Privacy Policy

Last updated: September 18, 2026

1. Introduction

QRC Dispatch (“QRC,” “we,” “us,” or “our”) is a transportation management system (TMS) operated by QRC Dispatch Inc., a California corporation, for freight brokerages. This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you when you use our web application and related services (the “Service”) at qrcdispatch.com. This Policy applies to our business customers (freight brokerages and their authorized users) and to motor carriers and their drivers who interact with a load-acceptance link we deliver on a brokerage’s behalf. The Service is intended for business use only and is not directed to consumers or to children under 18.

2. Information We Collect

a. Account and contact information. Names, business email addresses, telephone numbers, business names, and mailing or physical addresses that you or your organization provide when creating and managing an account.

b. Brokerage operational data. Information you enter or upload while using the Service, including load and shipment details, rate confirmations, bills of lading, carrier and customer records, contacts, invoices, and documents you attach to loads or carriers (such as proof-of-delivery files and certificates of insurance).

c. Uploaded documents processed for data extraction. When you use our document-parsing feature, the document you upload (for example, a rate confirmation PDF) is transmitted to our AI processing provider to automatically extract fields such as party names and addresses, rate amounts, pickup and delivery details, dates, weight, commodity, equipment, and reference numbers. See Section 4.

d. QuickBooks Online data (only if you connect QuickBooks). If you choose to connect your QuickBooks Online account, we access and process accounting data through Intuit’s API as described in Section 5.

e. Carrier verification data. When you select a carrier, we send the carrier’s MC and/or DOT number to the Federal Motor Carrier Safety Administration (FMCSA) to retrieve publicly available safety and authority information.

f. Technical and usage data. QRC uses Vercel Web Analytics, a cookieless analytics service, to understand aggregate site usage. It records page views with general device type, browser, operating system, referrer, and country. It does not use cookies, does not track you across other websites, and does not collect advertising identifiers. The application records the IP address of a carrier at the moment of rate-confirmation acceptance, for verification and audit. Our infrastructure providers (Vercel and Supabase) may log IP addresses and request metadata as part of operating the Service, and our error-monitoring provider (Sentry) captures application errors but is configured not to collect personal data by default and to redact identified sensitive values (see Section 4). On our public marketing pages (not inside the QRC application), Google Ads conversion measurement also records that a visitor who arrived from one of our ads opened the demo or created an account, as described in Section 9.

When you arrive at our public marketing pages from an ad or a tagged link, we record which source, campaign and page brought you, and the website that referred you. If you later create an account, we keep that record with the account. The record holds campaign details only and does not include advertising click identifiers.

g. Carrier load-acceptance data. When a motor carrier opens a load-acceptance link and confirms a rate confirmation, we record the name and telephone number of the person accepting, the assigned driver’s name and telephone number, the truck and trailer numbers where the brokerage requires them, and the IP address the acceptance was submitted from. This information is collected to record and evidence the carrier’s acceptance of that load, and it is made available to the brokerage that issued the link.

h. Billing and subscription data. Your subscription status, billing period dates, and the Stripe customer and subscription reference identifiers we use to manage your subscription. We do not store payment card numbers; card details are entered on and processed by Stripe’s hosted pages (see Section 4).

3. How We Use Information

We use the information we collect to: provide, operate, and maintain the Service; generate rate confirmations, bills of lading, invoices, and related documents; sync accounting data with QuickBooks Online when you connect it; automatically extract data from documents you upload; verify motor carriers against FMCSA records; secure the Service, prevent fraud and abuse, and diagnose and fix errors; communicate with you about your account, including transactional emails; to understand which of our own marketing brings customers to QRC; and comply with legal obligations. We do not use your financial data for advertising or marketing, and we do not sell your personal information.

4. How We Share Information — Service Providers

We share information with the following third-party service providers (sub-processors) only as needed to provide the Service. Each processes data on our behalf and is bound by its own terms and security obligations:

  • Intuit (QuickBooks Online) — accounting integration, when you connect QuickBooks (see Section 5). Your use of QuickBooks is also governed by Intuit’s own terms and privacy policy.
  • Stripe, Inc. — payment processing for subscription billing. When you subscribe, we send the account owner’s email address and a brokerage identifier to Stripe. Payment card details are entered on and processed by Stripe-hosted pages and are never stored by QRC; we receive subscription status information back from Stripe.
  • Anthropic, PBC — AI document parsing. Documents you submit to the parsing feature are processed by Anthropic’s commercial API to extract data fields. Anthropic does not use these inputs or outputs to train its models, and under its commercial API terms such data is retained for a limited period (currently up to 30 days), except where retention is required to comply with law or to investigate misuse.
  • Supabase (hosted on Amazon Web Services) — our primary database, authentication, and file storage.
  • Cloudflare — encrypted object storage (R2) used for automated nightly backups of uploaded files and documents and of our database; the database backup is encrypted by us before it is uploaded. Backup data is stored in the United States (Western North America).
  • Vercel — application hosting, content delivery, and cookieless site analytics (Vercel Web Analytics, described in Section 2(f)).
  • GitHub, Inc. (Microsoft) — source-code hosting and the automation that runs our nightly backup jobs. Copies of uploaded files and documents, and a nightly copy of our database, transit GitHub-hosted job runners while a backup is being written to the encrypted object storage described above; the database copy is encrypted on the runner before it is uploaded, and GitHub does not retain that content after the job completes.
  • Resend — delivery of transactional emails (such as document deliveries, invitations, and account notices).
  • Sentry — application error monitoring. Our configuration disables personal-data collection by default and redacts sensitive fields (such as credentials and tokens) from captured error events.
  • FMCSA (QCMobile API) — federal carrier verification using publicly available data; we send only carrier MC/DOT identifiers.
  • Postal-code lookup — when you enter a U.S. ZIP code, we may query a public postal-code lookup service that receives only the ZIP code and no other personal information.

