- Who we are
- What this policy covers
- The four groups of people in our system
- What we collect
- Why we collect it
- Consent, and where it doesn't apply
- If you are the subject of a report
- Who we share information with
- How long we keep it
- How we protect it
- Where it is stored
- Your rights
- Cookies and analytics
- Children
- Changes
- Contact and complaints
1. Who we are
The NotifyMe Solutions platform at notifymesolutions.com is operated by NotifyMe LLC, a Wyoming limited liability company ("NotifyMe," "we," "us" and "our").
Services to customers in Canada are provided by NotifyMe Inc., a Canadian federal corporation (#1805631-5), under a separate privacy policy at notifymesolutions.ca.
We store and process personal information on infrastructure located in Canada (see section 11). Because that information is processed in Canada, we handle it in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, and we apply the standards in this policy to everyone in our system wherever they are located. Commercial electronic messages are governed by Canada's Anti-Spam Legislation (CASL); see section 6.
2. What this policy covers
This policy applies to the NotifyMe Solutions platform and every product in it, including NotifyMeFleet, NotifyMeDriving and NotifyMeBins, together with our websites, reporting pages, mobile and web applications, and dashboards.
It does not cover:
- NotifyMeRV, our consumer product, which has its own privacy policy at notifymerv.com.
- Custom redirect destinations. Our customers can configure a scannable asset to send scans to their own system instead of ours. Once you leave our page, you are on our customer's system and their privacy practices apply. We have no visibility into or control over it.
- Third-party sites we link to.
3. The four groups of people in our system
Most privacy policies describe one kind of person. Ours has to describe four, because they have very different relationships with us and different rights.
a. Customers
Businesses that subscribe — fleet operators, waste haulers, and their staff, including safety managers, dispatchers and administrators who hold accounts.
b. Reporters
People who scan a NotifyMe QR code and submit a report. On NotifyMeFleet and NotifyMeDriving this is usually a member of the public with no relationship to us or to our customer. On NotifyMeBins it is usually a site supervisor authorised by our customer with a company PIN.
c. Subjects of reports
People a report is about — most often a commercial driver. This group has not chosen to interact with us, and we treat their information with corresponding care. Section 7 is written for them.
d. Website visitors
Anyone browsing our websites.
4. What we collect
From customers
- Name, business email, phone number, job title, company name
- Billing information — payment card details are handled by Stripe and never stored on our systems
- Account credentials, stored using one-way hashing
- Fleet or asset details you enter: unit numbers, container IDs, site names, driver names where you choose to add them
- Usage and audit logs — logins, actions taken in the dashboard, IP address
From reporters
- The identifier of the scanned asset — this comes from the sticker, not from you
- Report category and any free-text description you write
- Location — approximate GPS coordinates from your device at the moment you report, and only if you permit it. You can decline and still submit
- Date and time of submission
- Any photograph you choose to attach
- Company PIN, where the product requires one
- Contact details only if you volunteer them; reports may be submitted anonymously
- Limited technical data — IP address, browser and device type — used for abuse prevention and rate limiting
We do not ask for your name. We do not require an account. We capture where and when the report was made, because a report without a place and a time is useless to the person receiving it. If you want to be contacted about your report, you must tell us how — otherwise we cannot identify you and neither can our customer.
From subjects of reports
- The unit, vehicle or asset identified in the report, which may be associated with a named individual in our customer's own records
- The content of the report, including any description of conduct
- Where our customer chooses to record it: driver name, employee identifier, and the customer's own notes on coaching, review or resolution
From website visitors
- Information submitted through demo request forms — name, company, email, phone, and what you tell us about your operation
- Analytics data, only where you have accepted cookies. See section 13
5. Why we collect it
| Purpose | What it involves |
|---|---|
| Delivering reports | Routing a submitted report to the right customer, with the asset, location and time attached |
| Operating accounts | Authentication, dashboards, exports, support |
| Billing | Subscriptions, invoices, tax records |
| Abuse prevention | Automated screening of photos and text, rate limiting, and detecting malicious or fraudulent reports |
| Service improvement | Understanding aggregate usage patterns to improve the product |
| Legal obligations | Tax, corporate records, and responding to lawful requests |
We do not sell personal information. We do not share it with advertisers, data brokers, or anyone building marketing profiles. We do not use report content to train machine learning models offered to other customers.
6. Consent, and where it doesn't apply
Under PIPEDA we generally rely on your consent. How that consent is given varies:
- Customers consent expressly when opening an account and accepting our Terms of Service.
- Reporters consent by submitting a report. Location sharing requires a separate, explicit permission from your device that you may refuse.
- Website visitors consent to analytics through our cookie notice. Declining is a real choice — see section 13.
- Subjects of reports have generally not given consent to us directly. Section 7 explains why, and what governs it.
You may withdraw consent at any time, subject to legal and contractual limits, by contacting us. Withdrawing consent may mean we can no longer provide the service.
Commercial electronic messages we send are governed by CASL. Every one contains a working unsubscribe link, and transactional messages such as report alerts and billing notices are not marketing.
7. If you are the subject of a report
You did not choose to be in our system, and we think you are owed a straight explanation of how it works.
