Effective Date: September 1, 2026
1. Introduction
IFTAEASY, operated by Daystar Financial Services LLC ("we," "us," or "our"), provides a cloud-based and mobile interstate fuel tax management platform, driver GPS tracking portal, Driver Vehicle Inspection Report (DVIR) compliance suite, and automated document analysis system designed to help motor carriers maintain compliance with Federal Motor Carrier Safety Administration (FMCSA) regulations and International Fuel Tax Agreement (IFTA) requirements.
This Privacy Policy explains how we collect, use, disclose, and safeguard personal and operational information when you access our website, Progressive Web Application (PWA), driver portals, and cloud compliance services (collectively, the "Services").
By accessing or using our Services, you acknowledge that you have read, understood, and agree to the data collection and processing practices described in this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our Services.
2. Information We Collect
2.1 Information Provided by Motor Carriers (Account Administrators)
When motor carriers, fleet managers, or owner-operators create an account and configure the Services, we collect:
- Carrier Profile Details: Legal company name, DBA, USDOT Number, MC/FF Number, Base Jurisdiction (state or province), IFTA Account/License Number, physical address, and mailing address.
- Administrator Information: Full name, business email address, phone number, and encrypted authentication credentials.
- Fleet Asset Inventory: Vehicle Unit Numbers, Vehicle Identification Numbers (VINs), make, model, model year, gross vehicle weight (GVW), and designated primary fuel type (Diesel, Gasoline, Propane, LNG, CNG, Electric).
- Payment and Billing Information: Payment method tokens, subscription tier selections, transaction histories, and billing contact details processed securely through our third-party payment processor (Stripe).
- Support & Audit Communications: Support tickets, configuration preferences, and email correspondence with our compliance support team.
2.2 Driver Information Collected on Behalf of Motor Carriers
On behalf of motor carriers utilizing our Driver Portal and fleet tracking tools, we collect and process:
- Driver Identity & Contact Details: Full legal name, mobile phone number, email address, assigned truck unit number, and driver PIN/password.
- Commercial Credentials & Qualification Data (DQF): Commercial Driver’s License (CDL) number, state/province of issuance, CDL expiration date, medical examiner certificate expiration, and qualification status.
- Safety & Inspection Logs (DVIR): Pre-trip and post-trip vehicle inspection checklists (brakes, tires, steering, coupling, lighting, emergency equipment), reported defect descriptions, mechanic sign-offs, and driver digital signatures pursuant to 49 CFR Part 396.
2.3 SMS, Dispatch, and Mobile Communications Data
When drivers or fleet managers utilize our SMS-based dispatch, trip logging, or two-factor verification features, we collect:
- Mobile phone numbers of enrolled drivers and dispatchers.
- SMS message content, including trip start/stop commands, fuel purchase logs, and automated notification responses.
- Delivery timestamps, carrier routing metadata, and message delivery status.
- Records of express consent, TCPA opt-in confirmations, and opt-out/STOP requests.
- IP addresses and device timestamps associated with digital enrollment actions.
2.4 Automatically Collected Telemetry & Device Data
When you access the Services via web browsers or mobile devices, we automatically record:
- Device & Browser Diagnostics: Device model, operating system version, browser type, screen resolution, preferred language, and app version.
- Network & Security Information: Internet Protocol (IP) address, Internet Service Provider (ISP), approximate geographic region, referrers, and security session tokens.
- Interaction Logs: Pages viewed, calculation matrices generated, PDF export triggers, error logs, and session durations.
2.5 Real-Time Geolocation & Route Telemetry (Driver Portal)
When a driver initiates an active trip in the IFTAEASY Driver Portal, we collect high-precision location data:
Types of Location Data Collected:
- GPS coordinates (latitude, longitude, altitude, and horizontal accuracy).
- Heading, vehicle travel speed, and movement status (stationary vs. in motion).
- Geofenced state and provincial jurisdiction border crossing timestamps.
- Odometer starting and ending readings.
When Location Data Is Collected:
- In the foreground and background while a trip is marked as "Active" or "In Transit".
- At discrete waypoints during interstate border crossings to allocate mileage per jurisdiction.
- At the time of logging a fuel purchase or taking a rest break.
How Location Data Is Used:
- To automatically compute quarterly miles traveled per IFTA member jurisdiction (48 US states and 10 Canadian provinces).
- To reconcile driver odometer spans against GPS-calculated route distances.
- To display interactive route breadcrumb maps for carrier compliance audits.
- To verify that fuel purchases align geographically with logged vehicle routes.
