Skip to content

Privacy

Privacy Policy

Last updated: April 10, 2026

Overview

The Compliance Dashboard at compliance.ucbureau.com (“the Service”) is operated by UC Bureau, a private company not affiliated with any government agency. This policy describes what information we collect, how we use it, and your rights.

Information We Collect

Without an account (guest users):

  • No personal information is collected or transmitted to our servers
  • All data you enter (deadlines, audit responses, carrier lookups) is stored locally in your browser using localStorage
  • We use Vercel Analytics for anonymous, aggregated usage statistics (page views, country). No cookies are set for this purpose
  • Microsoft Clarity may set cookies for session analytics (see “Session Analytics” below)

With an account (signed-in users):

  • Email address and password (your password is cryptographically hashed; we never store plaintext passwords)
  • Tool data you choose to save (deadlines, audit scores, records) is stored in Supabase with row-level security — only you can access your data
  • Documents you upload (insurance certificates, authority letters, medical cards, CDL copies, W-9s, and other compliance files) are stored in Supabase cloud storage. We store the file contents, file name, file size, upload date, and associated metadata. Maximum 50 MB total storage per account, 10 MB per file.

Automatically collected information:

  • IP address, browser type, operating system, and referring URL — collected by Vercel and Cloudflare
  • Used for rate limiting, security, and abuse prevention
  • Not used to identify individual users

Session analytics:

  • We use Microsoft Clarity to collect behavioral analytics. Clarity records anonymized session replays (mouse movements, clicks, scrolls, and page content visible during your session), generates heatmaps, and collects device/browser metadata.
  • Session recordings may capture on-screen content including text you type or documents you view.
  • We use this data solely to improve usability. We do not use Clarity recordings to extract or store personal information from your uploaded documents.
  • For more information, see Microsoft's Privacy Statement.

Carrier data:

  • USDOT and MC numbers entered for carrier lookup are sent to the FMCSA SAFER API through our server-side proxy
  • FMCSA carrier data retrieved through lookups is cached on our servers for up to 1 hour to improve performance. The cache contains only the public FMCSA data, not your identity or the fact that you performed the lookup. After 1 hour, cached data is automatically purged.
  • All carrier data displayed is public information from federal databases

Shareable Carrier Packets

When you generate a shareable Carrier Packet link, the documents and data you select become accessible to anyone with that link for up to 30 days.

This is a user-initiated action. We do not share your documents with third parties except through links you choose to create.

Recipients are not bound by this privacy policy and may use shared data at their discretion.

Cached or indexed copies may persist beyond the 30-day expiry.

Email Communications

UC Bureau sends compliance-related email notices to motor carriers whose contact information appears in publicly available FMCSA new authority filing records. These are federal public records available to any member of the public.

Under CAN-SPAM (15 U.S.C. Section 7701 et seq.), prior consent is not required for commercial email, provided the message: (a) is not deceptive in its header or subject line, (b) identifies itself as a commercial message, (c) includes a valid physical postal address, and (d) includes a functioning unsubscribe mechanism.

All emails from UC Bureau comply with these requirements. You may unsubscribe from any email using the link included in every message. We honor all unsubscribe requests within 10 business days. Once unsubscribed, you will not receive further emails from UC Bureau.

Third-Party Services

The Service integrates with the following third-party services:

  • FMCSA SAFER / QC API — to retrieve publicly available carrier data
  • Vercel — hosting and anonymous analytics
  • Supabase — authentication and data storage (signed-in users only)
  • Brevo — email delivery for transactional messages (account verification, password reset) and compliance deadline reminders. We share your email address with Brevo for this purpose.
  • Microsoft Clarity — behavioral analytics, session recordings, and heatmaps
  • Cloudflare — content delivery, DDoS protection, bot verification (Turnstile captcha). Processes IP address and browser metadata.

This Service contains affiliate links to third-party products (ELD providers, loadboards). Clicking these links may share referral data with those providers per their own privacy policies.

Cookies

Guest users: no first-party cookies are set. Signed-in users: a session cookie is set by Supabase for authentication purposes only.

Microsoft Clarity may set cookies to support session analytics, including session replay and heatmap functionality. You can disable Clarity tracking by using browser extensions that block analytics scripts (such as uBlock Origin or Privacy Badger).

Your Privacy Rights (California and Other States)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Request correction of inaccurate personal information
  • Opt out of the sale or sharing of your personal information

We do not sell or share your personal information as defined by the CCPA.

To exercise any of these rights, email admin@ucbureau.com with the subject line “Privacy Rights Request.” We will respond within 45 days.

Residents of Virginia, Colorado, Connecticut, Texas, Oregon, and other states with consumer privacy laws may exercise equivalent rights by contacting us at the same address.

Data Retention and Deletion

Guest data is stored in your browser and can be cleared at any time by clearing your browser storage.

For active accounts, we retain your data for as long as your account remains active.

Inactive accounts (no login for 24 consecutive months) may be flagged for deletion with 30 days' email notice.

Account holders may request deletion of their account and all associated data by emailing admin@ucbureau.com with the subject line “Account Deletion Request.”

Upon account deletion, we delete your data from our primary database and file storage within 30 days. Residual copies in automated database backups may persist for up to 30 additional days before being overwritten.

Data Portability

You may request a copy of your personal information and uploaded documents by emailing admin@ucbureau.com with the subject line “Data Export Request.” We will fulfill export requests within 45 days.

Data Security and Breach Notification

We implement reasonable administrative and technical safeguards to protect your information. In the event of a data breach affecting your personal information, we will notify affected users and relevant authorities in accordance with applicable state and federal law.

Children's Privacy

This Service is not intended for individuals under the age of 18. We do not knowingly collect information from children.

If we learn that we have collected information from a child under 13, we will delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at admin@ucbureau.com.

International Users

The Service is operated from and intended for use in the United States. If you access the Service from outside the US, your information will be transferred to, stored, and processed in the United States.

If you are located in the European Economic Area (EEA) or the United Kingdom, you may have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectification, erasure, restriction of processing, data portability, and the right to object. To exercise these rights, contact admin@ucbureau.com.

Our legal bases for processing your personal data include: your consent, performance of a contract (providing the Service to you), and our legitimate interests in operating and improving the Service.

Changes to This Policy

We may update this policy at any time. Changes will be reflected on this page with an updated date.

Contact

UC Bureau
1570 Via Del Rio, Corona, CA 92882
22 Massachusetts Ave NE, Washington, DC 20002
100 Wellington St W, Toronto, ON M5J 2R2
Phone: (513) 696-9027
admin@ucbureau.com