Privacy Policy
Effective July 24, 2026 · Sync Technologies LLC (“Draylo”)
Draylo is a carrier-vetting and onboarding platform for US freight brokers. Brokers use Draylo to upload carrier documents, check carriers against their own rules and federal (FMCSA) records, and keep a permanent record of their approve/deny decisions. This policy explains what information we collect to do that, how we use it, who we share it with, and the choices you have.
1. Information we collect
Broker account information. When you sign up, we collect your name, company name, email address, and login credentials. If teammates are added to your account, we collect the same for them.
Uploaded carrier documents. Brokers upload documents about the carriers they vet, including Certificates of Insurance (COIs), W-9 forms, and operating-authority documents. W-9s contain taxpayer identification numbers (an EIN or, for sole proprietors, a Social Security number). We treat this as sensitive personal and financial information — see Section 7 for how we specifically handle it.
Extracted document fields. We use automated (AI-assisted) document reading to pull structured fields out of uploaded documents — for example, the insurance carrier, policy numbers, coverage amounts, and expiration dates from a COI, or the legal name and tax classification from a W-9. These extracted fields are stored so they can be checked against your rules and shown to you.
E-signature data. Brokers can have their broker-carrier agreement signed electronically during carrier onboarding. When a carrier representative signs, we collect the signer’s name and email address, and our e-signature provider (SignWell) collects the signature itself along with standard electronic-signature evidence — such as the signer’s IP address, browser and device information, and the date and time of each signing event — which is compiled into a tamper-evident audit trail attached to the signed document. The completed signed agreement, including that audit trail, is stored with the broker’s other carrier documents.
FMCSA data. We pull carrier and authority data live from the Federal Motor Carrier Safety Administration’s public systems. This includes information such as operating-authority status, DOT/MC numbers, and related public safety records. FMCSA is a public government data source; we retrieve this data on your behalf when you run a check.
Audit records. Every approve or deny decision made in Draylo is saved as a time-stamped, append-only audit record. These records cannot be edited after the fact — that immutability is a core feature of the product, because brokers rely on it to show what they knew and decided at the time.
Payment information. Payments are processed by Stripe. Your card number goes directly to Stripe; we do not store full card numbers on our systems. We keep only what Stripe returns to us to manage your subscription (for example, a customer reference, subscription status, and the card’s last four digits and expiration as provided by Stripe).
Usage data. Like most web services, we collect standard technical and usage information when you use Draylo — such as IP address, browser type and version, device type, pages and features used, referring site, and timestamps — to keep the service working, secure, and improving.
Website analytics (public pages). On our public website and free tools, we log each visit along with the visitor’s IP address, browser information, the page visited, the referring site, and any campaign tags on the link. From the IP address we derive an approximate location (city and state) and a network classification (for example, whether the visit came from a residential connection or a data center, which helps us tell human visitors from automated traffic). This location lookup happens on our own systems using a locally stored geolocation database — your IP address is not sent to a third party for this purpose. We use this information to understand our audience, measure our marketing, count unique visitors, and protect the site from abuse. Visitor analytics logs, including IP addresses, are retained for 12 months and then deleted or irreversibly anonymized.
Free-tool usage linked to your contact record. Our free tools (for example, the carrier check) can be used without an account and without telling us who you are. If you choose to give us your email address on one of our public forms (for example, to receive a result by email, subscribe to our guides, or set an expiration reminder), we set a first-party cookie in your browser at that moment. From then on, your use of our free tools from that browser (which carriers you check, and when) is associated with your contact record, so we can understand how people who’ve expressed interest use our tools and follow up helpfully. This cookie is set only when you submit your email, contains only a random identifier, is not shared with or readable by any third party, and expires after 12 months. Visitors who never share an email remain anonymous. Clearing your browser cookies unlinks your future tool usage.
Website visitor identification and tracking technologies (public pages) — with your consent. On our public marketing pages, we offer a third-party visitor-identification script (a “pixel” or tag) provided by Leadsy.ai and used with our outreach platform, Instantly. This pixel does not run unless you accept it. When you first visit our public pages, we show a cookie banner; the pixel is loaded only if you affirmatively accept, and it is not loaded if you decline, ignore the banner, or if your browser sends a recognized opt-out signal such as Global Privacy Control. If you accept, the pixel uses cookies and similar technologies to collect your IP address, browser and device information, and information about your visit (pages viewed, time on page, links clicked, referring site, timestamps). Using your IP address and third-party business-data sources, the service then attempts to identify the company and, in some cases, the individual professional associated with your visit — including, where available, a business email address, job title, LinkedIn profile, and employer — which we use for business-to-business marketing and outreach, including adding identified business contacts to our email campaigns. This tool operates only on visitors from United States IP addresses. It applies only to our public website and is never applied to the carrier documents, extracted fields, or audit records you upload inside the product. You can change your choice at any time — see Section 6.
