Privacy Policy
Last updated: June 18, 2026
1. Introduction
Cargo Atlanta ("we," "our," or "us") operates the Cargo Atlanta Finance platform (the "Service"), a fleet and maintenance management application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, including any integrations with third-party services such as Intuit QuickBooks Online.
By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
2. Information We Collect
2.1 Personal Information
When you create an account or use the Service, we may collect the following personal information:
- Name (first and last)
- Email address
- Phone number (optional)
- IP address and browser user agent (collected during authentication)
2.2 Fleet and Maintenance Data
We collect data you enter into the platform related to your fleet operations, including:
- Vehicle information (make, model, year, VIN, mileage, status)
- Maintenance records (service dates, types, costs, vendor details)
- Uploaded documents and invoices
- Vehicle issue reports
2.3 QuickBooks Online Data
If you choose to connect your QuickBooks Online account, we access and store the following data from Intuit QuickBooks via OAuth 2.0 authorization:
- Company name and QuickBooks company identifier (Realm ID)
- Transaction data (purchases, expenses, and vendor payments relevant to fleet maintenance)
- OAuth access and refresh tokens (stored securely for maintaining the connection)
We only access QuickBooks data within the scope you authorize during the OAuth consent flow. We do not access your full accounting ledger, payroll data, employee information, or any data beyond what is necessary for maintenance cost reconciliation.
2.4 Automatically Collected Information
When you access the Service, we may automatically collect certain information, including your IP address, browser type, operating system, and access timestamps. This information is used for security monitoring, session management, and service improvement.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Manage your account and authenticate your identity
- Track fleet vehicles, maintenance schedules, and service history
- Process and store maintenance invoices via AI-powered scanning
- Reconcile maintenance costs with QuickBooks Online transaction data (when you have connected your QuickBooks account)
- Compute next-service dates and maintenance cost analytics
- Communicate with you about your account, security alerts, and service updates
- Monitor and improve the security of the Service
4. QuickBooks Online Data
This section describes how we handle data obtained through your QuickBooks Online integration.
4.1 Purpose of Access
We access your QuickBooks Online data solely for the purpose of reconciling fleet maintenance expenses with your accounting records. This allows you to match maintenance records logged in our platform against actual financial transactions in QuickBooks.
4.2 Data Storage
QuickBooks transaction data synced to our platform is stored in a secure, encrypted database. OAuth tokens (access and refresh tokens) are stored separately and used only to maintain your authorized connection with QuickBooks.
4.3 No Selling or Sharing of QuickBooks Data
We do not sell, rent, trade, or otherwise share your QuickBooks data with any third party. Your financial data is used exclusively within the Service for the reconciliation features you have authorized.
4.4 Disconnecting QuickBooks
You may disconnect your QuickBooks Online account from the Service at any time through the Reconciliation page. When you disconnect:
- We revoke the OAuth tokens with Intuit, ending our access to your QuickBooks data
- The connection record is marked as disconnected in our system
- Previously synced transaction data may be retained for your historical records unless you request its deletion
- No further data will be fetched from your QuickBooks account
5. Data Sharing and Third Parties
We do not sell your personal information or fleet data. We may share your information only in the following circumstances:
- Intuit QuickBooks: When you authorize the QuickBooks integration, data flows between our Service and Intuit via their secured OAuth 2.0 APIs, subject to Intuit's Privacy Statement.
- Infrastructure providers: We use third-party hosting and database services (including Vercel and Neon) to operate the Service. These providers process data on our behalf and are bound by their own privacy and security obligations.
- Legal requirements: We may disclose your information if required to do so by law, court order, or governmental regulation.
6. Data Retention and Deletion
We retain your personal information and fleet data for as long as your account is active or as needed to provide you with the Service. Specifically:
- Account data: Retained while your account is active. Upon account deletion, personal information is removed within 30 days.
- Fleet and maintenance data: Retained while your account is active. You may request deletion at any time.
- QuickBooks data: Synced transaction data is retained for reconciliation purposes. Upon disconnecting QuickBooks or upon your request, this data can be deleted.
- Authentication logs: Session records (IP address, user agent, timestamps) are retained for up to 90 days for security auditing purposes.
To request deletion of your data, contact us at rentcargoatlanta@gmail.com. We will process your request within 30 days.
7. Security Measures
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted via TLS/HTTPS.
- Encryption at rest: Database storage is encrypted at rest using industry-standard encryption.
- Authentication: Passwordless magic-link authentication with time-limited tokens and server-side session management via signed JWTs and database-backed sessions.
- Access controls: Role-based access control (admin/customer) with session revocation capabilities.
- Rate limiting: Login attempts are rate-limited to prevent brute-force attacks.
- Token security: OAuth tokens and API keys are hashed before storage. Magic-link tokens are single-use and time-limited (15 minutes).
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Your Rights
You have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete personal information.
- Deletion: Request deletion of your personal information and account data.
- Disconnect: Disconnect your QuickBooks Online account at any time from within the Service.
- Data portability: Request your data in a structured, machine-readable format.
To exercise any of these rights, contact us at rentcargoatlanta@gmail.com.
9. Cookies and Tracking
We use a single, essential HTTP-only session cookie ("cargo_session") to maintain your authenticated session. This cookie is strictly necessary for the Service to function and cannot be disabled. We do not use advertising cookies, analytics trackers, or any third-party tracking scripts.
10. Children's Privacy
The Service is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.
12. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: