This Data Processing Addendum ("DPA") forms part of the BoxMaster Terms of Service between Herrera Master Solutions LLC ("BoxMaster," "we," "us") and the Customer that accepted them.
You accept this DPA when you accept the Terms of Service. No separate signature is required. If you need a countersigned copy for your records, write to us and we will provide one.
If anything in this DPA conflicts with the Terms of Service, this DPA controls for matters of data protection.
When you use BoxMaster, you put personal information into the platform: your drivers' names, license numbers, photographs, hours-of-service logs, and more.
That information is yours. We process it for you and on your instructions.
This DPA writes down exactly what that means, what we are allowed to do with it, what we are not, and what happens when the relationship ends. It exists because California law requires a written contract with these terms before a business can share personal information with a service provider without that sharing being treated as a sale.
Customer Personal Information — personal information contained in Customer Data, as defined in the Terms of Service, that we process on your behalf.
Business and Service Provider have the meanings given in the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). For Customer Personal Information, you are the Business and we are the Service Provider.
Consumer — an individual whose personal information is processed. In practice this means your drivers, your dispatchers, your administrators, and the contacts at other companies whose names and phone numbers appear in your routes.
Subprocessor — a third party we engage to help us provide the Services, and that processes Customer Personal Information in doing so.
Process and Processing — any operation performed on personal information, including collection, storage, use, disclosure, and deletion.
You are the Business. You decide what personal information goes into the platform, why, and what happens to it. You are responsible for having the right to put it there and for giving your people whatever notices the law requires.
We are the Service Provider. We process Customer Personal Information only to provide the Services to you, and only as this DPA permits.
For our own account and billing records — the name and email of the person who signed up, the company name, the subscription history — we act as a Business in our own right. That processing is described in our Privacy Policy, not here.
We certify that we understand the restrictions in this section and will comply with them. That sentence is required by California law and we mean it literally.
| Subject matter | Providing the BoxMaster fleet management platform |
| Duration | For as long as you have an account, plus the retention period in Section 9 |
| Nature and purpose | Dispatching routes, recording deliveries, logging hours of service, tracking vehicles, calculating pay, issuing invoices, and producing the records motor carriers are required to keep |
| Categories of Consumer | Your administrators, dispatchers, and drivers. Contacts at pickup and delivery locations whose names and phone numbers you enter. |
| Categories of personal information | Identifiers (name, email, phone). Government identifiers (driver's license number and state). Biometric-adjacent images (face photographs). Professional information (role, employment records, qualification documents). Geolocation (positions recorded by electronic logging devices). Commercial information (pay, invoices). Internet activity (IP address, session records). Signature images. |
Some of what you put into BoxMaster qualifies as sensitive personal information under the CCPA — driver's license numbers, and photographs that may be used to identify a person.
We process it only to provide the Services, and for no other purpose. We do not use it to infer characteristics about anyone. Under the CCPA, that limited use means Consumers do not have a right to limit our use of it, because we are not using it in any of the ways that right addresses.
If a Consumer contacts you with a request to access, delete, or correct their personal information, and you need our help to answer it, ask us. We will provide reasonable assistance, using the tools available in the platform, at no additional charge.
If a Consumer contacts us directly about information we process on your behalf, we will not answer it ourselves. We will tell them to contact you, and we will tell you that they contacted us — within five business days.
Some records cannot be deleted on request, and you should know this before promising anything to a driver. Federal law requires motor carriers to retain records of duty status and their supporting documents for six months (49 CFR 395.8(k) and 49 CFR 395.22(i)). A deletion request does not override that obligation, and it is your obligation, not ours.
You authorize us to engage the subprocessors listed below. Each is bound by written terms no less protective than this DPA, and we remain responsible to you for what they do.
| Subprocessor | What it processes | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage. All Customer Personal Information is stored here. | United States |
| Netlify | Application and website hosting | United States |
| Stripe | Subscription payment processing. Receives the account holder's email and company name. Card data goes directly to Stripe and never passes through our systems. | United States |
| Resend | Transactional email delivery, including invoices sent to your clients | United States |
| OpenAI | AI extraction from load documents and fuel receipt photographs. Does not receive driver license images, face photographs, signature images, or qualification documents. | United States |
| Maps and routing. Receives pickup and delivery addresses to calculate mileage. | United States | |
| Intuit | QuickBooks accounting sync. Only if you connect it. Receives client details, invoices, expenses, and driver pay records including driver names. | United States |
| IOSiX | Electronic logging device hardware and its telematics data | United States |
We will give you at least 30 days' notice before adding a new subprocessor or replacing one, by email to the address on your account.
