1. Introduction
SearchCarriers ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the SearchCarriers platform — including our website, web application, and API (collectively, the "Service").
The Service provides access to publicly available motor carrier data sourced from the Federal Motor Carrier Safety Administration (FMCSA) and other public data sources, enriched with additional intelligence and analysis tools. Please read this policy carefully. If you do not agree with its terms, please do not use the Service.
2. Information We Collect
2.1 Account Information
- Name, email address, and password when you register for an account.
- Organization name and billing details if you subscribe to a paid plan.
- Profile information you choose to provide in your account settings.
2.2 Usage Data
- Searches you perform, including company names, DOT numbers, MC numbers, and other search queries.
- Features you use such as carrier research, Watch lists, map searches, API calls, and custom reports.
- Pages and sections of the Service you access and how long you spend on them.
- Your IP address, browser type and version, operating system, and device identifiers.
- Referring URLs and navigation paths through the Service.
2.3 API Usage
- API keys generated, requests made, endpoints called, and response data delivered.
- Rate limit consumption and integration metadata associated with your API credentials.
2.4 Cookies and Similar Technologies
We use cookies and similar tracking technologies to maintain session state, remember your preferences (such as dark mode), and analyze how the Service is used. You can control cookies through your browser settings, though some features may not function properly if cookies are disabled.
2.5 Communications
- Messages you send us through support channels or contact forms.
- Feedback, tips, or other content you voluntarily submit through the Service.
2.6 Chrome Extension Data
Our Chrome Extension is designed to surface SearchCarriers data about carriers and other entities that appear on web pages you visit. When you use the Extension, it may access and process the following:
- Page URLs and page content: The Extension reads the URL and limited portions of the DOM of the active page to detect DOT numbers, MC numbers, company names, and other identifiers that can be used to look up entities on SearchCarriers.
- Detected identifiers: DOT numbers, MC numbers, and company names parsed from the page are sent to SearchCarriers so that we can return matching records for display within the Extension.
- Authentication tokens: The Extension stores the authentication token associated with your SearchCarriers account so that your Extension requests can be attributed to your account and subject to your plan's rate limits.
The Extension does not collect keystrokes, form inputs, passwords, financial information, health information, personal communications, or general browsing history. Page content is used only to identify carrier-related entities and is not stored beyond what is necessary to service your lookup request. Use of the Extension is subject to our single-purpose disclosure in the Chrome Web Store listing.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service, including carrier research tools, Watch alerts, map features, API access, and custom report generation.
- Create and manage your account and subscription.
- Process payments and manage billing.
- Send transactional emails such as account verification, password resets, Watch alert notifications, and report delivery.
- Send optional product update and marketing communications (you may opt out at any time).
- Monitor and analyze usage patterns to understand how people use the Service and to improve it.
- Detect, prevent, and address fraud, abuse, security incidents, and technical issues.
- Enforce our Terms of Service and other policies.
- Comply with applicable legal obligations.
4. Data We Surface — Carrier & Entity Data
The carrier and entity information displayed through the Service (safety ratings, SMS scores, inspection records, crash history, insurance data, authority status, equipment details, etc.) is sourced from publicly available government databases, primarily the FMCSA. We do not consider this third-party public data to be your personal information.
Your search queries and the specific data records you access are logged as usage data associated with your account for purposes such as audit trails, API billing, and service improvement.
5. Data Storage and Security
We use industry-standard security measures to protect your personal information:
- Data is encrypted in transit using TLS and encrypted at rest.
- Access to your personal data by our team is limited, role-based, and audited.
- We maintain regular backups to prevent data loss.
- API keys are hashed and never stored in plaintext.
No method of transmission over the Internet or electronic storage is 100% secure. While we take commercially reasonable steps to protect your information, we cannot guarantee absolute security.
6. Data Retention
We retain personal information only for as long as is reasonably necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are as follows:
- Account information (name, email, organization, profile): Retained for the life of your account, and deleted or anonymized within 90 days after account deletion, except where retention is required by law.
- Billing and transaction records (invoices, payment metadata): Retained for at least seven (7) years after the transaction to comply with tax, accounting, and financial recordkeeping obligations.
- Search history and product usage logs: Retained for up to twenty-four (24) months in association with your account, after which records are either aggregated, anonymized, or deleted.
- API request logs: Retained for up to twelve (12) months for billing, abuse prevention, rate-limit enforcement, and troubleshooting purposes.
- Security, authentication, and audit logs: Retained for up to twenty-four (24) months to support incident response and fraud detection.
- Support communications: Retained for up to thirty-six (36) months after the ticket is closed.
- Backups: Encrypted backups containing personal information may persist for up to ninety (90) days after deletion from production systems, after which they are overwritten in the ordinary course.
Where we retain information after an account deletion request, we do so only in the minimum form and for the minimum period necessary to satisfy the purposes identified above.
7. Sharing Your Information
We do not sell your personal information, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under California law. We may share your information in the following limited circumstances:
- Hosting and Infrastructure: Our application and databases are hosted with cloud infrastructure providers that store personal and usage data on our behalf.
