Privacy notice
How Cargovate LLC handles personal data in the Cargovate platform.
Last updated 16 September 2026
Draft — pending legal review
This document was prepared as a working text and has not been reviewed by counsel. It must be checked against our actual processing, retention periods and any GDPR/UK-GDPR obligations before it is relied on. Where it differs from a signed agreement, the agreement governs.
Two different roles, and the difference matters
For the data we hold about your account — who you are, how you signed in, what you did in the product — we are the controller and this notice applies.
For the operational data your organisation puts into the platform — shipments, parties, stock, documents, and any personal data inside them — your organisation is the controller and we act as processor on your instructions. That is governed by your agreement with us, not by this notice.
What we collect
Account data. Your name, work email address, the organisation you belong to, your role, and second-factor enrolment. Supplied when an account is created for you or when you accept an invitation.
Activity records. The platform keeps a hash-chained audit trail of actions taken in it — who did what, and when. This is a deliberate product feature: it is what makes a custody record defensible, and it cannot be edited after the fact.
Server logs. Standard web logs, which may include IP address, user agent, requested path and timestamp.
Enquiries. If you use a contact or order form, what you enter, plus your IP address and browser user agent to stop abuse.
No cookies for tracking. We set no advertising or tracking cookies. Visits to our public pages are counted with Umami, an analytics tool we run ourselves: it sets no cookies, stores nothing on your device, does not keep your IP address, and never runs inside your organisation's workspace.
Payments
Payments are handled by Stripe, by card or by invoice. Card details are entered on Stripe's own pages and never reach our servers — we hold a customer reference, a subscription identifier and the status of that subscription, which is what decides your access.
Why we process it
To provide the service you have contracted for, to keep it secure, to bill for it, and to maintain the audit record the product exists to produce. Where we rely on legitimate interests, those are operating and securing a service you asked for.
Who we share it with
Our hosting, email and payment providers, acting as processors. We do not sell personal data and we do not share it for advertising.
Optional anchoring writes a cryptographic hash to a public ledger when your organisation enables it. A hash is not the data and cannot be reversed into it — but it is public and permanent, so it is worth knowing that it is a deliberate choice your organisation makes, not a default.
How long we keep it
Account data for as long as the account exists, and for as long afterwards as we are required to keep records. Audit records are retained for the period agreed with your organisation, because deleting them on request would defeat their purpose — if you need a specific retention period, it belongs in your agreement.
Enquiries and order requests, and the messages we sent about them, are deleted automatically 24 months after the last contact about them, unless they led to your becoming a customer.
Your rights
Depending on where you are, you may have rights to access, correct, delete, restrict or object to processing, and to portability. For account data, contact us. For data your employer put into the platform, ask them — we act on their instructions, and passing their data to someone else on request is exactly what we must not do.
If you are in the UK or EU you may also complain to your local supervisory authority.
Security
Tenant isolation, audit trails, MFA and backups are described on our security page.
Contact
Questions about this notice, or to exercise a right: contact us.