Your data, your operation
We handle carrier data with the same operational discipline we build into the platform.
This policy explains what data RigBase collects, why we collect it, how we use and protect it, and what control you have over it. We've written it to be readable, not just legally compliant.
The short version
We collect what operations require
Account credentials, fleet records, driver profiles, load data, and compliance documents — only the data needed to run carrier operations.
We don't sell your data
Customer data is never sold, rented, or traded to third parties for advertising or data-broker purposes.
Org-scoped by design
Data is partitioned by organization. One carrier's records are never accessible to another tenant.
Encrypted in transit and at rest
All communication uses TLS 1.2+. Database records are encrypted at rest through our infrastructure provider.
You control your data
You can export, correct, or request deletion of your organizational data at any time by contacting our team.
US-based infrastructure
Primary data storage and processing occurs in US-East regions through our infrastructure provider, Supabase.
1. Information We Collect
Account and identity data
When you create a RigBase account or are added to an organization by an administrator, we collect your name, work email address, role, and authentication credentials. We do not store raw passwords — credentials are hashed using industry-standard algorithms.
Operational and fleet data
The core function of the platform requires operational records. This includes:
- Driver profiles: name, CDL number, license state, medical card status, endorsements, and linked contact details
- Vehicle records: VIN, unit number, license plate, year, make, model, and associated maintenance history
- Load records: origin and destination, commodity, weight, assigned driver and vehicle, status, and billing details
- Pre-trip inspection (PTI) submissions including inspection results, defects noted, and driver sign-off data
- Safety and compliance records: incidents, violations, FMCSA data links, CSA scores, and DOT inspection outcomes
- Work orders and PM schedules tied to fleet equipment
- Documents uploaded by users, including registrations, proof-of-delivery, and incident supporting files
Usage and telemetry data
We collect information about how users interact with the platform — page views, feature usage frequency, session duration, and error events. This data is aggregated and used to improve the product. We use Sentry for error monitoring and may capture stack traces and session context when application errors occur.
Device and network data
Standard HTTP request metadata is logged by our infrastructure: IP address, browser or app user-agent, device type, and referring URL. These logs are retained for security and diagnostic purposes for up to 90 days.
Communication data
If you contact our support team or submit a lead inquiry through the contact-sales form, we retain the content of those communications to respond to your request and improve our support processes.
2. How We Use Information
We use the data we collect for the following purposes:
- Delivering and maintaining the platform — authentication, feature access, real-time dispatch events, PTI sync, and notification delivery
- Providing customer support — diagnosing reported issues, reproducing bugs, and communicating resolutions
- Improving the product — analyzing aggregate usage patterns, prioritizing features, and identifying error-prone workflows
- Security and fraud prevention — detecting anomalous access patterns, protecting user accounts, and responding to incidents
- Billing and subscription management — processing payments, generating invoices, and managing subscription state
- Legal compliance — maintaining records required by applicable law and responding to lawful government requests
We do not use your operational fleet or driver data to train AI models or derive insights for third-party commercial purposes.
3. Data Sharing
We don't sell your data
RigBase does not sell, rent, or broker customer data to third parties for advertising, marketing, or data-broker purposes — ever.
Service providers
We share data with third-party vendors who help us operate the platform. These providers are contractually bound to use data only as directed and to maintain appropriate security practices. See Section 4 for the current subprocessor list.
Legal requirements
We may disclose data when required by law, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of RigBase, our customers, or the public.
Business transfers
In the event of a merger, acquisition, or sale of assets, customer data may be transferred as part of that transaction. We will notify affected account holders via email prior to any such transfer and before data becomes subject to a materially different privacy policy.
Within your organization
Users within the same organizational tenant can access data scoped to that organization based on their assigned role. Administrators control which roles can access which features and records. Cross-tenant data access is technically prevented at the database level.
4. Subprocessors
The following third-party service providers process data on behalf of RigBase:
| Provider | Purpose | Data region |
|---|---|---|
| Supabase | Database, authentication, and real-time infrastructure | US-East |
| Sentry | Error monitoring and session diagnostics | US |
| Resend / SendGrid | Transactional email delivery | US |
| Stripe | Payment processing and subscription billing | US |
| Vercel | Application hosting and edge delivery | US / Global CDN |
| Samsara | Vehicle telematics — GPS, odometer, and engine-hours data retrieved via API when vehicles are linked | US |
We review subprocessors periodically. Material additions will be announced via our changelog and reflected in an updated version of this policy.
6. Data Retention
We retain data for as long as your organization's account is active. Specific retention windows:
- Active account data (fleet records, loads, drivers, compliance docs): retained for the duration of the subscription plus a 90-day post-cancellation window
- Error and diagnostic logs: retained for up to 90 days in Sentry before rolling deletion
- Infrastructure access logs: retained for 90 days
- Billing and payment records: retained for 7 years to satisfy financial and tax compliance obligations
- Support communications: retained for 3 years after ticket closure
After account deletion is confirmed, we will remove or anonymize your organization's operational records within 30 days, except where retention is required by applicable law.
7. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
Access
Request a copy of the personal data we hold about you.
Correction
Request correction of inaccurate or incomplete personal data.
Deletion
Request deletion of your personal data, subject to legal retention requirements.
Portability
Request your data in a machine-readable format for transfer to another service.
To exercise any of these rights, contact us at privacy@rigbase.io. We will respond within 30 days. Identity verification may be required before we fulfill a data request.
For California residents (CCPA): You have the right to know, delete, and opt out of sale. We do not sell personal information, so the opt-out right is satisfied by default.
8. Security Practices
We apply the following controls to protect customer data:
- TLS 1.2+ encryption on all data in transit between clients, our application layer, and infrastructure providers
- AES-256 encryption at rest on all database storage through Supabase's managed infrastructure
- Role-based access control enforced at the database row level — users can only query data within their organization's scope
- Authentication tokens issued with short expiry windows and rotating refresh token mechanics
- Automated vulnerability scanning on application dependencies as part of the CI/CD pipeline
- Incident response procedures for security events with defined escalation and notification timelines
No system is perfectly secure. If you discover a potential security vulnerability in the platform, please disclose it responsibly to security@rigbase.io before public disclosure.
9. Children's Privacy
RigBase is a business-to-business platform designed for use by organizations and their employees in a commercial trucking context. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have inadvertently collected such data, we will delete it promptly.
10. International Transfers
RigBase is operated primarily from the United States. If you access the platform from outside the US, your data will be transferred to and processed in the United States. By using the platform, you acknowledge this transfer.
For users in the European Economic Area or UK, transfers occur under appropriate safeguards including Standard Contractual Clauses where applicable. Contact us for a copy of applicable transfer mechanisms.
11. Policy Changes
We may update this Privacy Policy as the platform evolves. When we make material changes — such as new data collection categories or changes to sharing practices — we will notify account administrators via email at least 14 days before the change takes effect.
Non-material changes (such as clarifying language or correcting formatting) will be reflected in an updated effective date at the top of this page. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
12. Contact Us
For questions, requests, or concerns about this Privacy Policy or our data practices:
RigBase — Privacy Team
Questions about how your carrier data is handled?
Our team can walk through data boundaries, org isolation, and infrastructure controls in the context of your specific operation and compliance requirements.