- Content Delivery and Security: We use Cloudflare for content delivery, DDoS protection, and network security, which may process your IP address and request metadata.
- Payment Processing: We use Stripe to process subscription payments. Payment card details are submitted directly to Stripe and are not stored on our servers; we receive only limited billing metadata (e.g., last four digits, card brand, billing country) for account and invoicing purposes.
- Email Delivery: We use third-party email delivery providers to send transactional and marketing emails (such as account verification, password resets, Watch alerts, and product updates).
- Product Analytics: We use PostHog for product analytics. Usage data may be shared with this provider in aggregated or pseudonymized form to help us understand how the Service is used.
- Other Service Providers: We may engage additional trusted third-party vendors to help us operate the Service (such as error monitoring, customer support tooling, and data enrichment providers). These vendors are contractually obligated to protect your data and may only use it to perform services for us.
- Business Transfers: If we are involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your personal data is subject to a different privacy policy.
- Legal Requirements: We may disclose your information if required by law or in response to a valid legal process, or to protect the rights, property, or safety of SearchCarriers, our users, or others.
8. Your Rights and Choices
You have the following rights regarding your personal information:
- Access and Update: You can review and update your account information at any time through your account settings.
- Marketing Opt-Out: You can opt out of marketing emails by clicking "unsubscribe" in any such email or through your account notification settings.
- Data Deletion: You may request deletion of your account and associated personal data by contacting us. Note that some data may be retained as described in Section 6 (Data Retention) where required by law or for legitimate business purposes.
- Data Portability: You may request an export of your personal data that we hold about you.
- Cookie Preferences: You can manage cookies through your browser settings.
To exercise any of these rights, please contact us using the information in Section 14.
9. State Privacy Rights and "Do Not Track"
This section describes additional rights that may apply to you depending on the U.S. state in which you reside, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive consumer privacy laws.
9.1 Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information, as defined under California law:
- Identifiers: name, email address, account username, IP address, device identifiers.
- Customer records: billing name, billing address, and limited payment metadata (handled by our payment processor).
- Commercial information: subscription plan, billing history, and product purchases.
- Internet or other electronic network activity: pages visited, features used, search queries, API calls, referring URLs, and interaction data.
- Geolocation data: approximate location inferred from IP address.
- Professional or employment-related information: organization name and role, if provided.
- Inferences: limited inferences drawn from usage patterns to operate and improve the Service.
Each of these categories is collected for the business purposes described in Section 3 (How We Use Your Information), including providing, securing, billing for, and improving the Service.
9.2 No Sale or Sharing of Personal Information
We do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioral advertising, in each case as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We have not sold or shared personal information in the preceding 12 months, and we do not sell or share the personal information of minors under 16.
9.3 Your State Privacy Rights
Depending on your state of residence, you may have the right to:
- Know or access the categories and specific pieces of personal information we have collected about you.
- Request deletion of personal information we have collected from you.
- Request correction of inaccurate personal information.
- Obtain a copy of your personal information in a portable format.
- Opt out of the "sale" or "sharing" of personal information (not applicable because we do not sell or share).
- Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects (we do not engage in such profiling).
- Limit the use of sensitive personal information (we do not use sensitive personal information for any purpose requiring a limit-use right).
- Be free from retaliation or discrimination for exercising any of these rights.
To exercise any of these rights, contact us using the information in Section 14. We may need to verify your identity before responding to your request. You may also designate an authorized agent to submit a request on your behalf, subject to verification.
9.4 "Do Not Track" Signals and Opt-Out Preference Signals
Some web browsers transmit "Do Not Track" (DNT) signals. Because there is not yet an industry or legal consensus on how to interpret DNT signals, the Service does not currently respond to DNT signals. We do, however, recognize opt-out preference signals (such as the Global Privacy Control) where required by applicable state law, and will treat a valid signal from a California resident as a request to opt out of sale/sharing (although, as stated above, we do not sell or share personal information in the first place).
10. International Users and U.S.-Based Processing
The Service is operated from the United States, and all personal information collected through the Service is stored and processed in the United States. The Service is offered exclusively to users located in North America (United States, Canada, and Mexico), as set forth in our Terms of Service, and we do not accept accounts from, or direct the Service to, users located outside of North America. By using the Service, you acknowledge that your personal information will be transferred to, stored in, and processed in the United States. We do not offer a GDPR-specific processing basis, standard contractual clauses, or other cross-border transfer mechanism for users located in the European Economic Area, United Kingdom, or Switzerland, and such users should not create accounts or submit personal information through the Service.
11. Third-Party Services and Links
The Service may contain links to or integrations with third-party websites and services (such as FMCSA resources, Chrome Extension stores, or partner platforms). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies separately.
12. Children's Privacy
The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will notify you via the email address associated with your account or through a notice within the Service. Your continued use of the Service after such changes constitutes your acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data — including requests to exercise any of your privacy rights — please contact us at:
SearchCarriers is based in North Carolina, USA.
You may also reach us through the support channels available within your account. We will respond to verified privacy requests within the timeframes required by applicable law.