Privacy Policy
Version 2026-08-04
Please read this first
This is a draft. It was written by reading the 360Loads software itself, line by line, and describing what that software actually does with your information. It has not been reviewed by a lawyer.
It must be reviewed and approved by a qualified legal professional before launch. Nothing here is legal advice, to you or to anyone else.
If anything in this document ever disagrees with what the app really does, the app is what is true and this document is what is wrong. Tell us and we will fix it.
Who we are
360Loads is a place where truck drivers, dispatchers, accountants and safety managers can be found by trucking companies, and where those companies can be found back. The legal entity that operates it is [TO BE COMPLETED BY OWNER]. That is also who to contact about anything in this document.
This version of this document is dated in its title and we keep the older versions. When you accepted a version, we recorded which one.
What we collect
Your account. Your name, your email address, your password, and the language you chose. Your password is not stored the way you typed it — it is scrambled with bcrypt, and nobody here, including us, can turn it back into your password.
Your phone number, but only sometimes. We never ask you for one. There is no phone field on sign-up, on your profile, or in your settings. The only way a phone number ends up on your account is if a member of our team typed it in when they invited you to 360Loads. It is not shown to companies. It is used for exactly one thing — a single text message inviting you to claim that account — and the section "The one text message we send" below says when that is allowed to happen, how to stop it for good, and what happens to the number itself when you delete your account.
Your profile. One profile per profession you hold. Across all of them: a headline, an "about you", years of experience, how soon you are available, your home city and state, whether you would relocate, and what pay you are looking for. Then the facts particular to your line of work — for a driver that is CDL class, endorsements, equipment, cargo, work types, home-time preference, whether your medical card is current, and miles driven; for office roles it is the software and ELD systems you know, your specialties, your certifications, the freight types and fleet sizes you have handled, and whether you work on site or remotely.
We do not collect your street address. A city and a state is as precise as it gets. We also do not ask for your date of birth, your Social Security number, your licence number, or any document — there is nowhere in 360Loads to put them.
Your photo, if you add one. A profile photo is optional; nothing asks you for one, and without it your initials are shown instead. A company can add a logo on the same terms. What we keep is not the file you sent us — the section "Photos and logos" below says what we do to it, who can see it, and when it is destroyed.
Your work history. The companies you have worked with, your title there, and the dates. This is the part of a profile most likely to reach your current employer, so it is treated as the most sensitive thing you give us. See "What other people can see".
Your messages. Once an introduction is accepted, you and the company can message each other inside 360Loads. We store what is written.
Your introductions. Which company, who started it, an optional note, whether it was accepted or declined, and the list of profile sections you agreed to share with them.
The rest of your use. Companies and roles you saved, notifications we sent you, and any report you filed about another member.
Activity records. Two kinds, both ours and neither shown to other members:
- Audit records: an append-only log of actions — who did what, to which record, and when. Message bodies, passwords and tokens are stripped out before anything is written, so they can never end up in this log. We keep these indefinitely, and "Deleting your account" below says why.
- Analytics events: one row each time something notable happens — an introduction requested, a password changed — carrying the name of the event, your account id, and a few non-identifying details such as which profession. The same stripping applies. We use them to count how 360Loads is being used. These are deleted once they are older than a retention window we set, which is 400 days unless we have changed it.
If you manage a company. The company's legal name, operating name, DOT and MC numbers, headquarters city and state, website, phone number, description, fleet size, equipment, cargo, work types, hiring states, home-time policy, pay description and benefits.
If you submit a company for verification. The DOT and MC numbers you are claiming, and your own name and your role at that company, because a verification badge is a statement about a business and somebody has to have stood behind it. It is a record about the company rather than about you, and "Deleting your account" explains what happens to it when you leave.
What other people can see
Never your contact details. Your email address and your phone number are not in any view another member can see. Not in search results, not on an introduction request, not after you connect. There is one exception, and it is not about strangers: if you are on a company's team, the other people on that same company's team can see your email address on the team screen, because they are your colleagues on a shared account. If you delete your account, you come off that team screen too — the exception ends when the reason for it does.
