Privacy Policy

Last updated: 15 September 2026

Welcome

We provide container visibility and workflow automation software for the logistics industry. Freight forwarders, brokers, drayage operators, and beneficial cargo owners use our technology to track containers, receive alerts on exceptions, and automate the work that surrounds a shipment.

This Privacy Policy (“Policy”) describes the information we collect in connection with the Services and Sites, including Personal Data, how we use and share that information, and the rights and choices you may have regarding your Personal Data.

Defined Terms

In this Policy, “OpenTrack”, “we”, “our”, or “us” refers to OpenTrack, Inc., 615 Main St G1, Nashville, TN 37206, United States.

“Personal Data” refers to information that identifies, relates to, describes, or can reasonably be linked to an identified or identifiable individual, as defined under applicable privacy law.

“Services” refers to the OpenTrack web application, the OpenTrack API, and connections you authorize between a third-party AI assistant and your OpenTrack account.

“Sites” refers to OpenTrack’s public websites.

“Business User” refers to a business or other organization that obtains or uses the Services from OpenTrack, including an organization on whose behalf an Account User accesses the Services.

“Shipment Data” refers to data we collect or use in relation to the shipments our Business Users track, such as container numbers, bills of lading, carrier and terminal data, milestones, and arrival estimates. Shipment Data generally describes cargo and its movement rather than individuals. OpenTrack does not intentionally collect individual shipper, consignee, or notify-party contact information as part of its standard shipment tracking service. To the extent Shipment Data contains Personal Data, we process that Personal Data in accordance with this Policy and our agreement with the applicable Business User.

Depending on the context, “you” may be an Account User, Visitor, or Business Contact:

  • Account Users. When you use the Services on behalf of a Business User, we refer to you as an “Account User.”
  • Visitors. When you interact with OpenTrack by visiting a Site without being logged into an account, we refer to you as a “Visitor.”
  • Business Contacts. When you interact with us in a business capacity, such as as a prospective customer, customer contact, billing contact, vendor contact, or other business representative, we refer to you as a “Business Contact.”

Our role. OpenTrack acts as a controller of Personal Data that we collect and process for our own business purposes, including account administration, security, communications, and operation of our Sites. When we process Personal Data on behalf of a Business User in providing the Services, we act as a processor or service provider on behalf of that Business User, and that processing is governed by our agreement with the Business User.

Where OpenTrack processes Personal Data on behalf of a Business User, the Business User is responsible for its own privacy practices and for providing any notices required by applicable law regarding that processing. If you have questions about Personal Data that a Business User has submitted to the Services, you should contact that Business User directly.

1. Information we collect and how we use and share it

1.1 Account Users

a. Information we collect in connection with Account Users

Registration and contact information. When your organization provisions your account, or when you register, we collect your name, business email address, employer, job title where provided, account role and permissions, and authentication and sign-in information associated with your use of the Services.

Shipment Data. We collect the Shipment Data your organization tracks through the Services, sourced from carrier and terminal systems, licensed data providers, and data your organization submits.

AI assistant connections. You can connect a third-party AI assistant to your account so that it can retrieve shipment information and carry out actions on your behalf. A connection can access only the data and actions permitted by your OpenTrack account permissions. You can revoke the connection using the controls OpenTrack makes available, and you may also be able to revoke it through your AI provider.

OpenTrack does not receive or store your conversation history with the assistant, its memory or saved context, or files you have uploaded to it, except for information the assistant sends to OpenTrack as necessary to perform an action you request.

In-app AI assistant. Where the OpenTrack web application offers a built-in AI assistant, we collect the messages you send it, the responses it returns, and a record of the actions it takes on your behalf. You can delete in-app AI conversations using the controls available in the Services. Deleted conversations are removed from active systems in accordance with our retention practices, subject to limited retention where permitted or required by law.

Your messages and the assistant’s responses are processed through AI model infrastructure we use to provide this feature. We configure our AI service providers not to use this data to train their general-purpose models, except where we expressly disclose otherwise or obtain appropriate authorization.

Billing information. Where applicable, we collect billing contact information, invoice and transaction records, and other information necessary to administer payments and our commercial relationship with a Business User.

Sources of information. We collect information directly from you, from the Business User on whose behalf you use the Services, automatically through your use of the Services, and from third parties that provide data or services used in connection with the Services.

b. How we use and share information in connection with Account Users

Services. We use the information described above to provide the Services, including tracking shipments, delivering alerts and webhooks, operating the API, administering accounts, and authenticating users.

