Privacy Policy
Effective October 8, 2026
privacy-2026-10-08-v2
This policy explains what information KeepCarrier collects, why, where it is stored, who it is shared with, and the choices you have. It applies to the KeepCarrier website and application (together, the "Service"), operated by KeepCarrier LLC ("we", "us"). It covers our handling of our customers' and their agents' information, and it explains how the carrier information in the product is sourced. It does not govern what our customers do with their own outreach lists; each customer is responsible for its own privacy practices.
On this page
- Processing roles and legal bases
- Trial eligibility and billing evidence
- Information we collect
- Carrier registry data
- How we use information
- How calling, texting, and email work
- Cookies
- Service providers and disclosures
- Our own social media accounts
- Storage and security
- Data retention
- Your rights and choices
- Children
- International users
- Changes to this policy
Processing roles and legal bases
For customer-controlled workspace data, your organization determines the purposes and KeepCarrier processes on its documented instructions under the Data Processing Addendum. For our account administration, billing, security, support and independently compiled public registry records, we determine the relevant purposes. A business record can still contain personal information, such as a sole trader name or contact number.
Where applicable law requires a legal basis, necessary account/service processing relies on contract, security and appropriate service improvement on legitimate interests, required records on legal obligations, and optional attribution/marketing on the separate choice or consent required for that purpose. We assess competing interests and minimize information; optional consent may be withdrawn without removing access to purchased service. Contact support about objections, restriction, portability or a complaint to your competent data-protection authority where applicable.
Trial eligibility and billing evidence
We record the exact published subscription, terms and privacy versions acknowledged at signup and commercial acceptance, the authenticated actor and organization, declared authority and original acceptance time. Marketing opt-in is separate and optional.
To prevent repeat-trial abuse and automated signup traffic, we use protected hashes of contact/company eligibility signals, a first-party device identifier and request velocity controls. Shared IPs, generic email services or recycled contact details alone do not prove fraud. Matching applications may require review, and support can consider an appeal. The first-party device hint lasts up to 180 days; deleting it does not renew trial eligibility.
Confirmed payment references, accepted quotes and approval outcomes are recorded separately from receipt uploads and unconfirmed requests. Delivery of a billing email does not determine whether a payment was received or extend an access deadline.
Information we collect
Account and organization information. When you sign up or are invited, we collect your name, work email address, password or Google sign-in identity, organization name, role, and billing contact details.
Data your organization creates. Lead notes and statuses, contact/call logs, customer-entered notes and any historical external recording references, chat and email content sent through the Service (including which of your mailboxes sent each email and whether it was delivered to the recipient's mail server), and your settings.
Usage and technical information. Actions taken in the product (searches, assignments, pages visited), sign-in events, and standard server logs that include IP addresses, browser and device type, and timestamps. We use this to operate, secure, and improve the Service.
Connected account credentials. When your organization connects a mailbox, we store the access tokens or passwords needed to send through it. External calling-app handoff does not create a KeepCarrier telephony connection. These are stored encrypted, used only server-side, and never sent to the browser.
Support communications. If you contact us for help, we keep that correspondence.
Carrier registry data
The product presents business contact and registration data about motor carriers drawn from public government sources, principally FMCSA registration and safety datasets and the National Highway Traffic Safety Administration's vPIC database. This is public data about businesses. We did not collect it from the carriers themselves, and we do not claim to own it.
If you are a carrier and your public record is wrong, the lasting fix is at the source with FMCSA. If you do not want a KeepCarrier customer to contact you, use the unsubscribe link in their email or tell their caller; our Unsubscribe page explains how this works. You may also contact us and we will route the request.
How we use information
We use the information we collect to: provide and operate the Service (sign-in, lead queues, calling, texting, and email); secure the Service and detect abuse; respond to support requests; send service communications such as receipts, security notices, and product updates; analyze aggregate usage to improve the product; and comply with the law.
