Privacy Policy
Version 2026-07-31
TRAINSIT, LTD., a Delaware corporation ("Trainsit", "we", "us", or "our"), provides a rail-focused intermodal freight marketplace and related services that let business users obtain quotes for, book, track, and manage intermodal and related freight transportation, including rail line-haul and associated drayage, together with related account, billing, and support functions (the "Service"). We may collect certain information from or about you in connection with the Service, our websites, and our marketing and business activities. By accessing the Service, using our websites, or otherwise providing us with information, you acknowledge and agree that Trainsit may collect, use, and disclose your personal information ("Personal Information", meaning information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household) as outlined in this Privacy Policy. This Privacy Policy is incorporated by reference into the Trainsit Terms of Service ("Terms of Service"). Capitalized terms not defined in this Policy have the meanings given in the Terms of Service.
We may update this Privacy Policy from time to time as our Service evolves and to comply with new and changing privacy laws, and we will notify you of such changes in compliance with applicable laws and our agreements with you. Trainsit processes the Personal Information described in this Policy as a controller or business, including information about visitors to our websites, account registrants, and the Authorized Users who access the Service on behalf of a business customer ("Customer"). The Service is offered to businesses, and the information submitted through the Service relates primarily to freight shipments and to the business personnel who arrange them, rather than to consumers acting in a personal capacity. This Privacy Policy supplements the Terms of Service, and Personal Information within Customer Data is handled as described in the Terms of Service and this Policy.
California Notice at Collection / State Privacy Rights Notice: See the State Privacy Rights Notice (Section 9) for important information about your rights under applicable US state privacy laws.
1. PERSONAL INFORMATION WE COLLECT
1.1 Information you provide. Personal Information you may provide includes:
- Account and contact data, such as your name, business email address, phone number, employer name, job title, and account credentials.
- Shipment and booking data, such as origin and destination information, commodity descriptions, weights and dimensions, equipment needs, pickup and delivery contacts, quotes, bookings, tracking information, and accessorial and claim records. This data may include the names and contact details of shippers, consignees, and facility personnel that you provide.
- Payment and transaction data, processed by our payment processor Stripe (or other as changed over time); we receive limited transaction-confirmation data and do not store full payment card details.
- Communications data, based on your exchanges with our sales and support teams.
- Feedback, if you provide ideas or suggestions about the Service.
1.2 Information collected automatically. When you use the Service, we and our service providers automatically collect:
- Log data, such as IP address, browser type, and access timestamps.
- Usage data, such as the features used and actions taken.
- Device data, such as device type and configuration.
- Cookies and similar technologies, as described in Section 2.
1.3 Information from other sources. We may receive limited Personal Information from:
- Your organization, for example when an administrator adds you as an Authorized User.
- Service providers, in connection with security and service delivery.
- Carriers and other logistics parties, in connection with the transportation of your Shipments.
1.4 Data about others. If you provide Personal Information about colleagues, shippers, consignees, or facility contacts, please ensure you have authority to share it and, where required, have informed those individuals.
2. TRACKING TECHNOLOGIES
2.1 Cookies and similar technologies. We use cookies and similar technologies to operate the Service, maintain your session and preferences.
2.2 No targeted advertising. We do not use advertising networks, retargeting pixels, or interest-based advertising technologies in connection with the Service, and we do not share Personal Information with advertising partners.
2.3 Your controls. You may manage cookie preferences through your browser.
2.4 Do Not Track. We do not currently respond to browser Do Not Track signals.
3. HOW WE USE YOUR PERSONAL INFORMATION
We use Personal Information for the purposes described below, or as otherwise described at the time of collection.
3.1 Service delivery and operations. We use Personal Information to:
- provide, operate, and maintain the Service, including generating quotes, arranging and booking transportation, and providing shipment tracking and support;
- establish and administer your account and process payments through our payment processor; and
- communicate with you, including service-related notices, security alerts, and responses to your inquiries.
3.2 Security, fraud prevention, and compliance. We use Personal Information to:
- detect, investigate, and prevent fraud, security incidents, and misuse, and enforce our agreements; and
- comply with applicable law and respond to lawful requests.
3.3 Service improvement and analytics. We use technical and usage data to analyze and improve the Service, including in de-identified or aggregated form.
3.4 Marketing communications. We may send you marketing communications about the Service, from which you may opt out at any time.
3.5 Aggregated and de-identified data. We may create aggregated, de-identified, or anonymized data derived from Personal Information and use and share it for lawful business purposes, including analyzing and improving the Service. We will not attempt to re-identify such data except to verify that our de-identification processes comply with applicable law.
3.6 No automated decision-making with legal effect. We do not use Personal Information for automated decision-making that produces legal effects concerning you or similarly significant effects on you, as those terms are understood under applicable US state privacy laws. We do not create or use automated profiles of individuals to make such decisions, and we do not engage in profiling of individuals in furtherance of such automated decision-making.