In search, you are a first name and an initial. A company searching for professionals sees "Marcus D.", your headline, years of experience, availability, home city and state, whether you would relocate, and your professional facts. It never sees your work history and never sees your pay expectation at this stage.
On an introduction, exactly the sections you ticked. When you ask a company for an introduction, you choose which sections of your profile go with it, and they see those and nothing more. Work history and pay expectation are never included unless you tick them.
When a company invites you and you accept, we record a standard set of sections for your profession — and that standard set never contains your work history or your pay expectation.
After you connect, the company sees your full name and your professional profile. Your pay expectation and your work history still appear only if they were part of what you agreed to share.
What you type is yours to decide. If you put your phone number into a message, the company reads your phone number. 360Loads keeps contact details out of profiles; it does not police conversations.
Your held interest in a company that has not joined. If you tell an unclaimed company listing that you are interested, that interest is held here. It is not delivered to anybody. It becomes visible to the company only if and when they claim their listing on 360Loads. It leaves us only as a count — "9 drivers in Ohio" — never as a name, never as an id.
Photos and logos
You can add a photo of yourself to your profile, and a company can add a logo. Both are optional. A photo is used for one thing: to put a face next to your name on the screens described below. We do not run face recognition on it, we do not use it to train anything, and there is no image search in 360Loads.
We never store the file you sent us
Every image you upload is taken apart and rebuilt before anything is saved. We decode it, resize it, and re-encode it as WebP at two sizes — a small one for lists and a larger one for a profile page — and it is those two rebuilt files we keep. Your original is never written to disk.
That is how the metadata goes. Photographs carry hidden data: EXIF, colour profiles, XMP, IPTC — and, on almost every phone, the GPS coordinates of the place the picture was taken. None of it survives the rebuild. Before we store an image we read the file we are about to write and refuse to store it at all if any of that is still attached.
This is not a detail. 360Loads shows your home city and state and never your street address, on purpose. A photo taken at home carries that address in a field no screen displays and nobody thinks to look at, and publishing it would undo the one thing this app promises about where you live.
The limits. A file has to be under 8 MB, and it has to really be a JPEG, PNG, WebP or AVIF — we read the file's own first bytes to decide that, rather than trusting its name or what your browser says it is. Anything else is refused before it is opened.
About iPhone photos. An iPhone saves pictures as HEIC unless you tell it otherwise. Our picker still lets you choose one, because an iPhone often converts it to a JPEG on its way to us and those work perfectly. The ones that do arrive as HEIC we cannot open, and we say so plainly and tell you the one camera setting that fixes it — we would rather refuse a photo with an explanation you can act on than pretend the file was broken.
Who can see a company logo
A company logo is public. Anyone can see it, including a visitor who is not signed in, because a business logo is public by nature. Two limits still apply: a listing we created from public records shows no logo, because nobody from that company has uploaded one; and a company that asked us to take it out of the directory shows none either.
Who can see your photo
Your photo is not public, and it is not in search. A company looking through professionals sees the same monogram of your initials it sees today. Your photo appears only after an introduction between you is accepted — the same gate your work history already sits behind — and it appears only to the company on the other side of that introduction.
A link to an image is not permission to see it. Every single request for an image is decided again, at that moment, against whoever is asking. So the link to your photo, if it ends up in a screenshot, a browser history or somebody's clipboard, shows that person nothing unless they were already allowed to see it. And if the introduction is only pending, if it was declined, if a block was set, or if the account was closed, the answer changes immediately and everywhere, with nothing left outstanding.
While your account is open you can always see your own photo.
Caching, honestly. Because a company logo is public, we allow the caches that sit between us and a reader — a browser, a company proxy — to keep a copy for a while, the way any public image on the web is kept. Your profile photo is marked private, so those shared caches are told not to store it at all.
