Legal

Privacy Policy

Last Updated: August 4, 2026

Your Employer's Records

We process driver records on behalf of the employer that entered them

Encrypted by Default

TLS in transit, AES-256 at rest, field-level encryption for Social Security numbers

Never Sold

We do not sell personal information or use it for advertising

How Avowant Handles Personal Information

This Privacy Policy describes how TraxSys LLC ("Avowant", "we", "us") collects, uses, and protects personal information in connection with the avowant.com DOT compliance management platform. It is incorporated into our End User License Agreement.

1. Two Roles, Two Kinds of Data

1.1 Customer account data (we decide how it's used): When a fleet, consultant, or other customer signs up, we collect name, work email, phone, company details, and billing information, and we log product usage needed to operate and secure the service.

1.2 Compliance records (your employer decides how they're used): The bulk of the data in Avowant — driver qualification files, licenses, medical certifications, drug and alcohol testing records, Social Security numbers, roadside inspection and accident records — is entered and controlled by the motor carrier or compliance administrator that employs or evaluates the driver. For these records we act as a service provider processing data on the customer's behalf and on their instructions. These are employment records maintained under DOT regulations; they are not medical records governed by HIPAA (45 CFR 160.103 excludes employment records from protected health information).

2. Information We Collect

  • Account and contact information you provide at signup
  • Compliance records entered by customers or submitted by drivers through intake forms (applications, license photos, medical cards, authorizations, e-signatures with date, IP address, and device information for attribution)
  • Billing information, processed by Stripe (we do not store full card numbers)
  • Technical data required to run and secure the service: sign-in events, access logs, and essential cookies for authentication and session security

We do not use third-party advertising cookies and we do not sell or share personal information for cross-context behavioral advertising.

3. How We Use Information

  • Providing, maintaining, and securing the platform
  • Generating the compliance artifacts our customers request (qualification files, audit reports, corrective action workflows, renewal notifications)
  • Sending transactional email and notifications tied to compliance workflows
  • Billing, support, and service communications
  • Complying with legal obligations, including DOT record-keeping requirements

Where document text is extracted automatically (for example, reading a license photo to pre-fill a form), the extraction serves only that workflow; extracted data is reviewed by your organization's staff before it becomes part of the record.

4. When We Disclose Information

We disclose personal information only:

  • To subprocessors that host and operate the service under contractual confidentiality obligations (cloud hosting, database, authentication, payment, and email delivery providers)
  • At the direction of the customer that controls the record — for example, furnishing a driver qualification packet to an auditor, insurer, or freight broker the customer chooses
  • When required by law, regulation, subpoena, or DOT/FMCSA audit authority
  • In connection with a merger, acquisition, or sale of assets, with notice to affected customers

5. Security

We protect personal information with encryption in transit (TLS 1.3) and at rest (AES-256), field-level encryption with masked display and audit-logged reveal for Social Security numbers, role-based access controls, per-user authentication, and audit logging of access to sensitive records. Our safeguards are modeled on the HIPAA Security Rule as a control template and support our customers' obligations under 49 CFR §40.321, 49 CFR §382.401, and the Americans with Disabilities Act's confidential-medical-file requirement (42 U.S.C. §12112(d)(3)(B)).

6. Retention

Compliance records are retained as long as the controlling customer's account directs, consistent with DOT-mandated retention periods (many driver qualification and testing records must be kept for one to five years by regulation). After account cancellation, data is retained for 90 days for reactivation, then permanently deleted unless the customer requests an export or extended compliance retention.

7. Your Rights

7.1 Drivers and other individuals: If your information is in Avowant because a motor carrier or compliance administrator maintains your records, that organization controls the record — direct access, correction, or deletion requests to them, and we will support the request at their direction. DOT regulations give drivers specific rights to review certain records (for example, 49 CFR §391.23 and Part 40 access rights), which your employer administers.

7.2 California residents: The California Consumer Privacy Act (CCPA) grants rights to know, delete, and correct personal information, and to be free from discrimination for exercising those rights. Much of the data we hold falls under CCPA's employment-context provisions and is administered through your employer. To exercise rights that apply to data we control, contact support@avowant.com. We do not sell personal information.

8. Children

The service is a workplace compliance tool for commercial motor vehicle operations and is not directed to anyone under 18.

9. Text Messaging (SMS)

Avowant Driver Texts is our optional SMS program for drivers: compliance reminders, renewal notices, inspection follow-ups, links to forms your company asks you to complete, and replies from your company's safety staff. Each driver opts in individually (on the sign-up page, during onboarding, or by texting START), and consent is never a condition of employment or of using the service. Program terms: /legal/sms-terms.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party except the messaging provider strictly necessary to transmit the message. Message frequency varies. Message and data rates may apply. Reply STOP to cancel, HELP for help.

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be announced via email to customer account contacts at least 30 days before taking effect, and the "Last Updated" date above will change.

11. Contact