Location notice: Precise route and location information is central to matching, live tracking, mileage calculation, Driver compensation, safety, and proof of delivery. Section 5 explains when it is collected and shared.

Privacy practices at a glance

This summary is qualified by the detailed sections below.

CategorySourcesPurposesRecipientsTypical retention
Identity and accountsYou, administrators, identity providersAccounts, authentication, support, securityIdentity, hosting, support and security providersRelationship plus up to 7 years where needed
Driver and screeningDrivers, applicants, screening, motor-vehicle and insurance sourcesEligibility, verification, safety and lawful qualificationScreening, identity, insurance, advisers and authoritiesUp to 7 years; biometrics follow separate schedule
Delivery and itemSenders, merchants, Drivers, Recipients and Platform eventsQuote, match, fulfill, track, support and claimsDelivery participants, merchants, support, insurersCore records up to 7 years; proof up to 5 years
Location and routeDevices, maps, registered trips and delivery eventsMatching, live tracking, mileage, safety and fraud preventionActive delivery participants, mapping, analytics and support providersGranular route data up to 24 months
Payments and taxYou, merchants, payment and payout providersCharges, payouts, refunds, tax and fraud reviewProcessors, financial institutions, tax and claims recipientsUp to 7 years or longer when legally required
Device and usageBrowsers, apps, cookies, SDKs and logsSecurity, preferences, diagnostics, analytics and attributionHosting, analytics, security and communications providersAs needed for purpose, security and legal claims
Communications and sensoryMessages, calls, uploads, cameras and supportDelivery proof, support, safety, disputes and qualityDelivery parties when needed, support, insurers and authoritiesRecordings up to 3 years; proof up to 5 years
Inferences and AI outputsPlatform activity, preferences, selections and outcomesMatching, ranking, pricing, risk, fraud and improvementAuthorized users as indicators; restricted AI and analytics providersSource-record schedule; de-identified patterns may persist

1. Scope and who we are

This Privacy Policy explains how CommuterCart (CommuterCart, we, us, or our) collects, uses, discloses, retains, and protects personal information through the CommuterCart websites, mobile experiences, dashboards, APIs, checkout widgets, point-of-sale products, delivery-matching tools, communications, and related services (collectively, the Platform).

This Policy applies to Drivers and Driver applicants; individual and business Senders; Recipients and pickup contacts; merchants and their personnel; website visitors; support contacts; and other people whose information is provided to us in connection with a delivery. It should be read with our Terms of Service at /terms and any applicable merchant, POS, API, or other written agreement. Drivers and applicants should also read the role-specific notice at /driver-privacy and Driver Platform Terms at /driver-terms.

For most Platform operations, CommuterCart determines why and how personal information is processed. When we process customer information solely on a merchant’s documented instructions through a white-label widget, POS, or API, the merchant may be the business or controller and CommuterCart may act as its service provider or processor. We may still process limited information for our own delivery, payment, safety, security, fraud-prevention, legal, and recordkeeping purposes.

The Platform initially serves approved delivery activity in Maine and is intended for use within the United States. Information about planned New England or national expansion does not mean service or data collection has launched in another state. Before entering a new state, CommuterCart will apply required notices, rights, registrations, and operational controls for that location.

2. Privacy summary

We collect information needed to operate a delivery network, verify participants, calculate and process payments, provide merchant software, improve TransportAI, and keep people and property safe. Because CommuterCart matches deliveries to existing trips, precise location and route information are central to the service.

We do not sell personal information for money. We do not use precise location, government identification, payment credentials, or delivery photographs for targeted advertising. We may create and commercialize aggregated or de-identified operational insights that are not reasonably capable of identifying a person, household, or individual merchant unless that merchant authorizes identification.

  • Drivers control whether to go online and may manage device location permissions, but disabling required location access may prevent matching, tracking, mileage verification, or payment calculation.
  • During an active delivery, limited Driver identity, vehicle, progress, and location information may be visible to the Sender, merchant, pickup contact, or Recipient.
  • Senders and merchants must provide only information they are authorized to share and must inform Recipients and pickup contacts that CommuterCart will process their information.
  • Privacy rights vary by state and may include access, correction, deletion, portability, opt-out, limitation, and appeal rights.

