Skip to main content
Legal

Privacy Policy

LanePilot Technology, LLC · Version 4.3 · Effective August 1, 2026 · Revised August 2, 2026
Supersedes Privacy Policy Version 4.1, dated August 1, 2026.
Governing Law: Pennsylvania

1About This Policy

This Privacy Policy explains how LanePilot Technology, LLC ("LanePilot," "we," "us," or "our") collects, uses, shares, and protects personal information. LanePilot is a Pennsylvania limited liability company located at 8370 Wattsburg Road, Erie, PA 16509.

This Policy applies to the LanePilotTech.com platform (the "Service"), to visitors to our website, to the business organizations that use the Service and their authorized users, to individuals whose information appears in customer records, and to business prospects we contact.

This Policy is incorporated by reference into our Terms of Service. Our Cookie Policy and AI Terms supplement it and are part of our overall privacy commitments.

The Service is a business-to-business platform. We do not offer a consumer, personal, or household tier.

2Who Is Responsible for What

The organization is our customer. When a business uses LanePilot, that organization is our customer, and its people use the Service on its behalf.

For the operational data an organization puts into the Service (shipments, quotes, invoices, receiving records, inventory, vendor records), the organization decides why and how that data is used and we act on its instructions. In privacy terms, the organization is the controller and LanePilot is the processor.

For a narrower set of purposes, LanePilot decides for itself and is the controller. These are: administering and securing accounts, billing, preventing fraud and abuse, our own marketing and prospecting, and meeting our own legal obligations.

Creating and publishing aggregated and de-identified statistical indices, reports, and market intelligence, including the Small Shipper Index. To the extent personal information is processed to create those outputs, LanePilot determines the purpose and essential means of that limited processing and acts as an independent controller. The resulting published information is not personal information where it has been aggregated and de-identified so that an individual is not reasonably identifiable.

An organization's own personnel. Where an organization gives its employees access to the Service, including dock workers with check-in-only logins, the organization is responsible for telling its people that it uses LanePilot and what the Service records about their activity. Our Terms require the organization to give any notice the law requires.

That allocation does not remove anyone's individual rights. Any individual may contact [email protected] directly about their own personal data, and we will handle that request in accordance with applicable law, regardless of what their employer has or has not told them.

3Data We Collect

Account and identity information. Business email address, name, company name, job title, role within the organization, and optional phone number. Provided when an account is created or a user is invited. Used to create and administer the account, authenticate users, and communicate about the Service.

Authentication data. Session tokens and authentication metadata. You sign in with an email address and a password. Your password is stored and managed by Clerk, our identity provider, under its own security controls. LanePilot does not store your password and cannot access it.

Shipment and freight data. Origin and destination, freight class, weight, dimensions, carrier selections, booking details, pickup and tracking status, and rate quotes. Entered by you or imported through integrations you authorize. Used to provide quoting, booking, tracking, audit, and scorecard features.

Uploaded documents. Bills of lading, invoices, carrier contracts, rate confirmations, and similar records. These may contain names, addresses, signatures, and contact details of your personnel or counterparties. Used to provide invoice audit, document parsing, and related features.

Invoice audit and dispute records. Audit findings, identified discrepancies, and the dispute letters and vendor chargeback letters the Service generates for you to send yourself.

Receiving, warehouse, and inventory data. Where an organization uses LanePilot Warehouse, we hold inbound receiving records including overage, shortage and damage findings, the warehouse map and digital bin locations, dock queue and cycle count records, vendor records and vendor contact details, vendor scorecards and chargeback records, inventory levels and movements, packing slips, outbound shipment contents, and product recipes covering assembly and raw-material processing.

Some of this describes what an organization stocks, builds, and ships. For a manufacturer, product recipes can amount to a bill of materials. We treat this as the organization's confidential information, we do not use it for any purpose other than providing the Service to that organization, and it is never included in benchmarking.

Dock worker and personnel activity data. Where an organization gives a worker a login, we record that account's identity (name and email as supplied by the employer) and their activity in the Service, such as check-ins and receiving actions recorded. Used to operate the feature and to give the employer an accurate operational record. LanePilot collects one labor rate at the organization level, as a single average with no individual attached. We do not collect individual wage information.

