1. Controller and contact
CargoDuo ("CargoDuo", "we", "us", "our") is the controller of the personal data processed through the CargoDuo platform, the websites operated under the cargoduo.com domain (including app.cargoduo.com), and our associated APIs and SDKs (together, the "Service"). This Privacy Policy (this "Policy") explains what personal data we process, for what purposes, on what legal bases, and the rights available to you. For any privacy matter — including requests to access, rectify, erase, restrict, or port your data, objections to processing, withdrawals of consent, complaints, and questions about this Policy — contact us at info@cargoduo.com. Postal correspondence may be sent to the address published at cargoduo.com/contact. We respond to verifiable requests within 30 calendar days. We may extend that period by up to a further 60 days for complex or numerous requests, in which case we will inform you of the extension and the reasons for it within the initial 30-day period (Article 12(3) GDPR).
2. Scope of this Policy
This Policy governs the personal data we process in connection with the Service, namely data relating to: (a) visitors to our marketing site; (b) registered users of the application; (c) individuals who contact us through email or support channels; and (d) personal data contained within the shipment, cargo, vehicle, project and roster records that our customers upload. Where you use the Service on behalf of an organization, that organization is the controller of the operational data it uploads, and CargoDuo acts as its processor under the Data Processing Agreement ("DPA") available at /legal/dpa or on request. In that capacity the organization — not CargoDuo — determines the purposes and means of processing that data; requests concerning such data should be directed to that organization, and we will support it in responding as required by the DPA.
3. Categories of personal data we process
We process the following categories of personal data. Account and identity data: full name, work email, hashed password, organization name, role, and locale and time-zone preferences. Authentication and security data: session identifiers (HttpOnly cookies scoped to .cargoduo.com), IP address, user-agent, login timestamps, failed-login counters, and device characteristics used for anomaly detection. Billing data: billing contact, billing address, VAT or other tax identifier, the last four digits of the payment instrument, and invoice history. Full card numbers and bank-account numbers are never seen or stored by CargoDuo: all payments are processed securely by Paddle, our merchant of record, and card data is handled exclusively within Paddle's PCI-DSS Level 1 environment (see Section 9). Customer Content: the project, vehicle, cargo, shipment, route, group, template and packing-result records you upload to or generate within the Service. Such records may incidentally contain personal data (for example, a driver or contact name on a manifest) that you, as customer, are responsible for collecting and processing lawfully. Communications: support tickets, emails, chat transcripts, and any documents you send us. Telemetry: anonymized product-usage events, error reports and performance traces required to operate, secure, debug and improve the Service. Cookies and similar technologies: described in full at /legal/cookies.
4. Sources of personal data
We obtain personal data from three sources. First, directly from you, when you create an account, configure your workspace, upload data, or contact us. Second, automatically from your browser or device when you interact with the Service, by way of server logs, telemetry and cookies. Third, from third parties acting on your instruction — for example, an organization administrator who invites you to a workspace, a single sign-on identity provider against which you authenticate, or our payment provider when it confirms a transaction. We do not acquire personal data from data brokers or enrich your profile with purchased data (see Section 12).
5. Purposes and legal bases (EU/UK GDPR)
We process personal data only where a lawful basis applies. Performance of a contract (Art. 6(1)(b) GDPR): creating and operating your account, providing the Service, processing payments through our merchant of record, providing customer support, and enforcing our Terms. Legitimate interests (Art. 6(1)(f) GDPR): securing the Service against fraud, abuse and unauthorized access; debugging and improving the product; conducting aggregated analytics; defending or establishing legal claims; and managing corporate transactions. Where we rely on legitimate interests we have conducted a balancing test, and you may object at any time (see Section 11). Compliance with legal obligations (Art. 6(1)(c) GDPR): retaining tax and accounting records, responding to lawful requests from competent authorities, and complying with sanctions and export-control rules. Consent (Art. 6(1)(a) GDPR): non-essential cookies and direct marketing, each withdrawable at any time without affecting the lawfulness of processing carried out before withdrawal.