4. HOW WE SHARE YOUR PERSONAL INFORMATION
4.1 Carriers and logistics parties. To arrange and complete transportation, we share shipment and contact information with Carriers, railroads, drayage providers, other brokers (Co-Brokers), and facilities as necessary to provide the Service.
4.2 Service providers. We share Personal Information with vendors that perform services on our behalf, including:
- Hosting and infrastructure providers.
- Payment processing providers.
- Mapping and rating providers.
- Communications providers.
- Artificial Intelligence providers.
These providers may use Personal Information only to provide services to us and are bound by contractual obligations.
4.3 Within your organization. Personal Information and Customer Data that you and your Authorized Users generate or store through the Service, such as quotes, bookings, tracking, and related records, are accessible to Authorized Users within your organization in accordance with the access controls your account administrator configures.
4.4 Professional advisors. We may share Personal Information with our lawyers, accountants, and auditors under appropriate confidentiality obligations.
4.5 Legal compliance and safety. We may disclose Personal Information where necessary to comply with law, respond to lawful requests, enforce our agreements, or protect the rights, safety, and property of Trainsit, our users, or others.
4.6 Business transfers. We may disclose Personal Information in connection with a merger, acquisition, financing, or sale of all or part of our business, including in insolvency or bankruptcy proceedings. In such cases, we will provide reasonable notice to affected Customers through the Service or by email.
4.7 Aggregated and de-identified information. We may create and share aggregated or de-identified information that cannot reasonably be used to identify you.
4.8 No sale; no targeted advertising. We do not sell Personal Information for monetary consideration, and we do not share Personal Information for cross-context behavioral advertising, as those terms are defined under applicable state privacy laws.
5. DATA RETENTION AND PRESERVATION
5.1 Retention. We retain Personal Information for as long as your account is active and as needed to provide the Service, and thereafter as necessary to comply with our legal obligations, resolve disputes, enforce our agreements, and protect our legitimate interests. To determine the appropriate retention period, we consider the nature and sensitivity of the information, the potential risk of harm, the purposes for which we process it, and applicable legal requirements. We delete or return Customer Data following account termination as described in the Terms of Service.
5.2 Preservation of shipment and claim records. Because freight transactions can give rise to claims, audits, and disputes, we retain shipment, booking, accessorial, payment, and Cargo Claim records for a period appropriate to the applicable claim, limitation, and recordkeeping requirements. Where we are on notice of an actual or anticipated claim, dispute, or legal proceeding, we preserve relevant records under a litigation hold until the matter is resolved, notwithstanding our ordinary deletion schedule.
5.3 Deletion. When we no longer need Personal Information, we delete, anonymize, or isolate it from further processing. Residual copies created in the ordinary course of business-continuity and disaster-recovery operations may be retained for a limited period and are used only for system recovery.
6. DATA SECURITY
We maintain administrative, technical, and organizational safeguards designed to protect Personal Information against loss, misuse, and unauthorized access, disclosure, alteration, or destruction, including appropriate access controls and encryption in transit. Security risk is inherent in all internet and information technologies, and no method of transmission or storage is completely secure. In the event of a personal data breach that requires notification under applicable law, we will notify affected parties in accordance with our legal obligations.
7. CHILDREN'S PRIVACY
The Service is intended for business users who are at least 18 years old. We do not knowingly collect Personal Information from individuals under 18. In particular, we do not knowingly collect Personal Information from children under 13 years of age in violation of the Children's Online Privacy Protection Act ("COPPA"). If we learn that we have collected Personal Information through the Service from a child without the consent of the child's parent or guardian as required by law, we will comply with applicable legal requirements to delete the information. If you are a parent or guardian who believes we have collected Personal Information from a child in your care, please contact us using the details in Section 12.
8. UNITED STATES; INTERNATIONAL DATA TRANSFERS
The Service is offered to users located in the United States, and we are headquartered in the United States. We may use service providers that operate infrastructure in other countries, in which case your Personal Information may be transferred to and processed in those locations subject to contractual data-protection obligations consistent with this Policy.
9. STATE PRIVACY RIGHTS NOTICE
For purposes of this Policy, “State Privacy Laws” means US state laws that grant privacy rights to their residents, including the California Consumer Privacy Act (as amended by the California Privacy Rights Act), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Texas Data Privacy and Security Act, and similar laws. This Section applies to residents of US states whose State Privacy Laws grant the rights described below, to the extent those laws apply to Trainsit.
Your privacy rights. Depending on your state of residence, and subject to applicable exceptions and limitations, you may have some or all of the following rights:
- Access / Know: confirm whether we process your Personal Information and access it.
- Correction: request correction of inaccurate Personal Information.
- Deletion: request deletion of Personal Information.
- Portability: obtain a portable copy of your Personal Information.
