Legal

Privacy Policy

How LogAI.ai collects, uses, stores, and protects personal information and freight operational data — including carrier data, call recordings, ELD position data, and your rights under GDPR and CCPA.

1.Who we are and scope of this policy

LogAI.ai is operated by erp.io, Inc. ("we," "us," or "our"). This Privacy Policy describes how we collect, use, store, share, and protect personal information and operational data in connection with the LogAI.ai platform, the LogAI Exchange load board, the Phony automated calling module, and all associated features and integrations.

This policy covers two categories of people: (a) Contacts — employees, contractors, and representatives of our customers and prospective customers who interact with the platform or our website; and (b) Third-party individuals whose data our customers enter into the platform in connection with their freight operations (carrier drivers and dispatchers, shipper and consignee contacts, referred to as "End Contacts").

For customers operating in the European Economic Area (EEA), Switzerland, or the United Kingdom, this policy also serves as the basis for data processing under the GDPR and applicable national laws. Our data processing addendum (DPA), which governs the processor-controller relationship for Customer Data, is available on request.

2.Controller and processor roles

For personal information about Contacts (our customers' employees and representatives): we are the data controller. We determine the purposes and means of processing this data to operate and improve the platform.

For Customer Data — load records, freight documents, carrier contact information, shipment history, and all other data that customers enter into the platform in the course of their freight operations: our customers are the data controllers. We are a data processor acting on their behalf. Processing of Customer Data is governed by our Terms of Service and, for customers requiring a data processing agreement, our DPA.

This distinction matters: if you are a carrier driver or dispatcher whose contact information appears in a LogAI.ai customer's load record, your data is controlled by that customer (our client), not directly by us. Requests relating to that data should be directed to the customer. We will assist customers in fulfilling data subject requests as required by law.

3.Data we collect

We collect the following categories of information:

(a) Account and contact data. Name, work email address, job title, company name, phone number, and password (stored as a hash). Collected when you create an account, submit a contact form, or engage with our sales team.

(b) Load and operational data (Customer Data). Freight load records including: shipper and consignee name, address, and contact information; carrier name, MC/DOT number, driver name, driver phone number, and contact email; commodity description, weight, dimensions, and NMFC classification; pickup and delivery dates, appointment times, and addresses; rate confirmation amounts, accessorial charges, and fuel surcharge rates; load status history and event timeline; and any documents uploaded by customers, including bills of lading (BOLs), signed proofs of delivery (PODs), carrier invoices, rate confirmations, lumper receipts, and scale tickets.

(c) Carrier and third-party compliance data. FMCSA-sourced data including carrier operating authority status, safety rating, out-of-service rate, insurance on file (Certificates of Insurance on file with FMCSA), and bonding information. This data is obtained from FMCSA public databases and third-party carrier data providers and is refreshed periodically. We do not control the accuracy of this data.

(d) Call recordings and transcripts. When the Phony automated calling module is used, outbound and inbound calls are recorded and transcribed. Recordings are stored as part of the load event record and are linked to the specific load for which the call was placed. Recordings may capture the voices and statements of carrier drivers, dispatchers, and other individuals.

(e) ELD and telematics position data. When customers connect a Samsara, Motive, or other ELD integration, position pings for in-transit loads are ingested. Position data includes: GPS coordinates, speed, heading, and ELD unit identifier. Position data is associated with the specific load record and is retained as part of the load event history.

(f) EDI transaction data. EDI 204 (load tenders), EDI 210 (carrier invoices), and EDI 214 (shipment status updates) transmitted through the platform are stored and associated with the relevant load record.

(g) Usage data. Pages visited, features used, session start and end times, browser type, operating system, IP address, and referral URL. Collected via server logs and first-party analytics.

(h) Communication data. Emails sent to or from LogAI.ai-connected inboxes (where customers have configured email integration), including sender, recipient, subject, and body — stored as part of the load capture workflow.

5.How we use data

Account and contact data is used to: create and manage your account; authenticate your identity; communicate with you about your subscription, billing, and service updates; provide customer support; and send product updates and announcements relevant to your use of the platform.

Load and operational data is used to: provide the load lifecycle management features of the platform; process documents, extract data, and classify freight records on your behalf; execute agent workflows including check calls, invoice audit, and POD collection; and display data in the shipper and carrier visibility portals.

Carrier compliance data is used to: display carrier safety information to dispatchers during carrier selection; and flag carriers with active out-of-service orders or authority revocations. We do not use this data to make credit or insurance decisions.

Call recordings and transcripts are used to: attach call evidence to the load event record; extract position and ETA information; and detect exceptions reported during calls. Recordings are accessible to the dispatchers and administrators of the customer account that directed the call.