Separately from the service providers above, Google LLC receives advertising-measurement data from our public marketing pages as described in Section 9. Google uses that data under its own privacy policy and is not our processor.

We may also disclose information when required by law, to enforce our agreements, or to protect the rights, safety, and security of QRC, our users, or others. If QRC is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

5. QuickBooks Online Data

If you connect your QuickBooks Online company to the Service, the following applies:

What we access. Using Intuit’s API and the accounting scope you authorize, we read limited reference data needed to sync (such as your company information and matching chart-of-accounts, item, payment-term, customer, and vendor records) and we create accounting records on your behalf — including invoices, bills, customers, vendors, a freight service item, and payment terms. We do not access payroll data, and we do not request payment-processing scopes.

Why we access it. Solely to provide the accounting-sync features you use within the Service — for example, pushing an invoice or a carrier bill into your QuickBooks.

How we protect it. The access and refresh tokens that authorize this connection are encrypted at rest using AES-256-GCM encryption and are accessible only to the systems that perform the sync. Each brokerage’s QuickBooks connection is isolated to that brokerage’s account.

How to disconnect. You may disconnect QuickBooks at any time from Settings → QuickBooks Online. When you disconnect, we delete the stored QuickBooks access and refresh credentials from our systems and clear the QuickBooks customer and vendor mappings stored on your contacts, after which we can no longer access your QuickBooks data. Accounting records already created in your QuickBooks remain in your QuickBooks, and we retain the internal reference identifiers on already-synced invoices and bills that link those past syncs for your historical records. You may also remove QRC’s access from within your Intuit account.

Our use of QuickBooks data is limited to providing the Service to you and complies with Intuit’s API terms and security policies. We do not use QuickBooks data for advertising, marketing, or any purpose unrelated to providing the Service.

6. Data Security

We use industry-standard measures to protect your information, including encryption of data in transit using TLS, encryption of sensitive credentials at rest, tenant isolation enforced at the database level so that each brokerage’s data is segregated from others, and role-based access controls within the Service. Administrative access to our production database requires multi-factor authentication and is logged. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Backups. The QRC Dispatch database is backed up nightly to independent, off-platform storage. These backups are encrypted before they leave our systems using modern public-key cryptography, and the decryption key is never stored alongside the backups or on any of the systems that produce or store them. We verify our backups by performing full decrypt-and-restore tests.

7. Data Retention

We retain your account and operational data for as long as your account is active and as needed to provide the Service. If your subscription is canceled, we retain your brokerage’s data so that you can reactivate the account; you may permanently delete your brokerage at any time from Settings.

When a brokerage account is deleted, its data is first marked for deletion and then permanently removed from our active systems after a 30-day window. Residual copies of deleted content may remain in our encrypted backup systems for up to 30 days after removal from our active systems, after which they are automatically and permanently deleted. Deleting your brokerage also immediately cancels any active subscription, and fees for the remaining billing period are not refunded. Encrypted QuickBooks credentials stored for a deleted account are permanently removed within that same 30-day window; you can also remove them immediately at any time by disconnecting QuickBooks in Settings.

For billing integrity we retain Stripe reference identifiers and webhook event records — limited to each event’s identifier, type, and timestamp, with no payment card data or payment payloads. Documents submitted to our AI parsing provider are subject to that provider’s limited retention period described in Section 4. We may retain limited information longer where required to comply with legal obligations, resolve disputes, or enforce our agreements.

8. Your Rights and Choices

You may access, update, or correct your account information within the Service, disconnect QuickBooks at any time, request a copy of the data you have provided to the Service, and request deletion of your account and associated data. Depending on your location, you may have additional rights under applicable law, such as the California Consumer Privacy Act. To exercise any of these rights, contact us at admin@qrcdispatch.com or support@qrcdispatch.com. Because we process most data on behalf of our business customers, requests from a customer’s end users may be directed to the customer organization.

9. Cookies

Inside the QRC application, we use only cookies that are strictly necessary for authentication and the operation of the Service; we do not use advertising or analytics tracking cookies there. On our public marketing pages we additionally use the Google Ads measurement cookies described under “Advertising measurement” below. On our public marketing pages we also set a QRC cookie that remembers which ad or link brought you to us, for up to 90 days. It holds the campaign details described in Section 2, never your name, your email address or an advertising click identifier. We read it only on our sign-up page, and we do not use it inside the QRC application. The site analytics described in Section 2(f) are cookieless: they set no cookie, and they do not follow you to other websites.

Advertising measurement. On our public marketing pages (not inside the QRC application), we load the Google tag for Google Ads conversion tracking. It sets cookies in your browser and tells Google when someone who clicked one of our Google ads opens the demo or creates an account, so we can see which ads work. It does not receive your name, email address, or anything you enter in QRC. You can opt out of ad personalization at https://adssettings.google.com, or block cookies in your browser. Google’s privacy policy: https://policies.google.com/privacy.

10. Data Location

The Service is operated in the United States, and information we collect is processed and stored primarily in the United States.

11. Children’s Privacy

The Service is intended for business use and is not directed to children under 18. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

13. Contact Us

QRC Dispatch Inc. — Email: admin@qrcdispatch.com or support@qrcdispatch.com

Back to sign in