Get started
Get started

Cookie Policy

Version 2.0.0 · Effective

What your choice covers, and what it does not

Revision 2, effective 2026-08-29. Your privacy choice on this site governs exactly one thing: whether TruckFix remembers your recent search locations in this browser. Accepting allows that. Declining prevents it, and removes any locations already stored.

The interactive map is not part of that choice. It is presented whether you accept, decline or never answer, because the map is the service this site exists to provide. Loading it connects your browser to Google, which can receive your IP address, browser and device details, the referring page, the request time, the map view and your interactions with it. Google's own terms govern what it does with that information. If you would rather not make that connection, the search results, filters, sort and every shop's information remain fully usable without looking at the map.

Storage that is strictly necessary — the record of this choice itself — is not optional and is not offered as a choice.

Effective date: 2026-08-27
Last updated: 2026-08-28

This Cookie and Similar Technologies Notice explains how TruckFix uses cookies, local storage and browser-connected services on the public marketplace at https://truckfix.net (the “Service”). Read it with the Privacy Policy and Terms of Use.

The Service is offered for the United States. TruckFix uses one nationwide prior-choice baseline for optional browser capabilities. This is a conservative product choice and does not claim that every US jurisdiction requires prior consent for every listed technology.

1. Categories

Strictly necessary

Strictly necessary technology records and honors the visitor's privacy choice, including a refusal, and operates passwordless sign-in, session security and sign-out when the visitor uses an account. It cannot be switched off through Cookie settings because without it TruckFix could not remember the privacy answer or complete a requested sign-in and authenticated session. These records are not used for advertising or profiling.

Preferences

Preferences stores up to five recent search locations in truckfix.recent-locations local storage on the visitor's device. It is off until granted. Without a valid Preferences grant, TruckFix does not read, create, update or offer the list and removes an existing value without using it.

Interactive maps — necessary, and not a choice

TruckFix loads interactive Google Maps on the search page and on shop profiles. This is not one of your privacy choices, and it is not off until granted. The map is the service you came to use, so it is presented whether you accept, decline or never answer.

When a map loads, your browser connects directly to Google, which can receive connection, device, map and interaction information and can use provider-controlled browser storage under its own terms. Google's own terms govern what it does with that information. If you would rather not make that connection, search, results, filters, sort and every shop's information remain fully usable without looking at the map.

Until 2026-08-29 this was an optional category named External services. It was withdrawn, not quietly reclassified: the record of your earlier answer was invalidated at the same time, so the Service asked you again rather than reading your old answer against a question it no longer asks.

There are no Analytics or Marketing categories in the current Service because it does not run an analytics, advertising or marketing tracker.

