Privacy Policy
Version 1.0.0 · Effective
Effective date: 2026-08-27
Last updated: 2026-08-29
This Privacy Policy explains how TruckFix collects, uses and discloses personal information when you use the TruckFix marketplace at https://truckfix.net, create or access an account through it, when the marketplace publishes shop or review information about you, and on public pages that link to this Policy (the “Service”). Read this Policy with the Cookie Policy and Terms of Use.
The Service helps adults and businesses search for commercial-vehicle service providers in the United States, view public shop information, use location and map features, and create or access an eligible fleet account. A separate or additional notice may apply to a shop dashboard, ERP product, fleet tool, mobile application or another TruckFix service if that service links to a different notice.
1. Who is responsible for your information
The operator responsible for personal information covered by this Policy is:
TruckFix
6428 Joliet Road, Suite 104, Countryside, IL 60525
Privacy email: support@truckfix.net
Telephone: +1 201-331-8994
2. Information we collect
We collect information in the following circumstances.
Information you provide or choose
- Search information. A location or address you type or select, place identifier, coordinates, search radius, requested service, date, time, filters and sorting.
- Device-location choice. If you activate
Use my locationand grant browser permission, the browser provides latitude and longitude for the requested search and a readable place label. You can type a city, ZIP code or address instead. - Privacy choices. Which optional categories you grant or refuse, the category-set version and the UTC time of your choice.
- Account and profile information. The email address used to identify the account, its recorded verification status, first and last name, telephone number, Driver or Fleet Owner selection, assigned fleet roles and the relationship between the profile, account and fleet. A Fleet Owner or Fleet Manager can provide these details when provisioning a Driver account; a Fleet Owner or Fleet Admin can provide them when provisioning a Manager account. Fleet provisioning creates the account, user profile and role before that person's first sign-in, with no email-verification timestamp at creation.
- Fleet information. A Fleet Owner provides a fleet name and a selected address, which can include address lines, city, state, postal code, longitude and latitude.
- Sign-in choice. An email address submitted for a one-time sign-in link, or the choice to continue with Google or Apple. Provider sign-in can supply a provider account identifier, verified email and first or last name. Apple name values supplied only on the first authorization are treated as provider hints and remain editable during profile completion.
- Communications. Information you include when you email, call or otherwise contact TruckFix, including contact details, messages and files you choose to send.
The current public Service accepts account creation and sign-in as described here. It does not accept a booking, payment, review submission or marketing subscription. Before a later feature begins one of those activities, TruckFix will provide the required notice and update this Policy.
Information collected when the Service operates
- Connection and device information. IP address, browser and device type, operating system, language, referring page, requested URL, request date and time, and similar network information used to deliver and secure a website.
- Usage and diagnostic information. Requested pages and features, response status, errors, security events and limited technical logs needed to operate, troubleshoot and protect the Service. A search URL can contain a location label, coordinates, date, time and filters.
- Authentication and session records. Magic-link request and use status, token hashes, provider verification results, account and session identifiers, refresh-token hashes, browser-binding values, issue, expiry, rotation and revocation times, return paths, retry state and related security events. Raw authentication cookies are stored in the browser and sent only to their permitted TruckFix paths; browser scripts cannot read them.
- Approximate location. An IP address can indicate an approximate city or region. TruckFix does not use IP-derived location to change a privacy choice.
- On-device information. If you grant Preferences, up to five recent locations are stored in local storage on that device. Selecting one sends the chosen search information to TruckFix in the same way as a newly entered search.
Search selections in a page address can remain in browser history or be exposed when the full link is copied or shared. The Service uses a strict-origin-when-cross-origin referrer policy: a same-origin request may include the full Service URL, while a cross-origin HTTPS request receives only the TruckFix origin. Check a search link before sharing it.
Information about shops and reviewers
TruckFix marketplace and ERP systems supply public shop and review records. Shop records can include a business name, address, telephone number, services, hours, images and aggregate rating. Review records can include a reviewer's name and profile image, rating, comment and date. Shops, authorized operators and TruckFix administrators maintain shop records; review records originate through TruckFix products. TruckFix displays those records for directory and review functions and processes correction, privacy, unlawful-content and rights-infringement reports through support@truckfix.net.
