Skip to main content
Privacy PolicyEffective April 26, 2026

Your data, your operation

We handle carrier data with the same operational discipline we build into the platform.

This policy explains what data RigBase collects, why we collect it, how we use and protect it, and what control you have over it. We've written it to be readable, not just legally compliant.

The short version

We collect what operations require

Account credentials, fleet records, driver profiles, load data, and compliance documents — only the data needed to run carrier operations.

We don't sell your data

Customer data is never sold, rented, or traded to third parties for advertising or data-broker purposes.

Org-scoped by design

Data is partitioned by organization. One carrier's records are never accessible to another tenant.

Encrypted in transit and at rest

All communication uses TLS 1.2+. Database records are encrypted at rest through our infrastructure provider.

You control your data

You can export, correct, or request deletion of your organizational data at any time by contacting our team.

US-based infrastructure

Primary data storage and processing occurs in US-East regions through our infrastructure provider, Supabase.

1. Information We Collect

Account and identity data

When you create a RigBase account or are added to an organization by an administrator, we collect your name, work email address, role, and authentication credentials. We do not store raw passwords — credentials are hashed using industry-standard algorithms.

Operational and fleet data

The core function of the platform requires operational records. This includes:

  • Driver profiles: name, CDL number, license state, medical card status, endorsements, and linked contact details
  • Vehicle records: VIN, unit number, license plate, year, make, model, and associated maintenance history
  • Load records: origin and destination, commodity, weight, assigned driver and vehicle, status, and billing details
  • Pre-trip inspection (PTI) submissions including inspection results, defects noted, and driver sign-off data
  • Safety and compliance records: incidents, violations, FMCSA data links, CSA scores, and DOT inspection outcomes
  • Work orders and PM schedules tied to fleet equipment
  • Documents uploaded by users, including registrations, proof-of-delivery, and incident supporting files

Usage and telemetry data

We collect information about how users interact with the platform — page views, feature usage frequency, session duration, and error events. This data is aggregated and used to improve the product. We use Sentry for error monitoring and may capture stack traces and session context when application errors occur.

Device and network data

Standard HTTP request metadata is logged by our infrastructure: IP address, browser or app user-agent, device type, and referring URL. These logs are retained for security and diagnostic purposes for up to 90 days.

Communication data

If you contact our support team or submit a lead inquiry through the contact-sales form, we retain the content of those communications to respond to your request and improve our support processes.

2. How We Use Information

We use the data we collect for the following purposes:

  • Delivering and maintaining the platform — authentication, feature access, real-time dispatch events, PTI sync, and notification delivery
  • Providing customer support — diagnosing reported issues, reproducing bugs, and communicating resolutions
  • Improving the product — analyzing aggregate usage patterns, prioritizing features, and identifying error-prone workflows
  • Security and fraud prevention — detecting anomalous access patterns, protecting user accounts, and responding to incidents
  • Billing and subscription management — processing payments, generating invoices, and managing subscription state
  • Legal compliance — maintaining records required by applicable law and responding to lawful government requests

We do not use your operational fleet or driver data to train AI models or derive insights for third-party commercial purposes.

3. Data Sharing

We don't sell your data

RigBase does not sell, rent, or broker customer data to third parties for advertising, marketing, or data-broker purposes — ever.

Service providers

We share data with third-party vendors who help us operate the platform. These providers are contractually bound to use data only as directed and to maintain appropriate security practices. See Section 4 for the current subprocessor list.

Legal requirements

We may disclose data when required by law, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of RigBase, our customers, or the public.

Business transfers

In the event of a merger, acquisition, or sale of assets, customer data may be transferred as part of that transaction. We will notify affected account holders via email prior to any such transfer and before data becomes subject to a materially different privacy policy.

Within your organization

Users within the same organizational tenant can access data scoped to that organization based on their assigned role. Administrators control which roles can access which features and records. Cross-tenant data access is technically prevented at the database level.