2. Technology inventory

Name or technologyProviderCategoryPurpose and dataWhen usedLifetime or control
truckfix.consentTruckFix; first partyStrictly necessaryStores only category answers, category-set version and the UTC time of the choice; no account identifier, address or coordinatesWritten after Accept all, Refuse all or Save choices, including refusal and withdrawalExpires at the exact six-UTC-calendar-month anniversary of the most recent recorded choice; Path=/; SameSite=Lax; Secure on HTTPS; client-readable so the Manage control can update and verify it
truckfix.accessTruckFix; first partyStrictly necessaryHolds the short-lived API access credential used only by TruckFix's server-side application boundaryWritten only after a successful sign-in or renewalPath=/; SameSite=Lax; Secure; HttpOnly/browser-script unreadable; normally expires about 30 seconds before the API's maximum 15-minute access-token lifetime and never later than that token
truckfix.refreshTruckFix; first partyStrictly necessaryHolds the rotating refresh credential used to renew or end the authenticated sessionWritten only after a successful sign-in or renewal and replaced on successful renewalPath=/; SameSite=Lax; Secure; HttpOnly/browser-script unreadable; maximum 30 days, and cleared on sign-out or failed/deactivated session establishment
__Host-truckfix.bindingTruckFix; first partyStrictly necessaryHolds a random browser identifier and TruckFix integrity proof used to bind sensitive session actions to this browser; it is not an account credentialWritten when a session is established and reused for that browser where validPath=/; SameSite=Strict; Secure; HttpOnly/browser-script unreadable; host-only by the __Host- browser rule; maximum 30 days and cleared on sign-out
truckfix.identityTruckFix; first partyStrictly necessaryHolds only the display label used by the signed-in header so a public page need not request the profile on every renderWritten after TruckFix verifies the signed-in profilePath=/; SameSite=Lax; Secure; HttpOnly/browser-script unreadable; maximum 30 days and cleared on sign-out or invalid session
truckfix.returnTruckFix; first partyStrictly necessaryHolds a validated same-site destination so the user can return to the public page from which sign-in beganWritten only when an allowed return target is capturedPath=/; SameSite=Lax; Secure; HttpOnly/browser-script unreadable; maximum 1 hour; spent once by sign-in completion, profile completion or an already-signed-in arrival at onboarding, and otherwise discarded unused on sign-out or when onboarding ends with an unusable, expired or already-completed state and no session
truckfix.oauthTruckFix; first partyStrictly necessaryHolds sealed provider, state, nonce and return information; Google state also contains its PKCE verifierWritten only after the user activates Google or Apple sign-in and cleared when the provider callback is handledPath=/api/auth/social; Secure; HttpOnly/browser-script unreadable; maximum 10 minutes; SameSite=Lax for Google and SameSite=None for Apple's required cross-site POST callback
truckfix.retryTruckFix; first partyStrictly necessaryHolds the single-use magic-link token only after the API says that same valid link may be retried; the token is opaque to the browser page but is not additionally sealed by the frontendWritten only for a structured temporary or rate-limit refusal and cleared when spentPath=/api/auth/retry; SameSite=Strict; Secure; HttpOnly/browser-script unreadable; uses the producer's bounded retry value and never more than 10 minutes
truckfix.onboardingTruckFix; first partyStrictly necessaryHolds the sealed sign-in completion state: the server-only completion credential, the immutable new-or-existing profile kind and the latest saved onboarding checkpoint, integrity-protected by TruckFix; it carries no email addressWritten only when a verified passwordless or provider sign-in still needs profile completion, and rewritten only when onboarding progress is savedPath=/onboarding; SameSite=Lax; Secure; HttpOnly/browser-script unreadable; host-only; its fixed signed deadline subtracts a five-second safety margin from the producer-declared completion lifetime and is never later than 595 seconds; a save never extends it and it clears at zero; deleted on completion and every other terminal outcome, and kept only for retry after a rejected value, rate limit or temporary outage
truckfix.recent-locationsTruckFix; first-party local storagePreferencesStores up to five location labels and precise coordinate pairs on the deviceRead and written only while Preferences is grantedRemoved without reading whenever no valid Preferences grant exists, including before an answer, after refusal or withdrawal, and after expiry or invalidation; clearing site data also removes it
Google Maps JavaScript API and provider-controlled storageGoogle; third partyNecessary — disclosed, not optionalLoads and operates interactive maps; Google can receive IP address, browser/device details, referrer, request time, map view/location and interactionsLoaded on every visit to a page that presents a map, whatever your privacy choice recordsGoogle-controlled keys, domains and lifetimes vary by browser, account and Google configuration; TruckFix neither sets nor reads that storage, and browser or Google settings provide its controls

The current browser origin inventory for interactive Maps includes https://maps.googleapis.com and https://maps.gstatic.com. Google can add or change provider-managed subresources under its service configuration and terms; a TruckFix response cannot widen the approved application inventory.

The truckfix.consent cookie is intentionally available to the first-party consent interface so it can save a choice, read it back and fail closed if a browser rejects the write. It is sent only over HTTPS in production. Refusal is stored because remembering a refusal prevents repeated requests.

Every listed authentication cookie is first-party, Secure and HttpOnly. Browser scripts cannot read it, and it is strictly necessary only for the account action or session the user requested. Granting or refusing Preferences neither creates nor authorizes an account cookie.

