1. Introduction
CargoGauge ("we", "us", or "our") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the General Data Protection Regulation (GDPR) and other applicable EU data protection laws.
2. Data Controller
Company Name: CargoGauge
CVR: 42423432
Address: Thomas Laubs Gade 23, 2100 Copenhagen, Denmark
Email: privacy@cargogauge.com
3. What Data We Collect
3.1 Account Information
- Operators/Users: Email address, first name, last name, phone number, company affiliation
- Drivers: Name, email, phone number, driver license number and expiry date
- Subcontractors: Company name, contact details, VAT number, business registration
3.2 Location Data
- GPS Coordinates: Latitude, longitude, accuracy, altitude
- Route Information: Planned routes, actual routes taken, timestamps
- Stop Data: Arrival times, departure times, delivery confirmations
- Speed and Heading: Vehicle speed and direction during active assignments
3.3 Usage Data
- Login times and IP addresses
- Feature usage patterns
- Device information (browser type, operating system)
- System interactions and errors
3.4 Operational Data
- Assignment details and schedules
- Route templates and configurations
- Customer location information
- Proof of delivery records
4. Legal Basis for Processing (GDPR Article 6)
We process your personal data based on the following legal grounds:
| Data Type | Legal Basis | Purpose |
|---|---|---|
| Account Information | Contract Performance (Art. 6(1)(b)) | Providing logistics tracking services |
| GPS Location Data | Contract Performance & Legitimate Interest (Art. 6(1)(b)(f)) | Real-time tracking, ETA calculations, and evidence if a shipment is disputed |
| Usage Data | Legitimate Interest (Art. 6(1)(f)) | Security, service improvement, fraud prevention |
| Marketing Communications | Consent (Art. 6(1)(a)) | Product updates and promotional content (opt-in only) |
5. How We Use Your Data
- Service Delivery: Provide real-time tracking, ETA calculations, route optimization
- Communication: Send assignment notifications, system alerts, support responses
- Analytics: Improve service quality, identify usage patterns, optimize performance
- Security: Detect and prevent fraud, unauthorized access, system abuse
- Compliance: Meet legal obligations, respond to lawful requests from authorities
- Customer Support: Respond to inquiries, troubleshoot issues, provide assistance
6. Data Storage & Location
Your platform data is stored in the European Union. The single exception is push notification delivery, set out in section 11.
- Primary Location: Hetzner data centre in Helsinki, Finland
- Backups: Held on the same server in Helsinki, Finland. We do not currently replicate backups to a second data centre.
- Data Transfer: Within the EU/EEA, apart from push delivery (section 11)
7. Data Retention Periods
We retain your data only for as long as necessary to fulfill the purposes outlined in this policy:
| Data Category | Retention Period | Reason |
|---|---|---|
| GPS Location Data | 13 months from the time the position was recorded | Evidence for claims. CMR sets a one-year limitation period for claims arising from carriage by road; 13 months covers it with room for a late filing. |
| Assignment Records | 2 years | Legal obligations, tax requirements |
| User Accounts (Active) | Until account deletion requested | Service provision |
| User Accounts (Inactive) | 3 years after last login | Reactivation possibility |
| Audit Logs | 2 years | Security, compliance |
| Financial Records | 7 years | Tax and accounting regulations |
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
8.1 Right of Access (Article 15)
Request a copy of all personal data we hold about you. We will provide this in a commonly used electronic format within 30 days.
8.2 Right to Rectification (Article 16)
Request correction of inaccurate or incomplete data. We will update your information within 30 days.
8.3 Right to Erasure / "Right to be Forgotten" (Article 17)
Request deletion of your personal data. We will delete your data within 30 days unless we have a legal obligation to retain it.
8.4 Right to Restriction of Processing (Article 18)
Request temporary restriction of data processing while we verify accuracy or assess legitimate grounds for processing.
8.5 Right to Data Portability (Article 20)
Receive your data in a structured, machine-readable format (JSON/CSV) and have it transferred to another service provider.
8.6 Right to Object (Article 21)
Object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds.
8.7 Automated Decision-Making (Article 22)
We do not use automated decision-making or profiling that produces legal effects or significantly affects you.
Email us at privacy@cargogauge.com with your request. We will respond within 30 days and provide confirmation of actions taken.