6. Purposes (United States — CCPA/CPRA, VCDPA, CTDPA, UCPA, CPA and other state laws)
We process the categories of personal information listed in Section 3 for the business purposes of (i) providing, supporting and securing the Service; (ii) managing customer relationships and billing; (iii) detecting and preventing fraud and abuse; (iv) complying with legal obligations; and (v) the additional business purposes enumerated in Cal. Civ. Code § 1798.140(e). We do NOT "sell" personal information, and we do NOT "share" it for cross-context behavioral advertising, as those terms are defined under the CPRA. We do not knowingly sell or share the personal information of consumers under 16. We do not use sensitive personal information for purposes beyond those permitted by § 1798.121 CPRA. Residents of California, Colorado, Connecticut, Utah, Virginia and other states with applicable laws have the right to know, access, correct, delete and port their personal information, and to opt out of targeted advertising and profiling — each exercisable through info@cargoduo.com or the in-product privacy console. We will not discriminate against you for exercising these rights.
7. Where your data is hosted (server locations)
All application servers, primary databases, queue workers and backups are hosted on Hetzner infrastructure located in Germany (EU/EEA territory). The marketing site, the Service's static assets, the API edge proxy, DDoS protection, the web application firewall and the global content-delivery network are operated by Cloudflare. Each provider is engaged under a data-processing agreement incorporating the European Commission's Standard Contractual Clauses (Module 2) and, where applicable, the UK International Data Transfer Addendum and the Swiss variant, to cover any transfer that could occur outside the EEA. Customer Content is processed in the EU; in-transit metadata may briefly traverse globally distributed edge points of presence solely for connection establishment, TLS termination, caching of public assets, and bot and abuse mitigation. We maintain technical and organizational measures — including TLS 1.2 or higher in transit, AES-256 encryption at rest, segmented networks, role-based access and audit logging — intended to satisfy the supplementary measures discussed in EDPB Recommendations 01/2020.
8. International data transfers
Where personal data leaves the EEA, the United Kingdom or Switzerland — for example, to a sub-processor such as Cloudflare or Paddle that operates outside those territories — the transfer is governed by an appropriate safeguard under Chapter V GDPR. We rely on the European Commission's 2021 Standard Contractual Clauses (SCCs) and, where required, the UK Information Commissioner's International Data Transfer Addendum (IDTA) and the Swiss variant. We assess each importer's exposure to third-country surveillance laws (including FISA 702, EO 12333 and the CLOUD Act) on a case-by-case basis and apply supplementary technical, organizational and contractual measures where appropriate. A copy of the SCCs covering a specific transfer is available on request to info@cargoduo.com.
9. Sub-processors
We engage the sub-processors listed below, each bound by a written contract imposing confidentiality, security, and processing-on-instruction obligations equivalent to those in our DPA. Hetzner (Germany) provides our primary infrastructure — application servers, databases and encrypted backups. Cloudflare provides our global edge — content-delivery network, web application firewall, DDoS protection, DNS, edge proxy, and static-asset hosting. Paddle acts as our merchant of record and reseller: it operates checkout, processes payments, issues invoices and receipts, and calculates, collects and remits the applicable VAT and sales tax worldwide; for the payment transaction itself Paddle acts as an independent controller, and for any personal data it processes on our behalf it is bound by its data-processing terms. We also engage an error-monitoring provider and a transactional-email provider in those roles. We will give at least 30 days' advance notice of any addition or replacement of a sub-processor through the in-product change log, and you may object on reasonable grounds; where an objection cannot be resolved, you may terminate the affected services.
10. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, and then delete or anonymize it. Account records: retained for the lifetime of the account, plus 30 days after a deletion request to allow restoration in the event of accidental deletion. Customer Content (projects, vehicles, cargo, shipments, packing results, share links): retained for the lifetime of the account and deleted within 30 days of account termination, unless we are required to retain it under applicable law. Billing and tax records: retained for 10 years from the end of the relevant fiscal year (Turkish Tax Procedural Law No. 213; § 147 AO, Germany; and comparable rules in other jurisdictions). Audit logs and security events: 24 months. Backups: encrypted backups are rotated on a 30-day cycle, and data deleted from production is purged from the most recent backup within that window. Support correspondence: 36 months. Marketing data: retained until consent is withdrawn.