The short-lived truckfix.onboarding carrier is implemented as inventoried above: a host-only, HttpOnly, Secure, SameSite=Lax cookie at Path=/onboarding. Its HMAC-authenticated value carries the completion credential, immutable new-or-existing profile kind, latest saved checkpoint and one current value for each non-email hinted or confirmed field. Its fixed signed deadline subtracts a five-second safety margin from the producer-declared completion_expires_in, never slides on a checkpoint save and clears at zero. Completion and every other terminal outcome delete it; a rejected value, rate limit or temporary outage retains it only for retry within that original lifetime.

The technology inventory above is the eight-auth-cookie inventory of the current implementation; with truckfix.consent, it contains nine strictly-necessary rows. The joint 008/009 release remains gated on the approved source and render commits that bind this inventory to the shipped implementation.

3. Location services that are not optional browser storage

Server-side address lookup

When a visitor types or selects a place, or asks TruckFix to label device coordinates, the browser calls a same-origin TruckFix route. TruckFix's server sends the needed query, Places session token, place identifier or coordinates to Google Places or Google Geocoding. No Google Places script or third-party Places cookie is loaded in the browser for this operation. The response is no-store.

This is personal-information processing for the visitor-requested location function. The TruckFix request and query data can enter deployment-controlled infrastructure logs described in the Privacy Policy.

Browser geolocation

If the visitor activates Use my location, the browser or operating system asks whether it may provide device coordinates. That platform permission is separate from a TruckFix cookie choice. The visitor can refuse or revoke it and type a location instead.

4. Marketplace images

Shop photographs and reviewer avatars are ordinary public-page content, not an optional category. The browser retrieves them only from TruckFix's same-origin /api/media route. Marketplace data cannot direct the browser to another host. The route accepts only authenticated references to configured origins, refuses redirects, serves only approved raster formats and applies a response size limit.

The route retrieves approved objects server-to-server from DigitalOcean Spaces. DigitalOcean receives the object path, request time and TruckFix server connection data, not the visitor's direct IP address, browser headers or referrer. Public media responses can be cached by the browser or an edge cache according to their response headers.

5. Your choices

On a first visit with no valid choice, the request offers:

  • Accept — allows the one optional category, Preferences; and
  • Decline — refuses it.

There is no third control, because there is one optional category and these two actions are the complete answer to it. Learn more links to this document.

Accepting and refusing require the same number of actions and have equal prominence. Refusal does not prevent searching, viewing results, filtering, viewing shop information, using core contact actions or requesting account sign-in. Google or Apple sign-in occurs only when that named provider action is activated; it is separate from the interactive maps described above, which are not a choice.

Cookie settings in the footer reopens the choice at any time. It states the recorded position and offers the same Accept and Decline actions, each of which records immediately; there is no separate save step. Cancel, Escape and dismissal keep the previous choice.

Withdrawal applies on the current page: Preferences stops future reads and writes and removes remembered locations. Nothing else changes — the map continues to be presented, because it was never governed by this choice. Clearing all site data also removes the strictly necessary choice record, so the Service asks again on the next visit.

6. Google controls

When Google Maps is enabled, Google's handling of information is governed by the Google Maps/Google Earth Additional Terms and Google Privacy Policy. Google account, browser and device settings can offer additional controls. Those controls do not replace TruckFix's Cookie settings.

7. Browser signals

The current Service does not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or run advertising or cross-site analytics. A Global Privacy Control or another legally recognized universal opt-out signal therefore has no covered sale, sharing or targeted-advertising activity to change and does not grant an optional TruckFix category. TruckFix will implement required signal handling before beginning any covered activity.

Do Not Track has no universally accepted technical meaning. Because the current Service does not run advertising or cross-site analytics, TruckFix does not change those activities in response to that signal. When optional Google Maps is enabled, Google can collect activity under its own terms as the Privacy Policy explains.

8. Changes to this Policy

TruckFix will update this inventory before adding or materially changing a browser technology. A new optional purpose or category makes the previous category-set version invalid and triggers a new choice; silence or an older answer is not permission for a new use.

9. Contact

Questions or complaints about browser technology and privacy choices may be sent to:

TruckFix — Privacy
6428 Joliet Road, Suite 104, Countryside, IL 60525
support@truckfix.net
+1 201-331-8994

Your privacy choices

We use cookies to improve experience. By accepting, you consent to this. Learn more