Your AI provider. When you use an AI assistant connection, information you provide to the assistant and information OpenTrack returns in response to its requests may pass through the provider of that assistant. The provider’s collection, use, retention, and disclosure of that information is governed by its own privacy practices and your relationship with that provider. OpenTrack does not control the provider’s independent processing of that information.

1.2 Visitors

a. Information we collect about Visitors

When you browse our Sites, we may collect information such as your IP address, browser or device information, pages you visit, referring URL, and approximate location derived from your IP address. We may collect some of this information through cookies and similar technologies, subject to the choices described in this Policy. If you complete a form on a Site, we collect the information you provide through that form.

b. How we use and share information about Visitors

We use this information to respond to your enquiries, provide information about our Services, operate and improve our Sites, and understand how our Sites are used.

Where required by applicable law, we obtain consent before using non-essential cookies or similar technologies. You can manage your cookie choices through the controls we make available on our Sites and through your browser settings.

1.3 Business Contacts

a. Information we collect about Business Contacts

When you interact with us in a business capacity, we may collect your name, business contact information, employer, job title or role, and information you provide in communications with us.

b. How we use and share information about Business Contacts

We use this information to manage our business relationships, respond to enquiries, administer contracts and billing, provide information about our Services, and communicate with you about matters relevant to your organization. We may share this information with service providers that support these activities, as described in this Policy.

Required information. Certain Personal Data, such as account and authentication information, is necessary for us to provide particular features of the Services. If you do not provide information that is required, we may be unable to create or administer your account or provide the relevant Service or feature.

Where we receive Personal Data about you from another source, we process it for the purposes described in this Policy and in accordance with applicable law.

2. More about how we collect, use, and share information

a. Collection of information

Online activity. For requests to the Services, we may record technical information such as the HTTP method, request URL, response status, IP address, and user agent. We do not intentionally include request or response bodies in standard operational logs. A request URL may contain an identifier associated with the record being accessed, such as a container identifier.

Error information. When a request fails, we may record technical information about the error to diagnose and resolve issues. Error records may include limited information associated with the affected request, such as record identifiers, but we do not intentionally include request or response bodies in standard error logs.

Support correspondence. We collect what you send us through support tickets, email, and other channels, including attachments, and use it to answer your questions and resolve issues.

b. Use of information

Analyzing, improving, and developing our Services. We use Personal Data to diagnose faults, improve reliability, understand how the Services are used, and generate aggregated or de-identified information that is not intended to identify an individual or Business User. This includes evaluating and improving the performance, accuracy, reliability, and functionality of the machine learning and artificial intelligence features that power the Services. These activities do not include Shipment Data or data reaching us through an AI assistant connection.

We may use and disclose aggregated or de-identified information that does not reasonably identify an individual or Business User for analytics, product development, benchmarking, and other business purposes.

Security and abuse prevention. We process IP addresses and request metadata to apply rate limits, detect abuse, and protect the Services against unauthorized access.

Communications. We use your contact information to deliver the Services and to respond to you. Subject to applicable law, we may also communicate with you about our Services. Marketing emails include an unsubscribe link or other mechanism to opt out of future marketing communications.

Minors. Our Services are intended for businesses and are not directed to children. We do not knowingly solicit Personal Data from children or permit them to create accounts. If you believe a child has provided us with Personal Data, please contact us so that we can take appropriate steps in accordance with applicable law.

c. Sharing of information

Service providers. We use service providers to help us operate, secure, support, and improve the Services. These providers include cloud hosting and infrastructure providers, communications providers, customer support providers, error-monitoring and security providers, and product analytics providers. Where they process Personal Data on our behalf, we require them to process it only as necessary to provide services to us and subject to appropriate contractual confidentiality, security, and data protection obligations.

Corporate transactions. If we enter or intend to enter a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, we may disclose Personal Data to prospective or actual transaction participants and their advisors as reasonably necessary in connection with the transaction. Where required by applicable law, we will provide notice of any material change in the ownership or use of Personal Data resulting from such a transaction.

Compliance and harm prevention. We may use or disclose Personal Data where reasonably necessary to comply with applicable law or legal process; enforce our contractual rights; establish, exercise, or defend legal claims; protect the rights, property, or safety of OpenTrack, our Business Users, users, or others; or respond to lawful requests from courts, law enforcement, and other public authorities.

We do not sell Personal Data, share it for cross-context behavioral advertising, or process it for targeted advertising as those terms are defined by applicable U.S. state privacy laws.