Taking one down
You can remove your own photo, and a company owner or manager can remove its logo, at any time, from the same screen you added it on.
Our team can remove a photo or a logo that breaks the rules, using the same permission that decides reports. Removing an image is not the same as deleting an account: only the picture goes, and the account, the profile and everything else on it stay exactly as they were. Every such removal is written to our audit records, naming who did it and whose image it was.
Removal means the file is deleted from our storage — both sizes, gone — and not merely detached from your profile. There is no bin to recover it from, here or anywhere. The file goes first and the link to it second, so if the deletion itself fails nothing is reported as removed: the picture stays where it was and pressing the button again really tries again.
Blocking
You can block a company, and a company can block you.
We do not announce it. No notification is sent, and nobody is ever told who blocked whom.
A block works both ways, whoever set it. Neither of you can request an introduction with the other, neither is shown to the other in search, and no new conversation can start.
It cleans up what already exists. Any open conversation between you is closed and any pending introduction between you is declined. If you were already in a conversation, the other person will see that it closed, and the screen tells them a block closed it — without saying which side did it. There is no way to end a live conversation that leaves no trace at all.
Our staff
Some of our team have staff permissions. What they can do depends on the permission they hold.
Message content is the strictest of them. A staff member cannot open a conversation's messages without first writing a reason. The record of that access — who opened it, when, why, and whether they read or exported it — is written before a single message is returned, so an access can never happen without leaving a trace.
The fact that a conversation exists is not held that strictly, and you should know it. Staff on our support tier can pull up a list of conversations without writing a reason, and that list view is not individually recorded the way opening messages is. It never contains a word anyone wrote. For each thread it does show the professional's first name and last initial, the company's name, the role the introduction came from, how many messages each side has sent, when the last one arrived, how long the first reply took, how long the thread has been quiet, and whether a block is in place. We use it to find introductions that went nowhere. It does mean a member of our team can see that you and a company are talking, and roughly how that exchange has gone, without asking anyone first.
Staff with the relevant permission can see accounts — including the email address and any phone number on them — as well as company records, verification submissions, and reports.
Our moderation screen does not show anyone's photo. Staff reviewing a complaint are told whether the reported record has an image on it and can remove it; they are not shown the picture. The staff permission that resolves reports is not a way around the rule above, and there is no screen anywhere that hands a member of our team a driver's face without an accepted introduction.
Cookies
360Loads sets two cookies. Both are needed for the site to work, neither is for advertising, and neither is readable by scripts in your browser.
- rp_session — set when you sign in. It holds a random token and nothing else; the token is stored on our side only as a SHA-256 hash. It lasts up to 30 days.
- rp_locale — the language you picked, so a signed-out visitor keeps it. It lasts a year.
There are no advertising cookies, no tracking pixels, and no third-party analytics scripts on 360Loads. The activity records described above are our own, stored in our own database.
We do not store your IP address in our database.
Getting your data out
Sign in and open Settings → Your data → Download my data, or go to /api/export directly. You get a JSON file containing:
- your account: id, email, name, phone, when your email was verified, and when you joined;
- every professional profile you hold, with its work history;
- your company memberships and your role in each;
- which policy versions you accepted and when;
- your saved items;
- the interest you registered in company listings that have not joined us, with the company, the profession it was registered under, and the state recorded at the time;
- the blocks you set;
- your introduction requests, with the note you sent;
- your conversations as a professional, with the full text of every message in them — if you use 360Loads on the company side, the conversation belongs to the company account and is not in your personal export;
- the titles of your notifications;
- the reports you filed, with the free text you wrote in them — but not our staff's notes on how each one was handled, or who handled it.
To be straight with you about the limits: this file does not include the audit records or the analytics events described above. Those are logs about actions rather than a copy of your profile, and today the export does not reach them. It also does not tell you whether a company has blocked you — blocking is silent in both directions, so the file carries the blocks you set and never the ones set on you. Your photo is not in it either: the download is a JSON file of your records, and the image is a separate file — while your account is open you can see it on your own profile, and you keep whatever original you uploaded from.
