SearchFreightBroker.com
Find brokers Carrier sign inSign in

Legal

Privacy Policy

Last updated: July 16, 2026

Overview

searchfreightbroker.com provides carrier-driven broker search, review, reputation, and discussion tools. This Privacy Policy explains what information we collect, how we use it, and the choices available to users of the website and related services.

Information We Collect

We may collect the following categories of information when you use the service:

  • Account information: phone number, display name, username, profile photo, short bio, and company connection details you choose to provide.
  • Carrier and company information: USDOT number, company name, membership or profile details, and information used to connect a user to a carrier company.
  • Private carrier-verification requests: connected company and membership, role, selected verification method, official company email or public business phone, private relationship explanation, attestation, request status, expiration date, administrator checks, internal notes, carrier-facing message, bounded decision history, and any factual reconsideration reason, attestations, response target, status, and outcome. Private contact details, appeal details, internal account identifiers, administrator identity, checks, and decision notes are not displayed publicly.
  • Community content: reviews, ratings, discussion posts, comments, votes, related broker/facility/lane selections, payment timing details, and other information you submit about carrier operations or broker experiences.
  • Private pending-review changes: the current unpublished review, a bounded history of prior pending versions, edit count and timestamps, and the account used to make each change. Pending content and prior versions are used for moderation and platform integrity and are not displayed publicly unless the current review is later approved for publication.
  • Private community workspace: discussions you save, your current post/comment votes, your unpublished post workflow state, and ownership records used to provide My posts and Saved views.
  • Private community reports: the reported post or comment, reason, details, good-faith attestation, reporter account and carrier-company identity, status, internal moderation notes, and bounded decision history.
  • Private account-moderation records: warnings, strikes, contribution restrictions, reason categories, carrier-facing messages, private administrator notes, referenced content where applicable, expiration and decision times, one private appeal for the current action, and bounded action and appeal history. Public visitors do not receive these records.
  • Private saved-broker workspace: brokers you save, your Trusted, Watching, or Avoid label, private notes, per-broker daily, weekly, or manual-only monitoring cadence, pause state, monitoring snapshots, and acknowledgement state. This information is private to your account when you are signed in.
  • Private saved facility and lane workspace: public facilities and equipment-specific lane views you save, your Preferred, Watch, or Avoid label, private notes, and bounded copies of the public aggregate evidence shown when the item was synced.
  • Private saved-search workspace: universal-search query text you explicitly save, the selected company filter and evidence sort, a private note, and sync or deletion timestamps. Saved searches remain browser-local while signed out and private to your account when synced after sign-in.
  • Device-local recent search history: up to five successful submitted universal-search queries, the selected company filter and evidence sort, a bounded match count, and search time. This history stays in the current browser, is not account-synced or included in analytics content, can be cleared from search, and is cleared from the current browser during account deletion.
  • Private moderation reports: broker concern category or review-report reason, description, referenced review when applicable, booking-verification interaction stage, event date and first-hand confirmation when required, whether supporting records are available, submission and resolution timestamps, the carrier account and company identity used to submit the report, administrator evidence-review state, source category, internal notes, and bounded decision history.
  • Private broker-representative requests: broker identity, job title, requested verification route, official company email or public business phone, relationship explanation, authorization attestation, claim status, administrator decision history, and the account used to submit the request.
  • Broker responses and corrections: company-response drafts, associated broker and review, correction or dispute details, publication state, moderation history, the approved representative account, and one private legal-record reconsideration with its response target and decision. Only an approved response or neutral correction outcome is displayed publicly.
  • Private payment-evidence reports: broker identity, payment method, written terms, invoice and paid dates, calculated payment timing, selected redacted-record types, private notes, attestations, moderation status and history, and the submitting carrier account and company identity. This version records record availability but does not accept or store the supporting document itself.
  • Factoring partner aggregate administration: source registry details, public methodology attribution, data-use attestation, aggregate broker/source/window metrics, optional external batch identifiers, private source or import notes, administrator attribution, import state, and changed aggregate snapshots. This workflow is designed not to accept or retain carrier identities, invoice identifiers, documents, or transaction-level partner records.
  • Private rate-confirmation analyses: document type, size, page count, extracted load and payment fields, clause findings, redacted source snippets, and analysis, expiration, or deletion timestamps. The raw file, full extracted text, and document fingerprint are not stored by the service.
  • Private review supporting records: a carrier-reviewed redacted excerpt, record type, validated file type, size and page count, extraction method, private fingerprint, attestation, submission and expiration timestamps, moderation status and history, an optional private appeal reason and decision, and the submitting carrier account. The raw file, filename, and full extracted text are not sent to or stored by the service.
  • Private lane-rate supporting records: an optional carrier-reviewed redacted rate-confirmation excerpt, validated file type, size and page count, extraction method, report-bound keyed document identifier, attestation, submission and expiration timestamps, matched-or-self-reported decision, and moderation history. The raw file, filename, full extracted text, reporter identity, and keyed identifier are not displayed publicly.
  • Private facility-photo submissions: a browser-prepared metadata-free image derivative, facility and category, date taken, optional caption, carrier/company attribution, attestations, image dimensions and checksum, private Storage reference, moderation status and checks, carrier-facing outcome, and bounded decision history. The original source file is not uploaded.
  • Request-scoped precise location: when you explicitly choose Facilities near me and grant browser permission, the browser sends a coordinate pair and bounded search radius over HTTPS for that lookup. Application code does not retain or return the origin, add it to analytics or saved tools, or place it in the request URL. Nearby results contain only published source-backed facility suggestions and rounded distance.
  • Aggregate product activity: allowlisted counts of searches, broker profile views, saves, comparisons, carrier tools, review, payment-evidence or comment completion, account creation, and return visits, reduced to broad device and signed-in audience categories. These counters do not contain search terms, broker or report identifiers, payment dates or terms, phone numbers, account identifiers, raw IP addresses, or event-level histories.
  • Private administrator audit history: allowlisted administrative route template, workflow category, action, decision enum, outcome, status code, owner-admin label, one-way keyed actor and target fingerprints, and occurrence, completion, and expiry times. This ledger does not store request or response bodies, moderation explanations, private notes, administrator phone numbers or email addresses, IP addresses, cookies, CSRF tokens, session values, credentials, raw target identifiers, or contribution text.
  • Technical information: device, browser, IP address, approximate location derived from network information, log data, security events, and cookie or local storage values needed to operate the service.
  • Public and licensed aggregate data: FMCSA, transportation, insurance, authority, factoring-partner aggregates, and other public or permitted third-party business records used to enrich broker and carrier profiles, including retained public company-name, address, and phone snapshots used to identify later public-record changes.

