Privacy policy
Effective: 29 September 2026
Carrier Watchlist runs at carrierwatchlist.com. It emails freight brokers when FMCSA publishes changes to carriers on their watchlist, and publishes pages built from FMCSA's public carrier records. This policy covers what we collect from you and what we do with it.
What we collect
- Your email address, to send your sign-in links, alerts and account messages.
- Your watchlist: the USDOT numbers you ask us to watch, and a record of which alerts we have sent you, so none is sent twice.
- The IP address you signed up from, kept with your subscription as a record of your consent.
- Billing details for the Broker plan are handled by Stripe. We never see or store your card number. We keep the Stripe customer and subscription IDs and the date your current period ends.
- Sign-in links: we keep only a one-way hash of the token in each link. A new link replaces the old one.
Analytics
We count visits with Fathom Analytics, which sets no cookies and collects no personal data, so there is no cookie banner. The site sets one first-party cookie only if you arrive through a partner link: it holds the partner's code for 30 days so the partner is credited if you subscribe.
Carrier information on this site
Carrier pages and the lookup show FMCSA's public records about motor carriers, which are businesses. We leave out phone numbers, email addresses, officer names and street addresses even where FMCSA publishes them. A carrier that wants its record corrected should correct it with FMCSA; our pages follow FMCSA's files. Write to us about anything else on a carrier page.
Who processes your data
- Stripe (payments and the billing portal)
- Mailgun (sending email from carrierwatchlist.com)
- Our hosting providers (Cloudflare for the site, Amazon Web Services for the service that sends alerts)
- Fathom Analytics (cookieless visit counts)
We do not sell or share your personal information
We do not sell your personal information or share it for cross-context behavioral advertising, as those terms are used in the California Consumer Privacy Act as amended by the CPRA. We honor the Global Privacy Control signal as an opt-out request.
How long we keep it
We keep your account while it is active. After you cancel, we keep your email and billing records as long as tax and accounting rules require, and delete your watchlist and alert history on request.
Your rights
You can ask to see, correct, export or delete your personal information by writing to [email protected]. We answer within the time the law where you live requires, and we will not treat you differently for asking.
Children
The service is for businesses and is not directed at children under 13. We do not knowingly collect their information.
Security
Everything travels over HTTPS. Card data stays with Stripe, sign-in tokens are stored only as hashes, and we hold as little personal data as the service needs.
Changes
If we change this policy we update the effective date above, and we email subscribers about material changes.