Third-party services. The Services and Sites may contain links to or integrate with websites, applications, and services operated by third parties. Their handling of Personal Data is governed by their own privacy practices, and this Policy does not apply to processing they conduct independently of OpenTrack.

3. Legal bases for processing Personal Data

For Personal Data that OpenTrack processes as a controller, we rely on the following legal bases under the General Data Protection Regulation (GDPR) and other applicable data protection laws.

a. Contractual and pre-contractual relationships. Where you enter into a contract with us in your individual capacity, or ask us to take steps before entering into such a contract, we process Personal Data as necessary to perform that contract or take the steps you request.

b. Legal compliance. We process Personal Data where necessary to comply with applicable legal and regulatory obligations, including tax, accounting, financial reporting, recordkeeping, and lawful requests from courts, regulators, and other public authorities.

c. Legitimate interests. Where permitted under applicable law, we rely on our legitimate business interests to process Personal Data. These interests include establishing and managing relationships with Business Users; provisioning and administering accounts for individuals who use the Services on their behalf; authenticating users and providing support; administering billing, commercial records, and our contractual relationships with Business Users; operating and improving our Sites, understanding how they are used, and responding to business enquiries; communicating with current and prospective Business Users about our Services where permitted by applicable law; applying rate limits, detecting abuse, and maintaining the security and availability of the Services; diagnosing faults and improving reliability; generating aggregate business intelligence that identifies no individual or Business User; evaluating and improving the machine learning and artificial intelligence features that power the Services; and using service providers to help carry out the activities described above. We rely on these interests only where they are not overridden by your rights and interests.

d. Consent. Where applicable, we may process Personal Data based on your consent, including for certain marketing activities or the use of non-essential cookies and similar technologies. Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Automated decision-making. We do not use Personal Data to make solely automated decisions about individuals that produce legal or similarly significant effects.

4. Your rights and choices

a. Opting out of receiving electronic communications from us

If you wish to stop receiving marketing communications, use the unsubscribe link or other opt-out mechanism provided in the communication. Even if you opt out, we retain the right to communicate with you about the Services you receive, including support matters and legal notices.

b. Your data protection rights

Depending on your location and subject to applicable law, you may have the following rights:

  • The right to confirmation of whether we process Personal Data associated with you, and to access it;
  • The right to have inaccurate, incomplete, or outdated Personal Data corrected;
  • The right to have your Personal Data erased;
  • The right to restrict our use of your Personal Data;
  • The right to data portability, where provided by applicable law;
  • The right to withdraw consent where processing is based on it;
  • The right to object to processing based on our legitimate interests;
  • The right to object at any time to the use of your Personal Data for direct marketing;
  • Where applicable, the right to opt out of the sale of your Personal Data, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you; and
  • The right not to be discriminated against for exercising these rights.

c. Process for exercising your data protection rights

Email support@opentrack.co to exercise your privacy rights.

We will respond to verified privacy requests within the time required by applicable law and will notify you if we are permitted to extend the response period.

We may take reasonable steps to verify your identity before processing a privacy request, including by asking you to confirm information associated with your account or your interactions with us. Where permitted by applicable law, you may designate an authorized agent to submit a request on your behalf, and we may require appropriate verification of the agent’s authority.

Where applicable law gives you the right to appeal our decision on a privacy request, you may submit an appeal by replying to our decision or by emailing support@opentrack.co with “Privacy Appeal” in the subject line.

Where we process Personal Data on behalf of a Business User, we may refer your request to that Business User or assist the Business User in responding to your request, as required by applicable law and our agreement with that Business User.

5. Security and retention

We use reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, loss, misuse, alteration, and disclosure. These measures include encryption in transit, access controls, authentication controls, logging and monitoring, and other security measures appropriate to the nature of the Personal Data we process.

No storage or transmission system can be guaranteed to be secure. We will notify affected Business Users of a personal data breach affecting their data without undue delay, as required by applicable law and our contractual obligations.

AI assistant connections. OpenTrack does not retain the assistant’s full conversation history through an AI assistant connection. We may retain limited records of requests made through the connection, including the action requested and information supplied to perform it, for the periods described below.

Authentication state. We retain authentication and session-related information for the periods described below.

  • Authorization code: 10 minutes
  • Access and ID token metadata: 1 hour
  • Interaction record: 1 hour
  • Cached user record: 5 minutes
  • Grant and login session: 14 days
  • Refresh token: 30 days

Logs.