2. How we use this information, and why we're allowed to
| Information | How we use it | Basis for processing |
|---|---|---|
| Broker account info | Create and secure your account, communicate with you about the service | Performing our contract with you |
| Uploaded carrier documents | Store them, read fields out of them, and run your vetting checks | Performing our contract with you |
| Extracted fields | Compare against your rules and FMCSA data; display results to you | Performing our contract with you |
| E-signature data (signer identity, signature, audit trail) | Facilitate electronic signing of the broker-carrier agreement and preserve tamper-evident proof of who signed, when, and how | Performing our contract with the broker; the broker's and our legitimate interest in an enforceable, verifiable signed agreement |
| FMCSA data | Verify carrier authority and status as part of your checks | Performing our contract with you |
| Audit records | Preserve a tamper-evident record of vetting decisions | Performing our contract with you; our and your legitimate interest in defensible records |
| Pickup verification media (VIN/CDL photos) | Record and support a broker's at-pickup vehicle/identity verification for a specific load | Performing our contract with the broker; the broker's and our legitimate interest in a defensible pickup record |
| Payment info (via Stripe) | Bill your subscription | Performing our contract with you |
| Support messages & in-app help chat | Answer your product questions (including via an AI assistant grounded in our own documentation) and respond to support requests | Performing our contract with you |
| Usage data | Operate, secure, debug, and improve the service | Our legitimate interest in running a reliable, secure service |
| Website analytics (public pages) | Measure marketing, estimate unique visitors, derive approximate location, detect automated traffic, prevent abuse | Our legitimate interest in understanding and protecting our public website |
| Free-tool usage linked to your contact record | Understand how people who shared an email use our free tools; prioritize helpful follow-up | Our legitimate interest in B2B marketing to people who expressed interest; set only when you submit your email |
| Website visitor identification & tracking (public pages) | With your consent, run a third-party pixel that collects IP, device, and browsing data and, via third-party B2B data, identifies the company/professional associated with a visit; add identified business contacts to marketing outreach | Your consent (given through our cookie banner; the pixel does not run without it) |
We do not sell your carriers’ information or the documents you upload, and we do not use uploaded documents for advertising. Our visitor-identification tool (above) operates only on public-website traffic and never on the carrier data you upload inside the product.
3. A note about carrier information
Most of the personal information in Draylo is about carriers — the businesses and individuals your brokerage vets — and is uploaded by you, the broker. In privacy terms, we process that information on your behalf and at your direction. You are responsible for having an appropriate basis to collect and upload carrier documents (in practice, carriers provide W-9s and COIs to brokers as a normal part of onboarding). If a carrier contacts us directly about their information, we will refer them to the broker who holds it and assist that broker in responding — see Section 8.
4. Who we share information with
We share information only with the service providers (subprocessors) we need to run Draylo, and with FMCSA as a data source:
| Category | Provider | What they handle |
|---|---|---|
| Document storage | Cloudflare (R2 object storage) | Uploaded documents, stored in private buckets |
| Payments | Stripe | Payment card details and billing information |
| AI processing | Anthropic | Uploaded document content (field extraction), load commodity descriptions (risk classification), and in-app help-chat messages (to generate answers). Chat conversations are not stored by Draylo unless you send one to our team |
| Application hosting & database | Render | Account data, extracted fields, audit records |
| Email delivery | Resend | Transactional emails (e.g., account and vetting notifications) |
| E-signature | SignWell (SignWell, Inc.) | The agreement document sent for signing, the signer's name and email, and the signature evidence SignWell collects during signing (IP address, device information, event timestamps) to produce the tamper-evident audit trail |
| Website visitor identification (consent-gated) | Leadsy.ai (visitor-ID pixel) and Instantly (outreach platform) | When a visitor accepts our cookie banner, a client-side pixel collects visitor IP, browser/device data, and page-view behavior via cookies, and matches it against third-party business data to identify companies and professionals; identified business contacts are routed into our Instantly marketing campaigns. The pixel does not run for visitors who decline |
| Carrier data source | FMCSA (federal government) | We retrieve public carrier data from FMCSA; we do not send them your documents |
We may also disclose information if required by law (for example, a subpoena or court order), or as part of a merger or sale of the business — in which case this policy would continue to apply to the information until you’re told otherwise.
We do not sell your account data, your carriers’ information, or the documents you upload, and we do not share them with advertisers. The only data-broker-backed service we use is the public-site visitor-identification tool described above (Leadsy.ai), which operates solely on marketing-website traffic — never on the carrier data, documents, or audit records inside the product.
5. Data retention and deletion
Uploaded documents. We keep your uploaded carrier documents for as long as your account is active. When you cancel your account, you can have your uploaded documents deleted — documents are deleted within 30 days of a deletion request.
Audit records. Audit records (the time-stamped approve/deny decisions) are different from raw documents. Their whole purpose is to remain intact so you can show, later, what was decided and when. We retain audit records for the life of your account and 5 years after it closes, even if the underlying document has been deleted. Audit records are append-only by design and are not edited or backdated for anyone, including us.
