1. Company Information
Data Controller
Grizzly Pine Software LLC
Owner: Brass Buffalo Holdings LLC
30 N Gould St, Ste N, Sheridan, WY 82801
Registered agent: Northwest Registered Agent Service Inc, 30 N Gould St, Ste N, Sheridan, WY 82801
Service and privacy: grizzlypinesaas@proton.me
Legal correspondence: grizzlypinelgl@proton.me
Intellectual Property Owner
Brass Buffalo Holdings LLC
Wyoming, United States
For data protection inquiries, contact the Data Controller above. For intellectual property questions, see our Terms of Service.
1.1 Parties
This Privacy Policy is issued by Grizzly Pine Software LLC, a Wyoming Limited Liability Company ("Service Provider"). For platform account data and Solo Workspace data, Grizzly Pine Software is referred to in this policy as "we", "us", or "our" as the data controller.
1.2 Intellectual Property Ownership
Grizzly Pine Software provides the Services using intellectual property owned by Brass Buffalo Holdings LLC ("IP Holder"), including the Pinegate Logistics (formerly Fleet Logistics USA) service mark. Pinegate Logistics (formerly Fleet Logistics USA) is a service mark of Brass Buffalo Holdings LLC, used under license by Grizzly Pine Software LLC. Ownership of the software and related technology does not make Brass Buffalo Holdings your service provider or data controller.
1.3 Contractual Privity
Your privacy relationship is solely with Grizzly Pine Software, not Brass Buffalo Holdings. Brass Buffalo Holdings is not a party to this Privacy Policy.
2. Data Roles
Grizzly Pine Software LLC is the controller of platform account data, technical logs, and Solo Workspace data. For data submitted to a DSP Workspace (driver rosters, HR records, schedules, broadcasts, DSP-provisioned gate codes), Grizzly Pine Software LLC acts as a processor on behalf of the DSP, under a Data Processing Addendum; the DSP is the controller of that data and bears employer obligations for notices and consents. Where state law uses the term "service provider," Grizzly Pine Software LLC is a service provider for DSP Workspace data and a controller for platform data.
2.1 Gate Codes
We store gate codes: (a) provisioned by DSPs for their fleets, and (b) submitted by Solo Workspace users based on their attestation of authorized knowledge (Section 4.1 of the Terms). Gate codes are encrypted at rest and in transit, scoped to authorized workspaces, and access is logged. Property owners, managers, and HOAs may request removal of any gate code referencing their property at grizzlypinesaas@proton.me; verified requests are honored within 3 business days.
3. Information We Collect
We collect information you provide when creating an account or using the Services, such as your name, email address, phone number, service area, driver identifiers, vehicle information (including VINs where applicable), and fleet-related operational data. We also collect technical information needed to operate and secure the platform, such as device and usage logs.
3.1 Driver Data
If you are a fleet operator submitting information about drivers, you represent that you have obtained necessary consents from any drivers whose information is submitted to the Services. You are responsible for complying with applicable employment law and privacy regulations regarding such data.
3.2 Data Minimization
We collect only data necessary for delivery operations. We do not collect:
- Customer names, phone numbers, or email addresses
- Residential addresses beyond what is required for navigation and gate access within the Services
- Payment information for end customers
We do collect:
- Driver contact information for account management and approval
- Gate codes necessary for property access
- Timestamped location and access data for route verification, security monitoring, and abuse investigation
- Access logs for abuse prevention, DSP escalation, and legal compliance
Users must not submit customer-identifying information or inappropriate content through the Services. Violations may affect account approval, trigger investigation, and result in notification to your DSP.
3.3 Cookies and Tracking Technologies
We use session cookies and analytics tools to operate the Services securely. These may track:
- Session authentication tokens
- Device and connection signals for abuse prevention
- Usage patterns for platform improvement and security monitoring
You may disable cookies in your browser, but this may limit functionality of the Services.
3.4 Operations Hub Data
When your DSP uses operations features, we may process:
- Broadcasts and acknowledgments: message content, delivery status, read receipts, and tap-to-acknowledge confirmations for wave and schedule communications
- Direct messages: one-to-one threads between drivers and dispatch or leadership, including timestamps and read status (no driver group chat)
- HR requests: sick call-outs, absence notes, and time-off requests submitted through structured forms
- Workforce documentation: reprimands, performance improvement plans, people files, and related attachments stored by DSP leadership; access is restricted by role
- Hours and scheduling: shift hours, attendance, wave confirmations, call-in status, and derived eligibility signals (for example whether a driver may be invited to call in under your DSP's rolling-hours rules)
3.5 DSP-Submitted Driver Data
Fleet administrators and DSP leadership may submit or maintain information about drivers and other workforce members (contact details, roster names, identifiers, HR records, and operational notes). The DSP is responsible for obtaining any consents required under employment and privacy law before submitting that information. Grizzly Pine Software processes such data on behalf of the DSP to provide the Services.
4. How We Use Information
We use collected information to provide and improve the Services, authenticate users, support fleet operations, communicate with you about your account, and protect the platform from abuse, breaches, and unauthorized access. We process personal data only as necessary to deliver the Services and fulfill our legal obligations under applicable U.S. federal and state law.