We are a service provider, not the decision-maker. When a report is made about a vehicle, we process it on behalf of the company that operates that vehicle. That company decides what the report means, whether it is credible, and what happens next. In privacy terms, they control the information and we handle it on their instructions.
What this means in practice:
- A report is an unverified account from a member of the public. It is a claim, not a finding, and it is not evidence of anything on its own.
- Our platform provides our customers with a review process, including the ability to record that a report was reviewed and dismissed. We encourage its use but we cannot compel it.
- To ask what has been recorded about you, or to correct it, contact your employer first. They hold the record and they can act on it. If you cannot resolve it with them, contact us and we will help you reach the right party and assist where we are able.
- If you are employed by a federally regulated carrier, PIPEDA likely governs your employer's handling of your personal information. If not, provincial legislation may apply. Either way, you have rights against them.
We do not disclose report content to anyone other than the customer who operates the asset, except as set out in section 8.
8. Who we share information with
We share personal information only in these circumstances:
- With our customer. A report goes to the business that operates the scanned asset. That is the entire point of the service.
- With service providers who help us operate, each bound by contract to protect it and use it only for what we've asked:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and application hosting | Canada (Montreal region) |
| Vercel | Website hosting | United States / global edge |
| Stripe | Payment processing | United States |
| Twilio | SMS alerts | United States |
| SendGrid | Email alerts | United States |
| Amazon Web Services | Automated photo screening | United States |
| OpenAI | Automated text screening for abusive content | United States |
| Google Analytics | Website analytics, only with consent | United States |
| Formspree | Demo request form delivery | United States |
| Microsoft 365 | Business email | United States and Canada |
- Where the law requires it — a valid court order, subpoena, or lawful demand.
- To protect safety where we believe in good faith there is a risk of serious harm.
- In a business transfer. Our products are designed to be sold individually. If a product line is sold, information relating to that product may transfer to the buyer, who will be bound by commitments no less protective than these. We will give notice before that happens.
9. How long we keep it
| Information | Retention |
|---|---|
| Report records, including location and time | 3 years from submission, or until the customer deletes them, whichever is sooner |
| Photographs attached to reports | 12 months from submission |
| Customer account records | Duration of the account, plus 2 years |
| Billing and tax records | As required by Canadian and US tax law, generally 6–7 years |
| Technical and abuse-prevention logs | 90 days |
Customers use report histories as documentation for safety audits and insurance renewals, which favours longer retention; privacy minimization favours shorter. These periods are our balance of the two. You can delete your own report records at any time, and we delete them on the schedule above.
10. How we protect it
- Encryption in transit using TLS, and encryption at rest
- Row-level access controls so customers can only reach their own data
- Passwords stored using one-way hashing; we cannot read them
- PIN validation performed server-side
- Access limited to personnel who need it, with audit logging
- Automated screening of submitted photos and text before delivery
No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as PIPEDA requires, and maintain records of breaches as required by law.
11. Where it is stored
Your account data and the reports you submit are stored in Canada, on database infrastructure hosted in the Montreal region. We chose Canadian data residency deliberately.
We say "stored in Canada," not "never leaves Canada," because that is the accurate description. Some of our service providers operate outside Canada: payment processing, SMS and email delivery, automated text screening, website hosting and analytics are handled by providers in the United States and other countries (see section 8), and automated screening of submitted photos is currently performed in the United States. Where personal information is handled by, or transmitted through, one of these providers, it is subject to the laws of the country it is in and may be accessible to that country's courts and authorities.
By using the service you acknowledge this. We use contractual protections with each provider requiring standards comparable to those we apply ourselves.
12. Your rights
Subject to legal limits, you may:
- Access the personal information we hold about you and be told how it has been used and disclosed
- Correct information that is inaccurate or incomplete
- Withdraw consent, subject to legal and contractual restrictions
- Request deletion, where we are not required to retain it
- Ask for a copy in a portable format
- Complain to us, and to a regulator if unsatisfied
Write to privacy@notifymesolutions.com. We respond within 30 days as PIPEDA requires, and may ask you to verify your identity first.
If you are the subject of a report, start with the company that operates the vehicle — see section 7.
13. Cookies and analytics
We use Google Analytics to understand how our websites are used. It does not run until you accept. Our cookie notice defaults to denied, and choosing Decline means no analytics cookies are set and no analytics data is collected. That choice is remembered.
Where analytics does run, IP addresses are anonymised. We do not use advertising cookies, remarketing, or cross-site tracking.
Strictly necessary cookies — those that keep you signed in, remember your cookie choice, and hold a report on your device when you are offline — are always active, because the service cannot function without them.
You can clear cookies or change your choice at any time in your browser settings.
14. Children
Our services are business tools and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided information to us, contact us and we will delete it.
15. Changes
We may update this policy. The effective date at the top will change, and for significant changes we will notify account holders by email at least 30 days before they take effect. Continued use after that constitutes acceptance.
16. Contact and complaints
Privacy Officer
David Boe, Privacy Officer
NotifyMe LLC
privacy@notifymesolutions.com
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca or 1-800-282-1376, or to your provincial privacy commissioner.
© 2026 NotifyMe LLC. See also our Terms of Service.