3. Personal information we collect

The information we collect depends on your role, the products you use, and the permissions you enable. It may include the categories below.

  • Identity and contact information: name, email, phone number, mailing or physical address, date of birth, profile image, signature, account identifier, and authentication credentials.
  • Driver and applicant information: driver’s license and other government identification, address history, vehicle type and capacity, registration, insurance information and documents, work authorization where required, screening status, driving or criminal-history results where permitted by law, emergency contact, availability, preferred routes, active days and times, detour tolerance, item restrictions, and onboarding records. For an approved specialized workflow, this may include a relevant commercial, medical, notary, security, handling, or other professional credential or confidentiality commitment.
  • Sender, Recipient, and pickup-contact information: names, phone numbers, email addresses, pickup and delivery addresses, access details, delivery preferences, signatures, and instructions provided by a Sender or merchant.
  • Delivery and item information: tracking identifiers, package description, dimensions, weight, configuration, declared value, general content category, packaging, fragility, noise, temperature or other handling limits, required qualifications, photographs, pickup and drop-off details, availability windows, delivery mode, route, stops, selections, confirmations, execution events, proof of tender, proof of delivery, claims, ratings, criteria, comments, and incident reports. Prohibited or regulated items remain subject to the Terms and are not authorized merely because the Platform can record a content category or qualification.
  • Business and POS information: business and personnel contacts, locations, hours, product catalog, inventory, orders, customers, suppliers, sales, refunds, loyalty activity, integration settings, API and webhook activity, analytics, support records, and account permissions.
  • Transaction information: quoted and final charges, Driver offers and payouts, tips, fees, refunds, execution events, payment status, payment method type, limited card details, bank or payout-account status, ACH records, tax records, invoices, and chargebacks. Payment providers generally collect complete card or bank credentials directly.
  • Communications and content: in-app messages, texts, call metadata, support requests, chatbot interactions, emails, reviews, survey responses, attachments, and recordings when notice and law permit.
  • Device, network, and usage information: IP address, device and advertising identifiers where enabled, browser, operating system, app version, language, referring page, pages or features used, clicks, session dates and times, diagnostics, crash reports, and security events.
  • Visual, audio, and sensor information: profile and identity images, delivery photographs, uploaded documents, support recordings, signatures, and device-generated location or movement signals.
  • Preferences, inferences, and scores: user-entered or system-suggested priority weights; route, item, Sender, and Driver compatibility; requirement, possibility, inclination, capability, and qualification labels; opportunity forecasts; eligible-item and potential-Driver rankings; estimated arrival and success probability; reliability, response, acceptance, cancellation, punctuality, rating, risk, trust, demand, and suspected-fraud measures; and reasons or principal factors associated with those outputs.

4. Sources of personal information

We collect personal information directly from you; automatically from your device and Platform activity; from Senders, merchants, Recipients, pickup contacts, Drivers, and authorized account administrators; and from service providers and other lawful sources.

  • Identity, screening, insurance, motor-vehicle, fraud-prevention, payment, payout, mapping, analytics, communications, and support providers.
  • Merchant POS systems, ecommerce services, checkout widgets, APIs, webhooks, and other integrations authorized by a business.
  • Public records and publicly available sources where permitted by law.
  • Referrals, business partners, claimants, law enforcement, insurers, and witnesses to safety or delivery incidents.
  • Other users who provide information about you, such as a Sender entering a Recipient’s address, a merchant creating a delivery for a customer, or a participant submitting a referral. A person making a referral represents that they are authorized to provide the contact information; we use it to send the referral, measure the program, prevent abuse, and honor opt-outs.

5. Precise location, commute routes, and live tracking

Location information is essential to the Human Network and TransportAI. A Driver may provide home and work areas, a registered commute or intended trip, typical departure and arrival times, active days, maximum detour, and preferred service area. We may collect precise GPS coordinates, geocodes, timestamps, heading, speed or movement signals, route progress, pickup and drop-off events, deviations, stop sequence, and return-to-route activity when the Driver is online, available for matching, or completing a delivery.