ELD and telematics data is used to: update load position and recalculate ETA; trigger state machine transitions (e.g., at_pickup, in_transit); and reduce the frequency of check calls when live ELD data is available.

Aggregated and de-identified data is used to: improve AI extraction accuracy and agent performance; develop new features; and produce industry benchmarks that do not identify any individual customer or shipper. De-identification is performed by removing or hashing all direct identifiers (company name, MC number, contact information) before this data is used for model training.

We do not sell personal data. We do not use Customer Data or load records for advertising purposes, whether on our own platform or third-party advertising networks.

6.FMCSA and publicly available carrier data

Carrier operating authority, safety ratings, out-of-service percentages, and insurance records displayed in the platform are sourced from the FMCSA's SAFER system and related public databases. This data is public information. We retrieve and cache it to provide convenient access within the load lifecycle workflow.

We update carrier FMCSA data periodically, but we do not guarantee that cached data reflects the current status at any given moment. Customers should independently verify carrier authority and insurance status for compliance purposes.

Carrier contact information (driver names, phone numbers, dispatcher email addresses) entered into load records by customers is Customer Data controlled by the customer. We process this data on the customer's behalf solely for the purposes of the load lifecycle workflow, including automated check calls and POD outreach.

7.Automated calling and call recording

The Phony module places automated calls at the direction of LogAI.ai customers. Calls are recorded and transcribed. The customer directing the call is responsible for complying with all applicable call recording disclosure laws in the jurisdictions where calls are placed and received, including: two-party or all-party consent states under applicable U.S. state wiretapping laws; the TCPA and FCC regulations; and applicable laws in non-U.S. jurisdictions.

LogAI.ai processes call recordings and transcripts as a data processor under the customer's instruction. The customer is responsible for ensuring that its use of automated calling and call recording complies with applicable law.

Call recordings are retained as part of the load event record for the duration of the customer's subscription plus 30 days. Customers may access, download, or request deletion of call recordings through their account settings or by contacting support.

8.ELD and telematics data

Position data from ELD integrations (Samsara, Motive, and other connected providers) is collected under the authority of the customer, who has established its own data sharing relationship with the ELD provider. LogAI.ai receives position data transmitted by the ELD provider's API in connection with specific load records.

ELD position data is used only for the load lifecycle purposes described in Section 5. Position data is not used to build profiles of individual drivers beyond the specific load context. We do not sell or disclose ELD position data to third parties except as required to operate the platform (e.g., displaying position in the shipper visibility portal) or as required by law.

Customers are responsible for ensuring their use of ELD data in the platform complies with applicable FMCSA ELD regulations, EEOC guidance on electronic monitoring, and any applicable collective bargaining agreements.

9.Third-party integrations and data sharing

Customers may connect LogAI.ai to third-party systems including TMS platforms (McLeod, MercuryGate, Trimble TMW), ERP and accounting systems (QuickBooks, NetSuite), ELD providers (Samsara, Motive), load board platforms (DAT, Truckstop), and EDI clearing networks. Data shared with these integrations is governed by the customer's agreements with those third parties.

We share data with third-party subprocessors necessary to operate the platform. A complete list of subprocessors is maintained at logai.ai/legal/sub-processors. We notify customers of material changes to subprocessor relationships at least 30 days in advance.

We do not share personal data with third parties for their own marketing or advertising purposes. We may share data with law enforcement, regulatory authorities, or other parties where required by applicable law, court order, or valid legal process.

10.Data retention

Customer Data (load records, freight documents, carrier contacts, call recordings, ELD position history, EDI transactions) is retained for the duration of the customer's active subscription. Upon termination, Customer Data is retained for 30 days to allow for export, and then deleted or de-identified within 60 days of termination.

Account and contact data for active users is retained for the duration of the subscription. For former users who retain access to historical records (e.g., after leaving an organization), contact data associated with their account is retained until the customer account terminates or the individual requests deletion.

Usage and analytics data (server logs, session metadata) is retained for up to 12 months and then purged or anonymized. Call recordings are retained with the load event record on the same schedule as Customer Data.

We may retain data for longer periods where required by applicable law (e.g., tax records, litigation holds) or where we have a legitimate interest in retention for fraud prevention or legal defense.

Customers may request a bulk export of their Customer Data at any time during the subscription. Export is available in JSON and CSV formats for load records and in PDF or original format for freight documents. Contact [email protected] to initiate an export.

11.Data security

We implement technical and organizational measures designed to protect Customer Data against unauthorized access, disclosure, alteration, or destruction. These measures include: encryption of data in transit (TLS 1.2+) and at rest; access controls and role-based permissions; multi-factor authentication for administrative access; audit logging of data access and modifications; and penetration testing by third-party security researchers on a periodic basis.

