Privacy Policy
Effective 26 July 2026
KARG is a B2B SaaS used by road-freight carriers to automate dispatching, tracking, driver communication and customs declarations. This Privacy Policy explains what personal data we process, why, on what legal basis, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who we are
The data controller for this website (karg.to) and for personal data processed about prospects, customer administrators and visitors is:
- Legal name: DANS ONLINE SRL
- Commercial Registry No.: J16/737/2021
- Tax ID (CUI): 43898240
- Registered address: Str. Independenței, Bl. 6F, Ap. 9, Craiova, Dolj, Romania 200333
- Email: privacy@karg.to
For personal data processed inside a customer's KARG workspace (drivers, dispatchers, freight-exchange contacts, end customers), the carrier that owns the workspace is the data controller and KARG acts as a data processor under a Data Processing Agreement.
2. What we collect
Account & billing
- Name, work email, phone, role, company name, VAT/CUI.
- Authentication identifiers (Supabase user ID, hashed password, sessions).
- Billing details and invoice history.
Operational data inside the workspace
- Driver records: name, mobile phone, Telegram handle, language.
- Vehicle records: registration plate, VIN, fuel type, telematics IDs.
- Loads, routes, GPS positions, ETAs, proof-of-delivery files, invoices.
- Customs documents (CMR, T1, road documents) including PDF attachments and structured data extracted from them.
Integrations
- Credentials you grant so the platform can act on your behalf, in the form each provider requires: OAuth client credentials for TimoCom, and the username and password of your FomCo API account (FomCo uses HTTP Basic authentication, not OAuth).
- The API key and tenant token of your NextUp account, where you select NextUp as your telematics provider.
- HMRC tokens for UK border declarations (encrypted at rest).
- The credentials of your French customs (DGDDI) account, where you use the ELO envelope (encrypted at rest).
- Telegram chat IDs for driver notifications.
Usage & technical
- Server-side request logs (IP, user-agent, timestamp, route).
- Audit logs of sensitive actions (login, role change, data export).
- Crash and performance traces collected by our error monitor.
3. Why we process it (purposes & legal bases)
| Purpose | Legal basis |
|---|---|
| Provide the service to the carrier (dispatching, tracking, notifications, customs) | Performance of contract — Art. 6(1)(b) GDPR |
| Account administration, billing, support | Performance of contract — Art. 6(1)(b) |
| Security monitoring, fraud and abuse prevention, audit logs | Legitimate interests — Art. 6(1)(f) |
| Statutory accounting, tax and customs record-keeping | Legal obligation — Art. 6(1)(c) |
| Product improvement using aggregated, non-identifying metrics | Legitimate interests — Art. 6(1)(f) |
| Marketing communications to existing customers (service updates) | Legitimate interests — Art. 6(1)(f), with opt-out |
We do not sell personal data and we do not use it to train third-party AI models.
4. Sub-processors
We rely on the providers listed below to operate KARG. The full register, with the exact categories of data each one receives, is at karg.to/sub-processors and is updated when we add or replace a provider.
- Supabase — Primary PostgreSQL database, authentication, file storage (EU (Frankfurt)).
- Vercel — Frontend and API hosting, edge network, image optimisation (EU — set in the Vercel project settings; not pinned in this repository (`vercel.json` declares no `regions`)).
- Upstash — Redis cache and QStash scheduled jobs (matching cycle) (EU (Frankfurt / Ireland)).
- Sentry — Application error and performance monitoring (EU).
- Brevo — Transactional email: the invitation that creates every new user account, and the authentication emails Supabase sends on our behalf (invitation and password reset) — Brevo is the SMTP provider behind them (EU (France)).
- OpenRouteService — Routing, distance and toll estimation, and place-name lookup for fleet positions (EU (Germany, HeiGIT / Heidelberg University)).
- Telegram (Bot API) — Driver and dispatcher notifications; and KARG's internal operations channel: admin events, error alerts, automatic delivery of loading-list PDFs (Outside the EEA — country not established. Telegram's Bot API is a single public endpoint with no region to choose, and we will not name a jurisdiction we cannot evidence. No Chapter V transfer safeguard (Standard Contractual Clauses or equivalent) is recorded for this transfer. This is an open point we are working on, stated rather than omitted.).
