Privacy Notice
What CargoIT knows about you and your company, why we hold it, who else sees it, and what you can make us do about it.
Version 1.0-draft · Updated September 30, 2026
Draft — not yet in force
This document is a draft and has not been reviewed by a lawyer. Do not rely on it.
Who is responsible for your data
Maria Petrova, a private individual established in Bulgaria, at Elenovo 176, 2700 Blagoevgrad, Bulgaria, is the data controller for the personal data described here. CargoIT is not operated by a company at present.
For anything in this notice — a question, a request, a complaint — write to [email protected].
What we collect
Your account
Your name, email address and a securely hashed form of your password. We never store the password itself. If you ask to change your login address we hold the new one until you confirm it from that mailbox. If you registered with a code from one of our business cards, we record which code, so the offer printed on the card is applied to your account.
Your company
Company name, whether it ships or carries, VAT number, country, city, street address and contact phone number. For a sole trader some of this is personal data about you as well as information about a business.
What you do on the platform
The loads you post, the offers you make and receive, the shipments that result, and the status updates and notes recorded against them. These records identify the person and company behind each action.
What you write
Messages attached to an offer, notes on a shipment, and anything you send through the support form. These fields are free text, so they contain whatever you choose to put in them.
Technical data
To keep you signed in we store a hashed session token, when it was issued and when it was used. Our servers keep short-lived connection logs, which include IP addresses, for security and troubleshooting.
When you register or ask for a password reset, the form runs a security check that tells people from automated programs. The check sees your IP address and technical details of your browser, such as its type and version. Clause 5 says who runs it.
What we do not collect
We use no analytics, no advertising and no tracking pixels, and no third-party cookies apart from the security check's, described in clause 4. We do not profile you, and we do not track you across other websites.
Why we hold it, and on what basis
- To run your account and the service you asked for — registering you, confirming your address, showing you loads, recording offers and shipments, and telling you when something happens. This is necessary to perform our contract with you (Art. 6(1)(b) GDPR).
- To check that companies here are real — reviewing a company before it can trade, and reviewing loads before they reach the pool. This is our legitimate interest, and yours, in a marketplace where businesses hand freight to strangers (Art. 6(1)(f)).
- To keep the platform secure — hashing passwords, rotating session tokens, detecting a stolen session, limiting request rates, and checking that a registration or a password reset comes from a person rather than a program. Legitimate interest, and our obligation to secure your data (Art. 6(1)(f) and Art. 32).
- To answer you — handling what you send through the support form. Performance of the contract and our legitimate interest in supporting users.
- To keep a record of concluded business — a completed haul is evidence for both companies, and may be needed if one of them later disputes it. Legitimate interest, and where applicable a legal obligation (Art. 6(1)(c)).
We send you email about your account and your loads — a confirmation link, a password reset, an offer on your load, a decision on your company. These are part of the service, not marketing. We do not send marketing email.
Cookies and what is stored on your device
One cookie, and it is the session itself. It is set when you sign in, it cannot be read by scripts, and it is what keeps you signed in until you sign out. Without it the platform does not work, so we do not ask for consent to it and you cannot turn it off while using the service.
Your browser also remembers your chosen language, a few display preferences such as how you like a list sorted, and whether you were signed in last time, so the home page can open straight onto your dashboard. These stay on your device, identify nobody, and are never sent to us.
On the registration and password-reset pages only, the security check runs in a small frame served by Cloudflare, which may store a short-lived cookie of its own there. It is used only to tell people from bots, and the check cannot work without it, so it is strictly necessary in the same way as the session cookie. No other page loads anything from Cloudflare.
That is the complete list. There is nothing here to consent to, which is why CargoIT does not show you a cookie banner.
Who else sees your data
The company you do business with
This is the point of the platform, so it is worth being precise. While a load is open, carriers see the load — its route, dates and requirements — but not your address, phone number or email. When you accept a carrier's request, each side then receives the other's company address, phone number and the email address of the account owner, so the haul can be arranged.
At that point the other company becomes responsible for those details in its own right. Our terms require them to use them for that shipment only.
