Privacy Policy
Effective Date: September 5, 2026
This Privacy Policy explains how PLACE STARS, INC. d/b/a Doft Dispatch (“Doft Dispatch,” “Doft,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you access or use our dispatch management platform, websites, applications, and related services, including https://dispatch.doft.com (collectively, the “Service”).
Doft Dispatch is a B2B SaaS platform for trucking carriers, dispatchers, and related transportation businesses. The Service may be used to manage dispatch operations, broker rate confirmations, driver location sharing, load documents, invoices, payments, and related business records.
Our contact information:
PLACE STARS, INC.
1887 Whitney Mesa Dr #9277
Henderson, NV 89014
Email: support@doft.com
1. Scope
This Privacy Policy applies to information we process in connection with the Service.
Where a business customer uses Doft Dispatch to manage information about its own drivers, employees, contractors, customers, brokers, shippers, consignees, or other third parties, Doft Dispatch generally acts as a service provider or processor on behalf of that business customer. In those cases, the business customer is responsible for providing any required notices and obtaining any required consents from those individuals.
2. Information We Collect
We may collect the following categories of information:
Account and Login Information
This may include name, business name, email address, phone number, login credentials, password hashes, account settings, workspace membership, role permissions, and authentication data.
Business and Dispatch Data
This may include carrier profiles, dispatcher records, driver records, truck and trailer information, broker information, load details, pickup and delivery information, rate confirmations, bills of lading, proof of delivery documents, invoices, uploaded files, notes, messages, and other business records entered, uploaded, imported, or generated through the Service.
Connected Accounting Software
If you connect QuickBooks Online or Xero, we send the invoices and expenses you create in Doft to the connected book. We read the company details and accounting references needed to post them, including contacts or customers, items and accounts, and read back the payment status and payment date of invoices created in Doft. We do not read or store unrelated transactions or access your bank data. A workspace has one active accounting connection at a time.
Marketing Leads
If you leave your email address on our marketing site to receive a product walkthrough, we store that address together with the time you submitted it. We send one email and no follow-up series. The address is kept for up to 12 months from submission and is then deleted; you can remove it at any time before that through the unsubscribe link in the email, which deletes the record rather than archiving it. A lead address is not linked to any account and is not used for advertising beyond the one email you asked for.
Driver and Load Tracking Information
A driver reaches the Service through a personal access link issued to them by the carrier they work for. The link is not limited to a single load and does not expire on its own; it remains valid until the carrier turns it off. It opens only the loads that driver is assigned to.
If a driver starts location sharing from that link, we may collect location data associated with that tracking session for the relevant load. Location is collected only while a tracking session is running — the driver starts it and can stop it, and it also stops when the load is delivered. Tracking is intended for dispatch and load visibility purposes. Doft Dispatch does not use driver location for advertising.
AI Document Processing Data
The Service may use artificial intelligence and machine learning tools to extract or structure information from uploaded documents, including broker rate confirmations, load documents, invoices, and related files. This processing may include document text, metadata, and extracted fields needed to provide the Service.
Usage and Technical Information
We may collect information about how users interact with the Service, including IP address, device type, browser type, operating system, pages viewed, features used, log data, diagnostics, error reports, session information, and approximate location derived from IP address.
Payment Information
Payments are processed by Stripe. We do not store full payment card numbers. We may receive limited payment-related information from Stripe, such as customer ID, subscription status, payment status, billing email, card brand, last four digits, and invoice history.
Communications
If you contact us for support, sales, onboarding, or account management, we may collect the contents of those communications and related contact information.
When you send a support request from within the Service, we automatically include technical context to help us answer it: the page you were on, the version of the application you were running, and your browser's identification string. This is shown to you in the request window before you send it.
You may attach a file to a support request — a screenshot, a document, or similar. You are responsible for what a file you send us contains. A screenshot of the Service may show information about drivers, brokers, rates, or other people who are not our users, and you should send only what is needed to explain the problem. We use attachments to answer your request and for no other purpose.
