Privacy Policy
Effective Date: May 19, 2026 · Last Updated: May 19, 2026
Jurisdiction: State of Colorado, United States of America
Summary (not a substitute for reading the full policy)
- We collect location data only with your permission, and only in the foreground.
- We never sell your personal information.
- Owner live-session GPS coordinates are public while the session is active, then removed.
- Colorado residents have specific rights under the Colorado Privacy Act — see Section 7.
- You can request deletion of your data at any time.
1. Who We Are
TruckTracker (“Company,” “we,” “our,” or “us”) is a technology company organized under the laws of the State of Colorado. We operate the TruckTracker mobile and web application (the “Service”), a platform that connects food-truck operators (“Owners”) with consumers (“Customers”) by enabling real-time location sharing and discovery. Our principal place of business is in Colorado, United States.
For purposes of applicable data-protection law, TruckTracker is the “controller” (or equivalent term) of personal information collected through the Service.
Contact Information:
Email: privacy@trucktracker.app
Mailing Address: TruckTracker, Colorado, United States
For data-rights requests specifically: datarights@trucktracker.app
2. Scope of This Policy
This Privacy Policy applies to all personal information collected, processed, stored, or transmitted by TruckTracker through:
- The TruckTracker web application accessible via any browser;
- Any future TruckTracker native mobile applications;
- Any APIs, integrations, or services that link to or incorporate this Policy;
- Communications between you and TruckTracker via email, support channels, or in-app messaging.
This Policy does not apply to third-party websites, services, or applications that may be linked to or from the Service. We encourage you to review the privacy policies of any third parties before providing your information to them.
3. Information We Collect
3.1 Information You Provide Directly
- Account Registration Data: When you create an account, we collect your name, email address, and password (stored as a cryptographic hash via our authentication provider). If you register as an Owner, we additionally collect your food truck's name, description, cuisine categories, phone number, Instagram handle, and website URL.
- Profile Information: Profile photographs or avatars you choose to upload.
- Menu Data (Owners): Menu item names, descriptions, prices, categories, and photographs you upload to your truck's profile.
- Live Session Data (Owners): When an Owner initiates a live session, we collect a photograph of the truck's current setup and real-time GPS coordinates. This data is voluntarily submitted by the Owner.
- Communications: Any messages, feedback, bug reports, or support requests you send to us.
- Schedule Data (Owners): Days of operation, hours, and location notes you enter in the scheduling feature.
3.2 Information Collected Automatically
- Precise Geolocation (with permission): If you grant location permission, we collect your device's GPS coordinates to show you nearby trucks. We request location access only when needed and only in the foreground. We do not track your location in the background.
- Device and Browser Information: We automatically collect your IP address, browser type and version, operating system, device identifiers, screen resolution, and time zone.
- Usage Data: Pages visited, features used, time spent in the Service, search queries entered, trucks viewed, filters applied, and navigation paths within the app.
- Log Data: Server-side logs recording request timestamps, response times, error events, and referring URLs.
- Cookies and Similar Technologies: We use session cookies to maintain your authenticated session. We do not currently use third-party advertising or cross-site tracking cookies. See Section 8 for full cookie details.
3.3 Information From Third Parties
- Authentication Providers: If you sign in via a third-party identity provider (e.g., Google or Apple via Clerk), we receive your name, email address, and profile photo URL as permitted by your authorization.
- Payment Processors (future): If we introduce paid features, payment information will be handled exclusively by a PCI-DSS-compliant processor. We will never store raw card numbers.
3.4 Sensitive Personal Information
We do not intentionally collect sensitive personal information such as racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, financial account numbers, or social security numbers. If you include such information in free-text fields (e.g., a truck description), you do so voluntarily. We encourage you not to share sensitive personal information through the Service.
4. How We Use Your Information
We process personal information for the following purposes and legal bases:
| Purpose | Legal Basis |
|---|---|
| Creating and managing your account | Contract performance |
| Displaying nearby food trucks based on your location | Contract performance / Consent |
| Enabling Owners to broadcast real-time location | Contract performance / Consent |
| Maintaining and improving the Service | Legitimate interests |
| Detecting fraud, abuse, and security threats | Legitimate interests / Legal obligation |
| Responding to your support requests | Contract performance |
| Sending transactional communications (e.g., password reset) | Contract performance |
| Sending optional product updates (with opt-out) | Consent / Legitimate interests |
| Complying with legal obligations | Legal obligation |
| Enforcing our Terms of Service | Legitimate interests / Contract |
We do not sell your personal information. We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects on you.
5. Disclosure of Your Information
5.1 Service Providers
We share personal information with third-party vendors who process data on our behalf under written data-processing agreements that prohibit them from using your information for their own purposes:
- Clerk, Inc. — Authentication and user identity management. Clerk Privacy Policy
- Supabase, Inc. — Database hosting, storage, and real-time infrastructure. Data hosted on servers in the United States. Supabase Privacy Policy
- Vercel, Inc. — Web application hosting and content delivery. Vercel Privacy Policy
- OpenStreetMap Foundation / CartoDB (Carto) — Map tile rendering. Map tile requests may include your IP address. Carto Privacy Policy
5.2 Public Disclosure of Owner Location Data
When an Owner activates a live session, their truck name, description, cuisine types, profile photo, and real-time GPS coordinates are made publicly visible within the Service to all users, including unauthenticated visitors. Owners should not share location information they wish to keep private. Live session data is removed from public display when the session ends.