How We Use Information

We use information to operate, secure, and improve the service, including to:

  • Authenticate carriers and administrators.
  • Display moderated reviews, carrier discussions, comments, ratings, and reputation signals to the community.
  • Accept, moderate, publish, and aggregate first-hand carrier facility visit reports.
  • Privately review first-hand facility photos for content, privacy, and facility/category match before any publication.
  • Prevent fraud, spam, abuse, duplicate accounts, and unauthorized access.
  • Apply deterministic content checks, hold possible spam or unrelated promotion for moderation, and administer warnings, strikes, contribution restrictions, and private appeals.
  • Connect carrier users to company profiles when they choose to do so.
  • Optionally review and administer a carrier user's relationship to the exact connected company for a time-limited review-author identity label.
  • Verify and administer authorized broker representatives, moderate company responses, and review correction requests.
  • Sync a signed-in user's private saved-broker workspace across browsers and check saved brokers for qualified changes using public and community aggregate data.
  • Sync a signed-in user's private saved facility and lane workspace across browsers and refresh its bounded public aggregate summaries.
  • Sync a signed-in user's explicitly saved query, company filter, evidence sort, and private note across browsers.
  • Analyze a signed-in user's rate confirmation for selected load, payment, and contract terms while keeping the raw file on the user's device.
  • Privately compare an optional carrier-redacted supporting-record excerpt with a submitted broker review before publication.
  • Privately compare an optional carrier-redacted rate-confirmation excerpt with a submitted structured lane rate before aggregation.
  • Moderate content, investigate reports, enforce our terms, and protect the integrity of the platform.
  • Record bounded administrator action intents and outcomes for access control, accountability, dispute handling, security, and operational review.
  • Analyze site performance and improve search, ranking, and review features.

Public Content

Reviews, comments, ratings, usernames, company names, profile photos, and related review details may be visible to other users and visitors. Do not submit private, confidential, personal, payment-card, medical, or legally privileged information in public reviews or comments.

A profile-photo source file is prepared in the carrier's browser. The service receives only a square 512 by 512 WebP or JPEG derivative with source metadata removed, stores it in an account-owned Firebase Storage path, and displays it publicly with the carrier's contributions. Other users cannot write to or delete that path. External image hosts and another account's stored image cannot be saved as a profile photo. The carrier can remove the photo from the profile; the service then clears the public database reference and attempts to delete the prior owned object.

A published broker review may display Company connected when the phone-authenticated account selected the displayed FMCSA carrier company and USDOT record. It may instead display Carrier verified when posted when an administrator had reviewed that account holder's relationship to the exact company, checked a current public company record, and the time-limited verification was active at submission. The public review receives only the label and applicable verification and expiration timestamps; it does not receive the private contact route, relationship explanation, internal account or membership identifier, administrator identity, checks, notes, message, or decision history. Neither label verifies the review statement or changes scores or rankings.

A published carrier-community post or comment may display the connected carrier company name, username, carrier USDOT number, company-connection label, post or comment text, selected topic and experience type, optional equipment, one related public broker/facility/lane profile, vote totals, comment count, and publication timestamps. Public community APIs do not display the internal account/profile ID, phone number, administrator identity, private moderation notes or history, private report details, or the identity of voters and users who saved a post. The connection label means only that the account selected the displayed FMCSA company and does not independently verify the relationship or every statement.

When a published broker review includes a public business facility name and city/state, that facility label and privacy-thresholded aggregate wait, stage-duration, amenity, or operating statistics may appear in a facility profile. Optional arrival, appointment, check-in, dock, and departure times may appear inside that originating review's evidence details, but the aggregate facility projection publishes only rounded duration metrics after the independent-carrier threshold is met. That aggregate does not expose the reviewer, reviewing carrier company, review text, broker, exact stop times, or private load reference.

A separate first-hand facility visit report may appear as an individual public report only after moderation. It can display the connected carrier company, username, carrier USDOT number, Company connected label, visit date, operation, rating, return intent, approved operational fields, narrative note, and optional visit timeline. It does not display the internal account/profile ID, phone number, administrator identity, internal decision note, or moderation history. Publishing an individual report does not waive the three-report and three-independent-company floor for aggregate statistics.

