Privacy Policy
Granite Logistics moves parcels, so we hold delivery addresses. This page says exactly what we collect, why we need it, who else sees it, and how to get it back or have it removed.
Who we are
Granite Logistics LLC, Dayton, Ohio. For anything about your data, email ken@usegl.com.
What we collect
When you create an account: your email address and the name you give us. Your password is never stored: we keep only a salted scrypt hash of it, which cannot be reversed.
When you place an order: the recipient's name, street address, city, state, ZIP and phone number, plus what the item is, its declared value and its weight. We need the address to deliver the parcel and the phone number so a driver can reach the recipient.
As the parcel moves: timestamps for each step (collected, in transit, out for delivery, delivered), the carrier and tracking number, and any condition photos taken by our staff at handover. Photos exist so that damage disputes can be settled with evidence.
If you turn on delivery alerts: a push subscription for that device, which is an address issued by your browser's push service plus two encryption keys. It is not tied to anything else about you, and you can turn it off from your Account tab at any time.
Security records: a count of recent failed sign-in attempts for your email address, so that someone cannot work through a password list against your account. These expire on their own.
What we do not do
- We do not sell your data, and we do not share it for anyone else's advertising.
- We do not use advertising or analytics cookies. The app stores data on your device only to keep you signed in and to let it work offline.
- We do not send you email at all. Delivery notifications, if you switch them on, are browser push only, and carry the tracking number and status only.
- Our public tracking page shows status, dates, carrier and destination city only. It never shows the recipient's name, street address, phone number, contents or photos.
Who processes it for us
We keep the number of third parties as small as we can. Each one only receives what it needs:
- Netlify (United States) hosts the site and stores the data.
- Your browser's push service (Google, Mozilla or Apple, depending on your browser) relays delivery alerts if you switch them on. It receives the tracking number and status, never your address.
- The carrier handling your parcel (for example UPS or FedEx) receives what it needs to deliver it, which includes the delivery address.
How long we keep it
Order records are kept as long as we need them for operational and tax purposes. Condition photos are kept with the order they belong to. Sign-in security counters expire within minutes. If you close your account we act immediately, as described next.
Your data, and closing your account
Both of these are in the app under Account → Your data, and neither needs you to email anyone:
- Download my data gives you a JSON file containing everything we hold that is linked to your account, including every order and address.
- Close my account deletes your sign-in details, your notification devices and your security counters, and removes any order we have not collected yet.
One honest limit: if a parcel of yours is already on its way, we cannot close the account until it is delivered, because the driver needs the address to complete the delivery. The app tells you which shipment is holding it up.
For shipments already delivered, we keep the record but remove you from it: your name, street address, phone number, email link and any photos are deleted, leaving the tracking number, dates and destination city as an operational record.
Children
This service is for businesses and adults arranging shipments. It is not intended for children.
Changes
If this policy changes in a way that affects you, we will update the date at the top of this page. We cannot email you about it, because we do not send email.
This policy describes how the software actually behaves. It is not legal advice, and it has not been reviewed by a lawyer. If you take on customers in California, the EU or the UK, have someone qualified check it against the CCPA, GDPR or UK GDPR before you rely on it.