Data processing addendum.
How CarShipDesk handles personal data that brokerages keep in the Service. This addendum forms part of the Terms of Service and needs no separate signature.
Effective . Last updated .
1. Scope and roles
- This Data Processing Addendum (“DPA”) forms part of the Terms of Service between CarShipDesk and the Customer and uses the terms defined there. It applies whenever CarShipDesk processes Customer Personal Data. To request a copy signed by both parties, write to hello@carshipdesk.com.
- “Customer Personal Data” means personal data within Customer Data that CarShipDesk processes on the Customer’s behalf to provide the Service: information about the Customer’s customers, carriers, other contacts and staff.
- “Data Protection Laws” means the U.S. federal and state privacy and data-protection laws that apply to that processing, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”).
- The Customer is the controller (the “business” under the CCPA). CarShipDesk is the processor (the “service provider” under the CCPA).
- CarShipDesk processes Customer Personal Data only on the Customer’s documented instructions. Those instructions are the Terms of Service, this DPA, the Customer’s configuration and use of the Service, and any other written instructions both parties agree. We will tell the Customer if we believe an instruction breaks Data Protection Laws. If the law requires other processing, we will tell the Customer first unless the law forbids it.
- The Customer is responsible for having a lawful basis and any consent needed for the processing, for giving the notices the law requires to the people whose data it enters, and for the lawfulness of its instructions.
2. Details of processing
- Subject matter
- Providing the Service to the Customer under the Terms of Service.
- Duration
- The term of the Terms of Service, plus the 30-day export period after termination and the time backups take to expire (section 6).
- Nature of processing
- Hosting, storing, organizing, retrieving, displaying and backing up Customer Personal Data; exchanging it with the services the Customer connects, on the Customer's instructions; and deleting it.
- Purpose
- To provide, secure and support the Service for the Customer.
- Data subjects
- The Customer's customers and prospective customers; the Customer's carriers and their dispatchers and drivers; pickup, delivery and other contacts the Customer records; and the Customer's Users (its staff).
- Categories of personal data
- Names and contact details (email addresses, phone numbers, postal addresses); shipment and vehicle details (pickup and delivery locations, dates, vehicle descriptions and VINs); quotes, prices and payment records (amounts and processor references, never full card numbers); messages and notes; carrier details (company, USDOT and MC numbers, contacts); User details (name, email, role, sign-in and session records, hours and commission records); and audit-log entries.
- Sensitive data
- None intended. The Customer must not enter card numbers, CVV codes, bank account numbers, Social Security numbers or health information.
3. Our obligations
- Confidentiality. Everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality and has access only as far as their work needs it.
- Security. We maintain the technical and organizational measures in Annex 1. We may update them over time, as long as the overall level of security does not go down.
- Data-subject requests. Taking into account the nature of the processing, we help the Customer answer requests from people to access, correct, delete or port their data or to opt out. If a person sends such a request to us directly, we pass it to the Customer and do not answer it ourselves, except to point the person to the Customer, unless the law requires otherwise.
- Other assistance. We give the Customer reasonable help with data-protection assessments and with inquiries from regulators about the processing.
4. Subprocessors
- The Customer authorizes CarShipDesk to use the subprocessors listed in Annex 2. We bind each subprocessor by written contract to data-protection obligations that protect Customer Personal Data at least as well as this DPA, and we remain responsible for their work.
- We will give at least 30 days’ notice before a new subprocessor starts processing Customer Personal Data, by updating Annex 2 and telling the Customer by email or in the Service.
- The Customer may object to a new subprocessor on reasonable data-protection grounds within that notice period by writing to hello@carshipdesk.com. We will discuss the objection in good faith. If we cannot resolve it, the Customer may end the affected part of the Service without penalty and receive a refund of any prepaid fees for the unused period.
5. Personal data breach
- We will notify the Customer without undue delay, and in any case within 72 hours, after we confirm a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- The notice will describe, as far as we know at the time, what happened, the categories and approximate number of people and records affected, the likely consequences, the measures taken or proposed, and a contact for more information. We will send updates as we learn more.