A carrier may submit a facility photo from a first-hand visit. The browser prepares a complete-frame WebP or JPEG derivative, removes source metadata, limits its dimensions and size, and uploads only that prepared copy to an account- and facility-bound private Storage path. The photo remains private while an administrator checks the complete frame for content, recognizable people, license plates, documents, gate codes, private details, and facility/category match. If published, visitors receive only the facility/category/date, approved caption, dimensions, reviewed-source label, and a same-origin image route. The public response does not include the submitting account, carrier company, username, original filename, Storage path, checksum, attestations, moderator identity, internal notes, or history. A carrier can withdraw a pending photo, and a dismissed or withdrawn photo's private object is deleted when the service completes that decision.

The original author can edit an unpublished facility report or privately propose a correction to a published report. A pending correction leaves the current public report unchanged. If approved, the public report may show an edited time and count, but not the private correction reason, proposed draft before approval, prior versions, administrator identity, internal notes, or decision history. A dismissed report may receive one private reconsideration request. The author's reason remains available only to administrators; the author receives only workflow status and a carrier-facing outcome. Reopening returns the report to private moderation and does not publish it.

An administrator-curated directory may add public business details such as a canonical name, aliases, street address, facility type, public phone, website, operating hours, coordinates, appointment/parking/restroom/lumper/dock states, check-in and arrival guidance, safety and gate requirements, truck-approach details, a confirmation date, and source attribution. Those details come from the displayed public source, not from carrier reports.

A carrier may privately suggest a correction to one source-backed directory field. The correction submission, carrier identity, explanation, evidence basis, source link, and moderation record do not appear on the public facility profile. If an administrator verifies the information and separately saves the canonical directory record, the resulting public field continues to use the directory's displayed source attribution and freshness context. A submitted or dismissed correction is not a public warning, allegation, rating, or carrier report.

When a published review or moderated private rate report includes an origin and destination city/state, those public route fields may appear in a directional community lane profile. A lane profile may show equipment represented, aggregate report and carrier-company counts, privacy-thresholded rate and payment statistics, brokers represented, and de-identified counts of rates with or without a reviewed supporting record. A separate record-reviewed median appears only after three matching rates from three carrier companies qualify. It does not expose the reviewer or rate reporter, carrier company or USDOT number, redacted extract, keyed document identifier, source metadata, review text, comments, contact details, private load references, moderator, internal notes, or decision history through the lane aggregate.

Private Tool Inputs

Facilities near me requests browser location permission only after you choose that action. The coordinate pair is used in request memory to find published source-backed facilities within the selected bounded radius and is not written to an application database, analytics record, saved history, URL, or response. Permission denial, unsupported browsers, and directory failure leave manual facility name or city search available. Hosting and network providers may process request and network metadata under their own operational and legal obligations.

Optional company name, broker phone, or email values entered in Before You Book are sent to the service only for comparison with available public FMCSA profile or Census data. They are not displayed publicly. Calculation responses and saved calculation records retain only the comparison result, the public-source name, and whether each field was supplied, not the raw entered company or contact value.

If you enter a broker email in Contact Check or Before You Book, the service extracts its domain. Shared mailbox providers are classified locally. For a company domain, only that domain, not the full email address, is sent to the registry RDAP service selected through the public IANA DNS RDAP bootstrap. The application does not retain the entered email, extracted domain, raw RDAP response, registrant data, nameservers, or registrar contacts; it caches only the public IANA bootstrap document. The registry may maintain its own operational request logs under its policies. The returned result contains only a registration-age band, registration-event date, source, check time, and neutral verification guidance.

Origin, destination, equipment, offered-rate economics, and optional pickup or delivery facility names are used to calculate the requested load and to retrieve aggregate lane or facility reports. When a user explicitly adds a private rate-confirmation scan, the browser may also send only bounded assessment and confidence keys, finding counts and keys, severities, and located-term keys. Finding wording, source excerpts, carrier identity, load number, and full document text are not sent to the calculation route. Tool inputs are returned only to the requesting browser. If a signed-in user explicitly saves a result, these values, aggregate result, and server-normalized contract-warning summary may be stored in that user's private calculation history. Separately, route fields already included in a published carrier review may contribute to the identity-free lane aggregates described above.

Private operating-cost defaults and saved calculations are kept behind the authenticated server. When the primary relational store is unavailable, a server-only account fallback may be used; direct browser access remains denied, history is limited to 25 records, and the same privacy filtering applies.

For the private rate-confirmation scanner, the raw PDF, JPG, or PNG remains in your browser. Self-hosted PDF text extraction and optical character recognition run on your device. The browser sends up to 60,000 characters of normalized extracted text over HTTPS for in-memory analysis, and the service discards that full text after the request. It stores only bounded load and payment fields, findings, and redacted source snippets in an account-isolated server record. A private document fingerprint is transmitted for duplicate handling, converted to a keyed storage identifier, and not retained as a field or displayed publicly.

Scanner redaction and text recognition can be incomplete. Remove bank, tax, personal, medical, privileged, and other confidential information before using the tool, and review every retained snippet. Scanner records are private, never become public reviews, and do not affect broker profiles, scores, rankings, or moderation outcomes. Your browser may cache the self-hosted recognition software for performance, but the application does not use that cache to retain the document itself.

Private Review Supporting Records

When you optionally select a PDF, JPG, or PNG while writing a broker review, text extraction and optical character recognition run in your browser. The browser automatically redacts common identifiers and shows you a bounded excerpt to inspect and edit. You must remove any remaining names, phone numbers, email addresses, addresses, financial or tax information, account details, and load, invoice, BOL, PRO, PO, or other private references before attesting and submitting.

The raw document, filename, and full extracted text do not leave your browser and are not included in the browser-tab review draft. The service receives only the carrier-reviewed redacted excerpt, bounded file metadata, a private fingerprint used for duplicate handling, redaction count, and attestation. The service applies common-pattern redaction again. Automated extraction and redaction may be incomplete or inaccurate, and the service does not authenticate the original file.