Deleting your account
Deleting is available in Settings → Your data. It happens in two stages: the account is switched off the moment you confirm, and then, after a waiting period, your identity is destroyed for good. Here is exactly what happens at each stage.
Immediately, when you confirm
- your account is marked deleted and suspended, and it stops being usable — you are not in search, on a team screen, or reachable by anybody. Signing in from that point does not simply let you back in; during the waiting period below it cancels the deletion instead, with one exception we describe there;
- every session on every device is destroyed;
- all of your profiles stop being discoverable, and your headline, "about you", pay expectation, home city and home state are erased;
- your work history entries are deleted outright — right then, permanently, and nothing later brings them back;
- any held interest you registered in company listings is deleted, so it stops speaking for you — right then, permanently, on the same terms;
- your photo stops being shown to anybody at all, including to you. The file is not destroyed yet — that happens at the end of the waiting period below — because the waiting period exists so you can change your mind, and a photo destroyed on the first day could not come back with the account. It is not shown to anyone in the meantime, so nothing is disclosed by our keeping it;
- your place on any company team is removed, so your name and email address stop appearing on that team's screen. The one case we cannot simply delete is a company whose only owner you are — deleting that would leave the company with nobody able to manage it — so that single membership is kept, and you are hidden from the team screen instead.
The waiting period, and how to change your mind
Nothing is destroyed straight away. There is a waiting period first. It is a setting we control, it is 30 days unless we have changed it, and the deletion screen reads the live setting and shows you the real number before you confirm — so the figure you were shown is the one that applies to you.
That is not a figure of speech. The day your account becomes due is written onto the account the moment you confirm, out of that same setting, and we do not move that date afterwards — not shorter and not longer. If we change the waiting period later it applies to people who delete their account after the change, and never to anybody already waiting.
Signing in with your email address and your password during that period cancels the deletion. That is all it takes: no message to us, no support ticket. Your account comes straight back on and your profiles can be made discoverable again.
There is one exception, and it is enforcement. If we suspend the account for breaking the rules after you asked to delete it — for example because a report about you was upheld — signing in stops cancelling the deletion, because a suspension you could lift by typing your own password would not be a suspension. We tell you that the account is suspended rather than pretending the password was wrong. The waiting period still runs out on schedule and the account is still destroyed at the end of it. If you think we got that wrong, write to us before it does.
What signing in does not do is undo the first stage. The work history and the held interest went the moment you confirmed, and no sign-in restores them. You get your account back, not the day before you pressed the button. Your photo does come back, because it was never destroyed — that is the reason we wait.
If you do nothing, the waiting period runs out, a scheduled job destroys the identity on the account, and from that point it cannot be recovered by us or by anyone.
When the waiting period runs out
All of this happens as a single step — either every one of these lands or none of them does. Deleting the stored photo file is the one part that sits just outside that step, because deleting a file is not something we could undo if anything else went wrong; the paragraph on the photo below says exactly what we do about that.
- your name is replaced with "Deleted user";
- your email address is replaced with a placeholder at the reserved domain deleted.invalid, which can never receive mail. That frees your original address: you can sign up with it again later, and the new account starts empty and shares nothing at all with the old one;
- your phone number is deleted — both the number as it was typed and the tidied-up copy we keep to check whether that handset has already had its one text — and the record that your email address was verified is cleared. In the same step we cut the link from your account to the consent record behind any invite text, and we destroy our log of the text itself, including the reference the messaging company gave it. That reference is not your number, but the messaging company would hand your number back to anyone holding it, so leaving it behind would have left a way to look the number up after we said it was gone. The consent record itself is kept, and it still lists the numbers its batch covered — see "The consent record behind a text" below, which says plainly what can and cannot be worked out from it afterwards;
- your password is replaced with a scrambled value nobody can type, so nobody — including us — can sign into the account;
- any staff permissions the account held are removed;
- your professional profiles, your work history, your saved companies, your notifications, your sessions, any outstanding verification or password-reset links, any held interest, and the blocks you set are all deleted outright;
- your photo is destroyed — both stored sizes are deleted from our storage, not merely detached from the account. This is the part that happens immediately after the rest rather than inside it, so we do it in an order that cannot lose the file: we write the file's address into a list of things to destroy, delete the file, and only then cross the address off. If our storage is unavailable at that moment the address stays on the list and the job tries again on its next run, and the number of files still waiting is on our own operations screen until it is zero. A photograph outliving the person it belongs to is the one outcome this whole section exists to prevent;
- the introduction requests you sent survive as the company's record, but the link from them back to your profile is cut.