3. How We Use Information
We use information to:
- provide, operate, maintain, and improve the Service;
- create and manage accounts and workspaces;
- process dispatch operations, load data, documents, invoices, and related business records;
- perform AI-assisted document extraction and data entry automation;
- provide driver tracking and load visibility features;
- send service emails, alerts, SMS messages, and administrative notices;
- process subscriptions, payments, invoices, and billing;
- provide customer support and troubleshoot issues;
- secure the Service, prevent fraud, monitor abuse, and enforce our Terms of Service;
- analyze usage, reliability, and performance;
- compute aggregated broker payment statistics across customer accounts, as described in our Terms of Service;
- read the payment status of invoices you created in Doft from accounting software you connect (QuickBooks Online, Xero); these payment dates are used the same way as broker payment notices, including in the aggregated broker payment data, and mark the invoice paid in Doft automatically;
- comply with legal obligations, law enforcement requests, tax, accounting, and regulatory requirements;
- protect the rights, property, and safety of Doft Dispatch, our users, and others.
4. How We Disclose Information
We do not sell personal information. We do not use personal information for cross-context behavioral advertising.
We may disclose information as follows:
Service Providers and Sub-Processors
We use third-party service providers and sub-processors to operate the Service. These providers may process information only as needed to provide services to us and are subject to contractual obligations.
Our current sub-processors include:
- Amazon Web Services (AWS) — cloud hosting, storage, infrastructure, security, and related cloud services, including AWS Bedrock for AI processing;
- Resend — transactional and service email delivery;
- Stripe — payment processing, billing, and subscription management;
- Twilio — SMS and communications services;
- Sentry — error monitoring, diagnostics, and application reliability;
- HERE — maps, geocoding, routing, and location-related services;
- PostHog — product analytics to understand which product actions work and where users encounter problems. We send account and record identifiers, action and outcome categories, and timing information. This can include subscription and invoice status, without monetary amounts, card or bank data. For drivers, we send limited operational observations through our own service, without tracking-page addresses, access links, location coordinates, messages or document content.
We may update this list from time to time as our Service evolves.
Business Customers and Workspace Users
Information in a workspace may be available to the business customer that controls the workspace and to users authorized by that customer, depending on their roles and permissions.
Aggregated broker payment data, in the form described in our Terms of Service, is shown to other customers.
Legal and Compliance
We may disclose information if required to do so by law, subpoena, court order, legal process, government request, or when we believe disclosure is necessary to protect our rights, users, business, safety, or the security of the Service.
Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, information may be disclosed or transferred as part of that transaction.
5. Data Isolation and Security
We use administrative, technical, and organizational safeguards designed to protect information, including:
- workspace-level data separation;
- HTTPS encryption in transit;
- encryption at rest where supported by our infrastructure providers;
- role-based access controls;
- authentication controls;
- signed or time-limited links for certain file downloads;
- access logging, monitoring, and error diagnostics;
- restricted internal access based on business need.
One deliberate exception to workspace-level separation is aggregated broker payment data: a median number of days and a count of invoices per broker, computed across customer accounts, with no customer identified or named and no customer count stated.
No system is completely secure. We cannot guarantee absolute security, but we work to protect the Service using commercially reasonable safeguards.
6. Data Retention
We retain information for as long as reasonably necessary to provide the Service, maintain business records, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and support legitimate business operations.
If a customer deletes an account or workspace, we will delete or anonymize associated data within a reasonable period, unless retention is required or permitted for legal, tax, accounting, fraud prevention, backup, security, or dispute-resolution purposes.
When an account is destroyed, the documents uploaded to it are permanently erased from our document store, including any earlier versions of them. This is automatic and we hold no way to recover them.
Two things are deliberately kept, and we would rather say so than leave them inside that exception.
The first is your own user record — your name, email address and password hash. Deleting a workspace removes the workspace and its business records; it ends your membership of that workspace and marks your user record deleted, but the record itself remains, so that a person who belongs to more than one account does not lose the others, and so that we can tell a returning sign-up from a new one. If you want your user record itself removed, ask us at support@doft.com.
The second is our analytics archive. Copies of some uploaded documents were written to a separate archive store before an account was deleted. Those copies are kept indefinitely and are not removed when an account is deleted.
If you create an account and never complete payment for it, we keep it for 14 days so you can come back and finish. After that the account is marked deleted, and it is then permanently deleted under the same rules as any other deleted account. Nothing is charged for an account that was never paid for. This automatic clearing out of unpaid sign-ups begins when paid subscriptions go live; until then, an unpaid account is removed if you ask us at support@doft.com.