A review with a supporting record remains private until an administrator reviews or dismisses each retained excerpt and separately publishes the review. The author receives only workflow status, a carrier-facing decision explanation, appeal eligibility, and a minimal appeal status or outcome. While the redacted extract is retained, the original author may submit one private factual appeal with a privacy attestation. The appeal reason, retained extract, administrator identity, and internal decision notes remain visible only to authorized administrators. Public visitors receive only an allowlisted type-only reviewed-record label, or the generic Supporting record reviewed fallback, and a disclosure after approval; they do not receive the excerpt, fingerprint, source metadata, appeal, carrier account identity, administrator identity, internal note, or decision history. The label does not independently verify payment or every statement, establish liability, or constitute a credit, legal, contract, or authenticity review, and it does not affect scores or rankings.

Private Lane-Rate Supporting Records

When you optionally select a PDF, JPG, or PNG while sharing a lane rate, local extraction and redaction follow the same browser-only process described above. The raw document and filename do not leave your browser. The service receives only the carrier-reviewed redacted excerpt, bounded file metadata, redaction count, attestation, and a fingerprint that is immediately converted to a report-bound keyed identifier before storage. The service applies common-pattern redaction again.

A moderator must explicitly classify the record as matching the structured broker, direction, pickup date, and total rate or publish the rate as self-reported without that classification. Public visitors may receive only de-identified category counts and, after the independent-company floor is met, a separately rounded record-reviewed median and range. “Supporting record reviewed” does not authenticate the original document, prove the load moved, verify payment, establish wrongdoing, or constitute legal, credit, contract, compliance, or financial advice.

Private Moderation Reports

A broker concern submitted through the Report concern tool is visible only to authorized administrators and is not displayed as a review, public allegation, or score input. The report includes your account and connected-company identity so moderators can investigate misuse and follow up when necessary. Booking-contact, brokerage-chain, and payment-instruction reports also include the selected interaction stage, event date, and direct-experience confirmation. Do not include phone numbers, email addresses, financial-account details, private documents, or other confidential information in the description. Automated checks reject common sensitive-data patterns, but no filter is perfect.

Reporting a published review records the referenced review, your selected moderation reason, your private explanation, and the same account and connected-company attribution. One open or reviewing report is accepted per account and review. The report and moderation outcome remain private, do not automatically hide or change the review, and do not affect votes, the Carrier Review Score, the Broker Vetting Status, search order, or rankings.

When a review author submits a correction, the service stores the complete proposed version, the author's private explanation and attestation, submission status, account attribution, and bounded moderation history. The currently published review remains visible until a moderator approves the correction. Prior approved versions, internal notes, and decision records are retained privately for accountability. Public visitors receive only the approved review plus an edit count and edit time; the author additionally receives only the minimal pending status needed to continue the workflow. Public and carrier-history APIs do not return the proposed version, prior-version history, moderator identity, or internal notes.

For a matching identity, contact, or dated first-hand booking-verification concern, an administrator may publish a neutral, time-bounded verification notice after independently reviewing supporting evidence. The public broker profile and carrier warning center receive only an allowlisted status, notice type and label, neutral summary, broad source label, publication time, re-review date, and active or expired state where applicable; the warning center may also show a separately published neutral resolution. They do not receive your identity, connected company, interaction stage, event date, private description, raw evidence, administrator attestation, internal source key, decision note, or moderation history. Current notices combine into at most one noncritical reason with relevant confirmation questions in the Broker Vetting Status, but they never change the Carrier Review Score, evidence confidence, review content, votes, search order, or rankings. Expired notices do not appear as active; a separately published neutral resolution may remain visible for accountability.

Community Moderation And Private Activity

Every community post is stored privately until an administrator completes content review and publishes it. Ordinary comments may publish after validation; comments containing serious allegation terms remain private until review. Administrators can view account and carrier-company attribution, submitted content, related-profile selections, evidence-availability state, private reports, internal notes, and bounded decision history to investigate abuse and document moderation. Those private fields are not included in public community responses.

Community votes and saves are tied privately to the signed-in account so the service can enforce one current vote per target and provide a Saved view. Public responses expose only aggregate vote totals and whether the current signed-in viewer voted or saved the post. A private report includes reporter identity for moderation, but does not automatically remove content or become public. Community content and activity do not affect broker scores, vetting status, rankings, authority, or verified legal summaries.

Carrier Desk may provide an owner-only recent list of already-public replies from other carriers to your published community posts. That response contains only the public reply text, public carrier company and username, vote score, timestamps, and public post title and link. It does not expose account identifiers, phone numbers, private moderation fields, pending or removed content, or your own comments, and it does not create durable read or unread tracking.

Account Standing And Automated Content Checks

Review, review-comment, community-post, and community-comment text may be checked for bounded deterministic signals such as repeated text, excessive capital letters, several links, or common unrelated promotional phrases. A signal can keep the submitted content private for administrator review. It is not a finding that the user acted improperly, does not by itself issue a warning or strike, and never changes a broker score, vetting status, search order, or ranking. We do not expose the private classifier result through public content APIs.

Authorized administrators may separately record a warning, issue a time-limited strike, pause new contributions for 1, 7, 30, or 90 days or until restored, revoke a strike, or restore access. Three active strikes cause a 30-day contribution pause; each strike remains active for up to 180 days unless revoked or revised. While contributions are paused, the account can still use public broker research and private account tools, but cannot add reviews, comments, votes, reports, or other community submissions. If account-standing storage cannot be checked, contribution writes fail closed while public research remains available.