Carrier account credentials. The login details, keys, or account numbers you connect so the Service can quote, book, and track on your own carrier accounts. Stored encrypted. Used only to act on your instructions with that carrier. Described further under Security below.

Payment information. The last four digits of your card, card brand, and billing address. Full card numbers go directly to Stripe and never reach LanePilot's servers. Used for subscription billing and support.

Usage data. Pages visited, features used, query counts, session duration, and interaction events, collected automatically through PostHog. Used to understand and improve the Service.

Technical data. IP address, browser and device type, operating system, and referrer, collected automatically through Cloudflare, Vercel, and our server logs. Used to secure the Service, prevent abuse, and maintain performance.

Error and diagnostic data. Error reports and diagnostic context collected through Sentry when something in the Service fails. Used to detect and fix faults.

Communications. Support requests, feedback, and correspondence with LanePilot. Used to answer questions and improve support.

Documents and contact details sent to us by email. If you email documents to an intake address such as invoices@ or contracts@, we receive those documents and your contact details. Where a business sends us an invoice and quote asking us to audit them, we process those documents to produce the result you asked for, and we retain your business contact details as a lead record. The basis is that you contacted us and supplied the documents for that purpose. You can ask us to remove your details at any time at [email protected].

Where we reply to such a message, the reply is a response to correspondence you began. Any commercial message we send carries our postal address and a working way to opt out, and we honor opt-outs permanently.

Business prospect data. Names, business email addresses, phone numbers, professional profile URLs, job titles, and company information about individuals who are not users, sourced from publicly available business sources rather than from the individual. Those sources include company websites, professional networking pages, public business directories, and business-contact discovery and verification services such as Hunter, which is a source for this category as well as a provider we send it to. We collect and use this information for our legitimate business interest in identifying and contacting businesses that may benefit from LanePilot. We limit it to business-to-business outreach, use professional rather than personal contact details, honor opt-out and deletion requests, and do not use it for any unrelated purpose. If you are a prospect, this is the only category we hold about you, and you may ask us to delete it at any time.

Outreach and communication tracking. Thread identifiers, reply classification labels, reply dates, and re-engagement dates, generated when we send outreach and receive responses. Used to manage outreach and to avoid contacting people who asked not to be contacted.

Feedback and interview data. Notes, transcripts, summaries, and sentiment scores from customer or prospect conversations, recorded with notice to participants as applicable law requires.

4How We Use Data

We use the information above to provide and operate the Service, administer and secure accounts, process billing, detect and prevent fraud and abuse, support customers, improve the Service, conduct business-to-business marketing and prospecting, and comply with law and respond to legal process.

Aggregated Market Intelligence: To create aggregated and de-identified statistics, indices, reports, and market intelligence about freight, invoice-audit, receiving, warehouse, and operational trends, and to publish those results externally through newsletters, reports, websites, presentations, and similar publications. This may include a recurring Small Shipper Index. We do not publish raw customer records or figures that reasonably identify an organization, individual, shipment, invoice, quote, or an organization's relationship with a carrier or vendor.

We do not use data for purposes incompatible with those without providing notice.

5Artificial Intelligence

LanePilot uses Anthropic's Claude API to read and interpret documents, generate findings and summaries, and support certain product and business functions. This covers content that customers submit, documents that non-customers email to us asking for an audit, and internal business operations such as drafting outreach and analyzing feedback.

LanePilot does not use your content to train or fine-tune any AI model.

Anthropic does not train its models on the inputs or outputs we send through its API. As last verified on August 1, 2026, under Anthropic's then-current terms, API content is retained for up to 30 days and then deleted, except that content flagged for policy enforcement may be retained for up to two years. LanePilot does not have a Zero Data Retention agreement with Anthropic. That retention is governed by Anthropic under its own terms and technical controls. A deletion request you make to us may not result in immediate deletion from those provider-controlled retention systems, although we will take the steps required by applicable law and by our agreement with Anthropic.