We do not sell personal information, and we do not share personal information with third parties for their own advertising.
How calling, texting, and email work
Calls and texts are handed to each user's selected external application. We do not operate an organization telephony account or observe the completion of those external calls. Emails to carriers are sent from your organization's own mailbox. Recipients see your number and your address, not ours, and replies go to your mailbox. We do not connect to your mailbox to read, download, or store the mail it receives, including replies.
Before an email is sent, the Service may look up the recipient's email domain in public DNS to check that it can receive mail. An address whose domain cannot receive mail, or that the recipient's mail server rejects, is added to your organization's suppression list so it is not emailed again.
We store contact/call logs, customer-entered notes, chat and sent email history so your team can see its own record. We do not record external calls or fetch calling-provider recordings; older imported references may remain in historical records. Your organization's owner and administrators can see their team's activity in the product.
Platform email, such as invitations, receipts, and security notices, is sent through our transactional email provider, currently Resend with Amazon SES as a configured alternative, from our own domain. Your outreach email does not pass through this pipeline.
Service providers and disclosures
We use a small number of service providers to run the Service. Amazon Web Services hosts the application, primary database and file storage in us-east-1 in the United States. Upstash supplies the configured Redis service for limits, coordination and cache/queue metadata. Resend is the current platform email provider, with Amazon SES as a configured alternative. The Subprocessor Notice explains purposes and international processing. The public data sources named above provide carrier registry data; data flows from those government sources to us, and we do not send your data to them.
Your selected external calling/messaging app and connected mailbox provider (Google, Microsoft or your own mail host) process communications under your arrangements with them. KeepCarrier calling/texting is an app handoff; there is no live organization-wide Zoom Phone connection. Their handling of your data is governed by your agreement with them, not by this policy.
We may disclose information where the law requires it, to protect the rights or safety of our customers or others, or in connection with a merger, acquisition, or sale of the business, in which case we will provide notice where the law allows.
Storage and security
The Service is hosted on Amazon Web Services in the us-east-1 region, and that is where your data is stored. We use encryption in transit, encrypted storage for connected-account credentials, isolation between customer organizations, and role-based access control. Platform-level administrative access is limited to operational needs such as billing support and abuse investigation, and it is logged.
No method of transmission or storage is perfectly secure. If a breach affects your data, we will notify you as the law requires.
Data retention
We keep account and organization data while your account is active. After an account closes, we delete or anonymize it within a reasonable period, except records we must keep for legal, security, or legitimate record-keeping purposes. Operational and security log retention follows the configured retention and review process; we do not promise that every log has the same retention period. Payment, accepted quote, eligibility and policy evidence may need to remain available for dispute, security and record-keeping review. A subscription hold does not automatically delete organization data.
Email suppression list entries (addresses that unsubscribed, complained, hard bounced, or were found undeliverable) are kept for as long as needed to honor the opt-out. Keeping the address is how we make sure it is not emailed again; deleting it would defeat the purpose.
Your rights and choices
You can see and update your own account information in the product. Organization owners and administrators manage their agents' accounts and their organization's data. To request an export or deletion of your organization's data, contact us at the address below.
Depending on where you live, you may have additional legal rights, such as the right to access, correct, delete, or receive a copy of your personal information, and the right not to be discriminated against for exercising those rights. We honor such requests as the law requires. We do not sell personal information, so there is no sale to opt out of.
If you are an agent, much of your activity data belongs to your organization, so ask your owner or administrator first. If you are a carrier contacted by one of our customers, that customer controls the outreach: contact them directly, use the unsubscribe link in their email, or tell their caller. You may also contact us and we will route your request to the right organization.
Children
The Service is a business product. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.
International users
KeepCarrier LLC is the United States service operator; its primary application database and object storage are in the United States. Authorized operations, providers and message delivery may involve other countries. Their laws can differ from yours. We assess and arrange safeguards where a restricted transfer requires them; agreement to use the website alone is not a substitute for an applicable legal transfer mechanism. The Data Processing Addendum and Subprocessor Notice explain this boundary.