The account holder receives only the current standing, carrier-facing explanation, applicable expiration time, bounded active-strike information, and minimal appeal status or outcome. The holder may submit one private appeal for the current strike or contribution restriction. The appeal reason is no longer returned to the carrier after submission and is never public. Authorized administrators receive the private reason, relevant account history, administrator notes, and audit events needed to decide the appeal. A final decision requires a private note, a carrier-facing message, and confirmation that the account history, related content, and appeal were reviewed.

Facility Visit Reports

A facility visit report is private while submitted, reviewing, or dismissed. During moderation it includes the internal account/profile ID, connected carrier company, username, carrier USDOT, structured visit facts including optional equipment and live/drop visit mode, optional note, first-hand attestation, and moderation history. The report identifier is a one-way hash used to prevent the same account from submitting the same facility/date/operation more than once. Direct browser access to the underlying storage is denied.

Moderators must explicitly review first-hand context, private information, and unsupported allegations before publication. Only the public fields described above are released. Submitted report events are counted only through aggregate analytics without a facility, account, company, or report identifier.

A source-backed facility correction remains private in every status. It includes the internal account/profile ID, connected carrier company, username, carrier USDOT, selected field and issue, confirmation date, evidence basis, optional proposed public value and public source URL, factual explanation, attestation, moderation checks, neutral carrier-facing outcome, and bounded decision history. Its one-way identifier prevents the same account from creating another correction for the same facility, field, and confirmation date. The owner receives only an owner-safe copy without reporter attribution, administrator identity, internal notes, or decision history; other carrier accounts cannot read it. Direct browser access to the underlying storage is denied.

Facility wait patterns use only published review and moderated visit-report facts from the last 12 months. A daypart, weekday, equipment, or live/drop visit-mode segment is omitted unless it has at least three total-wait observations from three carrier companies, and only the latest observation from each company in that segment is used. Reports without the optional segment field do not enter that breakdown. Public pattern responses contain rounded medians and bounded segment samples; they do not contain exact stop times, visit dates, report identifiers, account identifiers, or carrier-company keys.

Private Lane Rate Reports

An approved carrier-company member may submit a first-hand booked or completed load rate for private moderation. The private record includes the selected FMCSA broker, directional city-to-city lane, equipment, pickup and optional delivery dates, total rate, loaded and deadhead miles, extra stops, rate source, fuel-surcharge and accessorial inclusion, optional load categories, your account and connected-company identity, username, carrier USDOT, attestation, workflow status, and moderation history. After dismissal, the original carrier may submit one private factual reconsideration within 30 days. The service stores the reason, good-faith and privacy attestations, timing, a 14-day response target, status, private decision note, and carrier-facing outcome. The owner projection excludes the reason and private note; public endpoints receive no reconsideration record. A one-way identifier prevents the same account from submitting the same broker, lane, equipment, and pickup date more than once. Direct browser access to the record is denied.

A report has no public effect until an administrator documents review of the broker, lane, date, structured values, carrier-company identity, and duplicate risk. Public lane profiles receive only an identity-free aggregate row. They do not receive your account, username, carrier company, USDOT, raw report, administrator identity, internal note, or moderation history. Rates, loaded RPM, and all-in RPM remain hidden until each metric has at least three matching observations from three independent carrier companies. A 90-day movement comparison publishes a period median only when that period independently meets the same threshold; otherwise it shows aggregate counts and an insufficient-history state. A published aggregate is historical self-reported evidence, not a market quote, credit opinion, or guarantee of a future rate.

Broker Representative Claims, Responses, And Corrections

A broker representative claim is private to authorized administrators while it is submitted, reviewed, approved, denied, or revoked. The official company email, public business phone, job title, relationship explanation, account identity, verification checks, decision notes, and moderation history are not displayed on a broker profile. This version does not accept a claim-document upload. If an administrator uses manual business records through a separate controlled process, sensitive records must not be pasted into the claim form.

After a claim is denied or representative access is revoked, the same account may submit one private factual reconsideration within 30 days. The service stores the reason, good-faith and privacy attestations, submission time, a 14-day response target, status, representative-facing outcome, private moderator note, and bounded history. The representative receives only owner-safe timing, status, and final outcome fields. Public visitors receive no reconsideration record. Reopening clears prior verification checks and returns the claim to ordinary review; it does not approve access or create a public claimed status.

A public profile receives only a claimed, unclaimed, or temporarily unavailable state and limited verification timing or method information after approval. An unclaimed profile is not a negative signal. An approved representative may submit a response to a carrier review, but the draft remains private until moderation. The published response includes only the broker business name, approved body, a verified-representative label, and publication timing; it does not change the carrier review, rating, votes, Carrier Review Score, Broker Vetting Status, or rankings.

Correction and review-dispute requests remain private unless a moderator chooses to publish an allowlisted neutral outcome such as corrected, clarification added, no change, identity/contact/booking verification advised, or verification notice resolved. A public outcome excludes the reporter identity, private first-hand context and report details, official contact information, raw evidence, source keys, administrator attestations, and internal notes.

After an initial decision on a legal-record clarification, the same approved representative may submit one private factual reconsideration within 30 days. The service stores the reason, official-source and privacy attestations, submission time, a 14-day response target, status, representative-facing outcome, private moderator note, and bounded history. The representative receives only owner-safe workflow fields and the final explanation. Public visitors receive none of the reconsideration record, and submission or reopening does not automatically alter a court record, neutral public outcome, score, review, rating, search order, or ranking.