We operate on enterprise-grade cloud infrastructure with SOC 2 Type II certified subprocessors. Our security practices are described in the Security Overview at logai.ai/security.

In the event of a security incident that affects Customer Data, we will notify affected customers without undue delay and in accordance with applicable breach notification laws. Notification will be provided to the account's primary contact email.

12.International data transfers

LogAI.ai is operated primarily in the United States. If you or your organization are located in the EEA, Switzerland, or the United Kingdom, your data may be transferred to and processed in the United States. We transfer data under the following safeguards:

For transfers to our U.S. infrastructure: Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable, incorporated into our data processing addendum.

For transfers to U.S.-based subprocessors: We require subprocessors to implement equivalent transfer safeguards. Our subprocessor list indicates the country of operation and applicable transfer mechanism for each subprocessor.

For freight operations data involving cross-border shipments (e.g., U.S.-Canada, U.S.-Mexico): customs documents, BOLs, and shipping records may contain data subject to the data protection laws of the originating and destination countries. Customer is responsible for ensuring its cross-border data handling complies with applicable law.

13.Your rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

(a) Access. Request a copy of the personal data we hold about you as a Contact.

(b) Correction. Request correction of inaccurate personal data.

(c) Deletion. Request deletion of your personal data, subject to our legal retention obligations and the interests of other users.

(d) Data portability. Request a copy of your data in a machine-readable format, where technically feasible.

(e) Objection. Object to processing based on legitimate interests, or to direct marketing.

(f) Restriction. Request that we restrict processing of your data while a dispute is resolved.

For California residents under the CCPA: you have the right to know what categories of personal information we have collected about you, the right to delete personal information we have collected, the right to opt out of the sale of personal information (we do not sell personal information), and the right not to be discriminated against for exercising CCPA rights.

To exercise any of these rights, contact us at [email protected]. We will respond to verifiable requests within 30 days (or within the timeframe required by applicable law). We may request additional information to verify your identity before processing a request.

For requests relating to Customer Data (data entered by our customers into the platform): because we are a processor for that data, we will refer your request to the appropriate customer. We will assist customers in fulfilling data subject requests as required by applicable law.

14.Cookies and analytics

We use the following types of cookies and similar technologies:

(a) Essential cookies. Session authentication cookies and CSRF protection tokens. These are required for the platform to function and cannot be disabled.

(b) First-party analytics. We use first-party, privacy-focused analytics to measure page visits and feature usage. This analytics system does not use third-party cookies and does not track individuals across sites.

(c) Preference cookies. Cookies that remember your dashboard layout preferences and notification settings.

We do not use third-party advertising cookies, retargeting pixels, or cross-site tracking technologies. We do not share browsing data with advertising networks.

Most browsers allow you to block or delete cookies. Blocking essential cookies will prevent you from logging in and using the platform.

15.Children's privacy

LogAI.ai is a business-to-business platform intended for use by organizations and their authorized employees and contractors. We do not knowingly collect personal information from individuals under the age of 18. If we learn that we have collected personal information from a minor, we will delete it. If you believe a minor has provided us with personal information, contact [email protected].

16.Security incident notification

In the event of a security incident that involves unauthorized access to or disclosure of Customer Data, we will: (a) notify affected customers without undue delay, and in any event within 72 hours of becoming aware of the incident where required by applicable law; (b) provide the following information in the notification: the nature of the incident, the categories and approximate number of individuals and records affected, the likely consequences of the incident, and the measures taken or proposed to address the incident; and (c) cooperate with affected customers to help them meet their own notification obligations to end users and regulators.

Notifications will be sent to the primary contact email address on file for the account. Customers are responsible for providing accurate and current contact information.

17.Changes to this policy

We may update this Privacy Policy as the platform and applicable law evolve. Material changes — those that affect how we use Customer Data or the rights of individuals — will be communicated to the primary account contact by email at least 30 days before they take effect. Non-material changes (clarifications, additions that expand privacy protections) may be posted with shorter notice.

The "Last updated" date at the top of this policy indicates when it was most recently revised. Continued use of the service after the effective date of an updated policy constitutes acceptance of the updated terms.

18.Contact and data protection officer

For privacy questions, data subject requests, or concerns about this policy, contact us at:

Email: [email protected]

For enterprise customers requiring a data processing addendum (DPA) for GDPR compliance or a Business Associate Agreement (BAA) for HIPAA compliance, contact [email protected].

If you are located in the EEA and believe we have not addressed your concern adequately, you have the right to lodge a complaint with the supervisory authority in your country of residence.