9. Data Security Measures
We implement industry-standard security measures to protect your data:
9.1 Technical Measures
- Encryption in Transit: HTTPS/TLS for every connection, to the platform and between our own services
- Authentication: JSON Web Tokens, with every API endpoint requiring authentication unless it is explicitly marked public
- Two-Factor Authentication: available on operator accounts
- Access Controls: role-based access control, with each company's data separated at the query level
- Brute-Force Protection: rate limiting on sign-in attempts
- Audit Logging: security-relevant and administrative actions are recorded
- Backups: the database is backed up before every release, and a rolling window of recent backups is retained
9.2 Organizational Measures
- Data minimisation: we collect the data the service needs to work, and no more
- Privacy by design and default
- Access to production data is limited to the people who operate the service
10. Data Processors & Third Parties
We work with the following data processors who have access to certain data:
10.1 Hetzner Online GmbH (Infrastructure Provider)
- Location: Finland (EU)
- Purpose: Server hosting, database storage
- Data Processed: All platform data
- Safeguards: Data Processing Agreement (DPA) in place, ISO 27001 certified
10.2 TomTom (Traffic and Travel Times)
- Location: Netherlands (EU)
- Purpose: Live and historic traffic data used to calculate arrival times
- Data Processed: Road coordinates for the stretch being timed. No name, vehicle or account identifier is sent.
- Safeguards: EU processing
10.3 MapTiler (Map Imagery and Address Search)
- Location: Switzerland, covered by an EU adequacy decision
- Purpose: The map backgrounds in the operator dashboard, and address lookup when a stop is created
- Data Processed: The map area being viewed, the address text typed into search, and the IP address of the browser making the request
- Safeguards: Adequacy decision, no account data sent
10.4 Brevo (Email Delivery)
- Location: France (EU)
- Purpose: Sending account email such as invitations, password resets and operational notifications
- Data Processed: Name, email address, and the content of the message
- Safeguards: Data Processing Agreement in place, EU processing
10.5 GatewayAPI (SMS Delivery)
- Location: Denmark (EU)
- Purpose: Sending SMS, including driver sign-in codes
- Data Processed: Phone number and the content of the message
- Safeguards: Data Processing Agreement in place, EU processing
10.6 Google (Push Notifications to the Driver App)
- Location: United States
- Purpose: Delivering push notifications to the driver app through Firebase Cloud Messaging
- Data Processed: The device's push token, the reference numbers the app needs to open the right screen, and a short message. By default that message is generic and carries no trip, customer or location detail. An operator can switch their own company to full detail in notifications, and where they do, the message text is visible to the delivery service.
- Safeguards: EU-US Data Privacy Framework and Standard Contractual Clauses. See section 11.
11. International Data Transfers
Your platform data is stored and processed in the European Union. There is one exception. Push notifications to the driver app are delivered through Google's Firebase Cloud Messaging, which means a transfer to Google in the United States. That transfer covers the device's push token, the reference numbers the app needs to open the right screen, and the message text. By default the message is generic and carries no trip, customer or location detail; an operator can switch their own company to full detail, and where they do, that text is included. It is covered by the EU-US Data Privacy Framework and by Standard Contractual Clauses. A driver who does not enable push notifications is not subject to this transfer.
For any further international transfer we will:
- Obtain your explicit consent
- Use Standard Contractual Clauses (SCCs) approved by the EU Commission
- Ensure adequate safeguards are in place
- Notify you in advance
12. Cookies & Tracking
12.1 Essential Cookies (No Consent Required)
- Authentication Token: Keeps you logged in
- Session ID: Maintains your session state
- Security Token: Prevents CSRF attacks
- Language preference (website): Stored in your browser only if you choose a language on this website
12.2 Optional Cookies (Consent Required)
We do not use analytics, advertising, or tracking cookies without your explicit consent.
13. Children's Privacy
Our service is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If we discover we have collected data from a child, we will delete it immediately.
14. Data Breach Notification
In the unlikely event of a data breach that poses a risk to your rights and freedoms:
- We will notify the relevant supervisory authority within 72 hours (GDPR Article 33)
- We will notify affected individuals without undue delay (GDPR Article 34)
- Notifications will include: nature of breach, likely consequences, measures taken, contact point for more information
15. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe we have violated your data protection rights:
Danish Data Protection Agency (Datatilsynet)
Borgergade 28, 5
1300 Copenhagen K
Denmark
Email: dt@datatilsynet.dk
Phone: +45 33 19 32 00
You may also contact the supervisory authority in your EU member state.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will:
- Notify you via email of significant changes
- Update the "Last Updated" date at the top
- Maintain previous versions for your reference
- Obtain new consent if required by law
17. Contact Us
Privacy Inquiries
Email: privacy@cargogauge.com
Response Time: Within 30 days
For general support inquiries, please use: support@cargogauge.com