Legal

Privacy Policy

Last updated · April 2026

Overview

Certflo, operated by Mesquite Dev LLC, collects only the data necessary to provide compliance document management for motor carriers. We do not sell your data, serve ads, or share information with third parties except as required to operate the Service.

Certflo is not affiliated with, endorsed by, or sponsored by FMCSA, the U.S. Department of Transportation, PHMSA, OSHA, EPA, or any other government agency. References to federal regulations are factual citations only.

Information We Collect

  • Account information - name, email address, and company details provided during signup.
  • Payment information - processed and stored by Stripe. We do not store credit card numbers on our servers.
  • Compliance documents - CDLs, medical cards, MVRs, certificates, and other files you upload. These are stored securely and encrypted at rest.
  • Usage data - page views, feature usage, and session duration to improve the Service. No third-party analytics trackers are used.

How We Use Your Data

  • To provide and maintain the Service, including document tracking, expiration alerts, and DQF binder exports.
  • To process payments via Stripe.
  • To communicate service updates, billing notices, and account-related information.
  • To improve the Service based on aggregate, anonymized usage patterns.

Data Storage and Security

All data is stored on infrastructure located in the United States. Documents are encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Each carrier's data is isolated at the database level using row-level security policies. Access is restricted by role-based permissions enforced at the data layer.

Third-Party Services

  • Stripe - payment processing. Subject to Stripe's Privacy Policy.
  • Hosting provider - infrastructure hosting. Data remains in the United States.

We do not use Google Analytics, Facebook Pixel, or any third-party advertising or tracking services.

Data Retention

Your data is retained for as long as your account is active. Accident register records are retained for a minimum of 3 years per 49 CFR 390.15 requirements. Upon account deletion, all data except legally required records is permanently removed within 30 days.

Your Rights

  • You may export your data at any time through the DQF binder export feature.
  • You may request deletion of your account and all associated data.
  • You may update your personal and company information through your account settings.

Cookies

Certflo uses only essential cookies required for authentication and session management. We do not use tracking cookies or third-party cookies.

Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via the email address on your account. The "Last updated" date at the top of this page reflects the most recent revision.

Contact

For privacy-related questions, contact us through the in-app messaging system or at the address associated with Mesquite Dev LLC.