PlacardPro · Mile Marker Technologies

Privacy Policy

How we collect, use, and protect your information when you use PlacardPro.

// Last updated: June 2026  —  Effective immediately  —  Rev. 2.0
// 01

Information We Collect

Account Information. When a fleet administrator registers a carrier account, we collect the company name, administrator email address, and billing information. Billing card data is tokenized by Square and never stored on our servers.

Driver Records. Fleet administrators provide driver names and mobile phone numbers when provisioning driver accounts. This information is stored in our database and associated with your carrier account.

Scan Records. When a driver scans a Bill of Lading, we store the extracted text fields (shipper name, UN numbers, hazard classes, etc.), the validation result, timestamp, and which driver performed the scan. The BOL photograph is transmitted securely to our API and stored on AWS S3 cloud storage as part of the carrier's BOL audit trail. Images are associated with the carrier account, accessible to fleet administrators through the fleet console, and are not shared with third parties.

Derived Compliance Data. Mile Marker Technologies processes scan records across the platform to generate analytical outputs we own and use independently of your raw submissions. See Section 6 for a full description of what this data is and how it is used.

Usage Data. We collect basic usage logs including API request timestamps, scan counts, and error events for system reliability and debugging purposes.

Electronic Acceptance Records. When you accept our Terms of Service or End User License Agreement electronically, we record the date, time, IP address, and account identifier associated with that acceptance event. This information is retained to verify agreement formation and is not used for any other purpose.

// 02

How We Use Your Information

  • To provide BOL compliance verification and placard guidance services
  • To authenticate drivers and fleet administrators
  • To display scan history and compliance reports in the fleet console
  • To process subscription billing via Square
  • To operate, maintain, and improve the platform
  • To respond to support requests
  • To generate Derived Compliance Data — analytical outputs such as carrier compliance scores, driver risk rankings, fleet benchmarks, and hazard class frequency profiles — owned by Mile Marker Technologies and used for platform development and internal benchmarking as described in Section 6
  • To deliver optional SMS notifications via Twilio when a fleet administrator elects to use the SMS delivery feature for driver activation codes
  • To send transactional emails (account confirmations, billing notices, policy updates) via Resend

We do not use your information for advertising, marketing profiling, or any purpose beyond operating the PlacardPro service and the data uses described in this policy.

// 03

Information We Do Not Collect

Important

BOL photographs are stored securely on AWS S3 as part of the carrier's compliance audit trail. Images are accessible only to authorized fleet administrators within the carrier account and are never used for advertising or shared with third parties.

We do not collect:

  • Driver location or GPS data
  • Personal information beyond what is necessary to operate the service
  • Sensitive personal data (health, financial records beyond billing, government IDs)
  • Data from children — this service is for commercial carriers only
// 04

Data Storage & Security

Your data is stored in a PostgreSQL database hosted on Render's cloud infrastructure in the United States. All data transmission uses HTTPS/TLS encryption. Database access is restricted to authenticated application services only.

Driver authentication uses 6-digit one-time activation codes rather than passwords, reducing credential-related security risks. We do not store plaintext passwords — all passwords are hashed using bcrypt.

Payment card data is processed by Square and subject to Square's PCI DSS compliance standards. We never receive or store full card numbers.

Electronic acceptance records documenting your agreement to our Terms of Service and EULA are retained in our database and may be used as evidence of contract formation in the event of a dispute.

// 05

Third-Party Services

We use the following third-party services to operate PlacardPro. Each has its own privacy practices:

  • Anthropic (Claude API) — AI-powered BOL text extraction and compliance analysis. Anthropic's zero data retention policy applies to API usage. BOL content submitted to the API is not used to train AI models.
  • Square — Subscription payment processing. Card data is handled entirely by Square under their PCI DSS compliance program. We never receive or store full card numbers.
  • Render — Cloud hosting for our backend API and PostgreSQL database infrastructure.
  • Amazon Web Services (AWS S3) — Secure cloud storage for BOL scan images. Images are stored in a private, encrypted S3 bucket and are not publicly accessible.
  • Twilio — Optional SMS delivery service used when a fleet administrator elects to send a driver activation code via text message. Driver phone numbers are transmitted to Twilio solely for this purpose and are subject to Twilio's Privacy Policy. SMS delivery is optional — activation codes may be communicated directly by the fleet manager without using this feature.
  • Resend — Transactional email service used to deliver account confirmations, billing receipts, activation notifications, and policy update communications to fleet administrators. Email addresses are shared with Resend solely for this delivery purpose.
  • FMCSA QCMobile API — A public federal government API operated by the Federal Motor Carrier Safety Administration. We use this API to display live USDOT carrier safety profile data in the fleet console. No personal information is transmitted to FMCSA through this integration; the API is queried by USDOT number only, and the data returned is publicly available government safety records.

We do not sell, rent, or share your personal information with any third parties for their own commercial purposes.

// 06

Derived Compliance Data and Analytics

What this means for your account

Your raw scan submissions — BOL photographs, extracted text, shipper names, UN numbers — remain associated with your carrier account and are not sold to third parties. The analytical outputs Mile Marker Technologies generates from processing platform-wide scan data are a separate category of information that Mile Marker Technologies creates and owns independently.

What Derived Compliance Data Is. As the PlacardPro platform operates across all carrier accounts, Mile Marker Technologies processes scan records to generate analytical outputs that do not reproduce any single carrier's raw submission data. These outputs are owned exclusively by Mile Marker Technologies and include:

  • Carrier Compliance Scores — rolling pass/fail rates weighted by hazard class severity
  • Driver Risk Rankings — individual driver performance relative to fleet and industry averages
  • Fleet Benchmark Metrics — fleet-level compliance health indicators over time
  • Hazard Class Frequency Profiles — the mix of hazardous materials classes transported by a carrier
  • Violation Frequency Analytics — which 49 CFR provisions are most frequently flagged and how often
  • Shipper Quality Indices — compliance outcome patterns associated with specific shippers
  • Dispute Rate Metrics — the rate at which scan results are disputed and how those disputes are resolved
  • Pass/Fail Trend Data — compliance trajectory analysis over 30-, 60-, and 90-day windows

How Derived Compliance Data Is Used. Mile Marker Technologies uses Derived Compliance Data for improving and validating the accuracy of the AI compliance engine, developing platform benchmarks and industry reference data, internal analytics, and product development.

Anonymized and Aggregate Data. Derived Compliance Data that has been anonymized or aggregated — meaning it cannot reasonably identify a specific carrier, fleet, or individual — may be shared with third parties for research, benchmarking, or commercial purposes without additional consent. This is not a sale of your personal information.

Identified Carrier Data. Derived Compliance Data that is tied to your specific carrier identity (USDOT number, legal name, or other carrier-specific identifier) will only be shared with external parties for commercial purposes with your explicit opt-in consent. No identified carrier data sharing is currently active.

// 07

Driver Data & Account Provisioning

Driver phone numbers and names are entered into the system by fleet administrators when provisioning driver accounts. Fleet operators are responsible for ensuring that drivers are informed that their information is being entered into the PlacardPro platform before it is submitted. Mile Marker Technologies does not have a direct data relationship with individual drivers and relies on the carrier to fulfill applicable driver notification obligations.

Driver authentication uses a 6-digit one-time activation code generated by the fleet administrator through the fleet console. By default, the code is communicated directly to the driver by their fleet manager. If the fleet administrator elects to use the optional SMS delivery feature, the driver's phone number is transmitted to Twilio to deliver the code by text message. SMS delivery is optional — it is not required to complete driver activation.

Driver Compliance Performance Data. PlacardPro tracks individual driver scan activity, including per-driver pass rates, scan frequency, and dispute history, as part of the fleet compliance record accessible to fleet administrators. This data is associated with the driver's account within the carrier's fleet console and is subject to the same data rights provisions described in Section 6.

Driver phone numbers are never used for marketing, never shared with third parties for their own commercial purposes, and are removed from our systems upon account termination or upon written request from the carrier account holder.