4.1 Security Monitoring
To prevent misuse, stalking, unauthorized surveillance, and theft, we monitor and log user activity within the Services. This includes access to gate codes, timestamps, and location-related signals used to detect access on non-scheduled driving days or other suspicious patterns. Flagged activity may be escalated to administrators and your DSP. Monitoring-dependent features activate only after an in-app electronic monitoring disclosure is acknowledged by the user. Monitoring reports furnished to DSPs consist of factual access logs and timestamps only; Grizzly Pine Software LLC does not generate conclusions or recommendations regarding employment decisions.
4.2 Breach Notification
If we experience a security incident affecting personal information, we will notify affected users and DSP controllers without undue delay, and in no event later than 45 days after confirmation for users and 72 hours for DSP controllers under a Data Processing Addendum, in accordance with applicable state breach-notification law. Notifications will describe the categories of data involved and remediation steps.
4.3 Service Geography and International Users
Pinegate Logistics (formerly Fleet Logistics USA) is only approved for use within the United States. We do not offer, authorize, or endorse access to the Services outside U.S. territory. If you attempt to access the Services from outside the United States, your activity may be flagged, and your account may be suspended pending verification of U.S. location.
Where applicable law requires a legal basis for processing, we rely on contract performance, legitimate interests in operating and securing the Services, and compliance with legal obligations. If you are located outside the United States despite this restriction, you acknowledge that your information may be processed in the United States in accordance with U.S. law, which may not have equivalent data protection standards to your jurisdiction.
For EU or UK residents, standard contractual clauses for international transfers are available upon request at grizzlypinesaas@proton.me. We will comply with applicable laws to address foreign influence, platform abuse, data breaches, and other security threats.
4.4 Operations and Accountability Monitoring
We log operational activity needed to run the Services safely and fairly, including wave confirmations, broadcast delivery and acknowledgments, call-in invites, HR request submissions, and access to leadership-only workforce files. This monitoring supports abuse prevention, dispute resolution, and coordination between drivers and DSP leadership. We do not provide driver-to-driver messaging or open group chat.
5. Sharing
5.1 No Sale of Personal Information
Grizzly Pine Software does not sell, rent, or trade personal information to third parties. We share data only as described in this section (service providers, legal requirements, DSP escalations, and law enforcement cooperation). California residents may submit "Do Not Sell" requests, though none are applicable to our operations because we do not sell personal data.
5.2 When We Share Information
We may share information with service providers that help us operate Pinegate Logistics (formerly Fleet Logistics USA), when required by law, or to protect the rights and safety of users and Grizzly Pine Software. We may share information with your DSP when investigating suspected misuse, and we cooperate with law enforcement when valid legal process requires disclosure of records tied to criminal activity, abuse, or security breaches.
6. Data Security and Retention
We implement reasonable technical and organizational measures to protect personal information. Access logs and security monitoring records are retained for approximately 12 months, then deleted or anonymized unless a longer period is required for investigation, dispute resolution, or legal compliance. Other account data is retained only as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Upon account closure, Workspace data is deleted within 30 days except where retention is required by law or reasonably necessary to resolve a dispute.
7. Consumer Data Rights
Depending on your location, you may have the following rights under applicable U.S. state privacy laws:
- Access your personal data
- Delete your personal data
- Correct inaccurate information
- Opt out of certain processing, including sale or profiling where applicable
- Appeal a decision regarding your request, where required by law
Exercising any right under this Section — including deletion — will never result in retaliation, account degradation, or adverse notification to your DSP.
Where a DSP stores workforce records about you, your access rights to those records as an employee may be exercised directly with your employer under applicable state personnel-records law; we will assist your DSP in responding.
To exercise these rights, contact us at grizzlypinesaas@proton.me. We will verify your identity before processing requests. We will not discriminate against you for exercising any of these rights.
You may review and update certain account information from your account settings at any time.
7.1 State-Specific Rights
California Residents (CCPA/CPRA): You may request disclosure of personal information collected, sources, purposes, and third parties shared with. You may request deletion of personal information. You may opt out of sale or sharing of personal information (we do not sell data). You may limit use of sensitive personal information where applicable.
Florida Residents (FDDBR): You may request access to your personal data. We will respond within 45 days. You may request correction or deletion of inaccurate data. You may opt out of profiling for automated decision-making. You may appeal a denied request within 60 days.
Virginia, Colorado, Utah, and Connecticut Residents: Similar consumer rights apply under the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Utah Consumer Privacy Act (UCPA), and Connecticut Data Privacy Act (CTDPA), including rights to access, delete, correct, and opt out of certain processing.
To exercise state-specific rights, email grizzlypinesaas@proton.me with "[State] Rights Request" in the subject line.
7.2 Identity Verification
To process data rights requests, we may require:
- Your registered email address
- Your driver account identifier, if applicable
- Government-issued identification for high-risk requests (such as deletion or full data export)
We will respond within 45 days, or within the timeframe required by applicable state law. For urgent law enforcement or security matters, verification may occur after initial disclosure when permitted by law.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will give 30 days' notice of material changes by email or in-app notice. Continued use of the Services after the effective date constitutes acceptance of the revised policy.
9. Contact
Grizzly Pine Software LLC is the data controller for platform account data and Solo Workspace data. For privacy requests, account support, and general service inquiries, contact grizzlypinesaas@proton.me.
For formal legal notices and Terms of Service inquiries, contact grizzlypinelgl@proton.me. Do not direct legal correspondence to Brass Buffalo Holdings.