We keep a registry of broker identifiers — USDOT and MC numbers, which are public FMCSA registration numbers. It is not tied to any customer and is retained after a customer's account is deleted.
Support requests
Files attached to a support request, and the original copies of any emails exchanged within one, are kept for 12 months and then deleted. The text of the conversation is kept indefinitely.
Support requests belong to the person who sent them rather than to an account, and this is a deliberate exception to the paragraph above. A request survives that person being removed from an account, and it survives the account itself being deleted — a request may well be about exactly those events, and losing it with the account would leave nobody able to answer it. When an account is deleted, the link between it and any request is removed; the request stays with its author. You can ask us to delete a request you sent, including anything you attached to it.
Email you forward to us
If you connect a mailbox by forwarding, everything you forward reaches us. We keep only the messages that carry a document — a rate confirmation, a bill of lading, an invoice, and so on. Everything else, ordinary correspondence included, is discarded on arrival: we do not store its body, its subject or its sender.
There is one exception, and it is there so we can answer "where did my email go?". When a forwarded message cannot be matched to an account at all — most often because the mailbox it was sent to has been disconnected — we do not keep the message, but we do note that it arrived: the address it was sent to, the sender, the subject line, and the reason we could not place it. That note is kept for 30 days and then deleted.
There is a second exception, and it is about money. A broker's accounts-payable system often sends its payment notice as an ordinary letter — the payment details in the body, nothing attached. So a message with no document is kept when, and only when, its subject reads as a payment notice and it comes from an address we already correspond with about invoices: a broker's billing address, one of its contacts, or an address we have sent an invoice to. Everything else with no document is still discarded on arrival, unread. A message kept this way is kept as we keep any message that carries a document.
An email with attachments that has never been linked to a load or a financial record is eligible for deletion after 7 days from receipt. Deletion runs during nightly cleanup and removes its files and stored file versions. A link through the email, its conversation, or one of its documents to any load that has not been deleted keeps the source, even when that load is cancelled.
After the last such protection ends, including when the last linked load is deleted, we keep the email and its files for at least 7 more days. Relinking it starts a new protection period. Financial records and payment or remittance evidence can require longer retention, including after an invoice is paid or cancelled; we do not promise to delete those records after seven days. Uncertain historical links are retained for review. Emails without attachments remain outside this automatic cleanup policy. File previews follow the retention of their originals.
We keep an activity log recording actions taken in an account — who created or changed a load, changed a status, signed in, or removed a record — for as long as the account exists. It is deleted together with the account.
Backups and logs may persist for a limited period before being deleted or overwritten according to our normal retention practices.
7. Cookies and Similar Technologies
We use cookies and similar technologies that are necessary to operate the Service, including for authentication, session management, language preferences, security, and user settings.
We also use first-party analytics storage (provided by PostHog) to understand how the Service is used — which pages are visited and which product actions are taken. Analytics identifiers are tied to your account and are not used for advertising. Driver pages do not use PostHog cookies, persistent analytics identifiers, automatic click recording or session replay. Limited driver observations use existing operation identifiers or a temporary visit identifier and are forwarded by our service after validation.
On our public marketing pages we also collect anonymous usage events from visitors who do not have an account — for example that a pricing card, a demo button, or a question in the FAQ was clicked, and how far the page was scrolled. These events carry a random identifier that is not linked to a name or an email address, are not used for advertising, and never include the content you type. We use them only to understand which parts of the page are read and used.
We do not use advertising cookies or third-party behavioral advertising cookies in the Service.
8. AI Processing
Doft Dispatch may use AI services, including AWS Bedrock, to extract, classify, summarize, or structure information from documents and business records submitted through the Service.
AI outputs may be incomplete, inaccurate, or require human review. Users are responsible for reviewing extracted data before relying on it for dispatch, billing, compliance, or operational decisions.
We do not use customer business data to train public AI models. Where AI services are provided by third-party sub-processors, those services process data to provide the requested Service functionality.
9. Driver Location and Tracking
Driver location features are intended to support load tracking, dispatch visibility, delivery coordination, and operational recordkeeping.
Business customers are responsible for ensuring that drivers and other tracked individuals receive appropriate notice and, where required, provide consent before location tracking is used.