- We will take reasonable steps to contain, investigate and remedy the breach, and help the Customer meet any duty it has to notify regulators or the people affected. Notifying a breach is not an admission of fault.
6. Deletion or return at termination
- During the term, the Customer can export Customer Personal Data with the export features in the Service or by asking us at hello@carshipdesk.com.
- For 30 days after the Terms of Service end, we will, on request, make Customer Personal Data available for export. After that period we delete it from the Service.
- Copies in backups are deleted as the backups expire on their normal schedule, currently within 35 days, and are not restored except for disaster recovery. Any data the law requires us to keep stays confidential and is processed only for that purpose.
7. Audits and information
- On written request, we will give the Customer the information reasonably needed to show that we comply with this DPA, such as written answers to a security questionnaire and descriptions of our controls. Requests are limited to once a year, unless a regulator requires more or after a personal data breach.
- On-site audits take place only by mutual agreement on scope, timing, confidentiality and cost.
8. CCPA service-provider terms
For Customer Personal Data, CarShipDesk will not:
- sell or share it, as the CCPA defines those terms;
- keep, use or disclose it for any purpose other than the business purposes set out in the Terms of Service and this DPA, including any other commercial purpose;
- keep, use or disclose it outside the direct business relationship between CarShipDesk and the Customer;
- combine it with personal information we receive from anyone else or collect ourselves, except as the CCPA permits service providers to do.
We will comply with the obligations the CCPA places on service providers and give Customer Personal Data the level of privacy protection the CCPA requires. We will tell the Customer if we can no longer meet these obligations, and the Customer may then take reasonable steps to stop and remedy any unauthorized use. We understand and will comply with these restrictions.
9. Location, liability and precedence
- Customer Personal Data is stored and processed in the United States.
- Each party’s liability under this DPA is subject to the limitation of liability in the Terms of Service.
- If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA controls.
Annex 1: Security measures
- Encryption in transit. Connections to the website, the dashboard and the API use TLS.
- Encryption at rest. Stored data is encrypted at rest by our hosting and database providers.
- Tenant isolation. Every brokerage's records are separated by row-level security enforced in the database itself, not only in application code.
- Connected-service credentials. Keys and tokens for load boards, telephony and payment processors are encrypted with a separate key before they are stored.
- Access controls. Each person signs in individually through our authentication provider. Inside a workspace, roles and per-person grants decide who can see and do what. Access to production systems is limited to the CarShipDesk personnel who need it.
- Audit logging. Sensitive actions, such as grant changes, session actions, settings changes, payments and exports, are recorded with who did them and when.
- No stored card data. CarShipDesk never stores a full card number or CVV code. Card entry happens on the payment processor's hosted page.
- Backups. Continuous backups with point-in-time recovery, plus daily and weekly snapshots kept for up to 35 days, stored in the United States.
- Monitoring and incident response. We monitor the Service for errors and availability, investigate suspected security incidents, contain and remedy them, and notify the Customer under section 5.
- Personnel. People with access to Customer Personal Data are bound by confidentiality and have access only as far as their work needs it.
Annex 2: Subprocessors
The same list appears in the privacy policy. Integrations the Customer connects, such as Central Dispatch, Super Dispatch, RingCentral and the Customer’s own payment processor account, are the Customer’s own providers and not our subprocessors.
| Provider | Purpose | Data location |
|---|---|---|
| Fly.io | Application hosting: the API and background jobs | United States |
| Neon | Database hosting and backups | United States |
| Vercel | Hosting for the website and the dashboard | United States |
| WorkOS | Sign-in and user authentication | United States |
| Resend | Email delivery | United States |
| Sentry | Error monitoring | United States |
| Better Stack | Uptime checks of public pages; receives no personal data | Not applicable |
| Stripe | Billing for CarShipDesk's own subscription fees | United States |