Signed agreements. A signed broker-carrier agreement (including its audit-trail page) is part of the broker’s compliance record. We retain it like other uploaded carrier documents — for as long as the broker’s account is active, subject to the deletion rights described in this section — and its signature evidence is retained with the related audit records.
Account and billing data. We keep account and billing records as long as needed for legal, tax, and accounting purposes.
Visitor analytics data. Public-site visit logs that include IP addresses are kept for 12 months, after which the IP address is deleted or irreversibly anonymized. Aggregated statistics (counts, trends) that identify no one may be kept indefinitely. We may retain specific log entries longer where reasonably necessary to investigate abuse, fraud, or security incidents, or to comply with law.
6. Your rights and choices
You can:
- Access the information we hold about you or your account.
- Correct account information that’s inaccurate (most of it you can edit yourself in the app).
- Request deletion of your account and uploaded documents, subject to the audit-record retention described above and any legal retention obligations.
- Export your data — contact us and we’ll help.
- Choose whether to allow the visitor-identification pixel. Our public-site visitor-identification pixel (Leadsy.ai/Instantly) runs only if you accept it in our cookie banner. You can decline in the banner (the pixel will not run), change your choice at any time by reopening the banner from the “Cookie settings” link in our footer, or use browser privacy controls. We honor the Global Privacy Control (GPC) signal — if your browser sends it, we treat it as a decline and do not load the pixel. Our own first-party site analytics still run to keep the site working and measure our marketing. To ask us to delete data associated with you or your business, opt out of the sale or sharing of your personal information, or be excluded from our outreach, email hello@draylo.us. None of these tools ever apply to the carrier documents or records inside the product.
- Unlink your free-tool usage. If you shared an email on a public form, clearing your browser cookies (or using private browsing) stops future tool usage from being associated with your contact record. To have past linked usage or your lead record deleted, email hello@draylo.us.
To make any of these requests, email us at hello@draylo.us. We’ll respond within a reasonable time, and we may need to verify your identity first. Depending on where you live, state privacy laws may give you additional specific rights; we honor valid requests under applicable law.
7. How we handle tax identification numbers (W-9 data)
Because W-9s contain TINs (EINs or SSNs), we treat them with extra care:
- W-9s are stored in private, non-public storage (Cloudflare R2), encrypted at rest (AES-256) and in transit (TLS/HTTPS).
- They are never served from a public URL — access is only through short-lived, authenticated links generated for an authorized user of the owning broker account.
- Per-tenant isolation: only your brokerage's users can access your carriers' documents. Every access is authorization-checked, and storage keys are non-guessable identifiers.
- We use W-9 data only to run your vetting checks — never for marketing, and we do not sell or share it beyond the processing described in Section 4.
8. Pickup verification media (VIN and driver's-license photos)
Some brokers use an optional pickup-verification step. When a broker enables it for a load, we generate a secure, single-purpose link that the driver or a dock contact can open (no account required) to submit two photos at pickup: a photo of the truck’s VIN plate and a photo of the driver’s commercial driver’s license (CDL), plus an optional unit number. We use the VIN to confirm the vehicle against what the carrier dispatched (decoding it through the federal NHTSA vehicle database), and we store both photos as a dated record that the pickup verification took place.
A CDL is a government-issued identity document, and we treat it as sensitive personal information. We collect it only to record and support the broker’s pickup verification for that specific load — never for marketing, and we do not sell it or use it to identify drivers for any other purpose.
- The CDL image is stored in private, encrypted storage (Cloudflare R2), encrypted at rest (AES-256) and in transit (TLS/HTTPS).
- It is never served from a public URL — access is only through short-lived, authenticated links available to authorized users of the broker account that requested it.
- We do not perform facial recognition on it.
- Retention. Because a CDL is sensitive, we keep the CDL image only as long as reasonably necessary for the pickup verification — no longer than 30 days after the pickup capture — after which the image is permanently deleted and only a dated, non-image record that the verification occurred is retained as part of the audit trail. The VIN photo and the VIN/decoding results may be retained with the audit record.
The broker who requested the verification controls this data; Draylo processes it on the broker’s behalf. A driver with questions about their information should contact that broker — see the next section.
9. Requests from carriers
If you are a carrier (or a carrier’s driver or owner) and your documents are in Draylo, they were uploaded by a freight broker you did business with. This includes agreements you signed electronically during onboarding. The broker controls that data; contact them first. If you contact us at hello@draylo.us, we will identify the responsible broker where we reasonably can and support them in handling your request.
10. Where data is stored
Draylo’s data is stored and processed in the United States.
11. Children
Draylo is a business tool for freight brokers. It is not directed to children, and we do not knowingly collect information from anyone under 18.
12. Changes to this policy
If we make material changes to this policy, we’ll notify account holders by email or an in-app notice before the change takes effect, and update the effective date above.
13. Contact
Sync Technologies LLC
12672 Limonite Ave, Suite 3E-524, Eastvale, CA 92880
Email: hello@draylo.us
This product includes GeoLite2 Data created by MaxMind, available from https://www.maxmind.com. See also our Terms of Service.