Our administrators
A small number of staff can see company details, loads and support messages, in order to review companies, review loads and answer you.
Service providers
- Hetzner Online GmbH (Germany) hosts the application and the database. Your data is stored in Germany.
- Resend, Inc. (United States) sends our email. It receives the recipient address and the content of the message — a confirmation link, or a notice that your load has an offer — and our replies when you write to us.
- Cloudflare, Inc. (United States) receives email sent to our addresses, such as [email protected], and forwards it to our mailbox. It handles your address and your message on the way through.
- openrouteservice, operated by HeiGIT gGmbH in Germany, measures road distances. It receives the two towns of a lane, and nothing about you or your company.
Each of these acts on our instructions under a contract, and none of them may use your data for their own purposes.
The security check
The check on the registration and password-reset forms is Turnstile, from Cloudflare, Inc. (United States). It receives your IP address and technical details of your browser for the few seconds the check takes, and tells us only whether it passed. Cloudflare runs the check for us under our data processing agreement, and also uses the same signals, under its own privacy policy, to improve its detection of bots.
Our mailbox
Email you send to [email protected] is kept in a Gmail mailbox provided by Google Ireland Limited (Ireland), together with our replies. Google provides that mailbox under its own terms rather than a data processing agreement with us, and handles what is in it under its own privacy policy.
Nobody else
We do not sell your data, rent it, or share it with advertisers or data brokers. We would disclose it where the law requires us to, and we would tell you unless we were forbidden from doing so.
Data leaving the EU
The database, the backups and the logs stay in Germany. Distance measurement is a German provider. The exception is email, in both directions: Resend, which sends the email we write, and Cloudflare, which receives the email you write to us, are both companies established in the United States, so an email — the addresses and the message — is handled by a processor outside the EU. So is the security check on the registration and password-reset forms, which Cloudflare also runs.
Each of those transfers is covered by the European Commission's Standard Contractual Clauses, which form part of our data processing agreements with Resend and with Cloudflare. Write to [email protected] if you would like a copy.
Our mailbox is provided by Google Ireland Limited, which may store and process email outside the EU, including in the United States. Google relies on its certification under the EU–US Data Privacy Framework and on Standard Contractual Clauses for those transfers.
How long we keep it
We keep personal data for as long as we need it, and then we remove it.
- Your account and company — while your account is open, and while you have shipment history that the other side may still need.
- A registration never confirmed — deleted after 90 days. The address was never proven, so there is no account to keep.
- A company application we rejected — 12 months, so we can explain the decision and recognise a resubmission.
- Notifications — 12 months.
- Support messages — 24 months.
- Session tokens — removed shortly after they expire.
- Connection logs — a short period, for security and troubleshooting.
- Completed shipments — kept as the record of a concluded contract, but stripped of what identifies a person once neither side needs it.
Your rights
Under the GDPR you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it if it is wrong — much of this you can do yourself from your company page and your account settings;
- delete it. Because a shipment is also the other company's record, we do this by removing what identifies you — your name, address, phone number and email — while the record of the haul itself remains without you in it;
- give you your data in a portable form, as a structured file you can take elsewhere;
- restrict or stop a particular use, including objecting to anything we do on the basis of legitimate interest.
Write to [email protected]. We will answer within one month. We do not charge for this.
Some of this we cannot do while you have live obligations — we cannot erase a shipment that is still running, because the other company is relying on it.
Nothing here is decided by a machine
Whether your company is approved, and whether a load reaches the carrier pool, is decided by a person. We do not make automated decisions that produce legal effects for you, and we do not profile you.
The one automatic check is the security check on the registration and password-reset forms (clause 5). It decides nothing about you or your company: if it does not pass, you can simply try again, or write to us at [email protected].
If you are not happy
Tell us first at [email protected] — most things are quicker to fix directly. You also have the right to complain to a data protection authority, in the country where you live or work, or where you think something went wrong. Ours is the Commission for Personal Data Protection (CPDP) ( Комисия за защита на личните данни ).
Changes, and which version counts
We will update this notice as the platform changes. The version and date at the top say which one you are reading, and we will tell you about anything significant rather than changing it quietly.