Hopline Transfers Inc. (trading as GigFreight) is designed from the ground up to comply with the General Data Protection Regulation (GDPR) for EU users and the UK GDPR for users in the United Kingdom.
Privacy and data protection are not an afterthought at Hopline Transfers Inc. (trading as GigFreight) — they are built into the platform's architecture. We collect only the data we need, store it securely, and give you full control.
Our infrastructure uses Supabase (hosted in EU data centres), Row Level Security to prevent cross-user data access, SHA-256 hashing for API keys, and TLS encryption for all data in transit.
Data minimisation
We collect only what is necessary to provide the service.
Security by design
Row Level Security, encrypted storage, TLS in transit.
Transparent processing
We document every category of data we process and why.
DPO contact
privacy@gigfreight.com for all data protection enquiries.
Request a copy of all personal data we hold about you (Subject Access Request). We will respond within 30 days.
Ask us to correct any inaccurate or incomplete personal data at any time.
Request deletion of your personal data (“right to be forgotten”), subject to legal retention obligations.
Ask us to limit how we use your personal data while a query is resolved.
Receive your data in a structured, machine-readable format (JSON or CSV).
Object to processing based on legitimate interests, including profiling.
Withdraw consent for marketing communications at any time without penalty.
To exercise any of these rights, email privacy@gigfreight.com with the subject line “Data Subject Request”. We will acknowledge within 72 hours and respond within 30 days.
| Category | Data types | Legal basis | Retention |
|---|---|---|---|
| Account | Name, email, role, password hash | Contract | Account lifetime + 2 years |
| Company | Company name, VAT, country, vehicles | Contract | Account lifetime + 2 years |
| Loads | Route, rate, dates, status | Contract | 7 years (legal) |
| Payments | Subscription status (Stripe holds card data) | Contract | 7 years (legal) |
| Usage logs | IP address, session data | Legitimate interest | 90 days |
| API keys | Key prefix, SHA-256 hash | Contract | Until revoked |
If you believe your GDPR rights have been violated, you have the right to lodge a complaint with your national data protection authority.
Privacy questions? privacy@gigfreight.com · Read our Privacy Policy · Cookies Policy