Privacy Policy
Effective 21 August 2026
DwellWatch reads a trucking carrier's own ELD telemetry to find detention time their customers owe them for, and produces the evidence to bill it. This policy explains what that means for the data involved.
In summary: we retain vehicle location history because it is the evidence a detention claim depends on; we collect as little other information as the service permits; we do not sell any of it; and we are never a party to a carrier's claim nor do we handle their funds.
Who is responsible for your data
DwellWatch is operated by Neolite Digital Design & Development Inc., a company incorporated in Alberta, Canada. We are the organisation accountable for the personal information described here, including information we transfer to the service providers listed below.
Because we are Canadian, our handling of personal information is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Alberta, by the Personal Information Protection Act (PIPA). These protections apply to the personal information we hold regardless of where you or your fleet are located.
Questions, access requests and complaints should be directed to [email protected].
What we collect
Account information
Your name, email address and a hashed password when you create an account, plus the name of the carrier you belong to and your role within it. If you sign in with Google or Microsoft we receive your name and email from them; we never receive your password.
ELD connection credentials
The credentials you give us for your ELD provider, so we can read your fleet's telemetry. These are encrypted before they are stored and are used for nothing other than reading your own data.
Vehicle telemetry
From your ELD provider we read, for the vehicles you connect: the vehicle's identifier and name, its GPS position, speed and heading, and the time of each reading. We sample roughly once every five minutes rather than taking the raw feed.
Facilities you define, and the brokers you bill
The customer sites and your own yards that you draw or confirm, and the brokers you bill, including the accounts-payable name and email address you enter for each of them.
Billing
Our payment processor handles your card details; we never see or store them. We keep the subscription status and truck count needed to bill you correctly.
Technical records
When you sign in we record the IP address and browser your session came from, so a session can be recognised and, if necessary, ended. We keep a record of every invoice decision — who approved or discarded a claim, and when — because a claim you have sent to a broker has to be defensible.
What we do not collect
ELD interfaces make available considerably more data than this service requires. We request only what is necessary, and where a provider transmits additional fields regardless, those fields are discarded before any record is written to our database.
- Driver identity. No driver names, driver IDs, driver groups, or any identifier linking a vehicle's movements to a named person. Detention is a fact about a truck and a gate, not about a person, so we have no use for it.
- Hours-of-service and duty status. We never read a driver's logs.
- Driver performance and behavior data — harsh braking, speeding events, coaching scores, safety ratings.
- Camera and dashcam footage, of any kind, at any time.
- Fuel, maintenance and inspection records (DVIR).
These exclusions are a design constraint of the service: the information listed above is not required to determine detention and is therefore not collected.
Visitors to this website
This page and the rest of dwellwatch.app use Cloudflare Web Analytics to count page views and see which sites link to us. It is the only third-party script on this website.
It sets no cookies, and stores nothing on your device — no localStorage, no sessionStorage, no IndexedDB, and no identifier of any kind. It does not follow you between visits, between pages, or to any other website, and it cannot connect your visit to an account if you later create one.
What we see is a count: how many people read a page, and which site or search referred them. That is why this website has no cookie banner — there is nothing stored to ask you about.
Why we hold it, and what we do not do with it
Telemetry is used to detect when one of your vehicles was held at a customer facility past the free time in your contract, to build the evidence packet supporting that claim, and to show you the result. Account data is used to sign you in and to contact you about your account. Billing data is used to charge you. We do not use personal information for any purpose beyond these without asking you first.
- We do not sell your data, to anyone, for any purpose.
- We do not share one carrier's data with another carrier, and one carrier's account can never read another's.
- We do combine data across carriers into aggregate statistics — for example, what share of detention claims get paid — and use them to price the service and to describe how well it works. These are combined figures only: they are computed so that no individual carrier can be identified from them, and we do not publish a figure drawn from so few carriers that any one of them could be worked out from it.
- We do not use your telemetry to train models, and we do not use it for advertising.
- We are not a collections agency. Invoices are yours, sent under your own billing identity, and brokers pay you directly. We never touch the money and are not a party to any claim.
Sending invoices from your own email account
DwellWatch can send approved detention invoices and notices from your own company email address, so that a broker receives them from you rather than from a third party. There are three ways to do it: connecting a Google mailbox, connecting a Microsoft mailbox, or authorising your own domain. How your information is handled depends on which you choose.
You are not obliged to choose any of them. By default we send from our own billing subdomain under your carrier's name, which involves no access to your email system at all.
Connecting a Google or Microsoft account
When you connect a Google (Gmail) or Microsoft (Outlook or Microsoft 365) account, you grant DwellWatch permission to send mail on your behalf. The permissions we request are gmail.send for Google and delegated Mail.Send for Microsoft, together with sign-in permissions (openid and email) that tell us which address you connected, and offline access so the connection keeps working without asking you to sign in again every hour.
These are send-only permissions. They do not grant the ability to read a mailbox, and we do not have that ability:
- We use this access solely to deliver the invoices and detention notices that you have approved, or that you have configured us to send on your behalf.
- We do not read, scan, view, or store your inbox, your personal messages, your contacts, your calendar, or your email history.
- We never see or store your account password. Authentication happens with Google or Microsoft directly, and we receive only a token.
- That token is encrypted at rest with AES-256-GCM, under the same protection as every other credential you entrust to us.
Google API Services User Data Policy
DwellWatch's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used to serve advertisements, and is never used to train artificial intelligence or machine learning models.