Location Data Protection:
- Location data is strictly shared with the driver's employing motor carrier administrator.
- We never sell, rent, or monetize driver GPS location data to third-party data brokers or advertisers.
2.6 Fuel Receipts, ELD Summaries, and Document Scans
When users upload fuel receipts, fleet card statements (e.g., Comdata, EFS, WEX), or Electronic Logging Device (ELD) summary PDFs:
- Uploaded Images & Files: Scanned images, camera snapshots, and PDF documents.
- Extracted Purchase Metadata: Vendor/truck stop name, purchase date and time, city, state/province, fuel type, volume (gallons/liters), price per unit, total amount paid, and tax-paid status.
- OCR & AI Processing Records: Optical character recognition text and machine-readable structured records generated during document parsing.
3. How We Use Your Information
We use the collected information for the following specific operational, regulatory, and business purposes:
- IFTA Tax Computation: To accurately calculate gross miles, taxable miles, exempt miles, tax-paid fuel gallons, fleet average MPG, and net tax liabilities across all 58 IFTA member jurisdictions.
- Automated Return Generation: To compile official state tax return schedules, audit worksheets, and downloadable PDF compliance packets.
- Safety & DVIR Compliance: To facilitate pre-trip/post-trip safety inspections, notify fleet maintenance of equipment defects, and archive records in accordance with FMCSA 49 CFR Part 396.
- AI & OCR Document Processing: To parse scanned fuel receipts, invoices, and ELD mileage sheets into structured database entries.
- Carrier-Driver Dispatch Communication: To deliver trip dispatch notifications, system alerts, password resets, and compliance reminders via email and SMS.
- Billing & Account Management: To process subscription payments, maintain invoice records, and prevent payment fraud.
- Audit Defense & Recordkeeping: To preserve Individual Vehicle Distance Records (IVDRs) and fuel receipts for the mandatory 4-year IFTA statutory audit window.
- Platform Security & Fraud Prevention: To detect unauthorized access, prevent account takeover, monitor API abuse, and verify system integrity.
- Legal & Regulatory Compliance: To comply with court orders, tax authority summonses, and DOT statutory obligations.
4. How We Share Your Information
4.1 Trusted Service Providers and Infrastructure Sub-processors
We share information with vetted third-party vendors who provide foundational infrastructure for our Services:
- Supabase / PostgreSQL: Secure cloud database hosting, multi-tenant isolation, row-level security (RLS), and database backups.
- Payment Processors (Stripe): Tokenized payment processing and subscription billing. We do not store raw credit card numbers on our servers.
- Cloud Storage & Hosting (AWS / Google Cloud): Encrypted storage of receipt images, DVIR inspection photos, and PDF returns.
- Mapping & Geocoding APIs (Google Maps Platform / OpenStreetMap): Geolocation mapping, reverse-geocoding (converting GPS coordinates to city/state), and route distance calculation.
- Artificial Intelligence & OCR Processors (Google Gemini API): Automated optical parsing of fuel receipt images and ELD logs. Customer Data sent to these APIs is processed via zero-data-retention / enterprise confidentiality agreements and is not used to train public machine learning models.
- SMS: Transmission of SMS verification codes, trip tracking commands, and dispatch notifications.
- Transactional Email: Delivery of quarterly tax reports, password reset links, and compliance alerts.
- Analytics & Performance Monitoring (Google Analytics 4): Aggregated website interaction data and diagnostic crash monitoring.
4.2 Mobile Phone Number & SMS Opt-In Privacy
We do not sell, rent, or share mobile phone numbers, SMS consent records, or text messaging originator opt-in data with third parties or affiliates for marketing or promotional purposes. Mobile contact details are shared strictly to deliver operational and authentication messages.
4.3 Motor Carriers as Data Controllers
For driver accounts, the motor carrier is the legal Data Controller, and IFTAEASY acts as the Data Processor. Fleet administrators have full administrative access to view, download, correct, and audit their drivers' trip logs, GPS tracks, DVIR reports, and fuel receipts.
4.4 Regulatory, Audit, and Legal Disclosures
We may disclose information if required to do so by law or in good faith belief that such action is necessary to:
- Comply with a valid subpoena, court order, or government audit request.
- Support motor carriers during formal state or provincial IFTA audit examinations upon the carrier's authorized request.
- Enforce our Terms of Service, defend against legal claims, or protect the rights, property, or safety of Daystar Financial Services LLC & IFTAEASY, our users, or the public.