Changes to this policy
We may update this policy from time to time. If a change is material, we will announce it by email or inside the product before it takes effect. The effective date at the top of this page shows which version applies.
Related policies and agreements
Cookie and Browser Storage Policy
/policies/cookiesOctober 8, 2026
cookies-2026-10-08-v1
KeepCarrier uses necessary browser storage for requested service and a separate choice for optional website attribution. Accepting Terms or opting into product emails does not accept optional cookies. You can choose necessary-only and still use the website, signup and purchased service.
Necessary storage
Session and short-lived verification cookies support sign-in, secure signup and recovery. Preferences support theme, timezone and roster presentation. A protected trial-device hint can last up to 180 days and supports repeat-trial abuse protection. Browser storage may also preserve user-entered form preferences. These do not authorize unrelated advertising tracking.
The signed kc_cookie_choice cookie retains the current optional-attribution choice for up to 180 days, and a minimal server record retains its opaque event ID, policy version, choice and time. It is not a working-account credential and does not grant trial or paid access.
Optional attribution
Only after an affirmative current choice, kc_ft records the first marketing source for up to 90 days, kc_lt the latest source for up to 30 days, and kc_seo_landing an organic landing for up to 30 days. They can contain sanitized campaign tokens, referring host, landing path and time. Although they omit raw passwords and full query strings, they may be linked to signup attribution and should not be described as always anonymous.
Optional attribution is off until accepted, and refusal or a Global Privacy Control signal prevents it. Withdrawing the choice removes those browser cookies and stops their further use. Historical lawful aggregate records are subject to the Privacy Policy, not silently rewritten. We do not use third-party advertising cookies or sell this information to an advertising network.
Your controls
Use Cookie settings on the public website to accept optional attribution or choose necessary-only. You can change the choice later; a materially changed purpose or expired choice requires a new choice. Browser blocking or deletion is also available, but blocking necessary session cookies prevents sign-in. Changing cookies does not renew an expired trial or remove retained commercial evidence.
KeepCarrier LLC, 1207 Delaware Ave, Wilmington, DE 19806, USA. Contact support@mail.keepcarrier.com for privacy, security, billing and contractual requests.
Data Protection and Security Policy
/policies/data-protectionOctober 8, 2026
data-protection-2026-10-08-v1
This policy describes safeguards for KeepCarrier customer data and the responsibilities shared by KeepCarrier LLC and its customers. It is incorporated into the Terms of Service. It is not a certification, a promise of uninterrupted availability or a guarantee that every security incident can be prevented.
Data boundaries and access
Customer-owned leads, notes, communications, settings and uploaded files are scoped to their organization. Shared public carrier facts remain separate. Server-side authentication, role, ownership and current subscription checks protect workspace operations. Support access must be authorized, scoped and recorded; another customer has no right to your private activity.
Customers must grant only appropriate permissions, maintain accurate account contacts, protect credentials and connected mailboxes, promptly remove access that is no longer needed, and report suspected compromise. Do not upload passwords, payment-card details, sensitive health data or special-category personal data into lead notes or other general-purpose fields.
Technical safeguards
The production application uses HTTPS, a private PostgreSQL database with encrypted storage, encrypted object storage, and server-side secret references. Connected mailbox credentials are encrypted and are not sent to client browsers. Tenant photo and attachment downloads enforce current ownership and entitlement; private tenant photos do not have anonymous raw-bucket access. Shared vehicle imagery may remain public.
Safeguards include permission checks, rate limits, session controls, abuse review, immutable commercial evidence and application monitoring. No statement here claims that every account has mandatory multi-factor authentication, that all content is encrypted end to end, or that KeepCarrier has an ISO 27001, SOC 2 or other independent certification.