A company logo is not touched by any of this, and that is deliberate: it belongs to the business, not to you, and a company that did not ask to be deleted should not lose its identity because one of its people left. If you were the company's only owner, the note above about that membership applies here too.
What is kept after that, and why
- The messages in your conversations. The other person has already read them; the conversation is their record as much as yours, and you cannot unsend what somebody has read. Your name in that thread becomes "Deleted user".
- Your introduction requests, and the note you wrote on them. Same reason: they are the company's record of an exchange that really happened.
- Audit records — kept indefinitely, deliberately. They are the trail that makes abuse traceable, and an account that could erase them by closing itself would turn deletion into a way to destroy evidence. They carry your account id, which by then points at a row with no identity left in it, and never your name, address or phone number.
- Analytics events, on the same PII-free terms, deleted once they pass the retention window described above.
- Your recorded policy consents — which version of these documents you accepted, and when. That record is the only evidence either of us has that we asked and you agreed.
- Reports, including the free text written in them — both the ones you filed and the ones filed about you. A moderation complaint has to outlive the account it is about, or reporting somebody would stop working the moment they closed their account.
- A company membership you are the sole owner of, as described above.
- A block a company set on you. That is the company's decision for its whole team, and quietly lifting it as you left would be a decision we made on their behalf.
- Announcements our team sent, with their title and body, including one addressed to you individually.
Five places a name, an address or a number can still be read
We would rather name these than let you find them.
- A verification you submitted for a company. The form records the name and role of the person who submitted it, and that record is kept as written — it is not anonymized when that person deletes their account. It is evidence about a business, given in a professional capacity, and it is what stands behind a verification badge other members rely on. Only staff with the verification permission can read it; no other member ever sees it.
- The never-contact list. When an address tells us to stop mailing it — an unsubscribe, a bounce, a spam complaint — we keep the address itself on a suppression list. Removing it would be the opposite of honouring it: we would forget that it asked us to stop, and mail it again. Today only company contact addresses reach that list. If that ever changes, this is where your address would sit, and it would stay there.
- The never-text list. The same idea, for phone numbers, and it is not hypothetical: a number that replied STOP, or that a text failed on, is kept on a list we never text — after the account is deleted, on purpose, for the reason set out under "The one text message we send". The list holds the number, why it went on, and when. It holds no name and no account, so nothing in it says whose number it was.
- The consent record behind a text. When a member of our team ticks the box saying they have permission to text a batch of invited people, we keep what they ticked, who they were, when, and the numbers that batch covered. It is the only evidence a text was authorised, so it outlives the person who made it and the accounts it covered. It lists numbers and never accounts, and the link from your account to it is cut when the account is destroyed.
We would rather be exact about what that does and does not achieve. The record carries the date it was made and the member of our team who made it. An account created from that batch keeps the date it was created, and the record of who invited it. Those dates are seconds apart, because the record is written immediately before the accounts. So somebody with direct access to our database could narrow a kept number back to a deleted account — for a batch that covered several people, to one of that batch's numbers; for a one-person batch, to exactly that number. We do not remove that, and the reason is the honest one: deleting the number would destroy the only proof the text was allowed, for exactly the person most likely to need us to have it. What we have done instead is stop the record listing numbers in the order they were pasted, so position no longer matches a batch's numbers up with the accounts it created.