How long location data is kept. The location points recorded during a tracking session are part of the load's record. We do not delete them on a schedule of their own, and there is no separate expiry for them: they are kept for as long as the account exists and are removed with it, under the retention rules in Section 6. Location reporting stops when the tracking session ends — the driver stops it, the load is delivered, or the carrier turns the driver's access off — but the points already recorded remain part of that load's history.
Doft Dispatch does not sell driver location data and does not use driver location data for advertising.
10. International Transfers
Doft Dispatch is operated from the United States. Our primary hosting infrastructure is located in the United States, including AWS US regions.
If you access the Service from outside the United States, your information may be transferred to, stored in, or processed in the United States or other jurisdictions where our service providers operate. These jurisdictions may have data protection laws different from those in your country.
Where required, we use appropriate safeguards for international data transfers.
11. Your Privacy Rights
Depending on your location and applicable law, you may have rights to:
- access personal information we hold about you;
- request correction of inaccurate information;
- request deletion of information;
- request a copy or export of information;
- object to or restrict certain processing;
- opt out of certain processing, where applicable;
- appeal a denied privacy request, where applicable.
Doft Dispatch provides account data export and account deletion features in Settings where available.
You may also submit a request by contacting us at support@doft.com. We may need to verify your identity and authority before fulfilling a request.
If your information is controlled by one of our business customers, we may refer your request to that customer or process the request according to that customer’s instructions.
12. California and US State Privacy Rights
Residents of California and certain other US states may have additional rights under applicable privacy laws.
For California residents, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), may provide rights to know/access, delete, correct, obtain a copy of personal information, opt out of sale or sharing, limit the use of sensitive personal information, and be free from discrimination for exercising privacy rights.
Doft Dispatch does not sell personal information and does not share personal information for cross-context behavioral advertising.
We may collect the following categories of personal information as defined by California law:
- identifiers, such as name, email address, phone number, account ID, business contact information, IP address, and device identifiers;
- commercial information, such as subscription status, invoice records, payment status, and business transaction records;
- internet or electronic network activity information, such as usage logs, access logs, device information, and interaction with the Service;
- geolocation information, such as driver or load tracking location when tracking is active;
- professional or employment-related information, such as carrier, dispatcher, driver, or business role information entered into the Service;
- sensitive personal information, where applicable, such as account login credentials and precise geolocation used for active load tracking.
We use these categories for the purposes described in this Privacy Policy, including providing the Service, security, support, billing, legal compliance, and business operations.
We disclose these categories to service providers and sub-processors as described above. We do not knowingly sell or share personal information of individuals under 16 years of age.
To exercise applicable US state privacy rights, contact us at support@doft.com.
13. Email and SMS Communications
We may send administrative, transactional, billing, security, and service-related messages by email or SMS.
Where required, marketing emails will include an unsubscribe mechanism. SMS messages may include opt-out instructions such as replying STOP. Some service messages are necessary to operate your account and may not be fully opt-out unless you stop using the Service.
SMS notifications to drivers are operational: a link to view and track an assigned load, a notice when a driver is taken off a load or a load is cancelled, and a reminder when a delivery document (proof of delivery) is still missing. Consent for these messages is given by the driver themselves. A carrier or dispatcher may invite a driver to the Service, but cannot agree on their behalf: the driver opens their own invitation page, confirms their mobile number, and ticks a separate, optional box to receive text messages. Declining costs them nothing — they can still be assigned loads, and receive the same information by email. A driver may opt out at any time by replying STOP, or reply HELP for help.
Message frequency varies with the loads assigned to you. Message and data rates may apply.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be sold or shared with any third party; phone numbers and message content are shared only with service providers acting on our behalf to deliver the messages (for example, our SMS provider, Twilio).
14. Children
The Service is intended for business users and is not directed to children under 16. We do not knowingly collect personal information from children under 16.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by email, in-app notice, or by updating the effective date above.
Your continued use of the Service after an updated Privacy Policy becomes effective means you acknowledge the updated Privacy Policy.
16. Contact Us
For privacy questions or requests, contact:
PLACE STARS, INC. d/b/a Doft Dispatch
1887 Whitney Mesa Dr #9277
Henderson, NV 89014
Email: support@doft.com