Backups, retention and restoration
Database backups support operational recovery. They do not replace a customer's own lawful records or guarantee a particular recovery time or recovery point. Restored systems must preserve tenant isolation, opt-outs and commercial evidence. We review retention and deletion requests according to the Privacy Policy and Data Processing Addendum; payment holds do not erase stored data.
Commercial, security and suppression evidence may remain where necessary for legal obligations, disputes, abuse prevention or honoring an opt-out. Backups expire under their configured lifecycle. Where retained data cannot yet be erased lawfully, it remains restricted and is not used to restore a deleted customer's ordinary workspace.
Security incidents and reports
Report suspected exposure or a vulnerability to support@mail.keepcarrier.com with enough detail to investigate, without including passwords or unrelated personal data. Do not access other tenants, disrupt the service or conduct intrusive testing without written authorization.
We investigate reported incidents, contain unauthorized access, preserve relevant evidence and provide affected customers information without undue delay after becoming aware of a personal-data breach affecting data we process for them. Information may be provided in stages. Each party remains responsible for notifications to authorities or individuals that the applicable law requires. No paid subscription creates an unadvertised 24-hour incident-response SLA.
Assurance and data requests
Authorized organization representatives may request relevant security information, an export or a scoped deletion review through support. Identity and authority must be verified. Audit arrangements must protect other tenants and confidential security information; applicable legal audit rights are not excluded. Previously downloaded material, third-party caches and external communications cannot be recalled.
KeepCarrier LLC, 1207 Delaware Ave, Wilmington, DE 19806, USA. Contact support@mail.keepcarrier.com for privacy, security, billing and contractual requests.
Subprocessor and Third-party Services Notice
/policies/subprocessorsOctober 8, 2026
subprocessors-2026-10-08-v1
This notice identifies the principal service-provider categories used by KeepCarrier LLC. It distinguishes our processors from customer-selected communications providers and public data sources. It is incorporated into the Data Processing Addendum; a listing alone is not a claim of certification or an executed cross-border transfer agreement.
Hosting, storage and request protection
Amazon Web Services supplies application hosting, PostgreSQL database, object storage, network delivery, logs, backups and runtime secret infrastructure. The primary application database and storage are in us-east-1 in the United States; network delivery and authorized operations can involve other locations. Categories include customer workspace data, uploaded files and limited service/security metadata.
Upstash provides the configured Redis service for request limits, coordination and related cache/queue metadata. Its processing location follows the configured service and contractual terms; we do not describe every cache as residing in the same region as the main database. Data sent to this service is limited to what the feature needs.
Required service email
Resend is the current transactional email provider for signup, invitations, billing, recovery and platform support notices. It receives necessary recipient addresses, message content and delivery metadata. Amazon SES is a configured alternative, not a second route that duplicates every send. Email delivery crosses recipient networks and cannot be confined to the application's database region.
Customer-selected and independent services
A customer's chosen SMTP/mailbox and calling or messaging applications process under that customer's arrangements. KeepCarrier sends authorized outreach through the customer's connected mailbox; external calling/texting is a handoff, not a KeepCarrier telephony account. Optional Google sign-in uses Google's identity service under its applicable terms. Government registry sources such as FMCSA and NHTSA supply public records; they are not recipients of private tenant activity merely because we retrieve registry facts.
Our own social-media connections are for KeepCarrier's platform accounts, not access to customer social accounts. The Privacy Policy describes that independent activity. Paid third-party AI processing of customer content is not implied by this notice; introducing it requires appropriate disclosure, instructions and safeguards.
Changes and objections
We maintain this versioned notice and communicate material additions/replacements under the Data Processing Addendum. Contact support for current provider/transfer details or a reasonable data-protection objection. An organization's authorized representatives are responsible for maintaining a reachable contact address and reviewing notices.
KeepCarrier LLC, 1207 Delaware Ave, Wilmington, DE 19806, USA. Contact support@mail.keepcarrier.com for privacy, security, billing and contractual requests.