- Free text, wherever you typed it. A message, the note on an introduction, the details on a report: it stays exactly as written, including anything about yourself you put in it. We do not rewrite it, because it is somebody else's record of a real exchange and editing it would corrupt that record. If you put your phone number into a message, that message still carries your phone number after your account is gone.
The one thing we do not do
We do not delete your account row itself. It stays behind as an empty marker carrying no identity, because deleting it outright would cascade and take the conversations, introductions and messages of the people you talked to along with it. So the identity is destroyed in place, and the empty row is left for those records to point at.
In the words of the screen you confirm on: We retain audit records, moderation complaints, and messages already delivered to other people. Everything above is the long version of that sentence.
If you want more than this removed, ask us.
Company listings we created from public records
Some companies in the 360Loads directory did not sign themselves up. We added them from public FMCSA records so that professionals could find them. A listing like that holds only public-record information: legal name, operating name, DOT and MC numbers, headquarters city and state, website, fleet size, and a contact email address for the company. The contact email address is never shown to another member — not on the listing, not in search, and not in any view a member can reach. It is used only to send the outreach email and the claim link, and staff with the listings permission can see it on the company record, as described in "Our staff".
An unclaimed listing never shows a verification badge, and it never shows a phone number or a company description, because nobody from that company has written one.
If you are that carrier and you want out, click the unsubscribe link in the email we sent, or write to us. It is not only a mailing preference: the listing leaves the directory as well as the mail, the address goes on a never-contact list, and it is honoured immediately without waiting for anyone here to approve it.
Email we send a company that has not joined
There are exactly two, they are counted separately, and both are logged where our team can see them.
The cold email. Companies with an unclaimed listing may receive one, and the rules around it are strict:
- only after professionals have registered interest in that company — never to a company nobody has asked about;
- once, ever. One email per company. There is no follow-up sequence;
- counts only. The message says how many professionals are interested and which states they are in. It contains no name, no id, and nothing that identifies any individual;
- it carries a working unsubscribe link and our postal address, and the system refuses to send at all if either is missing;
- the whole feature ships switched off and cannot send anything until the owner turns it on.
The claim link. A member of our team can also email a company the link that turns its listing into a real account — because the company asked us for it, or because we are offering them the page. It is a different message with its own rules:
- sent by a person, not by the system. Nothing sends it automatically, and it never goes anywhere except the contact address on the listing itself;
- at most three, ever, per company, and every one of them is written into the same send log as the cold email, so our team can see exactly what a company has been sent. The cap exists so that a link the email provider never accepted can be tried again — not so that anyone can keep mailing;
- it carries the same unsubscribe link and postal address the cold email carries;
- never to an address that has asked us to stop. If the address is on the never-contact list, the send is refused outright.
If an email to a company bounces or is reported as spam, that address goes on the never-contact list too.
Members get transactional email only: the link that verifies your address, the link that resets your password, and — if a member of our team invited you — the link that lets you claim your account. We do not send members marketing email, and we do not send marketing texts either. The next section is the only text 360Loads sends to anybody.
The one text message we send
If a member of our team invited you and typed a mobile number in, that number may be used to send you one text message. It is the only kind of text 360Loads sends: there is no text notification, no text sign-in code, and no text about anything else. It says who set the profile up, carries the same claim link the invite email carries, and ends by telling you to reply STOP to opt out. It is sent in your language where we know it, and the word STOP stays STOP in all of them, because it is the keyword the network has to recognise rather than a word being translated.
- One, ever — one per handset, not one per invitation. Not one a week, not a reminder, not a follow-up. If our team resends your invite — and they can, more than once — the email goes again and no second text is sent. And if the same number is typed in twice, under two different email addresses, in one paste or in two: still one text. Both people are invited and both are emailed; only the second text is refused, because the promise is about your phone rather than about our paperwork.
