Privacy Policy

Last updated: February 9, 2026

Applies to: www.dispotag.com, app.dispotag.com, APIs, and related services operated by DispoTag.com, Inc. ("DispoTag," "we," "us," or "our").

Quick summary. We collect what we need to operate our website, sell and support our shipment‑tracking products, and provide related services. We don’t sell or share personal information — including mobile device data — for marketing or advertising purposes. Customers control the tracking data their deployments generate. You can manage cookies and advertising preferences via our cookie banner and settings.

1) Who we are & how to contact us

2) Scope

This policy describes how we handle personal information when you:

This policy does not apply to third‑party services we don’t control (e.g., carriers, app stores, payment processors, analytics providers). Their practices are governed by their own privacy policies.

3) Personal information we collect

3.1 Website visitors

3.2 Account holders & business contacts

3.3 End recipients & tracking subjects

Our customers may use DispoTag devices for shipments. In these contexts, customers are the controllers of any personal information they collect about recipients, consignees, drivers, or other individuals. We act as a processor/service provider and handle such data per our contracts and this policy. Data may include:

Customer responsibility: Customers must ensure they have a lawful basis to collect, disclose, and use personal information with our services and must provide any required notices to affected individuals.

3.4 Optional integrations

If you connect third‑party services (e.g., ecommerce, ERP, carrier portals), we will process the data those services send to us in order to provide the integration.

3.5 Mobile & device data

When you use our mobile applications, websites on a mobile device, or interact with DispoTag hardware, we may collect:

We do not sell, share, rent, or disclose mobile device data — including device identifiers, precise or approximate location data, or app usage data — to third parties for their own marketing, advertising, or promotional purposes. Mobile data is used solely to operate, secure, and improve our products and services.

4) How we use personal information

We may aggregate or de‑identify data and use it for benchmarking, analytics, or to improve our services. Aggregated/de‑identified data is not intended to identify you.

5) Our legal bases (EEA/UK)

6) Cookies, analytics, and ads

Global Privacy Control (GPC): Where legally required, we honor browser‑level GPC signals as an opt‑out of sale/sharing for the browser sending the signal.

Mobile advertising & tracking: We do not share mobile device identifiers (such as IDFA or GAID) with ad networks or data brokers for cross‑app tracking or targeted advertising. If we use analytics SDKs in our mobile applications, they are configured to support our own product improvement only — not to build advertising profiles or enable third‑party ad targeting.

7) When we disclose information

We do not sell or share personal information for money or other valuable consideration. This includes mobile device data such as device identifiers, location data, and app usage information — none of which are sold, shared, or made available to third parties for marketing, advertising, or promotional purposes. If we engage in targeted advertising or cross‑context behavioral advertising on our websites, you can opt out as described above; such activity does not involve the sale or sharing of mobile device data.

8) International data transfers

We may transfer, store, and process information in countries other than where it was collected. When transferring personal data from the EEA/UK/Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and supplementary measures, or other lawful mechanisms.

9) Data security

We implement reasonable and appropriate technical and organizational measures designed to protect personal information, including encryption in transit, access controls, logging, and regular backups. No system is 100% secure; we encourage you to use strong, unique passwords and enable multi‑factor authentication where available.

10) Data retention

We retain personal information for as long as necessary to fulfill the purposes outlined in this policy, including to meet legal, accounting, or reporting obligations. Customer‑generated tracking data is retained according to the customer’s chosen service tier:

Retention may be extended where required by law or to establish or defend legal claims.

11) Your privacy choices & rights

11.1 Email & marketing

11.2 SMS Terms and Conditions

Upon messaging opt‑in, the end user agrees to receive messages from DispoTag regarding general communications and customer support.

If you need assistance or have questions about our SMS service, reply with HELP to any SMS message you receive, or contact our customer support team at (818) 698‑8307.

11.3 Cookies & advertising preferences

11.4 U.S. state privacy rights

Depending on your state of residence, you may have rights to know/access, correct, delete, opt out of sale/sharing/targeted advertising and certain profiling, and appeal a decision if we deny your request. To exercise rights, use our Privacy Request Portal (if available) or contact us using the information provided on our website.

11.5 EEA/UK rights

Where GDPR/UK GDPR applies, you may request access, correction, deletion, restriction, portability, and object to processing where our basis is legitimate interest. Where processing is based on consent, you may withdraw consent at any time.

12) Children’s privacy

Our services are not directed to children under 13 (or the age required by local law). We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us so that we can take appropriate steps.

13) Customer responsibilities as controller

14) Payment processing

We use third‑party payment processors, including Stripe, to process payments. These processors collect and use payment data under their own privacy notices. We receive a limited set of information (e.g., last4, card brand, status) sufficient for records, fraud prevention, and refunds.

15) Third‑party links & services

Our services may contain links to or integrations with third‑party websites or platforms. We are not responsible for their privacy practices. Review their policies before sharing personal information.

16) Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by posting the updated policy and updating the “Last updated” date, and, where required, by additional notice.

17) Region‑specific disclosures

California (CPRA)

Virginia/Colorado/Connecticut/Utah and other U.S. state laws

We process personal data as a processor/service provider on behalf of customers and as a controller for our own business operations. You have the rights listed above.

EEA/UK/Switzerland

Where we act as a processor, we do so under a DPA with customers. For controller activities (e.g., website analytics, marketing), our legal bases are described earlier in this policy.

18) Cookie Notice (summary)

19) Data Processing Addendum (processor terms) – overview