Private Payment-Evidence Reports

A payment-evidence report is visible only to authorized administrators while it is submitted, reviewed, verified, or dismissed. It includes your account and connected-company identity so reports can be deduplicated, investigated, and moderated. Do not submit or offer unredacted bank, tax, personal, account, or other sensitive records. The current form does not upload a file. If supporting records are reviewed through a separate controlled process, they must be redacted before review.

A broker profile may display a method-separated aggregate only after an administrator records that the required redacted terms and payment records were reviewed. The public aggregate excludes your identity, private note, invoice and paid dates, proof metadata, administrator note, and moderation history. Verification means the records supported the reported dates; it does not guarantee future payment or establish a credit rating.

Factoring Partner Aggregate Data

Authorized administrators may register a factoring data source and import aggregate broker-to-factor payment metrics. Private source and batch records can include an administrator name, source status, data-use attestation, external batch identifier, internal note, broker association, and import timestamps. Public profiles receive only whitelisted aggregate metrics, source attribution, reporting windows, samples, freshness, confidence, and a public methodology URL when provided.

The factoring workflow is designed to discard unknown fields and not store carrier identities, invoice numbers, documents, contact details, or transaction-level partner records. Only the latest qualifying window from each active source enters the public aggregate. Paused sources and stale data do not affect current vetting. Aggregate snapshots may be retained to document historical changes and platform decisions; they do not become carrier-level records and do not establish a credit rating or payment guarantee.

Private Saved Vetting Workspace

Saved brokers, labels, monitoring cadence and pause selections, monitoring snapshots, alert acknowledgements, and private notes are stored locally when you are signed out. When you sign in, those values may be submitted to and stored by the service so they can follow your account across signed-in browsers. They are not displayed on public broker profiles or shared with other users. Do not store passwords, financial-account details, personal information, confidential documents, or legally privileged material in private notes.

For unpaused signed-in saved brokers using daily or weekly cadence, the service may periodically refresh a broker-only monitoring snapshot derived from FMCSA records, including the current public phone and business address, verified legal aggregates, and qualified community review or payment aggregates. Shared broker monitor targets do not contain your account identity, private label, note, cadence, pause state, or acknowledgement state. Daily cadence applies a newer snapshot no more often than every 24 hours; weekly cadence uses a seven-day floor. Manual-only cadence applies a new snapshot only when you request a check. An explicit check bypasses cadence but still respects pause state and request limits. Pausing stops new comparisons and subscription refreshes for that broker on your account while retaining prior notes, alerts, cadence, and the baseline. A shared public-data target may continue to be refreshed for another carrier and reveals no subscriber identity. Monitoring may be delayed, partial, or unavailable and does not replace independent verification before dispatch.

A signed-in carrier may separately opt in to a daily or weekly browser summary for newly detected unread saved-broker changes. The service requests browser permission only after the carrier chooses Enable and may retain up to five browser-vendor delivery endpoints, public encryption keys, authentication secrets used by the Web Push protocol, delivery status, cadence, and a private delivery cursor. Notification previews use only a generic bounded change count and a link to the signed-in Broker Alerts page. They do not contain broker names, saved labels or notes, alert reasons, review text, documents, or evidence details. The browser vendor's push service processes the delivery endpoint and encrypted message under its own policies. Browser notifications may appear on a device lock screen, may be delayed or unavailable, and are not sent by email or SMS. A carrier can pause summaries or remove a browser from the profile; account deletion removes all server subscriptions and attempts to unsubscribe the current browser. Browser-level permission remains controlled in the browser's site settings.

Saved facilities and lanes use a separate private workspace. A lane save includes the selected equipment view so different equipment views remain distinct. When signed in, the service regenerates the public name, location or direction, equipment label, link, confidence, sample counts, and qualified wait or rate summary from the current public profile. It does not copy review text, a private report, reviewer identity, carrier identity, or unqualified private evidence into the save. Facility and lane saves do not create monitoring alerts or change any public profile, score, ranking, or aggregate.

When a user explicitly requests a commercial truck toll estimate for an exact city-to-city lane, the server sends TollGuru only the normalized origin city and state, destination city and state, and selected 2–9 axle vehicle type. A completed Before You Book check may issue a signed route grant containing those city/state endpoints, an opaque lane identifier, and issue and expiration times. The grant expires after 30 minutes, cannot be changed into another route without becoming invalid, and is not retained in saved calculation history. It does not contain the user's identity, company, phone number, account identifier, review activity, private notes, rate, or load document. The service retains the bounded provider result in an in-memory cache for up to 12 hours and may present a clearly labeled recent saved estimate during a temporary provider outage. The public result excludes route geometry, coordinates, toll-plaza identifiers, raw provider data, and credentials. TollGuru processes the route request under its own policies. The estimate does not affect broker scores, vetting, rankings, warnings, or booking decisions.

Saved searches use another private workspace. The service retains only query text you deliberately save, one allowlisted company filter, one allowlisted evidence sort, an optional private note, and bounded timestamps. Running a saved search performs the ordinary current provider lookup; it does not guarantee the same result set, subscribe you to monitoring, create an alert, change provider relevance, or affect any public profile, aggregate, ranking, or score. Saved query text is not included in aggregate product analytics.

Independently verified members of the same connected carrier company may share a private Company broker board. It stores canonical FMCSA broker identity, a Preferred, Watch, or Avoid company decision, a note of up to 500 characters, timestamps, the updating member's username, and bounded note-free activity. Other companies and the public cannot read the board. Internal account and membership identifiers are used only to authorize and attribute changes and are not returned in the Carrier Desk response. Do not place personal information, passwords, account details, confidential documents, private load references, legally privileged material, or information your company is not authorized to share in a company note.