Depending on device settings and permissions, location may be collected while the app is visible and, when needed for availability, safety, or an active delivery, while it runs in the background. We use this information to find nearby or route-compatible opportunities; verify arrival, pickup, custody, delivery, and return legs; estimate timing; calculate distance-based charges and Driver compensation; detect route manipulation or fraud; provide support; investigate incidents; and improve matching and demand models. At or before collection, we provide contextual notice where required, including when enabling background location, camera or microphone access, identity or credential upload, screening, biometric verification, communication recording, or merchant submission of customer information.

During an active delivery, we may share the Driver’s approximate or precise progress, route map, estimated arrival, and pickup or delivery status with the Sender, applicable merchant, pickup contact, or Recipient. We may delay, reduce, or stop live sharing when reasonably necessary for safety or privacy. Live tracking ends after completion, cancellation, or other closure of the active delivery, but underlying route and event records may be retained as described below.

A Driver can manage location permissions through device settings and can stop new availability by going offline. Disabling or restricting location may prevent offers, active tracking, route confirmation, safety features, mileage calculation, or payment. Location collected for an active delivery may still be retained even if permission is later withdrawn.

6. Photographs, signatures, and private property

Drivers, Senders, merchants, and Recipients may be asked to provide item, pickup, damage, identity, or proof-of-delivery photographs and signatures. A delivery photograph may show a doorway, porch, receiving area, mailbox, vehicle, address marker, or other private property near the authorized delivery location, and may include location and time metadata.

Users should frame proof photographs around the item and authorized delivery location, avoid photographing through windows or into private living areas, and avoid capturing faces, children, license plates, documents, access codes, or unrelated property unless reasonably necessary to document delivery, damage, safety, or fraud. Proof records may be shared with the parties to the delivery, support providers, insurers, investigators, or authorities when needed for completion, claims, safety, or law.

7. How we use personal information

We use personal information for the following business and operational purposes:

  • Create and administer accounts, authenticate users, verify identity, eligibility, licenses, insurance, vehicles, businesses, and authorized personnel.
  • Receive, price, match, batch, dispatch, track, complete, return, and document deliveries across CC Commuter, CC Local, and CC Direct.
  • Operate Last Mile in a Box, merchant dashboards, checkout widgets, APIs, analytics, and CommuterCart POS products.
  • Calculate quotes, route deviations, distance bands, offers, fees, refunds, Driver compensation, taxes, and payouts; process transactions; and maintain financial records.
  • Communicate about offers, deliveries, account security, service changes, support, claims, disputes, marketing preferences, and legal notices.
  • Protect users, Recipients, merchants, the public, items, and the Platform; prevent fraud, theft, unsafe conduct, account sharing, manipulation, and prohibited-item activity.
  • Provide customer support, investigate incidents, resolve disputes, administer claims, enforce agreements, and comply with insurance and legal requirements.
  • Measure performance, troubleshoot, test, research, develop, secure, and improve the Platform, including TransportAI models that forecast Sender and Driver opportunities or requirements, qualify and rank potential matches, learn from selections and delivery outcomes, and update route, demand, pricing, reliability, trust, and risk measures.
  • Create aggregated or de-identified statistics, network benchmarks, market intelligence, and operational insights.
  • Comply with law, respond to valid legal process, establish or defend legal claims, and complete corporate transactions.

8. TransportAI, inferences, and automated processing

TransportAI and related systems use current and historical Sender requests, item and delivery details, Driver capabilities, upcoming trips, routes, timing, credentials, availability, preferences, priority weights, selections, confirmations, execution events, ratings, claims, fraud signals, and delivery outcomes to operate two-sided forecasting, matching, and qualification systems.

These systems may create requirement, possibility, inclination, capability, compatibility, and qualification labels; forecast Sender or Driver opportunities and future requirements; generate eligible-item or potential-Driver rankings; batch compatible deliveries; suggest prices, routes, and timing; seed user-adjustable priority settings; identify anomalies; and calculate or update reliability, trust, and risk measures. We do not use protected characteristics as matching criteria. A license, clearance, insurance, signature, confidentiality, equipment, or handling requirement must relate legitimately to the delivery.

