Version 1.0 · Effective August 30, 2026
1.1 Eden One is operated by Marius Cojocaru, an individual trader established in the Republic of Moldova.
1.2 Contact: hello@edenone.app, or Telegram @eden_one_support.
1.3 This policy explains what personal data we handle, on what basis, where it is stored, who can reach it, and how long it is kept.
2.1 Eden One handles personal data in two different capacities, and your rights depend on which applies.
2.2 Account data: we are the controller. This is data about the people who hold Eden One accounts: name, email address, company and role, sign-in records, support correspondence and billing correspondence. We decide how it is used, and sections 3, 8 and 10 apply.
2.3 Customer data: we are the processor. This is everything a carrier enters or uploads to run its business: loads, brokers, drivers, trucks, documents, invoices and settlements. The carrier is the controller. It decides what is collected and why; we process it only to provide the Service. Section 4 applies.
2.4 If you are a driver, dispatcher or other employee asking about information held about you inside a carrier's account, that carrier is responsible for answering. We will assist the carrier and will direct your request to them.
3.1 Given to us: name, email address, the company you belong to, and the role assigned to you.
3.2 Generated by use: sign-in times, IP address, browser and device type, pages requested, and errors recorded by the system.
3.3 Correspondence: messages you send us by email or Telegram, and the record of our replies.
3.4 Billing: the fact and status of your subscription. Card details are handled by the payment provider and are never received or stored by us.
3.5 We use this data to provide and secure the Service, to authenticate users, to diagnose faults, to invoice, to comply with legal obligations, and to contact account owners about changes that affect them. The legal bases are performance of the contract, our legitimate interest in operating and securing the Service, and compliance with law.
3.6 We do not run advertising networks or cross-site analytics, and we do not send marketing email to people who have not asked for it.
4.1 We process customer data on the carrier's instructions, given through use of the Service, and for no other purpose.
4.2 Customer data can include personal data about individuals who are not our customers, principally drivers. The categories the Service is designed to hold include:
(a) identity and contact details: name, telephone number, personal email address;
(b) licence data: commercial driver's licence number, issuing state, and expiry date;
(c) employment data: hire date, pay type and pay rate, settlement records;
(d) uploaded documents, which by design include commercial driver's licence images, medical examiner's certificates, motor vehicle records, drug and alcohol test results, employment applications and insurance certificates;
(e) vehicle data that may identify an individual indirectly: VIN, plate and registration details.
4.3 Some of this is sensitive. Drug and alcohol test results and medical examiner's certificates concern health. Motor vehicle records concern driving history. The carrier is responsible for having lawful authority to collect and store these, for notifying the individuals concerned, and for limiting who inside its own organisation can see them using the roles provided.
4.4 We do not sell customer data, disclose it to other carriers, or use it to train machine learning models.
4.5 A carrier may request a separate data processing agreement at any time.
5.1 The database, authentication records and every uploaded document are stored on Supabase infrastructure in the Central EU region, Frankfurt, Germany.
5.2 Backups run daily.
5.3 Data is therefore held under European data protection standards. Customers whose contracts or regulators require storage inside the United States should tell us before signing up.
5.4 Some processing necessarily occurs outside the European Economic Area. Support is provided from Moldova, and email delivery and payment processing involve providers operating in the United States. Where personal data is transferred outside the EEA, we rely on the transfer mechanisms available under the GDPR, including standard contractual clauses entered into by the relevant provider.
6.1 Every company that processes data on our behalf is listed, with what it handles and where it operates, on the subprocessors page.
6.2 We will notify account owners before adding a provider that will handle customer data.
6.3 The payment provider acts as merchant of record. It receives billing information directly and receives no operational data.
7.1 We are not a member of any customer's company within the Service. Our account does not appear in a carrier's membership list and cannot read its loads, rates, brokers, drivers or documents. This is enforced by database-level access rules rather than by application code.
7.2 Support operates at three levels:
(a) Level 0, questions. Most issues are resolved from a description or screenshot supplied by the customer.
(b) Level 1, metadata. We can see which companies exist, how many members they have, what roles are held, when a user last signed in, and errors recorded by the system. This does not include operational data.
(c) Level 2, customer data, with permission. Where an issue cannot be resolved otherwise, we ask the account owner, explain what needs to be examined, and access it for a limited period. We access records under our own identity. We do not sign in as a customer's user.
7.3 Level 2 access does not occur without the account owner's knowledge.
7.4 Personnel at our infrastructure providers hold technical access to the systems on which data is stored, as is the case with any hosted software. Their own policies and contractual commitments govern that access.
8.1 Each company's data is isolated by rules enforced in the database on every query, not by checks in application code. Access depends on membership and role. A user who has been invited but has not accepted cannot read any data.
8.2 Data is encrypted in transit. Passwords are stored only as irreversible hashes.
8.3 Documents are held in a private storage bucket, scoped by company, and served through short-lived signed links.
8.4 We hold no SOC 2 report and no ISO certification, and we do not claim otherwise.
8.5 Where a personal data breach affecting customer data occurs, we will notify the affected account owners without undue delay and provide the information they need to meet their own obligations.
8.6 Vulnerability reports may be sent to hello@edenone.app. We will not pursue anyone who reports an issue in good faith and allows a reasonable period for it to be fixed.
9.1 While a subscription is active, data is retained for as long as the Service requires it.
9.2 When a subscription ends, for any reason: the account is read-only for 30 days, and customer data is deleted within 60 days of the end of the subscription. Deletion may be requested earlier by the account owner.
9.3 Encrypted backups may retain copies until they expire on their ordinary cycle.
9.4 Customers are responsible for exporting records within the read-only period. Record-retention duties imposed on carriers by their own regulators do not extend this schedule. A longer period may be agreed in writing on request made before the period expires.
9.5 Account data and correspondence may be retained after deletion of customer data where required for legal, accounting or tax purposes, and for no longer than those purposes require.
10.1 Where we are the controller, you may ask us to provide a copy of your personal data, correct it, delete it, restrict or object to its processing, or provide it in a portable form. Write to hello@edenone.app.
10.2 We will respond within one month, and will tell you if we need longer.
10.3 Where we are the processor, requests should be made to the carrier that holds the account.
10.4 If you are in the European Economic Area or the United Kingdom, you may complain to your national supervisory authority. Because data is hosted in Germany, we apply the same standard to all users regardless of location.
10.5 There is no charge for exercising these rights.
11.1 We disclose data to a public authority only where compelled by an order that is legally binding on us in the jurisdiction where we operate.
11.2 We will notify the affected account owner unless prohibited by law.
11.3 We do not respond to informal requests for customer data from any party.
12.1 The Service uses cookies that are strictly necessary to keep you signed in and to maintain your session. It does not use advertising or tracking cookies.
13.1 Eden One is business software, is not directed at anyone under 18, and we do not knowingly collect data from minors.
14.1 We may update this policy. Where a change materially affects how personal data is handled, account owners will be notified before it takes effect.
14.2 The version and date at the top identify the current text. Each earlier version is retained in our public repository.
hello@edenone.app · Telegram @eden_one_support