  • Operational logs: 14 days
  • Application error events: 90 days
  • Request traces: 90 days

Account and business records.

  • Account data: For the life of the account and for 90 days after the account is closed, subject to the limited retention described in this Policy
  • Shipment Data: Retained in accordance with the Business User’s agreement and configured tracking lifecycle, and deleted or returned following termination as provided in the applicable agreement and our retention practices
  • Webhook configuration: Until deleted by the Business User or following termination of the applicable agreement in accordance with our retention practices
  • In-app AI assistant conversations: 90 days after last activity, unless deleted sooner through the controls available in the Services, subject to the limited retention described in this Policy
  • Support correspondence: 3 years after the matter is resolved, subject to the limited retention described in this Policy
  • Billing and transaction records: 7 years, or longer where required by applicable tax, accounting, or other legal requirements
  • Marketing contact data: Until you unsubscribe or we no longer need it for marketing purposes; after that, we may retain limited suppression and compliance records as necessary to honor your preferences and comply with applicable law
  • Visitor and Site usage data: Retained for as long as reasonably necessary to operate and secure our Sites, understand Site usage, respond to enquiries, and comply with applicable legal requirements, taking into account the nature of the data and the purposes for which it was collected
  • Business Contact data: For the duration of our business relationship and thereafter for as long as reasonably necessary to maintain business records, manage our relationship, resolve disputes, and comply with applicable legal requirements

We may retain Personal Data for longer than the periods described above where reasonably necessary to comply with applicable law, respond to legal process, resolve disputes, enforce our agreements, investigate security incidents, or maintain information in backup and disaster-recovery systems, in each case for no longer than reasonably necessary for those purposes.

6. International data transfers

OpenTrack is established in the United States. We and our service providers may process Personal Data in the United States and other countries in which we or they operate.

If you are located in the European Economic Area, the United Kingdom, or Switzerland, where required we use appropriate safeguards for transfers of Personal Data to the United States and other countries, including the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and applicable Swiss adaptations to the Standard Contractual Clauses. You can obtain information about the safeguards applicable to your Personal Data by contacting us.

7. Updates and notifications

We may change this Policy to reflect new services or changes in our privacy practices or relevant laws. Where a change materially affects how we handle Personal Data, we will provide appropriate notice as required by applicable law, which may include notice by email or through the Services.

8. Jurisdiction-specific provisions

  • European Economic Area, United Kingdom, and Switzerland. In addition to the rights described in Section 4.b, you may have the right to lodge a complaint with the data protection authority responsible for your jurisdiction.
  • California. California residents may have the rights described in Section 4, subject to applicable exceptions and verification requirements. The following additional disclosures apply to California residents under the CCPA.During the preceding 12 months, we have collected the following categories of Personal Data: identifiers, such as name, business email address, IP address, and online identifiers; professional or employment-related information, such as employer, job title, account role, and permissions; internet or other electronic network activity information, such as Site activity and request and device information; approximate geolocation information derived from IP address; customer and support records; commercial information, such as billing, invoice, and transaction records; and account authentication information that may constitute sensitive personal information under the CCPA.
  • We collect this information directly from you, from the Business User on whose behalf you use the Services, automatically when you use the Services or Sites, and from service providers and other third parties that support the Services. We use these categories of Personal Data for the purposes described in this Policy, including providing and administering the Services, authenticating users, communicating with users, providing support, securing and improving the Services, complying with law, and operating our business.
  • During the preceding 12 months, we have disclosed these categories of Personal Data to service providers and contractors for the business purposes described above. The categories of recipients include cloud hosting and infrastructure providers, communications providers, customer support providers, error-monitoring and security providers, and product analytics providers.
  • We do not sell Personal Data or share it for cross-context behavioral advertising, and we have not done so during the preceding 12 months. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA.
  • Do Not Track. Some browsers offer a “Do Not Track” signal. Because there is not a uniform industry standard for responding to these signals, our Sites do not currently respond to browser Do Not Track signals. This does not affect the privacy choices described in this Policy or any rights you may have under applicable law.
  • Other U.S. states. Residents of certain U.S. states may have additional rights regarding their Personal Data under applicable state privacy laws. These may include rights to access, correct, delete, or obtain a copy of Personal Data, and to opt out of certain sales, targeted advertising, or profiling. You may exercise applicable rights as described in Section 4.

9. Contact us

If you have questions or complaints about this Policy, contact us at support@opentrack.co, or write to OpenTrack, Inc., 615 Main St G1, Nashville, TN 37206, United States.

‍