There is exactly one way that number could be texted again, and it is a consequence of deletion rather than an exception to the promise: once the waiting period has run out and the account is destroyed, we have genuinely forgotten the number and that it was ever texted. If somebody later types it into a new invitation, we have nothing left to recognise it by. A number that replied STOP is different — that stays on the never-text list forever, precisely so that deletion cannot undo it.
- Only after somebody here says they have your permission. Before any text can go out, the person inviting you has to tick a box stating that they personally have your permission to text you about 360Loads, that you gave them the number for this, and that they can say when and how you gave it. We record the exact wording they were shown, who they are, when they ticked it, and which numbers it covered. It covers that one batch of invites and nothing else — a later batch with no box ticked is refused, even for a number an earlier batch covered.
- Not to anything that is not a mobile. A number we cannot read as one unambiguous US number, and a number that is not plausibly a mobile, is not texted at all — the invite goes by email only.
- The whole feature ships switched off. It sends nothing until the owner turns it on and configures a messaging company, and in the state 360Loads ships in there is no code in it that could reach a phone network.
STOP means stop, and it does not expire
Reply STOP — or UNSUBSCRIBE, CANCEL, END, QUIT, REVOKE or OPT OUT — and the number goes on a list we never text. Capitals, punctuation and stray spaces do not matter.
Nothing in 360Loads takes a number off that list. Not you, not us, not a later invite, and not texting START back: that word tells the messaging company to lift *its* block and it does not lift ours.
We keep that record even after the account is deleted, and it is worth saying why plainly. The list is kept by number, and it has to be. If we deleted it along with the account, we would have forgotten that the number ever asked us to stop — and the next time somebody typed it into an invite we would text it again. A stop that a deletion could undo is not a stop. So the number stays on the list, and it stays there without a name, an account, or anything else tying it to who you were.
A number is put on the same list if a message to it fails, or if the messaging company tells us it is not a working mobile, so we do not pay to text the same bad number twice.
What happens to the number itself
Deleting your account destroys the number — not the moment you confirm, but at the end of the waiting period described under "Deleting your account", in the same single step that replaces your name and your email address. Our log of the text we sent you is destroyed with it, reference and all. The link from your account to the consent record above is cut in that same step. What is left is a record that somebody attested to a list of numbers on a particular day, with nothing in it pointing back at you — and the bullet on that record under "Five places a name, an address or a number can still be read" says exactly what somebody with direct access to our database could still work out from the dates, because we would rather you read it from us.
Who else sees your data
We do not sell your data. Not to recruiters, not to lead brokers, not to anyone.
Two outside companies can receive anything, and each receives only what it needs to deliver one message:
- The email provider that delivers our email. It receives the recipient's address and the contents of that message. If no provider is configured, no email leaves the application at all.
- The messaging company that delivers the invite text, if the owner has turned texting on. It receives the mobile number and the words of that text. If no messaging company is configured — which is how 360Loads ships — no text leaves the application at all.
How we protect it
- Passwords are stored as bcrypt hashes.
- Session tokens, email verification links, password reset links and company claim links are stored only as SHA-256 hashes — the value in your link is never in our database.
- Reset and verification links expire and can be used once.
- Message bodies, passwords, tokens, email addresses and phone numbers are stripped out before anything is written to an audit or analytics record.
- Every uploaded image is rebuilt from its pixels and stripped of all metadata, including location, before it is stored — and the result is checked before it is written.
- The address of a stored image is 128 random bits with nothing in it derived from whose image it is, so nobody can work one out in order to ask whether an account has a photo.
- What the messaging company sends back to us — a STOP, a delivery failure — is checked against a cryptographic signature before a single word of it is acted on, so an outsider cannot write to the never-text list by pretending to be them.
No system is perfect, and this section describes what the code does rather than promising an outcome.
Changes to this document
Every version of this document has a date, and the old versions stay in our source history exactly as they were. We record which version you accepted and when, and you can see that list in Settings → Your data.