3. How we use information
| Purpose | Information used | What the use does |
|---|---|---|
| Provide public pages, directory results, shop profiles and a requested search | Search information, connection data and requested URLs | Returns the page, providers and shop information requested by the visitor |
| Request and verify a passwordless email link | Email address, request time, token hash, use/expiry status, IP address and security events | Sends the requested one-time link, limits abuse and verifies that the link is live and unused; requesting a link alone does not create an account |
| Sign in with Google or Apple | Provider identifier, verified email, provider verification result and available name values | Verifies the provider response, links it to the matching eligible account or carries verified details into profile completion |
| Create and administer an account | Email and recorded verification status, profile, account type, role, creator and fleet relationship; fleet details for a Fleet Owner | Creates a self-service Driver or Fleet Owner account during profile completion after email or provider verification; creates a fleet-provisioned Driver or Manager account before first sign-in; permits a Fleet Owner or Fleet Manager to provision Drivers, a Fleet Owner or Fleet Admin to provision Managers, and only a Fleet Owner to manage Fleet Admin status; and applies role-based access |
| Maintain an authenticated session | Account, session, binding and token records; browser cookies; return and retry state | Establishes, renews, protects and ends the signed-in session and returns the user only to an allowed destination |
| Use device location | Precise coordinates and the readable place label returned for them | Runs only after the visitor activates the location control and grants the browser's own permission prompt; a typed-location alternative remains available |
| Provide address suggestions, place details and reverse geocoding | Typed location, place identifier, coordinates and a short-lived Places session token | Sends the minimum lookup information through TruckFix's server to Google and returns a suggestion or label |
| Remember recent locations | Up to five location labels and coordinate pairs | Runs only while Preferences is granted; without a valid grant, an existing value is removed without being used |
| Load interactive Google Maps | Map context and browser/device information sent directly to Google | Runs only while External services is granted and stops after withdrawal through Cookie settings |
| Store and honor a privacy choice | Category answers, category-set version and choice time | Remembers a grant or refusal for six UTC calendar months without an account or advertising profile |
| Secure, rate-limit, diagnose and maintain the Service | IP address, request and security logs, errors and device/network data | Prevents abuse, troubleshoots failures and protects availability |
| Answer support, correction and privacy requests | Contact details, messages, attachments and proportionate verification information | Responds to the request and documents its resolution |
| Publish and correct shop and review information | Shop, contact and reviewer information | Operates and corrects the public directory and review display |
| Comply with law and protect people and the Service | Relevant records from the categories above | Responds to valid legal process, investigates misuse and establishes or defends legal claims |
Each location use begins with the visitor's own action. Typing a location and choosing a suggestion or submitting a search is the visitor's affirmative action for the address lookup; activating the device-location control and granting the browser's permission prompt is the visitor's affirmative action for precise location. This Policy is where those two uses are described; TruckFix does not create a separate identifier merely to record the action. Precise location is not used to infer a sensitive trait or for advertising.
The current public Service does not use automated processing to make a decision about a visitor that produces legal or similarly significant effects and does not build visitor profiles from advertising or cross-site analytics.
4. Location, Google Places and Google Maps
Address lookup through TruckFix
When the visitor types a location, the browser contacts a same-origin TruckFix route. TruckFix's server sends Google Places or Google Geocoding the information needed for the requested lookup, which can include typed text, a Places session token, place identifier, latitude and longitude. The response is returned with no-store and is not intentionally placed in a shared application cache. Request data can enter deployment-controlled infrastructure logs subject to the retention criteria in Section 8.
This server-side lookup is part of the location-search function the visitor requests and is not controlled by the optional External services category.
Browser geolocation
TruckFix asks the browser for device location only after the visitor activates the location control. The browser or operating system then presents and manages its own permission prompt, and TruckFix receives coordinates only if that permission is granted. The visitor can refuse or revoke permission and type a location instead.
Interactive maps
Google Maps browser code loads only after the visitor grants External services. Google can then receive IP address, browser/device information, referrer, request time, map view/location and interactions, and can use provider-controlled storage under its own terms. Google handles information it receives directly under its own privacy notice and the applicable Google Maps Platform terms.