- Twilio — WhatsApp / SMS channel for driver messages — built, but not switched on: production runs on Telegram (United States (EU SCC in place)).
- Google Gemini API — Structured extraction from PDF road documents (CMR, T1, invoices) (Google Cloud, EU SCC in place).
- FomCo — Telematics and freight-exchange access (only if connected) (Romania).
- TimoCom — European freight and tender exchange (only if connected) (Germany / EU).
- NextUp Telematics — Fleet tracking (only if selected as your telematics provider — the choice is offered in Settings → Integrations) (Operated by NextUp — the region follows your NextUp account).
- HMRC (UK Government) — UK customs declarations and notifications (where the carrier opts in) (United Kingdom).
- DGDDI — French Customs (douane.gouv.fr) — Enveloppe Logistique Obligatoire (ELO) for Channel crossings — live, for workspaces with the French border feature enabled (France).
- Google Maps — Opening a stop address or a truck position on a map — a link somebody clicks, never an automatic transfer (Google (United States / global)).
- WhatsApp (Meta) — “Send to driver” on a route opens WhatsApp with the message pre-filled — a direct link to Meta, not the Twilio channel above, and the one actually in use today (Meta Platforms Ireland / United States).
Inputs sent to our AI extraction provider are not used to train that provider's models, per the terms we operate under.
5. International transfers
Our primary processing region is the European Union. Where data does leave the EEA, these are the cases:
- Standard Contractual Clauses. Google, as our AI extraction provider; Twilio, if the WhatsApp/SMS channel is ever switched on; and Meta, when a dispatcher opens a WhatsApp link. We rely on the SCC approved by the European Commission, supplemented by the technical and organisational measures described in our Security page.
- Adequacy decision. The United Kingdom, when a carrier files UK customs declarations with HMRC. No SCC is required for this transfer.
- Open point, stated rather than omitted.Telegram, which carries the driver and dispatcher notifications and is the messaging channel running in production today. Telegram's Bot API is a single public endpoint with no EU region to select, and we cannot currently evidence either the jurisdiction of the operating entity or a Chapter V safeguard for this transfer. We are working to resolve it. In the meantime the register at karg.to/sub-processors sets out exactly what these messages contain, so the exposure can be assessed rather than assumed.
Two situations sit outside those three. A link somebody chooses to open (a stop address on Google Maps) transfers only what that link contains, at the moment it is clicked. And a provider you connect yourself — a telematics account such as NextUp — processes in whichever region your own account with them sits, which is a choice you make, not us.
6. Retention
- Account & workspace data: for the duration of your subscription, plus 30 days after termination during which the workspace can be reactivated, after which it is deleted within 90 days.
- Invoices and accounting records: 10 years, as required by Romanian tax law.
- Customs declarations: 4 years from acceptance, as required by EU customs law (UCC).
- Server access and audit logs: 12 months.
- Backups: rolling, deleted within 35 days.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data (subject to retention obligations above).
- Restrict or object to processing based on legitimate interests.
- Data portability for data you provided to us.
- Withdraw consent at any time, where consent is the basis.
- Lodge a complaint with the Romanian supervisory authority (ANSPDCP, dataprotection.ro) or with the supervisory authority in your country of residence.
If you are a driver or end-customer of one of our carrier customers, please direct your request first to that carrier. KARG will assist them in fulfilling it.
To exercise any right against KARG directly, write to privacy@karg.to. We respond within 30 days.
8. Security
We apply the technical and organisational measures described in our Security & Trust page, including TLS in transit, encryption at rest, multi-tenant isolation enforced both at the application layer and via PostgreSQL Row-Level Security, encrypted storage of integration credentials, audit logging and tested backups.
9. Cookies
The marketing site uses only strictly necessary cookies (session, CSRF). The product (the authenticated app) uses cookies needed to keep you signed in and to operate the dashboard. We do not use third-party advertising or cross-site tracking cookies.
10. Changes
We will post any material change to this Policy at this URL and notify customer administrators by email at least 30 days before it takes effect.
11. Contact
Privacy and data protection: privacy@karg.to
Security disclosures: security@karg.to
General: hello@karg.to