If you object to a new subprocessor on reasonable data protection grounds, tell us within those 30 days. We will work with you in good faith to find an alternative. If we cannot, you may terminate your subscription and we will refund any prepaid fees for the period after termination — an exception to the no-refund rule in the Terms of Service, and the only one.
OpenAI does not use data submitted through its API to train its models. It retains inputs and outputs for up to 30 days to detect abuse, then deletes them. We do not opt in to any program that would permit training on your data.
We maintain administrative, technical, and physical safeguards appropriate to the personal information we process, including:
You may request a summary of our security practices at any time.
Export your data before you close your account. While your account is active you can export from the Data Center at any time. After it closes, you cannot.
When your account closes, the following applies:
Access ends immediately. No one from your company can sign in.
Customer Personal Information is retained for at least six months. This is not our preference — it is the retention period federal law imposes on motor carriers for records of duty status and their supporting documents (49 CFR 395.8(k) and 49 CFR 395.22(i)). Neither of us can shorten it.
After that period, we delete it permanently. There is no backup and no recovery. Deletion is performed manually and reviewed before it runs, so it may occur some time after six months have elapsed — but never before.
During the retention period you may request a copy of your records. Write to us and we will provide them within 20 business days.
We may retain personal information for longer where the law requires it, or where it is subject to a litigation hold. If that happens we will tell you, and we will keep processing it only for that purpose.
If we become aware of a breach of security leading to the unauthorized acquisition of Customer Personal Information, we will:
Notifying the individuals affected is your obligation, because you are the Business and they are your people. We will support you in doing it.
We are separately subject to Utah's Protection of Personal Information Act, which requires us to investigate and, where misuse is likely, to notify affected Utah residents and — above certain thresholds — the Utah Attorney General and the Utah Cyber Center.
Once per twelve-month period, on 30 days' written notice, you may ask us for information reasonably necessary to confirm we are meeting our obligations under this DPA. We will respond in writing.
If a written response is not sufficient for your compliance obligations, we will work with you in good faith on an alternative — which may include a call with our technical staff or a review conducted under confidentiality.
We may take reasonable steps to verify that you are using Customer Personal Information consistently with your own obligations, as California law contemplates for a Business disclosing information to a Service Provider.
All processing takes place in the United States. We do not transfer Customer Personal Information outside the United States, and none of our subprocessors do so in providing the Services.
Because there is no international transfer, this DPA contains no Standard Contractual Clauses and no international transfer mechanism. We are stating that explicitly so that you do not go looking for a section that is not here.
If that ever changes, we will amend this DPA and give you notice before it takes effect.
This DPA is written around the CCPA because that is the U.S. state privacy law most likely to apply to your use of BoxMaster.
We are not subject to the Utah Consumer Privacy Act. It applies to businesses with at least $25 million in annual revenue that also meet a data volume threshold, and we meet neither.
If another state's privacy law applies to your operation and requires terms we have not included here, tell us. We will negotiate an amendment in good faith.
Term. This DPA takes effect when you accept the Terms of Service and continues until all Customer Personal Information has been deleted under Section 9.
Liability. Each party's liability under this DPA is subject to the limitations in Section 14 of the Terms of Service.
Changes. If we change this DPA in a way that materially affects your rights, we will notify account holders at least 30 days before it takes effect. Each version has a version number and an effective date, and we keep a record of which version each Customer accepted.
Order of precedence. Terms of Service, then this DPA, then the Privacy Policy — except that this DPA controls over the Terms of Service on matters of data protection.
Herrera Master Solutions LLC
3372 W Sanctuary Ct
Taylorsville, UT 84129
United States
Email: angelo@boxmaster2608.com
For data protection questions, subprocessor objections, audit requests, or a countersigned copy of this DPA.