Use of Google Maps features and content is subject to the Google Maps/Google Earth Additional Terms and Google Privacy Policy. Refusing or withdrawing External services does not prevent search, results, filters, profiles or core shop contact actions; an explanatory placeholder replaces the interactive map.
5. Cookies, local storage and privacy choices
The Service uses strictly necessary first-party consent and authentication cookies, optional truckfix.recent-locations local storage when Preferences is granted, and Google-controlled browser technology when External services is granted. Authentication cookies operate only when account entry or a session requires them. They are not controlled by an optional category because the requested sign-in and session cannot work without them. Optional categories are off until granted. The current optional category set is exactly Preferences and External services.
Marketplace shop images and reviewer avatars are ordinary public-page content delivered through the same-origin /api/media route. The browser connects only to TruckFix. The route retrieves approved raster media server-to-server from the configured DigitalOcean Spaces origin and does not forward the visitor's IP address, browser headers or referrer to that origin.
Accept all and Refuse all are available on the same surface, and categories can be chosen separately through Manage choices. Cookie settings can be reopened from the footer. Without a valid Preferences grant, any remembered-locations value is removed without using it. Withdrawing External services stops future Google Maps browser requests and replaces a displayed map with the withheld state. See the Cookie Policy for the technology inventory.
Refusing or withdrawing an optional category updates the strictly necessary record and starts a new six-month period. An invalid, expired or obsolete record grants nothing and is removed when possible.
6. How we disclose information
- Public visitors. Public shop and review fields are disclosed to anyone who opens the relevant result or profile page.
- Google. Google receives address/place query information from TruckFix's server for Places and Geocoding, and receives browser information directly only after External services is granted for Maps. If a user chooses Google sign-in, Google also receives the authorization request and TruckFix receives the verified identity response. Google handles information it receives under its applicable terms and privacy notice.
- Apple. If a user chooses Apple sign-in, Apple receives the authorization request and TruckFix receives the verified identity response under Apple's applicable terms and privacy notice.
- Email delivery. TruckFix's configured email-delivery service processes the recipient address, one-time-link message and delivery metadata needed to send a requested magic link or fleet account notice. The final production provider must be recorded in the release privacy inventory.
- Connected TruckFix services. TruckFix's account and messaging systems receive the fleet-user identifier, display name and, where already present, a device notification identifier needed to create or recover the user's connected TruckFix identity.
- DigitalOcean. DigitalOcean hosts current TruckFix infrastructure and DigitalOcean Spaces stores approved marketplace media. The media origin receives the object path, request time and TruckFix server connection data, not the visitor's direct browser connection.
- Google Workspace. Google Workspace processes email addresses, message content and attachments needed to deliver and answer support, legal and privacy email.
- Telephone carriers. The caller's carrier and TruckFix's carrier process telephone numbers and call-routing information needed to connect a call.
- Professional advisers and authorities. Information reasonably necessary for legal, audit, insurance or compliance work, valid legal process, or protection of rights, safety and security.
- Corporate transactions. Information reasonably necessary to evaluate or complete a merger, financing, acquisition, reorganization or sale of assets, subject to confidentiality and required notice.
TruckFix does not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or offer a financial incentive for personal information in the current public Service.
Browser signals and collection by other parties
Do Not Track has no universally accepted technical meaning. Because the current public Service does not run advertising or cross-site analytics, TruckFix does not change those activities in response to that signal. A Global Privacy Control signal does not grant an optional TruckFix category. The current Service has no sale, cross-context sharing or targeted-advertising activity for that signal to opt out of; TruckFix will implement legally required signal handling before beginning any such activity.
When Google Maps is enabled, Google may collect activity over time and combine it with activity on other Google services, devices or sites under its own terms. TruckFix treats this as a disclosed external-service connection, not as a sale, cross-context sharing by TruckFix or targeted advertising by the current Service.
7. Where information is processed
TruckFix operates from Illinois and offers this Service for the United States. Current hosting can process information on DigitalOcean infrastructure in Frankfurt, Germany; marketplace media is stored in DigitalOcean's SFO2 region in the United States; and Google services can process information in the United States and other locations described in Google's terms. Access is limited to the operational roles and purposes described in this Policy.