- Opt-out of sale or sharing: opt out of the sale of Personal Information or sharing for targeted advertising (we do not engage in either).
- Opt-out of profiling: opt out of profiling that produces legal or similarly significant effects (we do not engage in such profiling).
- Limit sensitive information: request that we limit the use and disclosure of sensitive personal information to purposes permitted under applicable law (we do not use sensitive personal information beyond what is necessary to provide the Service).
- Non-discrimination: we will not discriminate against you for exercising these rights.
No sale and no targeted advertising. We do not sell your Personal Information and do not share it for cross-context behavioral advertising. We honor GPC opt-out preference signals as required by applicable law.
How to exercise your rights. Submit a request by contacting us at 350 California Street, 4th floor pmb203, San Francisco, CA, 94104 or privacy@trainsit.com. We may need to verify your identity before processing your request. Verification may include matching information you provide with information we already maintain about you; for requests submitted through a non-authenticated channel, we may ask you to confirm your account email address and provide additional identifying details. We will respond within the period required by applicable law (generally 45 days, extendable by an additional 45 days with prior notice). You may designate an authorized agent to submit requests on your behalf by providing us with written authorization signed by you or a valid power of attorney; we may independently verify your identity in addition to verifying your agent's authority.
Right to appeal. If we deny your request, we will explain why, and you may appeal by contacting us at [●] with the subject line "Privacy Request Appeal." You may also contact your state attorney general.
Information practices. The following table summarizes the categories of Personal Information we process, the purposes for processing, and the categories of recipients. We do not sell Personal Information or share it for cross-context behavioral or targeted advertising.
| Category of Personal Information | CCPA Statutory Category | Purposes | Categories of Recipients | Sold or Shared for Advertising |
|---|---|---|---|---|
| Account and contact data (name, business email, phone, employer, job title) | Identifiers; Professional or employment information | Service delivery; account administration; communications; security; legal compliance | Hosting and infrastructure providers; communications providers; professional advisors (to be confirmed) | No |
| Shipment and booking data (origin and destination, commodity, weight, contacts, tracking, accessorial and claim records) | Identifiers; Commercial information | Arranging, booking, and tracking transportation; claims handling; service delivery | Carriers, railroads, drayage providers, Co-Brokers, and facilities; hosting and infrastructure; mapping and rating providers (to be confirmed) | No |
| Payment and transaction data (confirmation data only; full card data processed by the payment processor) | Financial information | Billing; fraud prevention | Payment processor (to be confirmed) | No |
| Usage and log data (IP address, feature interactions, access logs, browser and device data) | Identifiers; Internet or electronic network activity | Service delivery; security; de-identified or aggregated analytics | Hosting and infrastructure; analytics providers (to be confirmed) | No |
| Communications data (support and sales exchanges) | Identifiers; Commercial information | Customer support; relationship management | Communications and CRM providers (to be confirmed) | No |
Sensitive Personal Information. We do not intentionally collect Personal Information that qualifies as sensitive personal information under State Privacy Laws (such as government identifiers, financial account credentials, precise geolocation, biometric identifiers, or health data) in the course of providing the Service. If you believe you have submitted such information, please contact us.
Sources and purposes. We collect all categories of Personal Information listed above from the sources described in Section 1 and use them for the business and commercial purposes described in Section 3.
Retention. The criteria we use to determine retention periods are described in Section 5.
De-identification. We do not attempt to re-identify de-identified or anonymized information derived from Personal Information, except to verify that our de-identification processes comply with applicable law.
California Shine the Light. California residents may request information about disclosures of Personal Information to third parties for those third parties' direct marketing purposes. We do not make such disclosures. To submit a precautionary request, contact us at [●] with the subject line "Shine the Light Request."
Consumers under 16. We do not have actual knowledge that we collect, sell, or share the Personal Information of consumers under 16 years of age.
Additional state disclosures. We do not sell Personal Information (including for Nevada purposes) and do not sell sensitive personal data as defined by the Texas Data Privacy and Security Act.
10. THIRD-PARTY LINKS AND SERVICES
The Service may contain links to, or integrate with, websites and services operated by third parties, including Carriers, railroads, mapping providers, and payment processors. We do not control and are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. For material changes, we will provide advance notice as required by applicable law, for example by email or through the Service, and the updated Policy will take effect on the date stated in that notice. Your continued use of the Service after that date constitutes acknowledgment of the updated Policy. Where applicable law requires consent before material changes to our data practices, we will seek that consent.
12. HOW TO CONTACT US
TRAINSIT, LTD., 350 California Street, 4th Floor PMB203, San Francisco, CA, 94104. Privacy questions and data subject requests may be sent to privacy@trainsit.com. For requests under the State Privacy Rights Notice, see Section 9.
This Privacy Policy is available in alternative formats upon request; please contact us at the address or email above.