A verified company Owner or Manager may create a one-time, seven-day Company team invitation for a Member or Manager. The service returns the plain invitation code once and stores only a cryptographic hash, the selected role, creation and expiration times, status, and private creator or accepting-member attribution. Acceptance still requires current verification for the same connected carrier company. Carrier Desk team responses use one-way member keys and omit user-profile IDs, raw membership IDs, invitation hashes, verification evidence, and private contacts. Fixed team roles control only the private company workspace; they do not grant administrator access or change public broker data. Keep invitation codes private and do not place them in public content or company notes.

Public FMCSA Snapshot History

The service may retain bounded FMCSA business-name, DBA, public-phone, and business-address values with observation timestamps to identify public-record changes over time. The public broker profile shows only the changed field type, observation date, source, and general verification guidance; it does not return the prior phone number or address in the history event. These observations do not identify a subscriber, do not affect the Carrier Review Score, and do not establish impersonation, fraud, or wrongdoing.

Aggregate Product Measurement

We use first-party aggregate counters to understand whether core carrier-vetting workflows are useful. The browser sends only an allowlisted event name, a broad device category, and, for carrier tools, a fixed tool key. The service derives an anonymous, carrier, or administrator audience category from the current session. It does not place search text, broker, facility, or lane identifiers, MC or USDOT numbers, phone numbers, account identifiers, raw network addresses, referrers, or arbitrary metadata in product analytics. Product analytics do not affect public broker profiles, scores, rankings, moderation, or account access.

To count a return visit without creating a visitor identifier, the browser may store only the last UTC visit day in local storage. Clearing or blocking local storage removes or disables that measurement. The analytics client also honors enabled Global Privacy Control and Do Not Track browser signals by disabling product-event delivery and return-visit storage. Admin reporting shows aggregate event totals and event follow-through, not unique visitors or individual user journeys.

On public search, profile, community, resource, and carrier-tool pages, the browser may also classify Largest Contentful Paint, Interaction to Next Paint, and Cumulative Layout Shift as good, needs improvement, or poor. The service retains only the metric name, quality band, broad device category, derived audience category, and aggregate count. It does not retain the exact measurement, page path, query string, public-record identifier, clicked element, interaction target, resource name, navigation identifier, or browser fingerprint. Each available metric is sent at most once when that public page lifecycle ends or becomes hidden, and the same Global Privacy Control and Do Not Track rules disable it.

Integration Reliability Records

The service keeps server-only operational aggregates for requests to allowlisted database and public-data providers. These records contain only the provider category, success or failure counts, bounded response-status and latency values, a general failure class, and timestamps. They do not contain search terms, broker, carrier, facility, or lane identifiers, MC or USDOT numbers, account identifiers, phone numbers, network addresses, request or response bodies, URLs, credentials, raw provider errors, or arbitrary metadata. Authorized administrators use a bounded 24-hour view and deterministic recent failure thresholds to identify an unavailable integration. These records do not affect broker profiles, scores, rankings, reviews, warnings, moderation, or account access.

How We Share Information

We do not sell personal information. We may share information with:

  • Service providers that host, secure, authenticate, analyze, or support the platform.
  • Other users and visitors when information is part of public community content or public broker profile data.
  • Government authorities, courts, or parties to a legal process when required by law or necessary to protect rights, safety, and security.
  • Successors in connection with a merger, acquisition, financing, restructuring, or sale of assets.

Cookies And Local Storage

We use cookies and browser storage for sign-in sessions, CSRF protection, theme preferences, saved broker, facility, lane, and search lists, private notes, saved-list filter and sort preferences, recently viewed brokers, a five-item successful recent-search history, public broker comparison selections, the last UTC visit day used for aggregate return-visit measurement, and similar product functionality. Temporary text typed into the Find control for a saved broker or facility/lane list is not persisted. Universal-search query text is persisted when you explicitly choose Save search or when a submitted search returns at least one match; in the latter case, only the five most recent queries and their selected filter/sort state remain on that device until cleared. An in-progress signed-in new review, pending-review edit, or published-review correction may be kept in session storage for up to 24 hours, isolated by user, broker, workflow, and review target so one draft cannot overwrite another; it is not synced to the service and is removed after successful submission, reset, or discard. Comparison selections contain public broker record identifiers and display handles; a shared comparison URL contains only two or three public broker identifiers. Signed-out saved data remains in that browser unless it is imported after sign-in. Signed-in saved data uses a local browser copy and an account-synced server copy. Clearing site data removes the local copy but does not by itself delete data already synced to an account. Blocking cookies or browser storage may prevent portions of the service from working correctly.

Account Deletion

A signed-in carrier can permanently delete the account through Account and privacy on the carrier profile. The confirmation requires the last four digits of the account's verified phone number, the exact displayed deletion phrase, and separate acknowledgements about immediate loss of access and retention of published contributions. An administrator profile must first have its administrator access removed before it can use self-service deletion.

Account deletion removes the carrier's sign-in profile, phone-linked application account, profile photo and bio, company memberships, carrier-verification request, broker claims, account-owned private saved workspaces, browser-notification subscriptions and delivery state, private reports and evidence, votes, unpublished contributions, and other account-owned private records. A shared Company team and broker board belong to the carrier company: decisions and notes may remain for other verified members, while the deleted member is removed and matching attribution becomes Former member. If the deleted member owns the team, ownership passes to the oldest active Manager or Member when one exists. The service also requests deletion of the Firebase Authentication identity, clears the website session, attempts to unsubscribe the current browser from Web Push, and clears account-specific saved data and review drafts from the browser performing the deletion. Browser data or notification permission on another device remains on that device until it is cleared through that browser's site-data settings; it cannot restore the deleted server account or receive delivery after its server subscription is deleted.