AI output is an aid, not professional, legal, or accounting advice. Dollar figures the Service produces derive from documents you supplied and should be reviewed before you send anything to a carrier or vendor. Our AI Terms describe this in full.

6Specific Protections

Data isolation. Each organization's data is logically isolated from other organizations'. We do not share one customer's shipment data, rates, carrier selections, vendor terms, or inventory with another customer.

No sharing with carriers or vendors. We do not share your shipment, invoice, audit, scorecard, vendor, or inventory data with carriers or vendors except the information necessary to complete a booking you direct, and we never send, file, or negotiate a dispute or chargeback on your behalf.

Carriers are your own counterparties. When you connect a carrier, you connect your own account with that carrier, using your own credentials. When you request a rate, book a shipment, or track one, we transmit the shipment details and the contact information that shipment requires to that carrier, at your direction and on your own account with it. In this workflow the carrier receives that data as your transportation counterparty, under your own account and your own agreement with it. We do not appoint the carrier to process that data on our behalf and do not instruct it how to process it, which is why carriers do not appear in the sub-processor list below. The carrier handles that data as an independent controller under its own privacy policy and its own terms, which govern your relationship with it, so refer to your carriers' own privacy policies for how they handle it. We transmit these technical requests solely to perform the quoting, booking, and tracking you initiate. That is different from representing you. Consistent with the point immediately above and with our Terms, we do not submit dispute correspondence, negotiate charges, or advance any claim on your behalf.

Carrier contract and invoice data. Contracts and rate confirmations you upload are used only to power your own audit and comparison features. We do not disclose your negotiated terms to other customers, to carriers, or to third parties, except as required by law or with your written authorization.

7Small Shipper Index and External Market Intelligence

LanePilot may use data generated through use of the Service to create aggregated and de-identified market intelligence, including a recurring Small Shipper Index.

The Index may report industry-level patterns such as quote-to-invoice variance, apparent invoice-discrepancy rates, disputed accessorial trends, reclassification and reweigh frequency, price dispersion, fuel-surcharge differences, invoice-error patterns, and service variability. The particular measures may change as the Index develops.

Before publishing a figure, we apply aggregation, de-identification, suppression, and contribution-concentration controls designed to prevent the figure from reasonably identifying an organization, individual, shipment, invoice, quote, or an organization's relationship with a carrier or vendor. We do not publish raw uploaded documents, raw Customer Data, Carrier Credentials, or customer-specific rates or contract terms.

Where personal information must be processed to create these aggregate figures, LanePilot acts as an independent controller for that limited purpose. Once the resulting information has been sufficiently aggregated and de-identified so that no individual is reasonably identifiable, it is no longer treated as personal information.

The Small Shipper Index is separate from Network Benchmarking. Network Benchmarking is an opt-in feature that uses the limited lane-level fields described below and displays benchmark figures within the Service. The Small Shipper Index may use a broader range of aggregated Service data and may be distributed publicly. Choosing not to participate in Network Benchmarking does not opt an organization out of the aggregated and de-identified use described in this subsection.

We do not use Customer Data or these aggregate results to train, fine-tune, or develop any artificial-intelligence or machine-learning model.

8Network Benchmarking

Network Benchmarking is being built. We are collecting lane-level data now, from organizations that opt in, in order to build a LanePilot benchmark. The benchmark itself is not yet published. Once we hold enough contributed data to produce figures that meet the conditions below, we will publish them in the Service so participating organizations can compare their own lanes against aggregated figures. Until then the feature collects data and shows no figures.

It is opt-in and off by default. Nothing is contributed unless an organization turns it on in account settings. You can turn it off at any time, which stops future contributions. It does not reverse data already anonymized and aggregated, because that data no longer identifies anyone.

What is contributed. Only lane-level fields: origin ZIP, destination ZIP, freight class, weight, and charge. Company name, account identifiers, contact details, and specific addresses are removed before anything is aggregated. Inventory, product, vendor, and receiving data is never contributed.

