This Privacy Policy explains what information Vantrix Logistics, operated by RBM Business Holdings Inc. ("Vantrix," "we," "us"), collects through the Service, how we use it, and the choices you have. It covers both the Vantrix Logistics application at app.vantrixlogistics.com and our marketing website at vantrixlogistics.com. It should be read alongside our Terms of Service.
1. Information we collect
We collect information in the following ways:
- Account information you provide directly: name, email address, and password (stored as a salted scrypt hash — we never store or can see your plaintext password).
- Business data ("Customer Data") you or your team enter to use the Service: customer records, trucks and drivers, dispatches, invoices and payments, deals, and similar content. This is your data, described further in our Terms of Service.
- Usage and technical data collected automatically: IP address, browser user agent, pages visited, and timestamps of actions you take, primarily for security (login rate limiting, audit logging) and troubleshooting.
- Email from a connected Outlook mailbox, only if a user chooses to connect one (see "Outlook email sync" below).
- Marketing website visits. Our marketing website is hosted by GoDaddy, which collects basic visit information (such as IP address, browser, and pages viewed) and may set cookies to operate, protect, and measure the site. The marketing website does not ask for or collect account information; signing in and signing up happen in the application.
If you add an API key for a third-party telematics or dashcam provider under Settings → Integrations, we store that key encrypted (AES-256-GCM) and never display it in full again. As of this version we do not automatically retrieve data from that provider using the stored key — we'll update this section if and when that changes.
2. How we use information
- To provide, operate, and maintain the Service for your workspace;
- To authenticate you and secure your account (session cookies, login rate limiting, audit trails);
- To send account-related email: team invitations, password resets, email confirmation, and service notices (see "Email" below);
- To file emails from a connected Outlook mailbox on the matching customer or deal, when a user has turned that on;
- To bill your workspace for its subscription;
- To diagnose and fix errors — when the Service encounters an unexpected error, technical details (error message, stack trace, the page it happened on) are logged for us to review; this diagnostic log is not visible to other workspaces.
We do not sell your information or your Customer Data to third parties.
3. Email we send
Transactional email (invitations, password resets, email confirmation) is sent through Resend, our email delivery provider. We do not send marketing email without a separate opt-in.
4. Outlook email sync
Each user can choose to connect their own Microsoft 365 or Outlook mailbox under Settings. Nothing is read from a mailbox unless that user connects it and grants permission through Microsoft's sign-in screen. When a mailbox is connected:
- We request read-only access (Microsoft's
Mail.Read permission) plus the user's basic profile. We cannot send, delete, move, or change email. - When a new message arrives in the connected mailbox's Inbox, we check its sender and recipients against the email addresses of customers and deals in your workspace. We only store messages that match a customer or deal. Everything else, such as personal, internal, or unrelated mail, is not stored.
- For a matching message, we store the sender, recipients, subject, a short preview of the message text provided by Microsoft, a link back to the message in Outlook, and the time it was received, and show it on the matching customer or deal. We do not store the full message body or attachments, and we do not import mail received before the connection was made.
- Synced email is Customer Data and is visible to members of your workspace who can view those records.
- The Microsoft sign-in tokens that allow access are encrypted at rest (AES-256-GCM).
- A user can disconnect their mailbox at any time from Settings, which stops syncing and deletes the stored sign-in tokens. You can also revoke access from your Microsoft account. Emails already synced stay on the customer and deal records until they or your workspace are deleted; contact us if you want them removed sooner.
5. Maps
The live fleet map uses Google Maps with a Google Maps API key that your workspace provides under Settings → Integrations (we store it encrypted, like other integration credentials). When the map is shown, your browser loads the map directly from Google, so Google receives information such as your IP address, browser details, and the map area being viewed. That information is handled under Google's privacy policy and your workspace's agreement with Google. Truck locations are drawn onto the map in your browser.
6. Service providers
We use a small number of subprocessors to operate the Service, each with access limited to what they need to do their job:
- Neon — hosts our Postgres database (all Customer Data and account information).
- Vercel — hosts and serves the application.
- Resend — delivers transactional email on our behalf.
- Zoho — processes subscription billing and payment.
- Microsoft — provides mailbox access for users who connect Outlook email sync.
- Google — serves the live fleet map, using your workspace's own Google Maps API key.
- GoDaddy — hosts our marketing website and its visit analytics.
7. Data security
- Passwords are hashed with scrypt and a per-password random salt — never stored in plaintext.
- Third-party integration credentials and Outlook sign-in tokens are encrypted at rest with AES-256-GCM.
- Every workspace's data is isolated at the application layer by workspace id, enforced on every read and write.
- The Service is served exclusively over HTTPS.
No system is perfectly secure, and we can't guarantee absolute security. If we become aware of a breach affecting your data, we'll notify you as required by applicable law.
8. Data retention
We retain Customer Data for as long as your workspace is active. If your subscription is cancelled or terminated, we retain data for a reasonable period to allow export before deletion, except where we're required to delete it sooner, or retain it longer, by law.
9. Your rights and choices
You can access, correct, or delete most Customer Data directly within the Service. For anything you can't do yourself — a full account export, deleting your account entirely, or a question about what we hold — contact us using the details below and we'll respond within a reasonable time.
10. Cookies
The application uses a single essential session cookie to keep you signed in. It's httpOnly (not readable by page scripts) and required for the Service to function — there is no cookie banner in the application because it doesn't use non-essential tracking or advertising cookies. Our marketing website, hosted by GoDaddy, may set its own cookies for security and visit analytics, which you can control through your browser settings.
11. Children's privacy
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect information from anyone under 18.
12. Changes to this policy
We may update this Privacy Policy from time to time. We'll update the effective date above when we do, and for material changes we'll make a reasonable effort to notify account owners directly.
13. Contact
Questions about this Privacy Policy, or requests regarding your data, can be sent to support@vantrixlogistics.com, or to the contact address provided on your subscription invoice.