5. Data Retention & Archiving
We retain Customer Data in accordance with strict transportation and tax recordkeeping mandates:
- IFTA Tax Records & IVDRs: Retained for a minimum of four (4) years from the date the quarterly return was due or filed, satisfying mandatory IFTA audit retention standards.
- DVIR Safety Inspection Reports: Retained for a minimum of three (3) months to twelve (12) months pursuant to FMCSA 49 CFR § 396.11 regulations.
- Driver Qualification & Employment Files: Retained for the duration of the driver's active status plus three (3) years post-termination, as required by 49 CFR Part 391.
- Financial & Billing Transactions: Retained for seven (7) years to comply with federal tax and accounting laws.
- Account Deletion: Upon account closure, carriers may request an export of their database records. Data will be deleted or de-identified subject to our statutory tax and regulatory audit retention obligations.
6. Security Measures
We maintain comprehensive administrative, technical, and physical safeguards to protect Customer Data:
- Encryption in Transit: All network communications are encrypted using Transport Layer Security (TLS 1.2 / TLS 1.3).
- Encryption at Rest: Sensitive database columns, authentication tokens, and receipt images are encrypted using industry-standard AES-256 encryption.
- Multi-Tenant Row-Level Security (RLS): Carrier datasets are logically isolated at the database level so that no carrier or driver can view another organization's records.
- Role-Based Access Controls (RBAC): Strict permission boundaries separating carrier administrators, dispatchers, and individual mobile drivers.
Disclaimer & Limitation
While we employ rigorous commercial security controls, no method of transmission over the Internet or electronic storage is 100% impenetrable. We cannot guarantee absolute security against sophisticated unauthorized intrusions. Users are responsible for maintaining the confidentiality of their login credentials.
Data Breach Notification
In the event of a confirmed security incident resulting in the unauthorized access or disclosure of personal information, we will notify affected carriers and regulatory authorities without unreasonable delay, and within 72 hours where required by applicable state or federal law.
7. Your Privacy Rights & Choices
7.1 Carrier Administrators: Administrators may review, update, or correct fleet vehicle lists, tax rates, profile information, and user permissions directly within the app settings.
7.2 Commercial Drivers: Drivers seeking to access, correct, or delete their personal or trip data should contact their employing motor carrier (the Data Controller). We will assist carriers in fulfilling verified driver requests.
7.3 State-Specific Rights (California CCPA / CPRA)
California residents have specific statutory rights:
- Right to Know / Access: Request details on the categories and specific pieces of personal information collected.
- Right to Delete: Request deletion of personal information, subject to mandatory IFTA/FMCSA audit retention exceptions.
- Right to Correct: Request correction of inaccurate personal records.
- No Sale of Personal Data: We do not sell or share personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To submit a request, email us at legal@iftaeasy.com.
7.4 Canadian Commercial Operations (PIPEDA & Quebec Law 25)
For carriers and drivers operating across Canadian member jurisdictions (Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, Quebec, and Saskatchewan):
- Personal and location data collected during Canadian transit is processed in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial standards.
- Canadian users may request access to or correction of their personal data by contacting our Privacy Officer at legal@iftaeasy.com.
8. Cookies & Local Storage
We use browser cookies, IndexedDB, and HTML5 LocalStorage to provide an offline-first PWA experience:
- Essential Storage: Session tokens, dark/light theme preferences, selected tax quarters, and local trip drafts when operating outside cellular coverage.
- Analytical Cookies: Privacy-respecting analytics to track aggregated system performance, UI responsiveness, and error rates.
- Users can configure browser settings to decline cookies; however, disabling local storage may impair offline trip logging capabilities.
9. Children’s Privacy
Our Services are exclusively intended for commercial freight carriers, fleet operators, and licensed commercial drivers aged 18 and older (or 21+ for interstate commercial commerce). We do not knowingly collect personal data from individuals under 18.
10. International Data Transfers
Our servers and primary databases are located in the United States. If you access the Services from Canada or other jurisdictions, your information will be transferred to, stored, and processed in the United States under standard contractual safeguards.
11. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time. Material modifications will be announced via in-app banner notices or email notifications to account administrators prior to the effective date. Your continued use of the Services following posted updates signifies your acceptance.
12. Contact Information
If you have questions, comments, or data privacy requests regarding this Privacy Policy, please contact our legal and compliance department:
Daystar Financial Services LLC
(Parent Company of IFTAEASY)
211 N Main St, Unit 110
Simpsonville, SC 29681
United States
Legal & Privacy Inquiries: legal@iftaeasy.com
Technical Support: support@iftaeasy.com