This Privacy Policy explains how Hopline Transfers Inc. (trading as GigFreight)(“we”, “us”, “our”) collects and uses your personal data when you use our platform at gigfreight.com. It applies to all users in the EU and UK and complies with the General Data Protection Regulation (GDPR) and the UK GDPR.
1. Who we are
Hopline Transfers Inc. (trading as GigFreight) is a B2B freight marketplace connecting carriers, dispatchers and brokers across the European Union, United Kingdom, United States and Turkey. For the purposes of data protection law, we are the data controller responsible for your personal data.
Hopline Transfers Inc. (trading as GigFreight)
File No. 7648553
6411 19th Avenue, 2nd Floor
Brooklyn, New York 11204, United States
Data Protection contact: legal@gigfreight.com
2. Data we collect
Account data
- Full name, email address, password (stored as a bcrypt hash — never in plaintext)
- Role: carrier, dispatcher, or broker
- Phone number (optional)
Company data
- Company name, trading name
- Country of registration and EU VAT number
- Company type, rating, verified status
- Vehicle fleet details: type, registration number, capacity
Load and transaction data
- Pickup and delivery locations, addresses, dates and times
- Vehicle type, weight, commodity, special instructions
- Freight rate (EUR or GBP), distance (km)
- Load status history, accepted driver, interest records
Usage and technical data
- Pages visited, features used, search queries performed
- IP address, browser type and version, device type
- Session duration, click patterns, error logs
- Authentication tokens (stored as hashed values)
Payment data
We do not store your card number, CVV or bank account details. All payment processing is handled by Stripe. We receive only payment confirmation status and a Stripe customer/subscription ID.
API keys
API keys are generated with a fb_ prefix and stored as SHA-256 hashes only. The raw key is shown once at creation and cannot be recovered.
3. How we use your data
- To create and manage your GigFreight account
- To display your loads and company profile to relevant parties
- To match carriers with loads and facilitate contact between brokers and drivers
- To send in-app notifications (e.g. driver interest alerts, application updates)
- To process your subscription payment via Stripe
- To provide customer support and respond to enquiries
- To detect and prevent fraudulent activity and abuse
- To improve platform performance, features and user experience
- To comply with legal, tax and regulatory obligations
4. Legal basis for processing (GDPR)
Contract performance (Art. 6(1)(b))
Processing necessary to provide you with the GigFreight service as per your account agreement — including load management, notifications and account features.
Legitimate interests (Art. 6(1)(f))
Platform security, fraud prevention, analytics, and improving our service. We have assessed that these interests do not override your fundamental rights.
Legal obligation (Art. 6(1)(c))
Retaining financial records, responding to lawful law enforcement requests, and complying with EU/UK tax regulations.
Consent (Art. 6(1)(a))
Marketing communications and non-essential cookies. You may withdraw consent at any time without penalty.
5. Cookies
We use essential cookies for authentication and session management. These are strictly necessary for the platform to function and cannot be disabled.
We may use functional and analytics cookies to remember your preferences and understand how the platform is used. See our Cookies Policy for the full list of cookies, their duration and how to manage them.
6. Data sharing
We share your data only with the following trusted service providers and only to the extent necessary:
We never sell your personal data to any third party, advertiser or data broker. We do not share data for targeted advertising.
We may disclose data to law enforcement or regulatory bodies when required by law, with or without prior notice to you.
7. Data retention
| Data category | Retention period | Reason |
|---|---|---|
| Account data | Account lifetime + 2 years | Dispute resolution |
| Company data | Account lifetime + 2 years | Dispute resolution |
| Load records | 7 years after creation | Legal / tax compliance |
| Payment records | 7 years | EU/UK tax law |
| Usage logs | 90 days | Security monitoring |
| API keys (hash) | Until revoked | Authentication |
8. Your rights under GDPR
Under the GDPR (EU) and UK GDPR, you have the following rights regarding your personal data:
Right of access
Request a copy of all personal data we hold about you (Subject Access Request).
Right to rectification
Ask us to correct any inaccurate or incomplete data at any time.
Right to erasure
Request deletion of your data ('right to be forgotten'), subject to legal retention obligations.
Right to restrict
Ask us to limit processing while a dispute is being resolved.
Right to portability
Receive your data in a structured, machine-readable format (JSON or CSV).
Right to object
Object to processing based on legitimate interests, including any profiling.
Withdraw consent
Withdraw consent for marketing or non-essential cookies at any time without penalty.
To exercise any of these rights, email privacy@gigfreight.com with the subject “Data Subject Request”. We will acknowledge within 72 hours and respond within 30 days.
9. International transfers
Your personal data is primarily processed within the European Economic Area (EEA) and the United Kingdom. Supabase stores data in EU data centres.
Where data is transferred outside the EEA (e.g. Stripe's US infrastructure, Vercel's global edge network), we rely on appropriate safeguards including the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA).
10. Security measures
We implement industry-standard technical and organisational security measures, including:
- TLS/HTTPS encryption for all data in transit
- Row Level Security (RLS) in our PostgreSQL database — users can only access their own data
- Bcrypt password hashing — passwords are never stored in plaintext
- SHA-256 API key hashing — raw keys are never stored
- Authentication via Supabase Auth with JWT tokens
- Regular security dependency updates and code reviews
Despite these measures, no online platform can guarantee 100% security. If you suspect unauthorised access to your account, contact security@gigfreight.com immediately.
11. Supervisory authority
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority:
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- Germany: Bundesdatenschutzbeauftragter (BfDI)
- France: Commission Nationale de l'Informatique et des Libertés (CNIL)
- Poland: UrzÄ…d Ochrony Danych Osobowych (UODO)
- Other EU countries: your national Data Protection Authority
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the “Last updated” date at the top of this page. Continued use of the Platform after changes constitutes acceptance of the updated policy.
Minor updates (e.g. clarifying language, fixing typos) will not be separately notified.
13. Contact us
Privacy & data requests
privacy@gigfreight.comSecurity incidents
security@gigfreight.comGeneral support
support@gigfreight.comLegal enquiries
legal@gigfreight.com