Automated outputs may affect which opportunities, items, Senders, or Drivers are displayed, their order, suggested pricing or timing, requests for verification, and whether activity is restricted or sent for human review. Users choose whether to accept an available recommendation. We do not intend to make a decision producing legal or similarly significant effects solely through automated processing without the notice, safeguards, and rights required by applicable law.

When a User selects a recommendation, the Platform may send the related request or capability information to the other party and create selection and confirmation records. After an execution or delivery event, we may collect item, Sender, or Driver criteria and feedback, link it to the selection, store it with relevant Sender and Driver records, and use it in future recommendations, qualifications, and model updates.

We use supervised, unsupervised, on-demand, and other machine-learning methods to train, test, validate, and improve models. Prior selections and outcomes may continuously adjust later outputs. Where reasonably practicable, development data is minimized, aggregated, pseudonymized, or de-identified. We do not authorize model providers to use personal information submitted on our behalf for unrelated advertising profiles.

We do not intentionally use protected characteristics, unrelated medical information, complete credential documents, authentication secrets, or raw payment credentials to train ordinary matching or ranking models. We may filter, redact, restrict, or exclude free-text feedback and other information that appears discriminatory, unlawfully sensitive, unrelated to delivery performance, or unsuitable for model development. We use commercially reasonable testing and review designed to identify unlawful discriminatory outcomes and material proxy effects before and after material model changes.

Automated outputs can be incomplete or inaccurate and do not guarantee identity, credentials, legality, safety, availability, suitability, acceptance, earnings, or completion. When an automated output materially restricts an account, disqualifies a User, changes eligibility, or otherwise requires review by law, we provide available notice of the result, the categories of information used, and principal factors that contributed to it. A User may submit corrections or supporting information and request review by a person authorized to confirm, modify, or reverse the result. We respond within the period required by law and provide any available appeal or regulatory-complaint information without disclosing trade secrets or compromising security.

9. How we disclose personal information

We disclose personal information only as reasonably necessary for the purposes described in this Policy, including to:

  • Delivery participants: Drivers receive necessary pickup, item, contact, access, qualification, and drop-off information; Senders and merchants may receive Driver name, profile image, vehicle details, relevant capability, rating or verification indicators, contact tools, estimated arrival, live progress, route map, confirmations, and proof records. We may ask a party to submit delivery-related criteria or feedback about the other party or item. We do not disclose underlying model profiles, unrelated history, complete credentials, or another user’s sensitive documents merely because a recommendation or indicator is displayed.
  • Merchants and account administrators: businesses may access orders, customer-provided delivery details, delivery history, support records, live tracking, proof, billing, analytics, and authorized-user activity associated with their accounts.
  • Service providers: hosting, database, mapping, geocoding, payment, payout, identity, screening, insurance verification, communications, support, analytics, security, fraud-prevention, document storage, AI, and professional-services providers acting under appropriate restrictions.
  • Payment, insurance, and claims participants: processors, financial institutions, insurers, brokers, adjusters, claimants, and involved parties as needed to administer payments, coverage, incidents, disputes, or claims.
  • Authorities and legal recipients: courts, regulators, law enforcement, emergency services, and other parties when we reasonably believe disclosure is required or permitted to protect rights, safety, property, users, or the public; comply with legal process; or investigate unlawful activity. We review requests for apparent validity, authority, scope, and jurisdiction, seek clarification or narrowing when appropriate, disclose only information reasonably responsive to the request, and may preserve or disclose information without ordinary process when we reasonably believe an emergency involving danger of death or serious physical injury requires it. We notify the affected person when legally permitted and appropriate.
  • Corporate transaction participants: actual or prospective investors, lenders, advisers, buyers, successors, or transaction counterparties under appropriate confidentiality protections in connection with financing, reorganization, merger, acquisition, or asset transfer.
  • Other recipients at your direction, with your consent, or as otherwise clearly disclosed when information is collected.