Sending from your own domain instead
Rather than connecting a mailbox, you can authorise us to send from your domain by adding DNS records that we generate for you. Those records are published in your own DNS, and verification is performed through Amazon SES. This option involves no mailbox access of any kind: we are never given a password, a mail server, or a credential to your email system, because none is required to send this way.
Disconnecting
You can disconnect an email integration at any time in your DwellWatch settings, which deletes the stored token. You can also revoke our access directly from your Google or Microsoft account security settings, which has the same effect. Either way, invoices already sent are unaffected — they left from your account and are yours.
Consent, and how to withdraw it
We collect and use personal information with your knowledge and consent. Creating an account and connecting your ELD constitutes that consent, and this policy is provided so that the consent is informed.
You can withdraw it at any time, at three different scopes:
- Remove a vehicle from monitoring, and we stop collecting telemetry for that vehicle.
- Disconnect your ELD, and we stop collecting anything from your provider immediately.
- Disconnect your email account, and the stored token is deleted — we can no longer send anything on your behalf.
- Close your account by writing to [email protected].
Withdrawing consent stops future collection. It does not by itself erase evidence behind an invoice you have already sent — see How long we keep it, which explains why, and what you can ask for instead.
Personal information about people who are not our customers
When you set up a customer to bill, you provide that organisation's accounts-payable name and email address, and we keep a record of the notices and invoices sent to them and whether delivery succeeded. Those are real people who are not our customers and who never signed up for anything.
We use that information for one thing — delivering the claims you approve — and for nothing else. We do not market to it, enrich it, or share it between carriers: two carriers billing the same broker have two separate records that never meet.
You are responsible for entering business contact details you are entitled to use for this purpose. If someone at a broker asks us to tell them what we hold about them, we will, and we will tell them which carrier entered it.
Who else sees it, and where it is stored
We engage the service providers listed below to operate DwellWatch. Each receives only the information necessary to perform its function, none is permitted to use that information for its own purposes, and we remain accountable for personal information transferred to them.
| Provider | What it does | Where |
|---|---|---|
| Neon | Managed Postgres — the database holding all carrier data | Ohio, United States |
| Netlify | Application hosting | Ohio, United States |
| Google Cloud | Scheduled jobs that read telemetry and build evidence packets | Ohio and Virginia, United States |
| Amazon Web Services (SES) | Email delivery — invoices to brokers you choose, and account mail to you | Oregon, United States |
| Stripe | Subscription billing and card details, which never reach us | United States |
Your ELD provider is not on this list because it is not ours: it is the source of the telemetry, connected by you, under your agreement with them.
We may also disclose data where the law requires it. If we are ever compelled to, we will tell you unless we are legally prohibited from doing so.
How long we keep it
We keep your account and carrier records for as long as your account exists. We keep vehicle telemetry for as long as it may be needed to support a claim, and we keep evidence packets and the telemetry behind an invoice for as long as that invoice stands — deleting the evidence behind a claim you have already made would leave you unable to defend it.
If you evaluate DwellWatch and do not subscribe, we delete that telemetry. A weekly process removes position records more than 90 days old, once no new telemetry has arrived from the account for 30 days. Telemetry supporting an invoice is excluded from that process, for the reason given above.
For accounts that do subscribe we state no fixed period, because the records exist to support claims whose useful life we cannot predict. We do not delete a former customer's history on a timer either: an account that lapses may be reopened. If you close your account, contact us and we will delete your data, except where we are required to retain records for tax or legal purposes.
Keeping it accurate
Most of the information we hold is measured rather than entered, so inaccuracies typically arise from a facility boundary drawn incorrectly or a customer address entered in error. You may correct such information within the application, and corrections take effect on subsequent claims immediately. If information you cannot access is inaccurate, write to [email protected] and we will fix it.
Security
Your ELD credentials are encrypted before storage. Access to your carrier's data is restricted to members of your carrier, and actions that bill a broker are restricted further by role. Every invoice decision is recorded with who made it and when. Our security page describes this in more detail, including what we have not built yet.
If a breach of our security creates a real risk of significant harm to anyone whose information we hold, we will report it to the Office of the Privacy Commissioner of Canada and notify the people affected, as PIPEDA requires — promptly, and without waiting until we have a complete story.
No system can be guaranteed secure. If you believe you have found a vulnerability, write to [email protected] and we will respond.
Your rights, and how to complain
Under PIPEDA and Alberta's PIPA you can ask us for access to the personal information we hold about you, ask how it has been used and who it has been disclosed to, and ask us to correct it if it is wrong. Write to [email protected]. We will respond within 30 days, and if we need longer we will tell you why before that deadline rather than after it.
We do not charge for this, and exercising any of these rights will never change the service you receive.
There are narrow cases where the law does not let us hand something over — most often where doing so would reveal personal information about someone else. If we refuse any part of a request we will tell you which part, and why.
If you are not satisfied with how we handled it, please raise it with us first so that we can address it. You may also complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca), or, for matters under Alberta's PIPA, to the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca). Neither route costs you anything.
If you are based outside Canada, local law may give you further rights. We apply the standards on this page to everyone rather than sorting customers by where they live.
Changes, and contacting us
If we change this policy in a way that materially affects what we do with your data, we will tell account holders by email rather than quietly updating the date at the top.
Neolite Digital Design & Development Inc. is based in Alberta, Canada. Questions about this policy, and anything else on this page, go to [email protected].