cannot be used to rewrite the shape of the database
- Secrets Handling: credentials are read at start-up from files mounted as container secrets, not from environment files and not from source control
- Audit Logging: administrative and security-relevant actions are appended to a log that the application never updates or deletes
- Backups: nightly, encrypted, plus a backup taken before every release. The restore procedure is written down and rehearsed rather than assumed, and each rehearsal is recorded
9.2 Organizational Measures
- Data minimisation: we collect the data the service needs to work, and no more
- Privacy by design and default
- Access to production data is limited to the people who operate the service
- Every party outside our own servers that touches customer data is named in section 10, and the same list is an annex to the Databehandleraftale
10. Sub-Processors & Third Parties
This is the complete list of companies outside CargoGauge that hold or handle platform data, and what each of them gets. Where an operator is the controller (section 2.1) these are our sub-processors, engaged under the Databehandleraftale, whose annex carries the same list. We tell customers before we add one or swap one out, and they may object; the agreement sets out how.
10.1 Hetzner Online GmbH (Infrastructure Provider)
- Location: Finland (EU)
- Purpose: Server hosting, database storage
- Data Processed: All platform data
- Safeguards: Data Processing Agreement (DPA) in place, ISO 27001 certified
10.2 TomTom (Traffic and Travel Times)
- Location: Netherlands (EU)
- Purpose: Live and historic traffic data used to calculate arrival times
- Data Processed: Road coordinates for the stretch being timed. No name, vehicle or account identifier is sent.
- Safeguards: EU processing
10.3 MapTiler (Map Imagery and Address Search)
- Location: Switzerland, covered by an EU adequacy decision
- Purpose: The map backgrounds in the operator dashboard, and address lookup when a stop is created
- Data Processed: The map area being viewed, the address text typed into search, and the IP address of the browser making the request
- Safeguards: Adequacy decision, no account data sent
10.4 Brevo (Email Delivery)
- Location: France (EU)
- Purpose: Sending account email such as invitations, password resets and operational notifications, and delivering enquiries sent through the contact form on this website
- Data Processed: For account email, the recipient's name and email address and the content of the message. For the contact form, the details you enter: name, email address, phone number, company, fleet size, interest and your message.
- Safeguards: Data Processing Agreement in place, EU processing
10.5 GatewayAPI (SMS Delivery)
- Location: Denmark (EU)
- Purpose: Sending SMS, including driver sign-in codes
- Data Processed: Phone number and the content of the message
- Safeguards: Data Processing Agreement in place, EU processing
10.6 Google (Push Notifications to the Driver App)
- Location: United States
- Purpose: Delivering push notifications to the driver app through Firebase Cloud Messaging
- Data Processed: The device's push token, the reference numbers the app needs to open the right screen, and a short message. By default that message is generic and carries no trip, customer or location detail. An operator can switch their own company to full detail in notifications, and where they do, the message text is visible to the delivery service.
- Safeguards: EU-US Data Privacy Framework and Standard Contractual Clauses. See section 11.
11. International Data Transfers
Your platform data is stored and processed in the European Union. There is one exception. Push notifications to the driver app are delivered through Google's Firebase Cloud Messaging, which means a transfer to Google in the United States. That transfer covers the device's push token, the reference numbers the app needs to open the right screen, and the message text. By default the message is generic and carries no trip, customer or location detail; an operator can switch their own company to full detail, and where they do, that text is included. It is covered by the EU-US Data Privacy Framework and by Standard Contractual Clauses. A driver who does not enable push notifications is not subject to this transfer.
For any further international transfer we will:
- Obtain your explicit consent
- Use Standard Contractual Clauses (SCCs) approved by the EU Commission
- Ensure adequate safeguards are in place
- Notify you in advance
12. Cookies & Browser Storage
12.1 What is actually stored (no consent required)
Neither this website nor the platform sets a cookie of its own. Signing in does not produce one: the sign-in token is kept in your browser's own storage and sent back on each request as an ordinary header. What is held in your browser is:
- Sign-in token (platform): keeps you logged in, and is discarded when you sign out
- Your settings and interface preferences (platform): the things you chose, remembered so you do not have to choose them again
- Language preference (website): stored only if you pick a language here
- Your answer to the measurement question (website): Accept or Reject, the version of the question and the day you answered, kept for 12 months so we do not ask on every page. Only the script that decides whether to measure reads it, and it is never sent to us.