5.3 Legal Requirements
We may disclose personal information if we believe in good faith that such disclosure is necessary to: (a) comply with applicable law, regulation, or legal process, including a valid subpoena, court order, or government demand; (b) protect the rights, property, or safety of TruckTracker, our users, or the public; (c) detect, prevent, or otherwise address fraud, security, or technical issues; or (d) enforce our Terms of Service.
5.4 Business Transfers
If TruckTracker is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider, your personal information may be transferred as part of such transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
5.5 Aggregated and De-Identified Data
We may share aggregated, anonymized, or de-identified information — such as aggregate usage statistics or trend data — that cannot reasonably be used to identify you, with third parties for research, marketing, analytics, or other purposes.
6. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Our general retention practices are:
- Account data: Retained for the life of your account plus 90 days following deletion, to allow for account recovery and to resolve any outstanding disputes.
- Live session location data: Removed from public display immediately upon session end. Raw GPS coordinates are retained in our logs for up to 30 days for fraud detection and then deleted.
- Usage logs and analytics: Retained for up to 12 months.
- Server access logs: Retained for up to 90 days.
- Support communications: Retained for up to 3 years from the date of last communication.
- Backup copies: Backup systems may retain data for up to 30 additional days following deletion from primary systems.
7. Your Privacy Rights
7.1 Colorado Privacy Act (CPA)
If you are a Colorado resident, the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) grants you the following rights with respect to your personal data:
- Right to Access: You may request confirmation of whether we process your personal data and a copy of that data.
- Right to Correction: You may request that we correct inaccurate personal data.
- Right to Deletion: You may request deletion of personal data we hold about you, subject to certain exceptions.
- Right to Data Portability: You may request a copy of your personal data in a portable, machine-readable format.
- Right to Opt Out of Sale: We do not sell your personal data. No opt-out is required, but you may contact us to confirm.
- Right to Opt Out of Targeted Advertising: We do not currently engage in targeted advertising as defined by the CPA.
- Right to Opt Out of Profiling: We do not engage in profiling that produces legal or similarly significant effects.
- Right to Appeal: If we deny your request, you have the right to appeal our decision. See Section 7.4.
7.2 California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) may grant you additional rights, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share personal information with third parties for cross-context behavioral advertising purposes. To exercise California rights, contact us using the information in Section 7.3.
7.3 How to Submit a Rights Request
To exercise any of the rights described above, submit a verifiable consumer request to:
- Email: datarights@trucktracker.app
- Subject line: “Privacy Rights Request — [Your Right]”
We will respond within 45 days of receipt of a verifiable request. If we need additional time (up to an additional 45 days), we will notify you in writing. We will not discriminate against you for exercising your privacy rights.
We may need to verify your identity before processing your request. Verification may include confirming your email address or other account information. We cannot respond to requests if we cannot verify your identity.
7.4 Appeals Process
If we deny your privacy rights request, we will explain the reason. You may appeal by emailing datarights@trucktracker.app with the subject line “Privacy Rights Appeal.” We will respond within 45 days. If your appeal is denied, Colorado residents may contact the Colorado Attorney General at coag.gov.
7.5 Account Deletion
You may delete your account at any time through the app settings (when available) or by emailing datarights@trucktracker.app. Upon verified deletion, we will remove your personal data from active systems within 30 days, subject to legal holds and the backup retention schedule described in Section 6.
8. Cookies and Tracking Technologies
We use the following types of cookies and similar technologies:
- Strictly Necessary Cookies: Session cookies required to authenticate you and maintain your logged-in state. These cannot be disabled without breaking core functionality.
- Preference Cookies: Cookies that remember your settings (e.g., filter preferences) between sessions.
We do not use advertising cookies, cross-site tracking pixels, or third-party behavioral analytics cookies.
You may configure your browser to reject all cookies or to alert you when a cookie is set. Note that disabling strictly necessary cookies will prevent you from using authenticated features of the Service.
9. Children's Privacy
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has provided personal information to us, contact us immediately at privacy@trucktracker.app. We will promptly delete such information. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will take steps to delete that information.
Users between 13 and 18 years of age may use the Service only with the consent and supervision of a parent or legal guardian.
10. Security
We implement reasonable and appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of data at rest for our database;
- Role-based access controls limiting employee access to personal data;
- Use of SOC 2-compliant infrastructure providers;
- Passwords stored as salted cryptographic hashes (we never store plaintext passwords).
No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach that affects your rights and freedoms, we will notify affected users as required by applicable law.
11. International Data Transfers
TruckTracker is based in the United States. If you access the Service from outside the United States, your personal information may be transferred to and processed in the United States, where data-protection laws may differ from those in your jurisdiction. By using the Service, you consent to such transfer. Where required by applicable law, we will implement appropriate safeguards for international data transfers.
12. Do Not Track
The Service does not currently respond to “Do Not Track” signals from browsers, as no uniform standard for responding to such signals has been established. We do not engage in cross-site tracking for advertising purposes.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last Updated” date at the top of this page indicates when the Policy was last revised. If we make material changes, we will notify you by email (if you have provided one), by posting a prominent notice in the Service, or by other means required by applicable law, at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy.
14. Contact Us
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, contact us at:
- General privacy inquiries: privacy@trucktracker.app
- Data rights requests: datarights@trucktracker.app
Colorado residents who are not satisfied with our response may file a complaint with the Colorado Attorney General's Office at coag.gov.