Privacy Policy
1. Introduction
Ziply Fleet Inc. (“Ziply Fleet,” “we,” “us,” or “our”) provides a cloud-based fleet management platform for motor carriers, freight brokers, and related transportation businesses, available at ziplyfleet.com, together with associated applications and services (collectively, the “Service”).
This Privacy Policy describes how we collect, use, disclose, and safeguard information in connection with the Service. It applies to our business customers and their authorized users (“Customers”), to drivers and personnel whose information Customers submit to the Service, and to visitors of our public websites. By accessing or using the Service, you acknowledge the practices described in this Policy. This Policy should be read together with our Terms of Service.
Where a Customer submits information about its drivers, employees, or contractors to the Service, we process that information on the Customer’s behalf and at its direction. The Customer is responsible for providing any notices to, and obtaining any consents from, its personnel that applicable law requires.
2. Information We Collect
Account Information
When an account is created, we collect the account holder’s name, email address, and phone number; company name and role; account credentials (passwords are stored only in salted, hashed form); and operating authority identifiers such as USDOT and MC numbers.
Fleet and Operational Data
In the course of providing the Service, we store the records our Customers create and manage on the platform, including driver records and qualification files, vehicle and equipment records, load and dispatch records, settlement and timesheet data, and maintenance and service logs.
ELD and Telematics Data
When a Customer connects an electronic logging device (ELD) or telematics provider of its choosing, the Service receives data from that provider, which may include hours-of-service logs and duty status, GPS location data, driver vehicle inspection reports, and engine diagnostics. These integrations are initiated, authorized, and controlled by the Customer.
Driver Application and Qualification Data
Through driver application and onboarding workflows, we may collect employment history and references, commercial driver’s license information and endorsements, motor vehicle records and accident history, and the last four digits of a Social Security number where used for identity verification in employment-verification workflows.
Payment Information
Subscription payments are processed by Stripe, Inc. We do not receive or store full payment card numbers or bank account credentials on our systems. Stripe’s handling of payment information is governed by its own privacy policy.
Documents and Electronic Signatures
We store files uploaded to the Service — including driver, vehicle, carrier, and insurance documents — and electronic signature records captured in accordance with the U.S. Electronic Signatures in Global and National Commerce Act (ESIGN).
Usage Information
We automatically collect certain technical information when the Service is used, including login times and session activity, features accessed, IP address and approximate location derived from it, and browser and device characteristics. We use this information for security, support, and product improvement.
3. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Service, including dispatch, compliance, settlement, and reporting features;
- Administer accounts and process subscription billing;
- Send transactional communications, such as verification codes, password resets, document alerts, and service notices;
- Support Customers’ regulatory compliance activities, including driver qualification file management and FMCSA-related record keeping;
- Provide customer support and respond to inquiries;
- Monitor, secure, and improve the Service, including detecting and preventing fraud and unauthorized access;
- Process queries submitted to optional AI-assisted features, which operate on the Customer’s own fleet data; and
- Comply with legal obligations.
4. How We Share Information
We do not sell personal information, and we do not share personal information with advertisers, data brokers, or advertising networks. We disclose information only in the following circumstances:
- Service providers. We engage vendors that perform services on our behalf, including cloud infrastructure, database, and file-storage providers; email and SMS delivery providers; mapping and geocoding providers; communications providers; and AI processing providers supporting optional platform features. These vendors are permitted to process information only as necessary to provide their services to us. A current list of subprocessors is available upon request.
- Payment processing. Subscription billing is handled by Stripe, as described in Section 2.
- Customer-directed integrations. When a Customer connects an ELD, fuel card, accounting, or similar third-party integration, information is exchanged with that provider at the Customer’s direction and under the Customer’s agreement with that provider.
- FMCSA and public records. Compliance features may query publicly available government data sources, such as the FMCSA SAFER system, using carrier identifiers.
- Legal requirements. We may disclose information where required by law, regulation, subpoena, or court order, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of Ziply Fleet, our Customers, or others.
- Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy’s protections.
5. Cookies and Similar Technologies
The Service uses only the browser storage necessary for it to function: secure session tokens that maintain your login session, and local preferences such as interface settings. We do not use third-party advertising cookies, tracking pixels, or cross-site behavioral advertising technologies. Because we use only essential storage, no cookie-consent banner is presented.
6. Data Security
We maintain administrative, technical, and physical safeguards designed to protect information processed through the Service, including:
- Encryption of data in transit and at rest;
- Logical separation of each Customer’s data within our multi-tenant environment, with access controls enforced on every request;
- Role-based access controls within each Customer account;
- Optional two-factor authentication;
- Salted one-way hashing of passwords;
- Documents stored in private storage with access provided through expiring, signed links; and
- Rate limiting and monitoring designed to detect abuse and unauthorized access attempts.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for maintaining the confidentiality of their credentials and for appropriately managing user roles within their accounts.
7. Data Retention
We retain information for as long as an account remains active. Following cancellation, data remains available for export for thirty (30) days, after which it is deleted from our production systems, except where longer retention is required by law — for example, records subject to FMCSA retention requirements, such as driver qualification files, accident registers, and hours-of-service records. Residual copies may persist in encrypted backups for a limited period as part of our disaster-recovery processes before being overwritten in the ordinary course.
8. Security Incident Notification
If we become aware of a security incident affecting personal information, we will investigate, take appropriate remedial measures, and notify affected Customers without undue delay, consistent with applicable law and any legitimate needs of law enforcement. Notifications will describe the nature of the incident, the categories of information involved, and the measures taken in response.
9. Location Data and ELD Integrations
The Service displays GPS and location data received from ELD and telematics providers that Customers connect. Customers are responsible for obtaining any consents from their drivers that applicable law requires before enabling location tracking, and for complying with applicable employee-monitoring laws. Ziply Fleet does not independently track drivers outside of the integrations configured and controlled by the Customer.
10. Your Rights and Choices
Subject to applicable law, you may request access to, a copy of, correction of, or deletion of your personal information. Deletion requests are subject to legal retention obligations, including federally mandated record-keeping periods. Customers may export their data at any time through the platform. You may opt out of marketing communications at any time; transactional communications necessary to operate an active account (such as security alerts and password resets) will continue.
California Residents
California residents have the rights provided by the California Consumer Privacy Act, as amended, including the right to know the categories of personal information we collect and the purposes for which it is used, the right to request deletion, and the right not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under California law.
Users in the EEA and United Kingdom
Where the EU or UK General Data Protection Regulation applies, you have the rights of access, rectification, erasure, restriction, objection, and data portability, and the right to withdraw consent where processing is based on consent. Our legal bases for processing include performance of a contract, compliance with legal obligations, and our legitimate interests in operating and securing the Service.
To exercise any of these rights, contact us as described in Section 14. We respond to verified requests within thirty (30) days.
11. Children’s Privacy
The Service is designed for businesses and their authorized personnel and is not directed to individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe we have collected information from a minor, please contact us and we will delete it promptly.
12. International Data Transfers
The Service is operated from the United States, and information processed through the Service is stored and processed in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction.
13. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. For material changes, we will provide at least thirty (30) days’ notice by email or through the Service and will update the “Last Updated” date above. Continued use of the Service after the effective date of a revised Policy constitutes acceptance of the revision.
14. Contact Us
Questions or requests concerning this Policy may be directed to:
Ziply Fleet Inc.
Email: [email protected]
Web: ziplyfleet.com/contact