All of that is either strictly necessary for a service you asked for or set by you deliberately, which is why none of it asks for consent. None of it is sent anywhere or used to build a profile.
12.2 Measuring visits (only if you accept)
When you first open this website, a box at the bottom asks whether we may measure your visits. Until you click Accept, nothing on the site measures anything. If you click Reject, or do not answer, the site and the contact form work exactly the same.
If you accept, each page you open sends one small request to our own server with:
- the address of the page, without anything after the question mark, and the language version you are reading
- the site that linked to it, reduced to its domain name and left out when it is one of our own pages
- the campaign tags in the link, if there are any (utm_source, utm_medium, utm_campaign, utm_term and utm_content), and an advertising click identifier if the link carried one (gclid from Google, msclkid from Microsoft or li_fat_id from LinkedIn)
- whether the device is a phone, a tablet or a computer
Our server adds the time and a visitor code. The code is calculated from your IP address and the identification your browser sends, using a secret that changes every day (a keyed hash), so the same browser gets a new code each day. Your IP address and the browser string are not stored with the page view. The code is pseudonymous, not anonymous: it counts as personal data for as long as it exists.
If you then send an enquiry through the contact form, the campaign details and referring site of that day's first counted visit are stored with the enquiry, together with the day's code, so we can see which campaign led to it. Where no visit was counted, the details of the contact page itself are used. The form shows a line saying so while your answer is Accept.
Who receives it. Nobody outside CargoGauge. It is stored on our own servers at Hetzner (section 10) and read by our staff in our administration tools. Advertising click identifiers are stored, not sent back to Google, Microsoft or LinkedIn.
How long. Each page view is deleted after 90 days. Before that it is added to daily totals per page and source, which hold no visitor code and are kept. On an enquiry, the visitor code is cleared after the same 90 days, and the campaign details stay as long as the enquiry itself (section 7).
Legal basis. Your consent (GDPR Art. 6(1)(a)), which also covers the access to your browser that ePrivacy Art. 5(3), as implemented in the Danish cookie order (cookiebekendtgørelsen), allows only with consent.
Changing your mind. Cookie settings at the bottom of every page shows the same question again. A Reject stops measurement from the next page on and does not affect what was recorded before. Because the code changes every day and we keep nothing that ties it to you, we cannot usually find one person's earlier page views; they are deleted at the 90-day mark. Campaign details on an enquiry can be removed on request (section 8.8). We ask again after 12 months, or sooner if what we measure changes.
12.3 Third parties
We embed no third-party tags, pixels or advertising cookies, on this website or in the platform.
One third party is worth naming: the maps in the operator dashboard are loaded from MapTiler (section 10), and their content network may set a cookie of its own for rate limiting. It is strictly necessary for delivering the map and carries nothing about you.
13. Children's Privacy
Our service is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If we discover we have collected data from a child, we will delete it immediately.
14. Data Breach Notification
Who has to tell whom depends again on who the controller is.
- Data an operator controls. We notify that operator without undue delay after becoming aware of a breach, with what we know and what we are doing about it (GDPR Art. 33(2)). They are the controller, so the notification to the supervisory authority and to the people affected is theirs to make, and we help them make it.
- Data we control (logins, the driver sign-in register, our security records, this website). We notify the supervisory authority within 72 hours where the breach is likely to present a risk (Art. 33(1)), and the people affected without undue delay where the risk to them is high (Art. 34).
- Either way, a notification says what happened, what data was involved, what the likely consequences are, what we have done, and who to contact for more.
15. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe we have violated your data protection rights:
Danish Data Protection Agency (Datatilsynet)
Borgergade 28, 5
1300 Copenhagen K
Danmark
Email: dt@datatilsynet.dk
Phone: +45 33 19 32 00
You may also contact the supervisory authority in your EU member state. If your complaint is about how a haulage company uses the platform, rather than about us, the authority to approach is the one in the country where that company is established, because they are the controller.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will:
- Notify you via email of significant changes
- Update the "Last Updated" date at the top
- Provide the previous version on request
- Obtain new consent if required by law
Changes to the Databehandleraftale, including the sub-processor list, are notified to customers separately under that agreement's own terms.
17. Contact Us
Privacy Inquiries
Email: privacy@cargogauge.com
Response Time: Within 30 days
For general support inquiries, please use: support@cargogauge.com
To sign the Databehandleraftale or to ask about it before you buy: sales@cargogauge.com