8. Retention
TruckFix keeps personal information only for the stated purpose, legal obligations, security, disputes and enforcement.
| Information | Retention |
|---|---|
| Consent choice record | Until the exact six-UTC-calendar-month anniversary of the most recent recorded choice; refusal or withdrawal restarts that period, and invalid or obsolete records are removed when possible |
| Remembered recent locations | On the visitor's device only while Preferences remains valid; an existing value is removed without being read whenever no valid Preferences grant exists |
| Address and coordinate lookup response | Returned with no-store and not intentionally placed in a shared application cache |
| In-process address-lookup rate-limit entry | Never persisted; remains until the same IP requests again after its 60-second window, an expired-entry capacity sweep runs, or the process restarts |
| Marketplace search cache and rate-limit state | 60 seconds in the application; infrastructure copies follow deployment rotation |
| Infrastructure, request and security logs | Retained only under deployment-controlled size rotation and container lifecycle; older entries are overwritten by rotation or removed when the container is replaced, and the application keeps no separate archive |
| Magic-link records | A link is single-use and valid until its recorded expiry; the current service default is 15 minutes and the production setting must be recorded before publication. Its email, token hash, expiry and use status remain only for account security, abuse prevention, dispute handling and legal obligations under the operational retention schedule that must be approved before publication. Link validity is not a promise that the database row is deleted at expiry |
| Session and provider-link records | Access credentials are valid for no more than 15 minutes and refresh credentials for no more than 30 days unless ended sooner; session and provider-link records remain only for account operation, security, abuse prevention, dispute handling and legal obligations. Credential validity is not the same as database deletion |
| Account, profile, role and fleet records | While the account or authorized fleet relationship remains active. Deletion or removal depends on role, how the account was created, active service records and legal constraints; residual records remain only where needed for security, legal obligations, disputes and enforcement |
| Support, correction and privacy correspondence | 24 months after the request is closed, then deleted unless a documented legal hold or legal obligation requires longer retention |
| Public shop, contact and review information | While published in the source system; removed from public display within 30 days after an approved correction or deletion, with longer retention only for a documented legal hold or legal obligation |
| Records needed for legal claims or compliance | For the applicable limitation or legally required period, documented by record type |
Google and DigitalOcean can retain their operational records under their own terms and account settings.
9. Security
TruckFix uses administrative, technical and organizational safeguards designed for the nature and risk of the information processed. No internet service is completely secure, and TruckFix cannot guarantee that unauthorized access, loss or misuse will never occur.
10. Your US privacy rights and choices
TruckFix offers a nationwide request path. Depending on applicable law and its exceptions, a visitor may ask to access, correct, delete or obtain a portable copy of personal information; withdraw a sensitive-data choice; use an authorized agent; appeal a denied request; and receive equal service without unlawful discrimination.
Submit a request by emailing support@truckfix.net or calling +1 201-331-8994. State that the contact concerns a privacy request, describe the request and identify the US state of residence. TruckFix may request information reasonably necessary to verify identity, residence and authority and uses that information only for verification.
An authorized agent may submit a request where applicable law permits it. If a request is denied, reply to the denial or email support@truckfix.net with Privacy appeal in the subject line. The response will explain the result and any legally required regulator contact.
Cookie choices are managed through Cookie settings. Browser geolocation permission is managed in browser or device settings. These controls do not replace a statutory privacy request.
11. Additional US state disclosures
California Notice at Collection and privacy disclosures
The following notice describes the categories collected for the current public Service, their purposes, recipient categories, sale/share status and retention. TruckFix provides this notice as a clear collection summary regardless of whether a statutory applicability threshold is met.
