Introduction
Nexus Freight Technologies, Inc. ("Nexus Freight," "we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you visit our website, use our platform, or interact with our services.
By accessing or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.
Information We Collect
Information You Provide
- Account information: Name, email address, company name, job title, phone number, and password when you create an account.
- Shipment data: Origin and destination addresses, cargo descriptions, container specifications, and shipping documentation you upload or generate through our platform.
- Payment information: Billing address and payment details (processed securely by our payment provider, Stripe).
- Communications: Messages, feedback, and inquiries you send to us through our chat, email, or support channels.
Information Collected Automatically
- Usage data: Pages visited, features used, clicks, search queries, and interactions with our AI agent.
- Device information: Browser type, operating system, device identifiers, screen resolution, and language settings.
- Log data: IP address, access times, referring URLs, and error logs.
- Cookies and similar technologies: As described in our Cookie Policy.
Information from Third Parties
- Carrier and logistics partner data for shipment tracking and rate comparison.
- Business information from public databases for compliance verification.
- Data from integrated services (e.g., SAP, Oracle) that you connect to our platform.
How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: To provide, maintain, and improve our freight forwarding platform, AI agent, and related services.
- AI model improvement: To train and enhance our machine learning models for rate prediction, compliance checking, and ETA estimation. Your shipment data is anonymized and aggregated before being used for model training.
- Communications: To respond to your inquiries, send transactional notifications (e.g., shipment updates), and provide customer support.
- Marketing: To send promotional communications about our products and services (with your consent where required by law). You can opt out at any time.
- Analytics: To understand usage patterns, improve our website, and optimize user experience.
- Compliance: To meet legal obligations, enforce our terms of service, and protect against fraud.
Legal Basis for Processing (EEA/UK)
If you are located in the European Economic Area or United Kingdom, we process your personal data on the following legal bases:
- Contract performance: Processing necessary to provide our services to you.
- Legitimate interests: Processing for analytics, security, fraud prevention, and service improvement, where our interests are not overridden by your rights.
- Consent: Processing based on your explicit consent (e.g., marketing communications, non-essential cookies).
- Legal obligations: Processing required to comply with applicable laws and regulations.
Information Sharing & Disclosure
We do not sell your personal information. We may share your data with the following categories of recipients:
- Service providers: Third-party vendors who assist us in operating our platform (e.g., cloud hosting, payment processing, customer support tools). These providers are contractually obligated to protect your data.
- Carriers and logistics partners: When necessary to fulfill your shipment requests and provide tracking information.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction.
- Legal requirements: When required by law, subpoena, or government request, or to protect the rights, safety, or property of Nexus Freight and our users.
International Data Transfers
Our platform is operated from the United States. If you access our services from outside the US, your data may be transferred to and processed in the United States or other countries where our service providers operate.
For transfers from the EEA/UK, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions where applicable.
- Your explicit consent where appropriate.
For transfers involving data from China, we comply with the PIPL requirements, including security assessments and separate consent for cross-border transfers where required.
Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this policy, or as required by law. Specifically:
- Account data: Retained while your account is active and for 3 years after closure.
- Shipment data: Retained for 7 years to comply with customs and trade regulations.
- Usage and analytics data: Retained in anonymized form indefinitely; identifiable data is deleted after 2 years.
- Marketing data: Retained until you unsubscribe or withdraw consent.
Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (subject to legal retention requirements).
- Restriction: Request restriction of processing in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
California residents (CCPA/CPRA): You have the right to know, delete, correct, and opt out of the sale/sharing of personal information. We do not sell personal information. To exercise your rights, contact us at the address below.
China residents (PIPL): You have rights to access, copy, correct, delete, and withdraw consent for your personal information. You may also request an explanation of our data processing rules.
Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- SOC 2 Type II certified infrastructure.
- Regular penetration testing and vulnerability assessments.
- Role-based access controls and multi-factor authentication.
- Continuous monitoring and incident response procedures.
While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
Children's Privacy
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting a prominent notice on our website or by sending you an email. We encourage you to review this page regularly.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Nexus Freight Technologies, Inc.
Data Protection Officer
100 AI Boulevard, Suite 400
San Francisco, CA 94105, USA
Email: privacy@nexusfreight.com
If you are in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.