Privacy Policy
Effective Date: May 16, 2026
Last Updated: August 14, 2026
Crim Report Inc. ("Crim Report," "we," "us," "our") respects your privacy. This Policy explains what information we collect through our online service (the "Service"), how we use it, who we share it with, and your choices. By using the Service, you agree to this Policy.
This Policy is part of our Terms of Service.
1. Who We Are
Crim Report Inc. is a New York corporation operating a unified incident reporting system for the motor carrier and logistics industry. Through the Service, authorized users — including motor carriers, freight brokers, factoring companies, insurance providers, and other industry participants — can access motor carrier information drawn from public records and user submissions.
2. Information We Collect
From you.
- Account information: name, email, password (stored hashed, never in clear text), business affiliation, and similar details.
- Profile information: optional details like company name, MC or DOT number, phone, or job title.
- Payment information: billing data (cardholder name, billing address, last four digits, expiration, transaction reference). Full card numbers and CVV are processed by our payment processor and are not received or stored by Crim Report Inc.
- User Content: incident reports, descriptions, documents, photos, comments, and other content you submit, including communications you send us.
- Identity verification data. If you are asked to verify your identity through the Service (for example, a driver completing a pickup verification), we collect images of your government-issued identity document, a facial image (selfie), and related biometric and "liveness" data used to confirm your identity. This is collected only with your explicit consent and is handled as described in Section 15.
Automatically.
- Usage data: pages viewed, features used, search queries (including DOT, MC, or carrier names searched), interactions with User Content, timestamps, and session activity.
- Device and connection data: IP address, browser type, operating system, device identifiers, language, and referring URL.
- Cookies and similar technologies (see Section 7).
From third parties.
- Public records, including FMCSA motor carrier safety, registration, insurance, and authority data; state Secretary of State business filings; and other publicly available sources. Some of this references individuals who are made public by the regulatory or filing process (e.g., registered agents, officers, contact persons).
- Service providers that support our operations (see Section 4).
3. How We Use Information
We use the information we collect to:
- Operate, maintain, and improve the Service;
- Create and manage accounts and authenticate users;
- Process payments and manage subscriptions;
- Display User Content and public records in response to queries;
- Communicate with you about your account, billing, security, service updates, and (where permitted) marketing;
- Enforce our Terms, prevent fraud and abuse, and protect our users and the Service;
- Comply with legal obligations and respond to legal process;
- Conduct analytics and product development.
We do not sell your personal information for monetary consideration, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act.
4. Service Providers
We share information with vendors who help us operate the Service. Each receives only what it needs and is required to safeguard it. Categories include payment processing; hosting and infrastructure; authentication and database services; transactional email and SMS delivery; mapping and address validation; phone-number and email validation; identity and biometric verification; logging, monitoring, and observability; and other operational services. Our identity-verification provider processes identity and biometric data solely to provide verification services to us, under contract, and may not use it for its own purposes (see Section 15).
5. How We Share Information
We share information:
- With service providers as described in Section 4.
- With other users of the Service. User Content you submit, and public-record information displayed on the Service, may be viewable by other authorized users in accordance with their access tier.
- For legal reasons. To comply with law, court order, subpoena, or legal process; to enforce our Terms; to respond to claims; or to protect the rights, property, or safety of Crim Report Inc., our users, or the public.
- In a business transaction. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, with notice as required by law.
- With your consent or at your direction.
6. Public Records and User Content Visibility
The Service is built around publicly available motor carrier records and user-submitted incident reports. Information in those records and reports — and information you submit as User Content — may be visible to other authorized users of the Service and is not "private" once posted.
If you are an individual whose information appears in public records ingested by the Service (for example, as a carrier officer or contact), that information is sourced from the public record. To dispute accuracy, see Section 9.
7. Cookies
We use cookies and similar technologies to operate the Service, remember preferences, keep you signed in, secure your session, and analyze usage. You can manage cookies through your browser; some Service features may not work properly if cookies are disabled. We do not use cookies for cross-context behavioral advertising.
8. Data Retention
We retain personal information only for as long as needed to operate the Service, comply with legal obligations, resolve disputes, prevent abuse, and enforce our agreements. Specific retention periods include:
- Account information (name, email, organization, profile): retained while your account is active and deleted or anonymized within ninety (90) days after account closure, except where retention is required by law.
- Billing and transaction records: retained for at least seven (7) years after the transaction to comply with tax, accounting, and financial recordkeeping obligations.
- Search history and product usage logs: retained for up to twenty-four (24) months in association with your account, after which records are aggregated, anonymized, or deleted.
- Authentication, security, and audit logs: retained for up to twenty-four (24) months for incident response and fraud detection.
- Support communications: retained for up to thirty-six (36) months after the matter is closed.
- Encrypted backups containing personal information may persist for up to ninety (90) days after deletion from production systems, after which they are overwritten in the ordinary course.
