Privacy Policy

Last updated: July 2026

This Privacy Policy explains how FreightCMD ("we", "us") collects, uses and protects your personal information across the FreightCMD Management OS (tenant fleet software) and FCMD Connect (on-demand freight marketplace) products. We comply with the Sri Lanka Personal Data Protection Act No. 9 of 2022 (PDPA) where applicable.

1. Information we collect

  • Account details: name, email, phone, company, role (tenant owner, dispatcher, driver, shipper).
  • KYC data for marketplace drivers: NIC / passport number, driving licence, vehicle registration and insurance documents.
  • Operational data: pickups, drops, cargo, vehicles, drivers, invoices, payments, wallet ledger and COD hand-overs.
  • Location data from drivers' and trackers' devices while a trip or subscription is active.
  • Payment metadata: masked card BIN, gateway reference, PayHere / Stripe transaction IDs, bank-slip images. We do not store full card numbers or CVVs.
  • Device and usage data: IP address, browser, app version, device model, timestamps and push-notification tokens.

2. How we use information

  • To operate the dispatch platform, marketplace matching and live tracking.
  • To generate quotes, invoices, wallet transactions, payouts and per-trip P&L reports.
  • To verify marketplace-driver identity and enforce eligibility (5+ trips + KYC) before enabling fuel-float credit.
  • To send service notifications (SMS, email, push) related to your trips, wallet activity and subscription.
  • To reconcile wallets nightly, detect duplicate or fraudulent transactions, and comply with legal obligations.

3. Sharing between roles on the platform

FCMD is a multi-sided platform. Data flows only along the paths necessary to fulfil a trip or subscription:

  • Shipper → Driver / Tenant: pickup and drop address, contact number, cargo description, and shipper display name.
  • Driver → Shipper: display name, vehicle plate and photo, and live location while the trip is active.
  • Tenant → FCMD: full operational data for the tenant's own trips (needed for support, billing and reconciliation).
  • Marketplace driver → FCMD: KYC documents (accessible only to platform admins and compliance).

4. Sharing with third parties

We share data only with: (a) authenticated users in your organisation, per their assigned roles; (b) service providers under contract — Supabase (hosting / database), PayHere and Stripe (payments), Sampath Bank (settlements), Google Maps and Places (mapping and routing), Text.lk (SMS), Firebase Cloud Messaging (push); (c) authorities where required by law. We never sell personal data.

5. Driver & tracker location data

Driver GPS is captured only while a trip is active (status assigned, en route, at pickup, in transit). Vehicle-tracker GPS is captured while the tenant's tracker subscription is active. Both are used for dispatch visibility, customer ETA and per-trip P&L (distance measurement). Live points are shared with the paying shipper only for the duration of their trip. Historical points are retained for up to 186 days and then automatically purged.

6. Wallet, payment & audit data

Every wallet mutation is written to an immutable audit log for financial integrity. Payment gateway metadata is retained for chargeback and refund windows. Full card numbers and CVVs are never touched by our servers — they are collected directly by PayHere / Stripe.

7. Retention

Operational records (requests, invoices, wallet ledger, audit log) are retained for the period required by tax, accounting and financial-integrity regulations (typically 6 years in Sri Lanka). Account data is retained while your account is active. GPS points are purged after 186 days.

8. Your rights

Subject to applicable law, you may request access, correction, deletion or export of your personal data, and may withdraw consent for non-essential processing. Contact us at the address on the Contact page. Note that we may retain wallet, invoice and audit records after account deletion where required by law.

9. Security

We use encryption in transit, role-based access controls and row-level security on all sensitive tables. Server-side privileged operations (payouts, KYC, admin overrides) are gated behind an immutable audit log. No system is perfectly secure — please use a strong password and keep it private.

10. Changes

We may update this policy. We will post the updated date at the top of the page and, for material changes, notify you by email.