FreightShield legal

Privacy Policy

Version 1.0 · Draft dated 1 August 2026

Pre-launch legal status. Prepared for independent Australian legal review; this is not yet the final published policy. Before account registration or paid launch, FreightShield must insert its registered legal operator, ABN or ACN, service address and effective date.

Primary storage

Private Supabase storage in the Sydney region.

AI processing

Some document and case data is processed overseas.

Your control

Ask for access, correction, deletion or a privacy review.

1. Who we are and when this policy applies

FreightShield is a Melbourne-based service currently focused on helping Victorian owner-drivers organise pay, work and evidence records. This policy explains how FreightShield collects, holds, uses, discloses, secures and deletes personal information through its website, member portal and related support.

The registered legal operator and ABN or ACN will be inserted here before launch. We use privacy practices designed to reflect the Australian Privacy Principles where they apply, as well as other privacy rules that may apply to particular information. This policy does not create or limit rights you have under law.

2. Information we collect

Depending on the features you use, we may collect:

  • Account and identity details: email address, full name, FreightShield member ID, sign-in and acknowledgement records.
  • Business and contact details: ABN, business name, phone, postal address, Victorian location, worker type, vehicle type and vehicle description.
  • Pay and work records: dates, times, breaks, hours, kilometres, vehicle or run type, rates, gross pay, deductions, expected amounts, possible shortfalls, odometer readings, tolls, jobs, customer or delivery details, proof-of-delivery references and notes.
  • Documents: contracts, rate cards, payslips, RCTIs, work records, proof of delivery, licences, accreditations, registrations, insurance records, fuel cards, bank statements, messages and other evidence you choose to upload.
  • Case and communication records: carrier names and contact details, your statement and authority, correspondence, staff notes, evidence status and case history.
  • AI inputs and outputs: uploaded files, extracted fields, explanations, document checks, case-audit notes, draft correspondence and, if you use the Android voice helper, the text of what you said (never the audio), as described below.
  • Billing details: Stripe customer, subscription and transaction identifiers. Stripe processes full payment-card details; FreightShield does not store the full card number.
  • Technical data: IP address, browser and device information, authentication and security events, page and performance data, error diagnostics and support communications.

3. How we collect information

We collect information directly from you when you create an account, complete onboarding, enter work or pay details, upload a file, submit a case, authorise carrier contact, manage billing or contact support. We also generate information when the Service calculates a comparison or processes a document.

A document or case may contain information about a carrier, customer, dispatcher, adviser or another person. Only provide another person's information where it is relevant, you are permitted to provide it, and it is reasonable for FreightShield to handle it for the stated purpose.

4. Why we use information

We use personal information where reasonably necessary to:

  • create and secure accounts, confirm eligibility and provide customer support;
  • store and organise documents, work records and case evidence;
  • extract fields, run pay comparisons, explain results and identify missing or inconsistent evidence;
  • prepare staff-reviewed carrier correspondence or an evidence pack when you request and authorise it;
  • administer plans, subscriptions, payments and mandatory financial records;
  • detect abuse, investigate errors, protect users and improve reliability; and
  • meet legal obligations, respond to lawful requests and resolve complaints or disputes.

If we want to use personal information for a materially different purpose, we will seek permission or rely on another lawful basis. We do not sell personal information.

5. AI-assisted processing

FreightShield currently uses AI in the following ways:

Raw-document AI processing is disabled by default while sensitive-data safeguards are being finalised. It must not be enabled in production until the upload controls and provider settings have been approved.

  • Document reading and checking: uploaded PDF or image files may be sent to Anthropic's Claude API to extract contract or payslip fields and assess whether selected evidence is legible and relevant.
  • Pay explanations: a redacted set of figures and a reference label may be sent to Anthropic to create a plain-English explanation. Names, ABNs and account numbers are removed from this particular request.
  • Case-file review: structured case facts, including carrier, pay-period, work, payment, statement, evidence and confidence details, may be sent to Anthropic to identify inconsistencies or missing material.
  • Voice helper (Android app): if you tap the microphone button on the Daily Driver Log, your phone's own speech service turns what you say into text. FreightShield receives only that text, never the audio, and does not record or store audio. The words, with the run sheet as it stands, are sent to Anthropic to work out which fields to fill in. Your phone's speech service handles the audio under its provider's own terms. The microphone is used only while the voice panel is open, and typing instead is always available.
  • Draft carrier letters: driver and member identifiers, carrier details, dates, payment figures and confidence information may be sent to an OpenAI model through Vercel AI Gateway to prepare a draft for staff review.