10. Merchant, POS, widget, and API data

Merchants may submit customer, employee, supplier, product, inventory, order, payment-status, loyalty, and delivery information through Last Mile in a Box, CommuterCart POS, a widget, or an integration. Each merchant is responsible for providing required notices, obtaining required permissions, limiting data to what is necessary, honoring its customers’ rights, and configuring access for its personnel.

Statements that a merchant owns its customer relationship or data mean that CommuterCart does not claim ownership of the merchant’s underlying business records or use merchant-identifiable customer data to disintermediate the merchant. Personal information is not property in every jurisdiction. CommuterCart and the merchant may each have independent legal duties for information they control, and a written data-processing agreement may further allocate those responsibilities.

We may use merchant data to provide and secure contracted services, create and qualify delivery requests, rank potential Drivers, apply merchant or customer priority settings, exchange selections and confirmations, fulfill deliveries, process payments, provide analytics and support, improve TransportAI, comply with law, and create aggregated or de-identified insights. A merchant must use a secure approved workflow for sensitive credentials and may access Driver information only as needed for delivery, safety, support, or compliance. We will not disclose one merchant’s identifiable customer list, sales history, or inventory to another merchant or a data buyer without authorization or another lawful basis.

When CommuterCart acts as a processor or service provider for a merchant, the Data Processing Addendum available at /data-processing-addendum governs documented instructions, purpose limitations, confidentiality, subprocessors, security, rights-request assistance, incident notification, retention, deletion or return, audit information, and legally required transfer safeguards.

11. Payments, identity, screening, and insurance providers

Payment and payout providers may collect card, bank, ACH, tax, identity, and transaction information directly under their own privacy notices. CommuterCart generally receives tokens, limited account details, status, amounts, and transaction identifiers needed to administer charges, refunds, and payouts rather than complete payment credentials.

Where permitted, we may use third parties to verify identity, licenses, insurance, vehicle information, business records, driving history, or criminal history. Approved specialized workflows may verify a relevant commercial, medical, notary, security, confidentiality, handling, or other professional qualification. Providers may collect government identifiers and other sensitive information directly. We use verification results or limited indicators to determine eligibility, match a legitimate delivery requirement, prevent fraud, satisfy insurance or legal requirements, and conduct periodic reverification. Verification is not a guarantee. Consumer-report disclosure and authorization are presented separately from this Policy through the Screening Disclosure and Authorization at /screening-notice, and required pre-adverse and adverse-action notices are provided separately.

Authentication and transaction-security tools may use passwords, PINs, passphrases, one-time codes, security tokens, device signals, digital certificates, and confidence or risk scores. We use them to authenticate people and devices, protect accounts and payments, and investigate suspected misuse. We do not display complete credentials or authentication factors to other delivery participants.

Submitting an ID image or selfie does not by itself mean we create biometric identifiers. Before collecting or generating a legally regulated biometric identifier, we provide the Biometric Information Notice at /biometric-notice and obtain any consent or written release required by law. That notice identifies the data, purpose, provider, disclosure practices, safeguards, retention period, and destruction schedule. Unless a shorter period is required, biometric information is destroyed when its purpose is satisfied or no later than three years after the person’s last interaction with CommuterCart. Biometric data is not used for advertising or unrelated model training, and a reasonable non-biometric verification method will be offered where legally required.

12. Cookies, analytics, and advertising choices

We and our providers may use cookies, local storage, pixels, SDKs, and similar technologies for authentication, security, preferences, communications, diagnostics, analytics, attribution, and, if enabled, advertising. These technologies may collect device, browser, IP address, page, interaction, and approximate-location information over time.

You can manage available cookie choices through any consent tool we provide and through browser or device settings. Blocking necessary technologies may prevent login or other features. We honor legally required opt-out preference signals, such as Global Privacy Control, where they apply and can be associated with the relevant browser or device. Because there is no uniform industry response to browser Do Not Track signals, we do not respond to them unless legally required; use Global Privacy Control or the available consent controls for supported opt-outs.

