Privacy Policy
Effective date: May 14, 2026 · Last updated: May 14, 2026
This Privacy Policy describes how ABC LEGACY LLC ("4truck", "we", "us", or "our") collects, uses, and protects information when you use the 4truck fleet management platform available at https://4truck.us and related services (collectively, the "Service").
By using 4truck, you agree to the practices described below. If you do not agree, please do not use the Service.
1. Who We Are
2. What Information We Collect
2.1 Account information
When you register, we collect:
- Your name and email address
- Company name and contact information
- Authentication credentials (password hashes, OAuth tokens)
- Role and permissions within your company account
2.2 Fleet and logistics data
To provide fleet management services, we process:
- Driver records (CDL information, medical card status, hire date)
- Vehicle and truck data (VIN, registration, maintenance records)
- Telematics data integrated from third-party providers (e.g., Samsara) under your account
- Work orders, maintenance logs, fuel records, and reports
- Document metadata (filename, upload date, document type, associated driver/truck)
2.3 Google Drive integration (BYOS — Bring Your Own Storage)
If you choose to connect your Google Drive account, 4truck uses the drive.file OAuth scope. This means 4truck can only access:
- Files that 4truck itself creates inside your Drive (organized under a "4truck" folder)
- Files that you explicitly select via the Google Picker, if applicable
4truck cannot see, list, read, or modify any other files in your Google Drive. Your personal documents, photos, and unrelated business files remain completely private and inaccessible to 4truck.
The files themselves (CDL scans, truck documents, work orders, etc.) are stored in your own Google Drive account — not on our servers. We store only metadata (Drive file IDs, upload timestamps, categorization tags) in our database to enable search and organization features.
2.4 Usage and technical data
- IP address, browser type, device information
- Pages visited, features used, error logs
- Cookies and session tokens for authentication
3. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the 4truck platform
- Process documents, generate reports, and run scheduled tasks (alerts, scorecards, compliance checks)
- Authenticate users and enforce role-based access control
- Communicate with you about your account, support requests, and service updates
- Investigate and prevent fraud, abuse, or violations of our Terms of Service
- Comply with legal obligations and respond to lawful requests
Limited Use Disclosure (Google API Services User Data Policy):
4truck's use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements.
Specifically:
- We do not use Google Drive data for advertising purposes.
- We do not sell or transfer Google Drive data to third parties for advertising, credit scoring, or any unrelated purposes.
- We do not use Google Drive data to train artificial intelligence or machine learning models.
- Humans at 4truck do not read your Drive files except (a) with your explicit consent, (b) for security investigations of suspected abuse, or (c) where required by law.
4. How We Share Information
We do not sell your personal information. We share data only in these limited circumstances:
- Within your company account: Authorized users in your organization may see fleet data, driver records, and documents according to their assigned role.
- Service providers: We use trusted infrastructure providers (e.g., hosting, email delivery) under strict confidentiality and data-processing agreements. These providers do not have independent rights to your data.
- Telematics integrations: When you connect Samsara or another telematics provider, we exchange data with that provider per your authorization.
- Legal compliance: If required by valid legal process, court order, or to protect rights, safety, or property.
- Business transfer: In the event of a merger, acquisition, or asset sale, your information may transfer to the new entity, subject to this Privacy Policy.
5. Data Storage and Security
- OAuth refresh tokens are encrypted at rest using strong symmetric encryption (Fernet).
- Passwords are stored as salted hashes; we never store plaintext passwords.
- Database connections use TLS in transit.
- API requests are served over HTTPS only.
- Google Drive files remain in your own Drive account — 4truck never holds the file bytes long-term.
- We follow industry-standard practices for access control, logging, and incident response.
6. Data Retention
We retain different categories of data for different periods:
- Account data: retained while your account is active. Deleted within 30 days after account closure.
- Fleet and document metadata: retained while your account is active.
- Google Drive files: remain in your Drive; we never copy them to our servers permanently.
- Audit logs: retained for up to 3 years to support compliance with U.S. Department of Transportation regulations (49 CFR Part 391) for driver qualification files.
- Backups: rolling 30-day backups are purged automatically.
7. Your Rights and Choices
7.1 Disconnect Google Drive
You can disconnect 4truck from your Google Drive at any time:
When you disconnect, 4truck immediately deletes your encrypted refresh token from our database and revokes its OAuth access. Files previously stored in your Drive remain there — they belong to you.
7.2 Delete your account
To delete your 4truck account and all associated metadata, email [email protected] from your registered email address. We will confirm and complete deletion within 30 days. Files in your own Google Drive are not affected by 4truck account deletion.
7.3 Access and correction
You can view and update most of your account information directly in the dashboard. For any data not editable in-app, contact us.
7.4 California, EU, and other jurisdictions
Depending on your location, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA) or the EU General Data Protection Regulation (GDPR), including rights of access, portability, deletion, and the right to lodge a complaint with a supervisory authority. Contact us to exercise these rights.
8. Compliance Considerations for Trucking Operators
4truck is designed to help motor carriers organize records. However, you remain responsible for meeting record-retention requirements under U.S. Department of Transportation regulations (49 CFR Part 391, 395, and related rules), including driver qualification files, hours-of-service records, and inspection logs.
Because Google Drive files are stored under your own Google account, if you disconnect Drive or delete files from your Drive, those files become unavailable to 4truck. You remain responsible for retaining required compliance records in accordance with applicable law.
9. Children's Privacy
4truck is a business tool for commercial fleet operators and is not intended for use by individuals under 18. We do not knowingly collect information from children.
10. International Data Transfers
4truck is operated from the United States. If you access the Service from outside the U.S., your information may be transferred to and processed in the U.S., where data-protection laws may differ from those in your country.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to account administrators and posted at this URL with an updated "Effective date" at the top. Continued use of the Service after changes take effect constitutes acceptance.
12. Contact Us