AI can make mistakes. Extracted fields and outputs must be checked against source records. A person reviews carrier correspondence before sending, and FreightShield does not use AI to make a final legal determination about whether a carrier owes money. We use business/API services that state customer content is not used for model training by default. Draft carrier-letter requests also require zero-data-retention routing through Vercel AI Gateway and fall back to a non-AI template if that control is unavailable. Other provider retention and approved subprocessors remain governed by their current commercial terms and our configuration.

6. Who we disclose information to

We may disclose only the information reasonably required to:

  • Supabase for authentication, database and private file storage;
  • Vercel for website hosting, performance measurement and AI Gateway routing;
  • Anthropic and OpenAI for the AI-assisted functions described above;
  • Stripe for subscription and payment processing when billing is enabled;
  • Resend for account, support and authorised carrier emails;
  • Sentry for error and performance diagnostics;
  • authorised FreightShield staff and contractors who need access to operate, secure or support the Service;
  • a carrier or its nominated contact where you have authorised FreightShield to send correspondence;
  • an independent professional adviser where you instruct or separately engage them; and
  • regulators, courts, law-enforcement bodies or other parties where required or authorised by law.

We do not disclose your case to a lawyer or other professional merely because you create an evidence pack.

7. Storage and overseas disclosure

FreightShield's linked Supabase project uses the Sydney, Australia region for its primary database and private document storage. User files are stored in a private bucket and normally opened through short-lived, signed access links. Authorised server-side administration and support processes can access records where needed.

Other providers and their subprocessors may process or store personal information outside Australia, including in the United States and other countries in which they operate. This includes Vercel, Anthropic, OpenAI, Stripe, Resend and Sentry. Overseas privacy protections may differ from Australian protections. We take reasonable steps appropriate to our role and provider arrangements to protect information sent overseas.

8. Sensitive information and upload safety

Do not upload a tax file number, bank password, account login, health or medical record, or other sensitive information that FreightShield has not specifically requested. Payslips and contracts can contain hidden or unnecessary personal information; review and redact the file before uploading it.

If we identify information we did not request and are not permitted or reasonably required to hold, we may reject the upload or securely delete or de-identify that information where lawful and practicable. Contact us immediately if you upload sensitive information by mistake.

9. Security

We use measures designed for the type of information held, including encrypted connections, authentication, owner-scoped database access controls, private storage, short-lived file links, role-limited staff access, audit records and security monitoring. No online service can guarantee absolute security.

If an eligible data breach is likely to cause serious harm, we will assess it and notify affected people and the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires it.

10. Retention, deletion and account closure

We keep personal information only while reasonably needed for the Service, security, dispute handling and legal or financial record-keeping. Ordinary documents that are not linked to a submitted case can be deleted through the Service. Case-linked evidence and correspondence may be retained while a case, complaint, payment issue or legal obligation remains active so the record is not misleading or incomplete.

Account closure and full deletion are currently handled by verified written request, not by an automatic self-service button. We will verify identity, explain what can be deleted, remove eligible live data and separately address any active Stripe subscription. Some records may be retained where required by law or reasonably necessary for fraud, security, accounting or dispute purposes. Residual copies may remain in protected backups until those backups are overwritten under provider schedules.

11. Access, correction and privacy requests

You may ask for access to or correction of personal information we hold about you, request deletion of eligible information, withdraw an optional consent, or ask how an automated feature handled your information. We may need to verify your identity. If we refuse a request permitted by law, we will explain why and how to complain.

Email sasha@freightshield.com.au with the subject “Privacy request”. We aim to acknowledge requests promptly and respond within a reasonable period, ordinarily within 30 days.

12. Privacy complaints

Send the facts, relevant dates and the outcome you want tosasha@freightshield.com.au. We will investigate, keep you informed where more time is needed, and provide an outcome. If you are not satisfied, you may contact theOffice of the Australian Information Commissioner.

13. Analytics, cookies and communications

The Service uses essential authentication and security storage needed to keep you signed in. Vercel Analytics and Speed Insights provide page-usage and performance measurements, and Sentry provides diagnostic data. We do not use third-party behavioural advertising cookies in the current Service.

We may send account, security, billing and case-related messages needed to provide the Service. We will send marketing messages only where permitted and will include a working way to unsubscribe. Unsubscribing from marketing does not stop necessary service messages.

14. Children

The Service is for adults aged 18 or over. We do not knowingly offer accounts to children.

15. Changes and contact details

We may update this policy when the Service, providers or law changes. We will publish the revised date and give reasonable notice of a material change where practicable. The registered legal operator, ABN or ACN, service address and effective date must be inserted here before launch.

Pre-launch privacy contact: sasha@freightshield.com.au. See also our Terms of Service.

This policy describes FreightShield's current product flow; it is not a substitute for independent legal advice.