Privacy Policy

Last updated: June 21, 2026

CipherIQ ("we", "us", "our") provides operations management software for Amazon Delivery Service Partners (DSPs). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

This is a plain-language summary. If anything is unclear, reach out at [email protected].

1. Who this applies to

This policy covers anyone who uses cipheriq.ai or the CipherIQ web application, including DSP owners, dispatchers, and other authorized team members ("users").

If you are a driver or employee of a DSP that uses CipherIQ to track operations, your employer (the DSP) is the data controller for information about you. Direct privacy questions to your employer first; we process that data on their behalf.

2. Information we collect

Account information

  • Name, email address, phone number
  • Username and password (passwords stored hashed, never in plaintext)
  • Company name and DSP station code
  • Your role (owner, dispatcher, etc.)

Operational data you enter

  • Driver and employee records (names, contact info, employment data)
  • Vehicle records (VINs, license plates, make/model)
  • Daily operations data (routes, package counts, incidents, callouts)
  • Discipline notices, coaching reviews, and related notes
  • Documents you upload (scorecards, employee documents)
  • Comments, tasks, and notes you create in the app

Usage information

  • Log data (pages visited, actions taken, timestamps)
  • IP address and basic browser information
  • Device information for sessions

Automated inferences

When you ask Cipher (our AI assistant) a question, we send the question and relevant operational context to Anthropic's Claude API. Anthropic does not train its models on this data per their enterprise terms.

3. How we use information

We use the information collected to:

  • Provide and operate the CipherIQ platform
  • Authenticate your account and keep it secure
  • Generate insights and recommendations through Cipher (our AI)
  • Send transactional emails (account confirmations, password resets, billing receipts)
  • Improve product features based on aggregate usage patterns
  • Comply with legal obligations

We do NOT:

  • Sell your data to advertisers or third parties
  • Use your operational data to train AI models
  • Share data between tenants (each DSP's data is isolated)
  • Send marketing emails to your dispatchers or drivers

4. Where your data lives

Our infrastructure is hosted in the United States:

  • Application servers and database: DigitalOcean (US data centers)
  • File storage (uploaded documents): DigitalOcean Spaces, NYC region
  • Transactional email: Postmark
  • AI processing: Anthropic Claude API

All connections to CipherIQ use HTTPS. Database backups are encrypted at rest. Production access is restricted to authorized personnel only.

5. Data retention

We keep your data for as long as your account is active. If you cancel your account, we will:

  • Retain your data for 60 days in case of accidental cancellation
  • After 60 days, delete or anonymize your data
  • Some records may be kept longer if required for legal, tax, or fraud-prevention reasons

6. Your choices and rights

Depending on your location, you may have the right to:

  • Request a copy of your data
  • Correct inaccurate information
  • Request deletion of your data
  • Object to certain processing

To exercise any of these, email [email protected]. We will respond within 30 days.

Account holders can also:

  • Update profile information in Profile settings
  • Change password via the app
  • Deactivate dispatcher accounts under Team

7. Security

We use industry-standard practices to protect your data, including:

  • HTTPS for all connections
  • Encrypted database backups
  • Password hashing (bcrypt)
  • Multi-tenant data isolation (each company's data is scoped separately at the database query level)
  • Limited employee access on a need-to-know basis

No system is 100% secure. If you believe your account has been compromised, contact [email protected] immediately.

8. Cookies and tracking

CipherIQ uses cookies only for essential functionality:

  • Session cookies (to keep you logged in)
  • CSRF tokens (to prevent cross-site request forgery)

We do not use third-party advertising cookies, tracking pixels, or analytics that share data with other companies.

9. Children

CipherIQ is intended for business use and is not directed at children under 13. We do not knowingly collect information from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do:

  • We will update the "Last updated" date above
  • For material changes, we will notify account owners by email
  • Continued use after the effective date means you accept the new policy

11. Contact us

Questions about this policy or your data?

Email: [email protected]

Legal notice: This Privacy Policy is provided as a transparent statement of our practices. It has not been reviewed by legal counsel and does not constitute legal advice. If you are an enterprise customer or have specific compliance requirements (HIPAA, SOC 2, GDPR, etc.), please contact us before relying on this document for compliance purposes.