CommuterCart does not currently sell personal information for money or share personal information for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws. If that practice changes, we will update this Policy and provide required notice and opt-out methods before applying the change. If session-replay, chatbot, social-login, referral-attribution, cross-device measurement, or advertising technologies are enabled, we identify their purpose through this Policy and any legally required collection-time or cookie notice. Before offering a loyalty program or financial incentive involving personal information, we will publish the material terms, valuation method where required, and withdrawal process and obtain any required opt-in.

13. Aggregated and de-identified information

We may combine and transform sales, inventory, delivery, route, timing, demand, pricing, and network information into aggregated or de-identified data for analytics, benchmarking, forecasting, product development, community planning, research, investor reporting, or commercial insights for merchants, distributors, brands, and supply-chain participants.

We maintain de-identified information in de-identified form, use reasonable measures designed to prevent it from being associated with a person or household, and do not attempt to re-identify it except to test whether de-identification controls are effective or as permitted by law. We require recipients to use it only in de-identified or aggregate form. Merchant-identifiable analytics are disclosed outside that merchant only with authorization or under an agreement allowing the disclosure.

14. Sensitive information, pharmacy, and health-related deliveries

Precise location, government identifiers, account and authentication credentials, payment information, background information, biometrics, professional licenses, security clearances, medical or commercial qualifications, insurance, confidentiality commitments, and certain contents of communications may be considered sensitive personal information. We use sensitive information only for reasonably necessary Platform, delivery, payment, safety, security, verification, lawful qualification, legal, and other disclosed purposes; restrict access to personnel and providers with a need to know; and obtain consent or provide limitation rights where required. The ordinary Platform does not use sensitive information to infer protected characteristics or for targeted advertising.

The ordinary Platform is not intended for users to submit diagnoses, treatment details, prescription names, or other unnecessary health information. A pharmacy, medical office, or other regulated entity must not submit protected health information unless CommuterCart has approved the workflow and the parties have entered any agreement required by law, including a business associate agreement when applicable. We do not use health-related delivery information for targeted advertising and do not use route, address, delivery, browsing, or purchase information to infer a person's health condition, treatment, religion, immigration status, sexual orientation, or other sensitive trait for advertising, eligibility, or unrelated profiling. Prescription, specimen, and other regulated deliveries remain prohibited unless separately approved and legally supported. The Consumer Health Data Notice at /consumer-health-notice applies to an approved workflow when a state consumer-health law governs the information.

15. Retention and deletion

We retain personal information only for as long as reasonably necessary for service delivery, account administration, transactions, taxes, Driver payments, merchant contracts, security, fraud prevention, insurance, claims, litigation holds, and legal compliance. Under our claims-focused schedule, we ordinarily retain core delivery, payment, payout, tax, business transaction, screening, and credential-verification records for up to seven years after the transaction or relationship; proof photographs and signatures for up to five years; precise route traces and granular movement data for up to twenty-four months; and recorded support communications for up to three years.

Live location stops being displayed after an active delivery closes. A pending claim, investigation, safety matter, chargeback, legal hold, insurance requirement, or law may require longer retention. Biometric information follows the shorter period in Section 11 and the Biometric Information Notice. Training records or model parameters may retain learned patterns after source records are deleted, but we remove or isolate identifiable source data when required and reasonably feasible. When retention ends, information is deleted, de-identified, aggregated, or securely isolated under our retention procedures.

You may request account deletion and deletion of eligible personal information. Deleting an account does not require deletion of records we must or are permitted to retain, including completed transactions, tax and payout records, fraud and safety records, legal claims, consent records, de-identified data, or information needed to protect other users. When retention ends, we delete, de-identify, aggregate, or securely isolate the information under our retention procedures. Backup copies may persist for a limited period before routine overwrite.

16. Information security

We use administrative, technical, and physical safeguards designed for the nature of the information we process, which may include access controls, least-privilege permissions, authentication, encryption in transit and at rest where appropriate, logging, monitoring, vendor review, secure development, incident response, and personnel confidentiality obligations.

No system, transmission, or storage method is completely secure. Users are responsible for safeguarding credentials, devices, API keys, POS access, and verification codes and for notifying us promptly of suspected unauthorized access. Do not send complete payment credentials, government identifiers, medical details, or access codes through ordinary messages unless specifically requested through a secure workflow.

