Privacy Policy

Effective Date: January 1, 2025

Last Updated: January 1, 2025

At Cenntrax, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our transportation management platform and related services.

By using Cenntrax, you agree to the terms outlined in this Privacy Policy. If you do not agree with our practices, please do not use our services.

1. Information We Collect

Personal Information: When you register for Cenntrax, we collect information such as your name, email address, phone number, company name, and billing information.

Usage Data: We automatically collect information about how you use our services, including delivery data, route information, driver performance metrics, and system logs.

Device Information: We collect information about the devices you use to access our services, including IP address, browser type, operating system, and mobile device identifiers.

Location Data: With your permission, we collect GPS location data from your drivers' devices to enable real-time tracking and route optimization features.

2. How We Use Your Information

Service Delivery: We use your information to provide, maintain, and improve our transportation management services, including route optimization, fleet tracking, and delivery management.

Communication: We may send you service-related emails, updates about your account, and important notices about changes to our services or policies.

Analytics: We analyze usage patterns to improve our platform, develop new features, and enhance user experience.

Security: We use your information to protect against fraud, abuse, and security threats, and to ensure the safety of our platform.

Legal Compliance: We may use your information to comply with applicable laws, regulations, and legal processes.

3. Information Sharing and Disclosure

Multi-Tenant Isolation: Cenntrax operates as a multi-tenant platform with complete data isolation. Your data is never shared with other tenants or organizations.

Service Providers: We may share information with trusted third-party service providers who assist us in operating our platform, such as cloud hosting providers (AWS), payment processors, and email service providers.

Legal Requirements: We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to the same privacy protections.

With Your Consent: We will share information for any other purposes with your explicit consent.

4. Data Security

Encryption: All data is encrypted both at rest and in transit using industry-standard encryption protocols (TLS 1.2/1.3, AES-256).

Dedicated Infrastructure: Each client receives dedicated AWS resources (EC2, S3, Aurora) with complete isolation from other tenants.

Access Controls: We implement strict access controls, multi-factor authentication, and role-based permissions to protect your data.

Regular Audits: We conduct regular security audits, vulnerability assessments, and penetration testing to identify and address potential security risks.

Backup and Recovery: Automated daily backups ensure data recovery in case of system failures or data loss incidents.

Security Monitoring: 24/7 security monitoring and intrusion detection systems protect against unauthorized access.

5. Data Retention

Active Accounts: We retain your data for as long as your account remains active and you continue to use our services.

Terminated Accounts: After account termination, we retain your data for up to 90 days to allow for data export and account recovery.

Legal Requirements: We may retain certain information longer if required by law or for legitimate business purposes, such as fraud prevention and financial records.

Anonymized Data: We may retain anonymized or aggregated data indefinitely for analytics and service improvement purposes.

6. Your Privacy Rights

Access: You have the right to access your personal information and request a copy of the data we hold about you.

Correction: You can request corrections to inaccurate or incomplete personal information.

Deletion: You have the right to request deletion of your personal information, subject to legal and contractual obligations.

Data Portability: You can request a copy of your data in a structured, machine-readable format for transfer to another service provider.

Opt-Out: You can opt out of marketing communications at any time by clicking the unsubscribe link in our emails.

Restriction: You can request restriction of processing your personal data in certain circumstances.

7. Regulatory Compliance

PIPEDA (Canada): We comply with Canada's Personal Information Protection and Electronic Documents Act for the collection, use, and disclosure of personal information.

GDPR (European Union): For users in the EU, we comply with the General Data Protection Regulation, including data subject rights and lawful bases for processing.

CCPA (California): California residents have specific rights under the California Consumer Privacy Act, including the right to know, delete, and opt-out of the sale of personal information.

HIPAA Ready: For healthcare logistics clients, we provide HIPAA-compliant infrastructure and security controls.

SOC 2 Type II: Our platform is SOC 2 Type II certified, demonstrating our commitment to security, availability, and confidentiality.

8. Cookies and Tracking Technologies

Essential Cookies: We use necessary cookies to enable core functionality, such as authentication and session management.

Analytics Cookies: We use analytics tools to understand how users interact with our platform and improve user experience.

Preference Cookies: These cookies remember your preferences and settings for a personalized experience.

Cookie Control: You can control cookie preferences through your browser settings, though disabling certain cookies may affect platform functionality.

9. Children's Privacy

Cenntrax is designed for business use and is not intended for children under the age of 13. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information.

10. International Data Transfers

Data Location: Your data is stored in AWS data centers in your selected region (US, Canada, or EU).

Cross-Border Transfers: If data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses and data processing agreements.

Data Residency: Enterprise clients can specify data residency requirements to ensure compliance with local regulations.

11. Changes to Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes via email or through our platform. Your continued use of Cenntrax after changes become effective constitutes acceptance of the updated Privacy Policy.

12. Contact Us

Questions about our Privacy Policy

If you have questions or concerns about this Privacy Policy or our data practices, please contact our Privacy Team:

We're Committed to Your Privacy

Cenntrax is compliant with major privacy regulations and certified to the highest security standards.

✓ PIPEDA Compliant
✓ GDPR Compliant
✓ SOC 2 Type II
✓ HIPAA Ready
✓ ISO 27001