Privacy Policy
Last updated: September 20, 2026 · v1.0
1. Scope & Our Role (Controller vs. Processor)
This Privacy Policy explains how ABY Platform LLC (“ABY,” “we,” “us,” “our”) handles personal data for which ABY is the data controller — visitors to abyplatform.com, people who contact us, and account holders who sign up for the ABY Yard Management System (the “Service”).
For personal data that customers submit into the Service to run their yard operations — including their users’ and drivers’ information and any driver identification data (driver’s license / CDL / government-issued IDs) — ABY acts as a processor (service provider) on the customer’s behalf. That processing is governed by the customer’s agreement and our Data Processing Addendum (DPA), not by this website policy. If you are a driver or an employee of an ABY customer, please contact that organization about its own privacy practices.
| Context | ABY’s role | Governing document |
|---|---|---|
| Marketing site, contact form, account signup, billing | Controller | This Privacy Policy |
| Data entered into the Service by a customer (incl. Driver ID Data) | Processor / Service Provider | The customer’s Agreement + DPA |
2. Information We Collect
We collect the following categories of personal data as a controller:
- Contact information — name, email address, company name, and message content when you use our contact form or request a demo.
- Account data — email, name, and role when you or your organization creates an account.
- Billing data — billing contact and transaction records. Card payments are processed by Stripe; ABY does not store full card numbers.
- Usage / analytics data — where enabled and only with your consent, aggregated analytics about how visitors use abyplatform.com (see Cookies & Tracking). No analytics are collected without consent.
- Device and log data — IP address, browser type, and access timestamps collected automatically (used for security, fraud prevention, and reliability).
We do not collect Social Security numbers, financial-account numbers, health data, or other special/sensitive categories about site visitors or account holders. (Driver identification data is processor-side — see Scope above.)
3. How We Use Your Information
We use personal data to: respond to inquiries and demo requests; create and operate accounts; process billing; secure and improve the Service; and send transactional/service communications (account, billing, support, and service notifications). We do not send marketing/promotional email campaigns, and we do not sell, rent, or trade your personal information.
4. Legal Bases for Processing (GDPR Article 6)
Where GDPR applies, we rely on:
- Contract performance — to provide and operate the Service you signed up for.
- Consent — when you submit information via the contact form, or opt into non-essential cookies/analytics. You may withdraw consent at any time.
- Legitimate interests — to secure the Service, prevent fraud, and communicate relevant service updates, balanced against your rights.
- Legal obligation — to comply with applicable laws, regulations, or valid legal process.
5. Cookies & Tracking
- Strictly-necessary cookies — session/authentication and security cookies required to log in and operate the app. Always on; they do not track you across other sites.
- Analytics cookies (consent-based) — with your consent, our marketing site uses Google Analytics (cookies such as _ga, _ga_*) to understand aggregate usage. These load only after you accept via our cookie banner, never before.
- No advertising / retargeting cookies — we set none.
- Managing your choices — a cookie consent banner appears on your first visit with Accept, Reject non-essential, and Manage options. Change or withdraw your choice anytime via “Cookie Settings” in the site footer.
Payment pages may set cookies from Stripe for fraud prevention and session integrity; these are essential to process a payment. See our Cookie Policy for details.
6. “Do Not Track” Signals (CalOPPA)
Because there is no common industry standard for how to interpret browser “Do Not Track” (DNT) signals, ABY does not respond to DNT signals. Instead, we honor your privacy choices through our cookie consent banner (see Cookies & Tracking). We do not permit third parties to collect personally identifiable information about your online activities across different websites through our site.
7. How We Share Your Information — Sub-processors
We share personal data only with trusted service providers (“sub-processors”) who process it on our behalf and are contractually bound to protect it and use it only for the services they provide to us:
| Sub-processor | Purpose | Data touched |
|---|---|---|
| Amazon Web Services (AWS) | Hosting / infrastructure (incl. Amazon SES email) | All platform data at rest/in transit; email content |
| Stripe | Payment processing (PCI DSS Level 1) | Billing/cardholder data (ABY never stores raw cards) |
| Resend | Transactional email delivery | Recipient email, message content |
| Twilio | SMS notifications (product / on customers’ behalf) | Name/phone, message content |
| Google Analytics (consent-based) | Aggregate website usage analytics | Usage/IP (only with consent) |
We do not sell or “share” (as defined by CCPA/CPRA) personal information. We may disclose data if required by law, regulation, or valid legal process, or to protect ABY’s rights and the security of the Service.
8. International Data Transfers
Our infrastructure is hosted in the United States. If you are located outside the U.S. (including the EEA, UK, or Switzerland), your data may be transferred to and processed in the U.S. We use appropriate safeguards, including Standard Contractual Clauses (SCCs) where applicable, to protect your data in accordance with GDPR requirements.
9. Data Retention
We retain personal data only as long as necessary for the purposes in this policy or as required by law:
| Data | Retention |
|---|---|
| Contact-form submissions | Up to 24 months |
| Account data | Duration of the subscription + 90 days after closure or deletion request |
| Billing / transaction records | As required for tax and audit (typically ~7 years) |
| Access / audit logs | 24 months |
| Backups | 90 days rolling |
| Analytics data | Per Google Analytics retention settings (14 months) once enabled |
You may request earlier deletion at any time (see Your Rights).
10. Data Security
All data is encrypted in transit (TLS) and at rest. Our infrastructure runs on enterprise-grade cloud services (AWS — SOC 2 Type II / ISO 27001) with role-based access controls. Card data is handled exclusively by Stripe (PCI DSS Level 1). We are pursuing SOC 2 Type II compliance. No system is 100% secure, but we take commercially reasonable measures to protect your data.
11. Your Rights (GDPR / UK GDPR)
Depending on your location, you may have the right to: access a copy of your data; rectify inaccurate data; erase your data (“right to be forgotten”); port your data in a machine-readable format; restrict or object to processing based on legitimate interests; and withdraw consent where processing is based on consent. To exercise any right, email privacy@abyplatform.com; we respond within 30 days. You will not be discriminated against for exercising these rights.
12. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose.
- Access and delete your personal information.
- Correct inaccurate personal information (CPRA).
- Opt out of the sale or sharing of personal information — we do not sell or share personal information.
- Non-discrimination for exercising your privacy rights.
Sensitive Personal Information (CPRA): We do not collect Sensitive Personal Information about website visitors or account holders, so the “right to limit use of Sensitive PI” does not apply to controller data. Where the Service processes driver identification data on a customer’s behalf, ABY acts as a service provider and processes it only per the customer’s instructions and the DPA — not for our own purposes, and never sold or shared. To exercise these rights, email privacy@abyplatform.com.
13. Children’s Privacy
The Service is not directed to individuals under 16, and we do not knowingly collect personal data from children. If we learn we have collected data from a child under 16, we will delete it promptly.
14. Supervisory Authority (EEA / UK)
If you are in the EEA or UK and believe we have not adequately addressed your concerns, you may lodge a complaint with your local Data Protection Authority.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or a notice on our website. The “Last updated” date at the top reflects the most recent revision.
16. Contact Us
Questions about this Privacy Policy or our data practices: privacy@abyplatform.com · ABY Platform LLC, 2108 N ST STE 7028, Sacramento, CA 95816.