Data handling

How we use and protect your data

How the current CarrierTrail service handles information, updated 2026-09-13.

Public source records

We import selected public FMCSA records to support lookup, monitoring and directory pages. The free lookup shows company identity, reported location and fleet fields. Directory pages publish aggregate statistics and a limited selection of public company records.

Workspace information

Account email addresses, password hashes, sessions, workspace memberships, watchlists, notes and decisions are stored to provide the private service. Passwords are stored using scrypt hashes. Membership checks restrict workspace access. Pausing a carrier retains its notes and decisions; it does not delete them.

Service providers and browser storage

The service runs on Netcup with PostgreSQL. Cloudflare handles public HTTPS traffic and stores private source archives and backups. Resend processes requested account and alert emails. Stripe processes subscription payments and billing details; CarrierTrail stores customer and subscription identifiers, plan, payment status and the paid access period. Card details are entered on Stripe, not stored in the CarrierTrail database. Necessary cookies support sign-in and protection against forged requests. Cloudflare Turnstile checks signup, sign-in, password recovery and contact submissions for automated abuse. Dashboard fonts are loaded from Google Fonts; the public site uses system fonts. No advertising or marketing analytics scripts are added by this site.

Contact requests and abuse prevention

The contact form stores the email, optional company, request type, message and submission time for review. It does not enroll the sender in marketing emails. Public request limits use a keyed hash of the connecting network address; these rate-limit records are removed after 24 hours when subsequent requests are processed. Hosting and security providers may separately process network request information.

Retention and questions

Workspace records and contact requests are retained until handled through the service’s administrative process. Private offsite database backups have a 30-day expiration rule; local cleanup removes offsite-verified database backups older than 30 days while retaining at least seven local dumps. Use the contact form to ask about your data, request correction or request removal. See the subscription terms for billing and cancellation details.

Continuing a carrier review

When you choose a monitoring plan from a public carrier profile, this browser tab temporarily remembers the public USDOT number and selection time in session storage. This keeps your selection through signup and payment on the same tab. It is used for navigation, not analytics, expires from use after 24 hours and is cleared when the workspace opens the review prompt. It does not automatically add a carrier or store customer notes.