17. Your choices and privacy rights

Depending on your location and relationship with us, you may have the right to confirm whether we process your personal information; access or receive a portable copy; correct inaccuracies; delete eligible information; withdraw consent; limit certain uses of sensitive information; opt out of sale, sharing, targeted advertising, or qualifying profiling; and appeal a denied request.

Submit a request through in-app support or the Privacy Request form at /privacy-request. We verify identity and authority using information reasonably related to the request. An authorized agent may submit a request where permitted, but we may require proof of authority and direct identity confirmation. We generally acknowledge and respond within forty-five days unless applicable law provides a different period or permits an extension. If we deny a request, we explain the basis and provide available appeal instructions. Submit an appeal through the same form by selecting Privacy Appeal; we respond within the period required by applicable law and provide any required regulator-complaint method. We do not discriminate against a person for exercising a privacy right, although deleting or limiting information may make a service unavailable.

You may update certain profile, capability, credential, preference, and priority information in your account; manage device permissions; go offline to stop new Driver availability; unsubscribe from marketing; and control cookies as described above. You may also report inaccurate criteria or feedback and question a material automated qualification or ranking through support. Transactional, safety, account, payment, and legal communications are not marketing and may continue while relevant. Alternative accessible formats of this Policy and reasonable assistance with the privacy-request process are available through in-app support or /privacy-request.

18. Supplemental notice for U.S. state residents

During the preceding 12 months, we may have collected the categories described in Section 3, including identifiers; customer records; commercial, financial, professional, internet, device, geolocation, sensory, and inference information; and sensitive information such as precise location, government identifiers, credentials, and screening data. We collect these categories from the sources in Section 4, use them for the purposes in Sections 5 through 8, and disclose them to the recipients in Section 9.

We do not sell personal information for money. We do not knowingly sell or share personal information of people under 18. We do not use or disclose sensitive personal information for purposes that require a right to limit under applicable law without providing that right. We may disclose personal information to service providers, contractors, delivery participants, merchants, processors, insurers, professional advisers, authorities, and transaction counterparties for the purposes described in this Policy; those operational disclosures are not necessarily a sale or sharing under state law.

Residents of any U.S. state whose comprehensive privacy law applies to our processing may exercise the rights provided by that law through Section 17, subject to statutory scope, thresholds, exemptions, and verification. Depending on the applicable law, rights may include access, correction, deletion, portability, opt-out of sale, sharing, targeted advertising or qualifying profiling, consent or limitation for sensitive data, a list of relevant third parties, and appeal. We recognize legally required universal opt-out preference signals where applicable. If we deny an appeal, we provide any required regulator-complaint method. California residents may request qualifying direct-marketing disclosures under Shine the Light; Nevada residents may submit a verified request to opt out of covered sales, although we do not currently engage in such sales. Before materially launching in a new state, we review and publish any additional state-specific notice, consent, assessment, or appeal procedure required there.

18A. Maine privacy and data-security notice

Privacy rights available to Maine residents depend on applicable federal and Maine law. CommuterCart also voluntarily makes the request process in Section 17 available to Maine residents, subject to identity verification, lawful exceptions, operational necessity, and technical feasibility. We review this Maine notice before material changes and before expansion into another state rather than relying on a fixed statement about pending legislation.

CommuterCart maintains an information-security and incident-response program designed to comply with Maine’s Notice of Risk to Personal Data Act, 10 M.R.S. chapter 210-B. If we discover unauthorized acquisition, release, or use of covered personal information, we will investigate scope and likelihood of misuse, take reasonable containment and remediation steps, and notify affected Maine residents, the Maine Attorney General, consumer reporting agencies, or other recipients when and in the time and manner required by law.

Driver, applicant, identity, insurance, and screening information may be subject to the Maine Fair Credit Reporting Act, 10 M.R.S. chapter 209-B, as well as federal law. When CommuterCart uses a covered consumer report, we will use it only for a permissible purpose and provide required authorization, disclosure, adverse-action, source, file-access, and dispute information. Identity documents and report contents are limited to personnel and providers with an operational need.

