Legal
Privacy policy
Draft for legal review · not yet in effect
Effective: To be set before this takes effect: set when this is published Last updated: 2026-09-05
To be set before this takes effect: the legal name of the company that operates Dispatch ("Dispatch", "we", "us") operates Dispatch, software that carriers use to run their dispatch board. This policy explains what personal information Dispatch handles, why, and what happens to it.
It is written from the database schema rather than from a template. Every category below is something the software actually stores; nothing is listed that it does not.
1. The most important thing: whose data this is
Dispatch holds two kinds of personal information, and our role is different for each.
Information a carrier puts in about their own people. Driver names, CDL numbers, duty status logs, vehicle positions. The carrier decides what to collect, who to collect it about, and what to do with it. They are the controller of that information and we process it on their instructions. If you are a driver or a dispatcher asking what is held about you, ask your employer first — they hold the relationship, and we cannot release their records to a third party without their say-so.
Information you give us directly. An account you create, or a form you fill in asking us to call you. We are the controller of that, and the rest of this policy tells you what we do with it.
2. What we hold, and why
If you create an account
| What | Why |
|---|---|
| Your name and email address | To identify you and let you sign in |
| A scrypt hash of your password | To check your password without knowing it |
| Your role at the carrier | To decide what you are allowed to do |
| When you last signed in | To spot dormant accounts |
| Your carrier's name and USDOT number | To identify the business |
We never store your password. What is stored is a scrypt hash, which is deliberately slow to compute and cannot be turned back into your password.
Session records, while you are signed in
A session record holds a SHA-256 digest of your session token, when it was issued and last used, and keyed HMAC fingerprints of your IP address and browser. Those fingerprints let us tell one device from another without storing where you were: they are hashed with a server-held key, so they cannot be reduced back to an address.
If your carrier adds you as a driver
Your name, CDL number and issuing state, CDL class and endorsements, licence and medical certificate expiry dates, employment status, and the latitude and longitude of your reporting location.
We hold the expiry date of your medical certificate. We do not hold the certificate, its contents, or anything else about your health.
Duty status logs, and why they are the sensitive part
If your carrier uses Dispatch to record hours of service, we hold a record of which duty status you were in and when — driving, on duty, off duty, sleeper berth — over time.
We are not going to soften this: that is a detailed record of your working life. Read across a week it shows when you started, when you stopped, how long you drove, and when you rested. It exists because 49 CFR Part 395 requires your employer to keep it and because the software refuses to assign you a load your hours cannot legally cover. It is not used for anything else.
Vehicle positions
Latitude, longitude and a timestamp, recorded against a load. While you are assigned to that load, that is a record of where you were.
If you fill in the "talk to us" form
Your name, email, phone number if you gave one, your carrier's name, USDOT number if you gave one, how many trucks you run, what you use today, and what you wrote in the free-text box. We use it to decide whether to contact you and to have a sensible conversation when we do. Filling the form again replaces your earlier answers rather than adding a second record.
Records of what happened
An audit trail of which account took which action and when, and a record of each time an AI agent ran — which agent, which model, how many tokens, what it was asked and what it decided.
3. What we send to AI model providers
Dispatch uses large language models to draft messages, read documents and explain decisions. When an agent runs, some of your carrier's information is sent to a model provider — currently OpenRouter, which routes to the model your carrier has configured (today, OpenAI models).
What is sent:
- —Internal identifiers (opaque UUIDs)
- —Hours-of-service figures — minutes available, minutes remaining, which limit binds
- —Load facts: cities, appointment times, weight, commodity, rate
- —Broker company names
- —Text a person typed: a message to the driver copilot, or the text of a document being read
What is not sent: driver names, CDL numbers, medical certificate details, user names, email addresses, passwords, or session tokens. The driver copilot identifies a driver by their internal id, not their name.
Two things follow from that. A driver's hours and location patterns can leave our systems attached to an identifier. And anything typed into a free-text box is sent as typed — if a driver types their own name or a specific location into the copilot, that text goes to the provider.
Model providers process this to return an answer. We do not authorise them to train models on it. Their own terms govern what they do, and we will name the provider in force at any time on request.
A carrier that does not want any of this can run Dispatch with no model configured. The dispatch board, hours-of-service checks, credential checks and the emergency path all work without one — the agents are what stop.
4. What we do not collect
- —No payment card details. We do not run card payments. The paid plan is unlocked with a redemption code issued after payment is arranged separately, and only a hash of that code is stored.
- —No Social Security numbers, passport or government ID numbers.
- —No uploaded file contents. When a document is filed, we store its SHA-256 hash and metadata — not the file.
- —No advertising or third-party tracking. There are no analytics scripts, no advertising pixels and no cookies beyond what is needed to keep you signed in.
- —No selling of personal information, ever, to anyone.
5. How long we keep it
Duty status logs are kept, deliberately. 49 CFR 395.8(k) requires a carrier to retain records of duty status for at least six months, and their supporting documents with them. Deleting a driver's logs on request could put the carrier in violation of federal law. So we retain them for the carrier, and a request to delete them goes to the carrier, who must weigh it against that obligation.
Everything else:
| What | How long |
|---|---|
| Account records | While the account exists, then To be set before this takes effect: confirm after |
| Session records | Sessions expire; revoked and expired rows are cleared routinely |
| Audit and agent records | Kept as long as the carrier's account, as an evidence trail |
| Waitlist entries | Until you ask us to remove them, or To be set before this takes effect: confirm |
6. Who else can see it
- —The model provider, as described in section 3.
- —Our hosting and database provider — Railway, which runs the application and its database, and Cloudflare, which serves this website.
- —Nobody else. We do not share personal information with advertisers, data brokers or partners.
Dispatch enforces separation between carriers in the database itself, using PostgreSQL row-level security. One carrier cannot read another carrier's freight, drivers or logs.
We may disclose information if we are legally required to. If we can lawfully tell the affected carrier first, we will.
7. Your rights
Depending on where you live, you may have the right to ask what is held about you, to correct it, to get a copy, or to have it deleted.
- —If your carrier put the data in — driver records, duty logs, positions — ask your carrier. We will help them answer.
- —If you gave it to us directly — your account, or the contact form — write to To be set before this takes effect: PRIVACY CONTACT EMAIL and we will answer.
We will not charge you, and we will not make the product worse for you for asking.
Two honest limits. Duty logs are subject to section 5. And a deletion that would break an evidence trail a carrier is relying on may need to wait for their retention period to run.
8. Security
- —Passwords are stored as scrypt hashes, never in the clear.
- —Session tokens are 32 random bytes; only a SHA-256 digest is stored.
- —IP addresses and browser strings are stored as keyed HMAC fingerprints, not as raw values.
- —Carrier separation is enforced by the database, not only by application code.
- —Credentials are held in environment configuration, never in the codebase.
No system is perfectly secure, and we are not going to claim otherwise. If we discover a breach affecting your information, we will tell affected carriers without undue delay and comply with applicable notification law.
9. Where your information is held
To be set before this takes effect: where data is hosted, pending confirmation
10. Children
Dispatch is business software for commercial carriers. It is not for anyone under 18, and we do not knowingly collect information from children.
11. Changes
If we change this policy in a way that materially affects what we do with your information, we will tell account holders before it takes effect. The date at the top always reflects the current version, and older versions are in the project's version history.
12. Contact
To be set before this takes effect: PRIVACY CONTACT EMAIL To be set before this takes effect: required in several jurisdictions