How we will operate it. These are the conditions that will govern the benchmark when it launches, and we will not publish a figure that does not meet them. LanePilot will operate the benchmark itself. Contributed data will be at least three months old before inclusion. Any figure we show will rest on data from at least five participating organizations, and no single participant will account for more than approximately twenty-five percent of a figure. Output will be aggregated so that an individual contributor cannot be identified or reconstructed. The removal of identifiers described above happens now, at the point of contribution, not only when a figure is published.

We do not sell, license, or otherwise provide this data to carriers, third-party logistics providers, brokers, or logistics technology companies. Benchmarking exists so our own users can see where they stand.

Network Benchmarking is separate from the Small Shipper Index and other externally published Aggregated Market Intelligence. Its opt-in requirement, limited contributed fields, and in-Service purpose apply only to Network Benchmarking and are not expanded by the separate Index disclosure above.

9Sub-Processors and Service Providers

We use the providers below. The Role column states which of three capacities each provider acts in, because they are not the same and should not be read as one list. The table below is grouped into those three capacities. Most are processors that handle data on our instructions and are contractually restricted from using it for their own purposes. Some also act as independent controllers for their own regulatory purposes, which is noted in their row and is governed by that provider's own terms rather than our instructions. Hunter is a processor, but in a third capacity: it processes only our own business prospecting data and never receives customer data. That is why it appears here, where we disclose our own prospecting, but not in the subprocessor exhibit to our Data Processing Agreement, which covers only providers that process customer data.

This list was last verified on August 1, 2026.

Group 1. Providers that process customer data on LanePilot's instructions.

ProviderRoleWhat it handles
ClerkProcessor. Identity and authenticationEmail address, name, session tokens, passwords (stored by Clerk, never by LanePilot)
BubbleProcessor. Primary application databaseAccount, shipment, audit, vendor, receiving, and inventory data
CloudflareProcessor. Application workers, object storage, key-value storage, security and DDoS protectionUploaded documents, IP address, traffic metadata, cookie data
VercelProcessor. Website and application hostingRequest data, IP address, technical logs
Anthropic, PBCProcessor. AI processing via the Claude APIDocument content, query text, and other content submitted for AI processing
SendGrid (Twilio)Processor. Transactional customer email onlyRecipient email addresses and the content of the account, billing, deletion, and restore emails we send to our own customers. Not used for prospecting or cold outreach. Also receives a deleted user's email address for SendGrid's suppression list
Google WorkspaceProcessor. Email intake and internal business recordsDocuments and contact details sent to our intake addresses, customer communications, internal records
SentryProcessor. Error and performance monitoringError reports and diagnostic context, which may include limited technical identifiers
PostHogProcessor. Product analyticsUsage events, pseudonymous identifiers, session data

Group 2. Providers that also act as independent controllers for their own regulatory purposes.

ProviderRoleWhat it handles
Stripe, Inc.Processor for payment processing, and independent controller for fraud prevention and anti-money-laundering and know-your-customer complianceBilling address, payment method details, transaction records

Group 3. Providers that support LanePilot's own business operations rather than customer data.

ProviderRoleWhat it handles
HunterProcessor. Business email discovery and verification for our own prospectingBusiness prospect contact data only. Does not receive customer data

Vendor-governed retention. Two providers retain data on their own terms, which our deletion process cannot reach and which we disclose rather than obscure:

  • Anthropic retains API content for up to 30 days by default, and up to two years for content flagged under its usage policies. It does not train on our content.
  • Stripe retains data while providing services and afterwards for legal, regulatory, tax, accounting, and fraud-prevention purposes, generally five or more years from the end of the relationship or the last transaction, including in its capacity as an independent controller.

Exited providers. CloudConvert was removed from the Service on 2026-07-18 and Apollo was removed on 2026-07-17. Neither receives any data now. We retain the executed data processing agreement for CloudConvert covering the historical period only.

We may also disclose personal information to comply with legal obligations or valid legal process, to protect the rights, property, or safety of LanePilot, our users, or others, or in connection with a merger, acquisition, or sale of assets, subject to this Policy continuing to apply.

10Where We Process Data

We process data primarily in the United States, through our hosting providers and the sub-processors listed above.