// 08

Data Retention

Scan Records. BOL scan records — including extracted text fields, validation results, timestamps, and associated compliance data — are retained for a minimum of two (2) years from the date of the scan, consistent with federal motor carrier recordkeeping requirements under 49 CFR Part 379. BOL photographs stored on AWS S3 are retained for the same period.

Post-Termination Export Window. Following account termination, scan records remain available for export through the fleet console or upon written request for thirty (30) days. After this export window closes, identifiable scan records are eligible for permanent deletion from our production systems. We recommend fleet administrators export their compliance records before terminating an account.

Derived Compliance Data. Derived Compliance Data created from scan records — including anonymized performance analytics, compliance scores, and benchmarks — may be retained by Mile Marker Technologies in aggregate or anonymized form indefinitely. This data constitutes an independently created analytical work product owned by Mile Marker Technologies and is not subject to the same deletion timeline as raw scan records.

Driver Records. Driver names and phone numbers are removed from our systems upon account termination or upon receipt of a verified written deletion request from the carrier account holder.

Billing Records. Billing and payment records are retained as required by applicable law and Square's payment processing requirements, typically a minimum of seven (7) years.

Electronic Acceptance Records. Records of electronic acceptance of the Terms of Service and EULA are retained for a minimum of seven (7) years from the date of acceptance for contract enforcement and dispute resolution purposes.

// 09

Your Rights

Access and Correction. Fleet administrators may request access to or correction of their carrier account data by contacting us at support@milemarkertech.com. We will respond to verified requests within 30 days.

Deletion. Fleet administrators may request deletion of their account and associated data. Upon receipt of a verified deletion request, we will delete identifiable scan records, driver records, and account information within a commercially reasonable time, subject to the retention obligations described in Section 8 and any applicable legal holds.

Data Portability. Fleet administrators may request an export of their carrier's scan records in a standard machine-readable format (CSV or JSON) through the fleet console or by contacting support@milemarkertech.com. Exports are made available within 5 business days of a verified request.

Driver Records. Drivers wishing to have their records removed should contact their fleet administrator, who may submit a deletion request on their behalf. Drivers may also contact us directly at support@milemarkertech.com and we will coordinate with the carrier account holder.

We will acknowledge all data rights requests within 5 business days and complete verified requests within 30 days. Requests that cannot be fulfilled due to legal retention obligations will receive a written explanation.

// 10

Government and Regulatory Disclosure

Mile Marker Technologies may disclose account data, scan records, driver records, or other information to federal, state, or local government authorities — including the U.S. Department of Transportation, FMCSA, PHMSA, or law enforcement agencies — in the following circumstances:

  • In response to a lawful subpoena, court order, or other compulsory legal process
  • In connection with a regulatory investigation or enforcement proceeding involving a carrier account
  • Where disclosure is required by applicable law or regulation
  • To protect the safety of any person or to prevent fraud or illegal activity

Where legally permitted and practicable, Mile Marker Technologies will make reasonable efforts to notify the relevant carrier account holder before disclosing data in response to a government demand, so the carrier may seek a protective order or other appropriate relief. Mile Marker Technologies cannot provide advance notice where prohibited by law, including where a demand is accompanied by a non-disclosure order.

Government disclosures are made only to the extent required by the applicable legal demand and do not constitute a general sharing of data with government agencies.

// 11

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes — including any new data uses, changes to data sharing arrangements, or changes to retention periods — will be communicated to fleet administrators via email at least 30 days before the change takes effect. Non-material corrections and clarifications may be made without advance notice. The revision number and effective date at the top of this page will always reflect the most recent update. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

// 12

Contact Us

Questions about this Privacy Policy or your data:

Mile Marker Technologies
Oxford, Mississippi
support@milemarkertech.com
placardpro.ai

This Privacy Policy is governed by the laws of the State of Mississippi. Disputes arising under this policy are subject to the dispute resolution and arbitration provisions of the PlacardPro Terms of Service.