← Back to Carrier Base
CARRIER BASE / HELP & POLICIES

Privacy policy

How we handle information when you visit our website, contact us, or use a Carrier Base workspace.

Effective September 7, 2026

1. Scope

This policy covers carrierbasecrm.com and app.carrierbasecrm.com. Carrier Base handles account, website, support, and billing information to run the service. When an agency enters information about its customers, drivers, employees, or prospects, the agency determines why that information is used; we process it to provide the agency’s workspace. The agency’s own privacy notices also apply to its use of that information.

2. Information we collect

  • Account and team information: names, work email addresses, agency details, roles, invitations, and account security information.
  • Agency records: the contact, business, driver, vehicle, coverage, policy, task, note, and activity information users enter into their workspace, including uploaded documents.
  • Requests and support: the name, email, phone number, agency name, and message you choose to provide.
  • Billing information: subscription choices, billing status, customer identifiers, and transaction records. Stripe collects payment details in its hosted checkout; Carrier Base does not receive your full payment card number or card security code through that checkout.
  • Technical and security information: request and device information, sign-in activity, timestamps, service errors, usage events, and audit records needed to operate, troubleshoot, and protect the service.

3. How we use information

We use information to create and secure accounts, provide agency workspaces, process subscriptions, respond to requests, send account and security emails, understand service usage, diagnose problems, prevent abuse, and meet legal obligations. Account and security emails are part of operating the service.

4. When information is shared

Authorized members of your agency can access information according to their role. Authorized Carrier Base staff may access agency information when needed for support or administration; customer workspace access uses time limits, a recorded reason, and audit logging.

We use service providers to host the website and app, store data, authenticate users, process payments, and deliver emails. These currently include OpenAI Sites and its hosting infrastructure, Vercel, Supabase, Stripe, and Resend. When document scanning is enabled, uploaded file content is sent to Cloudmersive to check for malware and unsafe content before downloads are allowed. They process information needed to perform their services and may maintain operational or security records. We may also disclose information to comply with law, protect rights and safety, or complete a business transfer subject to appropriate protections.

5. Cookies and similar technology

The application uses authentication cookies and related browser storage to maintain sign-in and security. Blocking necessary cookies can prevent sign-in or other features from working. Our application code does not currently include an advertising pixel or third-party advertising analytics. Hosting and payment providers may use their own necessary technologies when you interact with their services.

6. Retention and deletion

We retain information as needed to provide the service, maintain security and backups, resolve disputes, and meet accounting or legal obligations. Retention depends on the information and purpose. Cancellation stops subscription renewal; it does not automatically request deletion of all agency data. Contact us to request an export or deletion. Some information may remain in backups until those backups expire, or in records that must be retained for legal or security reasons.

7. Security

We use controls including encrypted connections, agency access policies, restricted administrative access, and security logging. No service can guarantee absolute security. Use a unique password, enable multifactor authentication, keep each person’s sign-in separate, and promptly remove access that is no longer needed. Report a suspected account or data security issue to kmorrissy@carrierbasecrm.com.

8. Requests and choices

Contact kmorrissy@carrierbasecrm.com to ask about access, correction, export, or deletion of your information, or other rights available under applicable law. We may verify your identity and authority before acting. For records held by an agency using Carrier Base, contact that agency first; we can help it respond. An authorized agent may contact us with evidence of authorization where applicable.

9. Location and intended users

The service is intended for adults using it for business. It is not directed to children under 18. Our providers may process information in the United States and other locations where they operate. Contact us before entering information that requires a specific data location or a separate processing agreement.

10. Changes and contact

We will update the effective date when this policy changes and provide additional notice of material changes where required. For privacy questions, contact kmorrissy@carrierbasecrm.com.