| California category and examples | Business/commercial purposes | Recipient categories | Sold/shared | Retention period or criterion |
|---|---|---|---|---|
| Identifiers — IP address; account, email, provider, session and device identifiers; shop, contact or reviewer name; support contact details | Create and authenticate accounts; secure the Service; support, correction and legal compliance | DigitalOcean; chosen Google or Apple identity provider; email-delivery service; connected TruckFix services; public visitors for public fields; Google Workspace; telephone carriers; advisers and authorities as required | No | Account and provider identifiers follow the active-account and legal/security criteria in Section 8; session/link validity and retention are separate; request/security logs follow deployment rotation; support records remain 24 months after closure; public fields remain while published and are removed within 30 days after approved correction/deletion |
| Customer-record information — account name, postal or fleet address, telephone number and support-contact information | Account and fleet administration, directory display, support and correction | DigitalOcean; email-delivery service; connected TruckFix services; public visitors for public shop fields; Google Workspace; telephone carriers | No | Account and fleet records follow the active-account and legal/security criteria in Section 8; public fields remain while published and are removed within 30 days after approved correction/deletion; support records remain 24 months after closure |
| Commercial information — requested service, date/time, radius, filters and services considered | Perform the requested search | DigitalOcean and Google when needed for a visitor-requested location feature | No | Application cache/rate-limit state is 60 seconds; infrastructure records follow deployment rotation |
| Internet or electronic-network activity — requested URLs, referrer, device details, sign-in/session activity, status, errors and security events | Delivery, authentication, security, rate limiting and diagnostics | DigitalOcean, chosen identity provider, email-delivery service and operational/security providers | No | Session/link records follow Section 8; application state is 60 seconds; infrastructure records follow deployment rotation and container lifecycle |
| Geolocation — typed/selected location, fleet address and coordinates, device coordinates and approximate area inferred from IP | Location search, fleet setup, place labeling, results and maps | Google and DigitalOcean | No | Account fleet location follows the active-account and legal/security criteria in Section 8; lookup response is no-store; remembered locations remain only while Preferences is valid; application cache is 60 seconds; infrastructure records follow deployment rotation |
| Professional or employment-related information — Driver, Fleet Owner, Fleet Manager or Fleet Admin role; shop role or business contact information | Apply account/fleet permissions and operate and correct the public directory | Connected TruckFix services, DigitalOcean and public visitors for public fields | No | Account role follows the active-account and legal/security criteria in Section 8; public information remains while published, with removal from public display within 30 days after approved correction/deletion |
| Communications and submitted content | Respond, verify, document and protect legal claims | Google Workspace, telephone carriers and professional advisers | No | 24 months after closure, then deletion unless a documented legal hold or legal obligation applies |
| Sensitive personal information — precise geolocation; account login and credentials that permit account access | Perform a requested search, fleet setup, place labeling and maps; authenticate and protect the account; not used to infer characteristics or for advertising | Google, DigitalOcean, chosen identity provider and email-delivery service as needed for the requested feature | No | Account credentials and auth records follow Section 8; lookup response is no-store; remembered locations remain only while Preferences is valid; application cache is 60 seconds; infrastructure records follow deployment rotation |
TruckFix has no actual knowledge that it sold or shared personal information of a person under 16 in the preceding 12 months, and the current Service did not sell or share any consumer's personal information. If future processing requires a California limit-use or opt-out method, TruckFix will implement it before that processing begins.
Other US states
TruckFix uses the nationwide rights and appeal path in Section 10. No separate state-specific supplement is needed for the current release facts. TruckFix will update this Policy and add any required registered name, request method, opt-out language or regulator route before a later market, threshold or processing change makes it necessary.
12. Children
The Service is intended for adults aged 18 or older and is not directed to children under 13. If you believe a child provided personal information, contact support@truckfix.net. This statement does not limit an obligation that applies if TruckFix has actual knowledge of a child's information.
13. Third-party sites and services
Shop websites, telephone services, map features and other third-party destinations have their own terms and privacy practices. A link or contact control does not make TruckFix responsible for a third party's independent processing.
14. Changes to this Policy
TruckFix may update this Policy to reflect a change in the Service, law or practices. The updated version will state its effective date. A materially broader use receives any additional notice or choice required by law before it begins. A new optional purpose or category requires a new privacy choice rather than relying on an older answer.
15. Contact us
Questions, complaints and privacy requests may be sent to:
TruckFix — Privacy
6428 Joliet Road, Suite 104, Countryside, IL 60525
support@truckfix.net
+1 201-331-8994