11. Your rights
Subject to applicable law, you have the right to: access the personal data we hold about you (Art. 15 GDPR / § 1798.110 CCPA); rectify inaccurate or incomplete data (Art. 16 GDPR / § 1798.106 CCPA); request erasure (Art. 17 GDPR / § 1798.105 CCPA, the "right to be forgotten"); restrict processing (Art. 18 GDPR); receive your data in a structured, commonly used and machine-readable format and transmit it to another controller (Art. 20 GDPR / § 1798.130(a)(3) CCPA); object to processing carried out on the basis of our legitimate interests, including profiling (Art. 21 GDPR); withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR); and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22 GDPR — our packing algorithm is advisory and never produces such decisions about individuals; see Section 12). You may also opt out of any "sale" or "sharing" of personal information under the CPRA, although we engage in neither. You may exercise these rights by contacting info@cargoduo.com or using the in-product privacy console, and you may lodge a complaint with a supervisory authority — including the Turkish Personal Data Protection Authority (KVKK Kurumu, kvkk.gov.tr), your local EU/EEA Data Protection Authority, the UK Information Commissioner's Office, the Swiss Federal Data Protection and Information Commissioner, or the California Privacy Protection Agency, depending on your residence.
12. Automated decisions and AI
The packing algorithm produces optimization suggestions for cargo placement; it is purely advisory and does not make decisions that produce legal or similarly significant effects on individuals within the meaning of Article 22 GDPR. We do not use Customer Content to train any third-party artificial-intelligence system or large-language model. We do not enrich customer profiles by purchasing data from data brokers. Any internal product-quality models are trained exclusively on aggregated, de-identified telemetry, and never on the contents of your shipment, vehicle or cargo records.
13. Children
The Service is a business-to-business product and is not directed to children. We do not knowingly collect personal data from anyone under 16 (EU/EEA), under 13 (United States, COPPA), or under the equivalent age of consent in your jurisdiction. If you believe a child has provided us with personal data, contact info@cargoduo.com and we will delete it without undue delay.
14. Security
We apply technical and organizational measures appropriate to the risk. These include TLS 1.2 or higher encryption in transit; AES-256 encryption at rest for primary stores and backups; HttpOnly and Secure session cookies scoped to .cargoduo.com with a strict SameSite policy; passwords hashed and salted with Argon2id; least-privilege access controls; segregated production and staging networks; mandatory code review; dependency scanning; vulnerability monitoring; and centralized audit logging. No system is impregnable. You are responsible for keeping your credentials confidential and for notifying us immediately at info@cargoduo.com of any suspected compromise. In the event of a personal-data breach, we will notify the competent supervisory authority within 72 hours where required and, where the breach is likely to result in a high risk to your rights and freedoms, we will notify affected individuals without undue delay (Arts. 33–34 GDPR).
15. EU representative and complaints authority
Until a formal Article 27 GDPR representative is designated, EU/EEA data subjects may contact our designated privacy contact at info@cargoduo.com regarding the processing of their personal data. The lead supervisory authority for an inquiry originating in the EU/EEA is your local Data Protection Authority, and Turkish data subjects may contact the Turkish Personal Data Protection Authority (KVKK) at kvkk.gov.tr. Exercising your rights under this Section is without prejudice to any other remedy available to you under applicable law (see Section 11).
16. Cookies and tracking technologies
We use a small set of strictly necessary cookies for authentication, CSRF protection and load balancing; a small set of functional cookies to remember your locale, theme and last-viewed route; and, on an opt-in basis only in the EU/EEA, the United Kingdom and Switzerland, anonymized product-analytics cookies. We do not run advertising cookies, we do not embed third-party social-media pixels, and we do not participate in cross-context behavioral advertising. Full details — including the name, purpose, provider and lifetime of each cookie — are set out at /legal/cookies.
17. Changes to this Policy
We may update this Policy to reflect changes in our practices, our list of sub-processors, applicable law, or supervisory-authority guidance. We will revise the "Last Updated" date shown above and, for material changes, notify registered users by email or in-product banner at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acknowledgment of the revised Policy, to the extent permitted by applicable law.