Published reviews, review comments, community posts and comments, facility reports, lane-rate reports, published company responses, and limited neutral public resolutions may remain when needed to preserve community context, evidence aggregates, moderation integrity, and public discussion. The service detaches the account and personal profile identity, removes the profile photo and bio, and identifies the author as Former carrier. A historical carrier company name and USDOT snapshot may remain as business attribution for a published contribution. Private review or lane supporting-record material is removed; any retained lane rate is thereafter treated as self-reported. Verified payment reports are removed and affected aggregates are recalculated.

A completed deletion is permanent and the same Firebase identity cannot recreate or restore the account. To enforce that boundary, the service retains a server-only one-way keyed deletion marker. The marker does not store the raw Firebase user ID, phone number, profile, username, or company membership. Limited backups, security logs, legally required records, and public-source business data may remain for their applicable retention periods and are not used to restore the deleted account.

Data Retention

We retain information for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and preserve the integrity of public review records. After account deletion, published contributions may remain only under the anonymized and business-attribution boundaries described above unless removal is required by law or approved through moderation.

Private moderation reports, carrier-verification requests and reconsiderations, community submissions, votes and saves, facility visit submissions, broker-representative claims, response drafts, correction requests, payment-evidence reports, evidence-review state, and internal decision history may be retained as needed to provide account features, investigate concerns, prevent repeat abuse, document platform decisions, resolve disputes, and meet legal or security obligations. They do not become public merely because they are retained. An expired or revoked carrier verification stops qualifying future review-author labels, while a published review may retain the bounded fact that verification was active when it was submitted. Reconsideration never changes that historical snapshot and reopening does not restore current verification without a separate ordinary decision. An identity/contact or booking-verification notice stops affecting the current vetting result after its review date, but the private moderation record and a neutral public resolution history may be retained for accountability. A published community post or comment contributes only its approved public projection and aggregate interaction counts; a published facility report contributes only its approved public projection and thresholded aggregate fields; a verified payment report contributes only the separate aggregate fields described above.

Account-synced saved-broker, facility, lane, and search data and optional browser-notification delivery state are retained while needed to provide the workspace or until you remove them, subject to operational, security, legal, and backup requirements. Expired browser-vendor subscriptions are removed when the provider reports expiration. A Company team and broker board are retained while needed by the connected carrier company; removed-member state may remain to enforce access revocation, invitation and activity histories remain bounded, and broker entries remain until an authorized team member removes them. Limited deletion markers may be retained to prevent an older browser from restoring a saved item you removed on another device.

Structured rate-confirmation analyses expire after 30 days and can be deleted earlier from the scanner. The raw document and full extracted text are not retained by the service. Scheduled and managed deletion may occur asynchronously after an expiration or deletion request, and limited operational or security records may remain where required by law or necessary to protect the service.

A private review supporting-record excerpt and its fingerprint are scheduled to be scrubbed after 30 days. A non-sensitive moderation outcome, timestamps, and public reviewed-record label may remain to preserve review integrity and platform decisions. The raw file was never retained by the service.

A private lane-rate supporting-record excerpt and its report-bound keyed identifier are scheduled to be scrubbed after 30 days. Bounded source metadata, timestamps, and the matched-or-self-reported decision may remain to preserve aggregate integrity and moderation history. The raw file and filename were never retained by the service.

To enforce short-term abuse limits, the service converts a network address into a keyed, non-public identifier and stores only a brief request-count window. Those limiter records are configured to expire shortly after the window ends, although managed deletion may occur asynchronously.

Account-moderation records retain at most 20 strikes, 20 appeal-history entries, and 50 action-history entries. A strike expires for enforcement after 180 days unless ended earlier, but bounded historical action and decision records may remain for abuse prevention, dispute handling, security, legal compliance, and platform integrity. Public visitors never receive that history.

Aggregate product-activity documents are retained for up to 400 days and then removed in bounded scheduled batches. Because they contain daily aggregate counters rather than event records, they cannot be used to reconstruct an individual user journey.

Integration reliability records are retained for up to 90 days and removed in bounded scheduled batches. They contain provider-level operational counts and timing categories rather than user activity or request content.

Private administrator audit events are retained for up to 400 days and then removed in bounded scheduled batches. They use one-way keyed fingerprints instead of raw actor or target identifiers and are not user-activity analytics or a permanent archive. Feature-specific private moderation histories may follow the separate retention purposes and limits described above.

Security

We use administrative, technical, and organizational safeguards designed to protect information. No online service can guarantee absolute security, and users are responsible for keeping account access secure.

Your Choices

You may update profile information through your account tools where available, remove individual saved items and eligible private records through their controls, or permanently delete a non-administrator carrier account through Account and privacy on the carrier profile. You may request correction, review, or legally required removal of other information by contacting the site operator. We may need to retain limited information when required for security, legal compliance, dispute resolution, or protection of the review platform, subject to the account-deletion boundaries above.

Children

The service is intended for business users and is not directed to children under 13. We do not knowingly collect personal information from children.

Changes To This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised effective date. Continued use of the service after an update means the updated policy applies.

Contact

Questions about privacy or data requests may be sent to the site operator through the contact method provided by searchfreightbroker.com.

© searchfreightbroker.com Trust & scoring Privacy Policy Terms of Service Find brokers