The website uses first-party analytics to understand page visits, freight-quote activity, sign-in, order and service conversion. Random visitor/session identifiers are used; no browser fingerprinting is performed and raw IP addresses are not stored in AnalyticsEvent. Public tracking analytics never records a tracking number. Front-end analytics stops when Global Privacy Control (GPC), Do Not Track (DNT), or the local analytics opt-out is enabled. Coarse location is recorded only when supplied by a trusted reverse proxy. Security and audit logs do not store raw session tokens, passwords or authentication secrets. New security-audit IP values are pseudonymized with a server-side key, while user-agent and error text are sanitized for obvious sensitive values. Authentication uses HttpOnly cookies with Secure and SameSite enabled in production. The company must still approve and publish the complete policy through CMS before production launch.
LEGAL