4. Subprocessors

The following third-party service providers process data on behalf of RigBase:

ProviderPurposeData region
SupabaseDatabase, authentication, and real-time infrastructureUS-East
SentryError monitoring and session diagnosticsUS
Resend / SendGridTransactional email deliveryUS
StripePayment processing and subscription billingUS
VercelApplication hosting and edge deliveryUS / Global CDN
SamsaraVehicle telematics — GPS, odometer, and engine-hours data retrieved via API when vehicles are linkedUS

We review subprocessors periodically. Material additions will be announced via our changelog and reflected in an updated version of this policy.

5. Cookies & Tracking

RigBase uses a minimal set of cookies and browser storage mechanisms necessary to operate the platform. We do not use third-party advertising cookies or cross-site tracking.

Session cookies

Authentication tokens issued by Supabase Auth are stored as secure, HttpOnly cookies scoped to the platform domain. These are required to maintain your authenticated session.

Functional storage

Certain user preferences — such as notification settings and UI state — are persisted in localStorage or as short-lived session cookies. This data never leaves your browser to third-party domains.

Analytics

If we use analytics tooling, it is configured to anonymize IP addresses, respect browser Do-Not-Track signals, and avoid fingerprinting. We do not use behavioral advertising pixels from ad platforms.

You can clear all locally stored data at any time through your browser's settings without impacting your organizational records stored server-side.

6. Data Retention

We retain data for as long as your organization's account is active. Specific retention windows:

  • Active account data (fleet records, loads, drivers, compliance docs): retained for the duration of the subscription plus a 90-day post-cancellation window
  • Error and diagnostic logs: retained for up to 90 days in Sentry before rolling deletion
  • Infrastructure access logs: retained for 90 days
  • Billing and payment records: retained for 7 years to satisfy financial and tax compliance obligations
  • Support communications: retained for 3 years after ticket closure

After account deletion is confirmed, we will remove or anonymize your organization's operational records within 30 days, except where retention is required by applicable law.

7. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

Access

Request a copy of the personal data we hold about you.

Correction

Request correction of inaccurate or incomplete personal data.

Deletion

Request deletion of your personal data, subject to legal retention requirements.

Portability

Request your data in a machine-readable format for transfer to another service.

To exercise any of these rights, contact us at privacy@rigbase.io. We will respond within 30 days. Identity verification may be required before we fulfill a data request.

For California residents (CCPA): You have the right to know, delete, and opt out of sale. We do not sell personal information, so the opt-out right is satisfied by default.

8. Security Practices

We apply the following controls to protect customer data:

  • TLS 1.2+ encryption on all data in transit between clients, our application layer, and infrastructure providers
  • AES-256 encryption at rest on all database storage through Supabase's managed infrastructure
  • Role-based access control enforced at the database row level — users can only query data within their organization's scope
  • Authentication tokens issued with short expiry windows and rotating refresh token mechanics
  • Automated vulnerability scanning on application dependencies as part of the CI/CD pipeline
  • Incident response procedures for security events with defined escalation and notification timelines

No system is perfectly secure. If you discover a potential security vulnerability in the platform, please disclose it responsibly to security@rigbase.io before public disclosure.

9. Children's Privacy

RigBase is a business-to-business platform designed for use by organizations and their employees in a commercial trucking context. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have inadvertently collected such data, we will delete it promptly.

10. International Transfers

RigBase is operated primarily from the United States. If you access the platform from outside the US, your data will be transferred to and processed in the United States. By using the platform, you acknowledge this transfer.

For users in the European Economic Area or UK, transfers occur under appropriate safeguards including Standard Contractual Clauses where applicable. Contact us for a copy of applicable transfer mechanisms.

11. Policy Changes

We may update this Privacy Policy as the platform evolves. When we make material changes — such as new data collection categories or changes to sharing practices — we will notify account administrators via email at least 14 days before the change takes effect.

Non-material changes (such as clarifying language or correcting formatting) will be reflected in an updated effective date at the top of this page. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

12. Contact Us

For questions, requests, or concerns about this Privacy Policy or our data practices:

RigBase — Privacy Team

Questions about how your carrier data is handled?

Our team can walk through data boundaries, org isolation, and infrastructure controls in the context of your specific operation and compliance requirements.