11Do Not Sell or Share

LanePilot does not sell, rent, or trade personal data to third parties for their own marketing purposes, and does not share it for cross-context behavioral advertising.

As a transparency measure we offer a Do Not Sell or Share mechanism regardless. Email [email protected] at any time. We offer this voluntarily and do not concede that any particular state privacy statute applies to our operations.

12How Long We Keep Data

We keep personal information only as long as needed for the purposes in this Policy, or as required by law. The periods below are LanePilot's adopted retention schedule.

CategoryRetention period
Tax and financial substantiation, customer invoices, bad debt, LanePilot billing records7 years
Payroll and employment tax records6 years
Account and identity data, for billing, fraud, and compliance purposes4 years after the account closes
Freight operational data (quotes, bookings, bills of lading, tracking) and saved shipmentsRetained while actively used, and for four years after the later of final shipment disposition and the final invoice, audit, or dispute activity relating to that shipment
Invoice and audit data, audit findings, dispute letters, and vendor chargeback lettersFour years after final resolution, or the last material activity involving the applicable audit, dispute, credit, refund, or chargeback
Customer-uploaded carrier agreements and rate confirmationsRetained while actively relied upon, and for four years after the later of expiration, termination, or supersession of the agreement and final resolution of the transactions or disputes it governs
Carrier credentials, active secretDeleted immediately on disconnection or account closure. Never retained, never placed under legal hold
Carrier credential non-secret records (metadata, access and audit logs)1 year
Prospect and marketing data24 months from last activity
Opt-out and suppression recordsKept indefinitely, as a minimal record, solely so we do not contact you again. Never used for marketing
Erasure records and security incident records6 years
Consent and acceptance records4 years after the relationship ends
Product activity records (actions taken in the Service, attributed to a user)User identifiers severed once no longer necessary. Entries retained in identified form only under a specific retention purpose or a legal hold
Privacy request records24 months
Contracts, data processing agreements, and vendor agreementsTerm, plus 6 years
Support tickets and customer correspondence2 years
BackupsExpire on a 35-day rotation

Receiving, warehouse, vendor, and inventory records follow the freight operational schedule above and are covered by the deletion process described below.

Backups. Deleting data from our live systems does not immediately remove it from backups. Backup copies expire on the rotation stated above.

13Cancellation, Deletion, and the Recovery Window

Canceling a subscription does not start a deletion clock. Your data is retained under the schedule above until you request deletion or a Pause period expires.

The Pause tier preserves your data in read-only form for up to twelve months and does not auto-renew.

The 29-day recovery window. If you request account deletion, or if a Pause period ends without resubscription, we begin a 29-day recovery window. We intend to send reminder emails on or about day 7, day 21, and day 28. An organization may restore its account one time. If it requests deletion again after using that one restoration, no further restoration is available and the deletion becomes permanent when the window ends.

What deletion covers. When the window ends we delete the organization's data from our active production systems, including shipment and quote records, uploaded documents, invoice and audit records, dispute and chargeback letters, vendor records and vendor contact details, receiving records, and inventory and product records. We retain only what the schedule above and the legal hold section below require. Residual copies in encrypted backups are isolated from ordinary use and expire through our ordinary backup rotation, which completes within 35 days.

Removing an individual is different from deleting an organization. Removing a user removes that person and severs their identifiers from the organization's records. Severing reaches their name, business email address, direct telephone number, user identifier, captured signature, and personal identifiers appearing in free-text notes or location data. It is not limited to the name field. It does not destroy the organization's operational history, which belongs to the organization.

Where the organization is a separate legal entity, such as a limited liability company or a corporation, this holds even if the entity has only one user. The entity remains our customer and its records survive the removal of any individual.

Where the customer is not a separate legal entity, for example a sole proprietorship in which the individual and the business are the same, there is no organization left to hold the records once that person is removed. In that case we treat a deletion request from that individual as a deletion of the entire account. We erase the operational records at the end of the recovery window, except for the categories the retention schedule above requires us to keep, and we minimize or anonymize personal identifiers in anything that must remain.