- User Content (incident reports and submissions) may be retained as part of the historical record of the Service, including after your account is closed, except where removed under our moderation policies or as required by law.
Account inactivity. If you do not sign in to your account for twenty-four (24) consecutive months, we may delete or anonymize associated personal data, except where retention is required by law or for legitimate business purposes.
9. Carrier Dispute and Data Correction
If you are the subject of information displayed on the Service — public-record data or User Content — and believe a specific item is materially inaccurate, you may submit a written request to privacy@crimreport.com and CC support@crimreport.com. Identify the item, the alleged inaccuracy, and provide supporting documentation. We may, at our discretion, review such requests and, in our sole discretion, annotate, correct, remove, or take no action. Review is informal, undertaken without obligation, and our determination is final. For public-record data, we may direct you to the original source (e.g., FMCSA or a Secretary of State office), where the authoritative correction is made.
10. Security
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, or alteration, including encryption in transit, hashed password storage, role-based access controls, and monitoring. No system is perfectly secure, and we cannot guarantee security. You are responsible for safeguarding your account credentials. If a security incident affects your personal information, we will notify you and applicable authorities as required by law, including the New York SHIELD Act.
11. Your Choices and Rights
Depending on where you live, you may have rights under applicable privacy laws, including the California Consumer Privacy Act ("CCPA," as amended by the California Privacy Rights Act), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, and the New York SHIELD Act. Subject to verification and applicable exceptions, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate personal information;
- Request deletion;
- Port your information to another service;
- Opt out of certain processing activities;
- Not be discriminated against for exercising these rights.
To submit a request, email privacy@crimreport.com. We will respond within the time period required by law and will verify your identity before processing. You may designate an authorized agent to submit a request on your behalf; we will verify the agent's authority and your identity.
Some information cannot be deleted while it remains necessary for the operation of the Service, the maintenance of public records, fraud prevention, legal compliance, or the rights of other users (including users who submitted User Content about a third party).
Categories of personal information collected. Under the CCPA, we have collected the following categories of personal information in the preceding twelve (12) months: identifiers (name, email, account credentials, IP address, device identifiers); customer records (billing name, billing metadata); commercial information (subscription plan, billing history); internet or network activity (pages visited, features used, search queries, interaction data); geolocation data (approximate location inferred from IP address); professional or employment-related information (organization name and role, if provided); and limited inferences drawn from usage patterns. Each category is collected for the business purposes described in Section 3.
Sensitive personal information. For users who complete identity verification (Section 15), we collect government identification information and biometric information (facial images and identifiers), which are "sensitive personal information" under the CCPA. We use this information only to verify identity and prevent fraud — that is, only for purposes permitted under CCPA § 7027(m) — and not to infer characteristics about you. We do not sell or share sensitive personal information, and we do not use or disclose it for purposes other than those permitted.
Sale and sharing. We do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioral advertising as those terms are defined under the CCPA. We have not sold or shared personal information in the preceding twelve (12) months and do not sell or share the personal information of minors under 16.
Opt-out preference signals. We do not respond to "Do Not Track" browser signals because there is no industry or legal consensus on how to interpret them. We do recognize valid opt-out preference signals such as the Global Privacy Control where required by applicable state law. Because we do not sell or share personal information in the first place, such signals do not change our processing of your information.
12. Children
The Service is intended for business users 18 and older. We do not knowingly collect personal information from individuals under 13. If you believe a child under 13 has provided us with personal information, contact privacy@crimreport.com and we will take appropriate steps to delete it.
13. International Users
The Service is operated from the United States and intended for U.S. users. If you access the Service from outside the U.S., you understand that your information will be transferred to and processed in the U.S. The Service is not designed to comply with the European Union's General Data Protection Regulation or similar non-U.S. regimes; if you are subject to those regimes, you should not use the Service.
14. Changes to This Policy
We may update this Policy. When changes are material, we will update the "Last Updated" date and provide notice through the Service, by email, or by other reasonable means. Continued use after the effective date constitutes acceptance.
15. Identity Verification and Biometric Information
Certain features of the Service — including CrimCheck driver and pickup verification — involve verifying an individual's identity. When you are asked to verify your identity through the Service:
- What we collect. Images of your government-issued identity document, a facial image (selfie), and related biometric and "liveness" data derived from those images, along with the device and connection data described in Section 2. This includes biometric identifiers, which we treat as sensitive personal information.
- Why we collect it. Solely to confirm that you are who you claim to be, to match your identity again at pickup, and to detect and prevent fraud, identity theft, and double-brokering. We do not use identity or biometric data for advertising, for profiling unrelated to verification, or to infer characteristics about you.
- Consent. We obtain your explicit, informed consent before any identity document or biometric data is captured. Verification is voluntary — if you decline, the verification will not proceed and the party who requested it will simply be told it was not completed.