Precise location, route traces, and proof photographs are used as described in Sections 5 and 6. Users may not use Platform location or camera features for unlawful tracking, secret surveillance, or recording in violation of Maine law, including 17-A M.R.S. §511. CommuterCart provides notice and obtains consent for recorded support calls or other communications when required by Maine and federal law.

Maine’s internet-service-provider privacy law in 35-A M.R.S. chapter 94 regulates providers of broadband Internet access service and does not generally make CommuterCart an Internet service provider. We nevertheless do not sell precise location, government identification, payment credentials, or delivery photographs and do not use them for targeted advertising. If our role or Maine law changes, we will update our practices and notices before undertaking newly regulated processing.

18B. Federal postal-law compliance data

CommuterCart is a private goods-and-parcel delivery platform and does not offer ordinary paid carriage of matter reserved to the United States Postal Service. To comply with 39 U.S.C. §§601-606, 18 U.S.C. §§1693-1699, and 39 C.F.R. parts 310 and 320, we may collect a shipment’s packaging type, weight, dimensions, general content category, sender and recipient, relationship of an enclosed document to accompanying cargo, requested and actual timing, price, route, delivery purpose, postage evidence, and the exclusion, exception, or suspension asserted by a customer.

We use this information to distinguish goods and cargo-related papers from potentially regulated letters; screen, approve, refuse, reroute, return, or document a request; prevent use of USPS mailboxes; preserve evidence of timing, price, postage, and cargo relationship; seek a USPS advisory opinion; investigate suspected misuse; and respond to lawful postal inquiries. A user must not place unrelated correspondence inside merchandise to avoid disclosure. We ordinarily do not need to read a document’s substantive message, but may require the Sender to describe it, provide a nonconfidential sample, or show enough information to establish lawful carriage before acceptance.

Postal-compliance records may be disclosed to the Sender, Recipient, merchant, or Driver as needed to correct or refuse a shipment; to legal, audit, insurance, and compliance providers; and to USPS, the U.S. Postal Inspection Service, the Postal Regulatory Commission, courts, or law enforcement when required or reasonably necessary to address suspected unlawful carriage, unpaid postage, mailbox misuse, seizure, legal process, or a safety or fraud matter. We do not use the substantive content of a document obtained solely for postal classification for targeted advertising, and we limit retention to the period reasonably needed for the delivery, audit, dispute, investigation, legal hold, or applicable recordkeeping requirement.

19. Children’s privacy

The Platform is not directed to children under 18, and people under 18 may not create Sender or Driver accounts. We do not knowingly collect personal information directly from a child under 13. A Sender or merchant may provide a minor Recipient’s limited delivery details only when legally authorized and reasonably necessary to complete the delivery. If you believe a child provided information improperly, contact us so we can review and delete it where required.

20. U.S. processing and third-party services

CommuterCart is operated in the United States, and information may be processed and stored in the United States and other locations where our providers operate. Those locations may have different privacy laws. Where required, we use appropriate contractual or legal safeguards for transfers.

The Platform may link to or interoperate with third-party services, merchant sites, payment providers, mapping tools, identity providers, POS products, and social platforms. Their independent privacy policies apply when they determine how information is processed. CommuterCart is not responsible for an unaffiliated service’s privacy practices.

21. Changes to this Policy

We may update this Policy as the Platform, data practices, or law changes. We will post the revised version with a new effective date and provide additional notice or obtain consent when required. Material changes apply prospectively unless law permits otherwise.

22. Contact and privacy requests

Privacy questions, complaints, rights requests, appeals, and concerns about location, photographs, merchant data, or automated processing may be submitted through the Privacy Request form at /privacy-request, or mailed to CommuterCart, 186 Main Street, Farmington, ME 04938, United States. Accessibility requests, delivery claims, safety reports, legal notices, copyright notices, arbitration opt-outs, and general support requests must use /support. Include your name, account contact information, state of residence, relationship to CommuterCart, and enough detail for us to understand and verify the request. Do not include sensitive documents unless we ask you to use a secure method.