Privacy Policy
This Privacy Policy explains what data Keelway ("Keelway," "we," "us") collects from users of keelway.com (the "Site") and the Keelway carrier-email triage application (the "Service"), how we use that data, who we share it with, and what rights you have over it.
Keelway is operated by Keelway, Inc., a Delaware C-corporation with a principal place of business in Atlanta, GA, USA. Questions about this policy should go to hello@keelway.com.
1. What we collect
1a. From visitors to keelway.com
- Standard request data — IP address, user agent, referrer, and pages visited, captured by our hosting provider (Vercel) and our web analytics tools (Google Tag Manager / Google Analytics, Microsoft Clarity).
- Contact-form submissions — name, email address, company, role, and the message you submit through the form on keelway.com/contact. We use Resend to deliver these to our team inbox.
1b. From customers using the Service
- Account data — your name, work email, company name, role, and the TMS your brokerage runs.
- Gmail message data — when you connect your Gmail account via Google OAuth, Keelway accesses messages in the labels you authorize (typically your carrier-reply inbox). We use the Gmail API with the
gmail.readonly,gmail.modify, andgmail.metadatascopes as needed for the features you enable. We never read your Gmail outside of the labels you authorize. - Carrier reply content — the text and attachments of inbound carrier emails we triage on your behalf, including extracted rate, MC/DOT, equipment, origin, destination, and contact metadata.
- FMCSA + carrier-identity data — public FMCSA QCMobile records pulled per carrier to compute the trust score, plus enrichment from third-party carrier- identity providers where you have authorized us to do so (e.g., Highway).
- TMS data — when you connect a TMS (Tai, McLeod, Aljex, Revenova, Turvo, Rose Rocket), Keelway reads load metadata and writes accepted carriers + agreed rates back into the load record. We do not read billing, shipper, or settlement data unless you explicitly enable those features.
- Usage data — actions you take in the Keelway dashboard, including which carrier you accepted / countered / declined per load, which is used to calibrate ranking weights for your brokerage.
2. How we use it
- To provide the Service — extract rates, score trust, rank replies, write back to your TMS, and surface ranked lists in your Keelway dashboard.
- To improve ranking accuracy — your historical accept / counter / decline decisions are used to tune the ranking weights for your brokerage. We do not use one customer's data to train models served to other customers.
- To detect fraud — email-domain checks, FMCSA authority drift, double-brokering signals, and chameleon-carrier flags. Flagged signals are surfaced to you, not to other customers.
- To communicate with you — service notifications (deploy, downtime, security), feature updates, and (only if you opt in) marketing emails.
- To meet legal obligations — comply with applicable law, respond to lawful requests, enforce our Terms.
3. Google API services and Gmail data
Keelway's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only request the OAuth scopes necessary to provide the Service.
- We do not use Gmail data for advertising.
- We do not sell, lease, or transfer Gmail data to any third party for unrelated purposes.
- We do not allow humans to read Gmail data except (a) with your explicit consent, (b) for security investigations, (c) to comply with applicable law, or (d) where data is aggregated and anonymized for internal operations.
- You can revoke Keelway's Gmail access at any time via Google Account Permissions.
4. Subprocessors
Keelway uses the following third-party processors. Each is bound by data-processing terms and is used only as necessary to operate the Service.
- Vercel — application hosting and edge request handling.
- Supabase — managed Postgres database and object storage.
- Anthropic — language-model inference for email parsing and trust-signal extraction. Carrier email content is sent for inference and is not used by Anthropic to train their models per their commercial terms.
- Resend — outbound transactional and contact-form emails.
- Google (Gmail API) — read/modify access to authorized Gmail labels.
- FMCSA (public QCMobile API) — public carrier authority and safety data.
- Google Tag Manager / Analytics — site analytics on keelway.com.
- Microsoft Clarity — site behavior analytics on keelway.com.
- Highway (where you opt in) — supplemental carrier-identity data.
A current subprocessor list is maintained on request — email hello@keelway.com.
5. Data retention
- Carrier reply data — retained while your account is active; purgeable on request within 30 days of a written deletion request. Deleted on account closure unless you ask us to retain it.
- Account + usage data — retained while your account is active. Deleted within 90 days of account closure, except where we are required to retain records to meet legal obligations.
- Contact-form submissions — retained for up to 24 months in our team inbox.
- Backups — retained for up to 30 days beyond active deletion to support disaster recovery.
6. Security
Data is encrypted in transit (TLS) and at rest. Access to customer data inside Keelway is restricted to a small number of authorized engineers and only for support, debugging, and security purposes. We log all access. We will notify affected customers of any confirmed data breach affecting their data without undue delay.
7. Your rights
Depending on where you live, you may have rights to access, correct, port, or delete your personal data, and to object to or restrict certain uses of it. You can exercise any of these by emailing hello@keelway.com. We will respond within 30 days.
California residents have rights under the CCPA / CPRA; European users have rights under the GDPR; UK users have rights under the UK GDPR. Keelway does not sell personal information.
8. Cookies
The Site uses essential cookies for authentication and a small number of analytics cookies set by Google Tag Manager and Microsoft Clarity. You can disable cookies in your browser; doing so will not affect the Service's core functionality.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16.
10. Changes
We may update this Privacy Policy from time to time. The "Last updated" date at the top of the page reflects the most recent change. Material changes will be communicated to active customers by email at least 30 days before they take effect.
11. Contact
Email hello@keelway.com or write to Keelway, Inc., Atlanta, GA, USA. For DPA / data processing addendum requests, mention "DPA" in the subject line.