We ask each customer to tell us which of these two it is when the account is created, because the answer changes what a deletion request does. Deleting an entire organization's account is a separate, deliberate action available only to the account owner.

14Legal Hold

Scheduled deletion is suspended where preservation is required for litigation, an investigation, legal process, enforcement of an agreement, or another applicable legal obligation. We may also retain data beyond the periods above where retention is necessary to establish, exercise, or defend legal claims, or to comply with a legal obligation. Where a hold applies, the affected records are withheld from deletion and our erasure record notes them as withheld rather than deleted, so our own record of what happened stays accurate. Where a record is kept only to establish, exercise, or defend a legal claim, we keep no more than is necessary for that purpose and restrict it to storage and authorized legal or compliance access rather than ordinary operational use.

A legal hold never retains a live carrier credential. Active credentials are deleted in all cases.

15Your Rights and Choices

Depending on your circumstances you may have the right to request access to the personal information we hold about you, correction of inaccurate information, deletion of your personal information (subject to the retention obligations and legal holds described above), a copy of your information in a portable form, and to opt out of marketing at any time.

If you are an employee or authorized user of an organization that uses LanePilot, you may exercise these rights directly with us. Where the request concerns your employer's business records rather than your personal information, we will generally remove or sever your personal identifiers and retain the organization's underlying record, and we will tell you that is what we did.

If you are a business prospect, you may ask us to delete your data at any time even though you never registered.

To exercise any right, contact [email protected]. We respond within the time applicable law requires and may need to verify your identity first. We keep a record of privacy requests as shown in the retention schedule.

16Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption of data in transit and, where applicable, at rest; encryption of stored carrier credentials; access controls limiting internal access to those who need it; authentication managed by Clerk as a third-party identity provider, which stores passwords under its own controls rather than LanePilot storing them; account lockout and abuse-prevention controls; monitoring and logging through Cloudflare; and vendor security review.

One limitation we disclose rather than hide. For a small number of carriers, that carrier's own interface requires credentials to be transmitted as part of the request address, which means they may appear in that carrier's server logs. This is a property of those carriers' systems, and we cannot control what a carrier records in its own systems. We identify the affected carriers at the point where you enter those credentials, so you can decide whether to connect them, and we apply the controls available to us to keep credentials out of the logs and monitoring systems we control. Where a carrier offers a restricted or scoped API credential, we recommend using it, and you may revoke or rotate a credential with the carrier at any time.

No security system is perfect and we cannot guarantee absolute security. If we become aware of a breach of security affecting unencrypted personal information in a manner covered by Pennsylvania's Breach of Personal Information Notification Act, we will notify affected individuals and any required regulators as that statute and other applicable law require.

17Children's Privacy

The Service is not directed at and is not intended for anyone under 18. We do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it promptly. Contact [email protected] if you believe a child has provided us with personal information. We do not collect biometric information from anyone.

18Changes to This Policy

We may update this Policy to reflect changes in our practices or applicable law. If we make material changes we will provide notice through the Service, by email, or by posting an updated effective date, and where the change is material we may require you to accept the updated Policy before continuing to use the Service.

19Contact

LanePilot Technology, LLC
8370 Wattsburg Road
Erie, PA 16509

20Change Record

This Policy was revised on August 2, 2026 without a version change, because no user had accepted Version 4.3 at the time of revision. The revisions state retention triggers as defined closing events rather than record-creation dates, add a retention period for customer-uploaded carrier agreements and rate confirmations, replace a retention entry for security and access logs with one describing our product activity records, state that scheduled deletion is suspended under a legal hold, limit records kept solely to defend a legal claim to storage and authorized access, and describe what happens to a deletion request where the customer is not a separate legal entity. They follow outside counsel advice of August 1 and August 2, 2026.

Once account sign-ups open, any further change to this Policy will carry a new version number.

By creating an account or using the Service, you confirm that you have read and understood this Privacy Policy.
LanePilot Technology, LLC · Privacy Policy v4.3 · Effective August 1, 2026 · Revised August 2, 2026

© 2026 LanePilot Technology, LLC · Erie, Pennsylvania · Terms of Service ·