- Who processes it. The verification is performed on our behalf by a specialized third-party identity-verification provider acting as our service provider (processor) under contract. That provider is permitted to use the information only to provide verification services to us, is contractually prohibited from using it for its own purposes, and is required to protect it. See Section 4.
- Retention and deletion. Identity documents, facial images, and biometric identifiers are retained only as long as needed to perform and evidence the verification and to meet legal, security, and fraud-prevention obligations, and are then deleted or de-identified. Except where a longer period is required by law or to establish or defend legal claims, the source images and biometric identifiers associated with a verification are deleted within sixty (60) days of the verification. A minimal, non-biometric record (such as the pass/fail outcome and timestamps) may be retained as part of the fraud-prevention and audit record described in Section 8.
- No sale or sharing. We do not sell or share identity or biometric information, and we do not disclose it except to the verification provider above, as required by law, or with your consent.
- Your rights. Subject to the exceptions in Section 11, you may request access to or deletion of your identity or biometric information by emailing
privacy@crimreport.com.
16. Operational Communications with Drivers and Shippers (CrimCheck Notifications)
Certain features of the Service — specifically our CrimCheck product — send operational messages by SMS (text message) and by email to drivers and shipper contacts involved in a specific dispatched load. The full channel-specific terms (sender identity, content, opt-out mechanics, HELP handling, and the initiating party's consent warranty) are set out in Section 22 of our Terms of Service. This Section explains what we do with the personal information involved.
SMS / mobile information sharing — summary statement. No mobile information (including mobile phone numbers) collected in connection with the CrimCheck SMS program, and no text-messaging opt-in data or consent, will be shared with any third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors that support the messaging service itself (for example, our SMS delivery provider) is permitted solely to deliver the operational messages described below and is governed by contract. All other use categories exclude text-messaging originator opt-in data and consent — that information is never shared with third parties for any purpose other than delivering the message the recipient consented to receive.
- What we collect. For these purposes we process the recipient's mobile phone number and/or email address, the load context (broker, carrier, pickup city/state, pickup date/time, load reference), the identity of the initiating broker user, and delivery/interaction metadata returned by our SMS and email providers (delivered, failed, replied STOP, unsubscribed, etc.).
- How we get the contact details. Mobile phone numbers and email addresses of drivers and shippers are provided to us by the initiating freight broker as part of a specific dispatched load. The broker warrants in Section 22.8 of the Terms of Service that they have obtained the recipient's consent — either directly or through the recipient's carrier or dispatcher — to be contacted by SMS and email about the pickup and the related verification process. We do not purchase contact details, we do not obtain them from data brokers, and we do not collect them through public web forms for this purpose.
- How we use it. Solely to send the transactional messages described in Terms Section 22.2 — one verification-link message per session per channel, plus up to two retries if the first is not completed, and pickup-time process updates tied to the same session. We do not use these contact details for marketing, promotional messaging, newsletters, product announcements, up-sell, cross-sell, lead-scoring, ad targeting, look-alike modeling, or profile enrichment.
- Who processes it. SMS and email delivery are performed by third-party service providers acting on our behalf under contract. Each provider is permitted to use the information only to deliver the message on our behalf and is contractually prohibited from using it for any other purpose. See Section 4.
- No sale, no sharing, no promotional use. We do not sell CrimCheck recipient information. We do not share it with any third party or affiliate for advertising, marketing, promotional, or commercial-communication purposes. No mobile information — including mobile phone numbers, text-messaging opt-in data, and consent records — collected for CrimCheck operational communications will be shared with any third parties or affiliates for marketing or promotional purposes under any circumstances. Sharing with subcontractors that deliver the messaging service on our behalf is permitted only to send the operational messages described in this Section. This restriction survives any change of ownership of Crim Report Inc.
- Retention. Contact details provided for a CrimCheck session are retained with the session record (see Section 8). Contacts that opt out are retained in a suppression list solely to ensure we honor the opt-out; that suppression record is not used for any other purpose. Except as required by law or to establish or defend legal claims, delivery metadata is retained no longer than the underlying session record.
- Opt-out. Recipients may opt out at any time. For SMS, reply with STOP (or any equivalent keyword listed in Terms Section 22.5). For email, use the unsubscribe link in any message or email
support@crimreport.com. Once opted out on a channel, no further messages will be sent on that channel from any Crim Report campaign. Opt-out is honored per channel.
- Your rights. If your mobile number or email address has been used in a CrimCheck message and you would like to access, correct, or delete the associated record, email
privacy@crimreport.com. Requests are subject to Section 11.
17. Contact
- Privacy questions, requests, or dispute submissions:
privacy@crimreport.com (please CC support@crimreport.com)
- Account or billing:
support@crimreport.com
- Formal legal notices:
legal@crimreport.com
Back to home