The short version.

  • We collect only what we need to run the service: account info, container numbers you submit, vessel positions we already get from public AIS, and basic usage telemetry.
  • We do not sell your data. Ever. To anyone.
  • We do not use cookies for advertising. The only cookies we set are essential (auth, session).
  • Data lives in Canada (Hetzner Nuremberg fallback) — covered by PIPEDA and GDPR where applicable.
  • You can export or delete your data any time by emailing [email protected].

01 Scope & controller

This policy describes how Broadpath Logistics Inc. ("Broadpath", "we") collects and processes personal information when you use our website (broadpath.app), the customer app (app.broadpath.app), the admin platform (admin.broadpath.app), and the REST API.

For the purposes of GDPR, Broadpath is the data controller for personal information collected directly from end users. For Customer Data submitted by enterprise customers (container numbers, account hierarchy, etc.), Broadpath acts as a data processor on behalf of the customer.

Broadpath is incorporated in Ontario, Canada. Our principal place of business is Toronto, Ontario.

02 What we collect

Three categories of information, summarized below.

CategoryExamplesSource
Account information Name, email, hashed password, company name, billing address, payment method (via Stripe), API keys You provide it at sign-up or in settings
Customer Data Container numbers, vessel MMSIs of interest, alias/label fields, webhook URLs, internal notes You submit it via the dashboard or API
Usage telemetry IP address, browser/OS, request paths, error logs, feature interactions (aggregated) Server logs + first-party privacy-respecting analytics

What we do not collect:

  • Government IDs, passport scans, biometric data — irrelevant to our service.
  • Precise geolocation of you the user — we plot ships, not people.
  • Browsing history outside of our domains. No third-party advertising trackers.
  • Special categories of personal data under GDPR (health, religion, political opinion, etc.).

2.1 Data from third parties

To operate the service we ingest data from third parties — ocean carriers, AIS aggregators (aisstream.io, datalastic), and a third-party carrier-data aggregator. This data is about ships and containers, not individuals, and is sourced from public broadcasts (AIS) or commercial APIs under our paid agreements.

03 How we use it

We process personal information only for the purposes below, and only on a lawful basis under GDPR (contract performance, legitimate interest, or your consent — whichever applies):

  • Operate the service — authenticate you, run container polling, return API responses, send transactional emails (contract).
  • Bill you — process payments via Stripe, send invoices, refund unused credits (contract).
  • Support you — respond to emails and tickets, investigate bugs (legitimate interest).
  • Secure the service — detect abuse, rate-limit, audit logs (legitimate interest).
  • Improve the service — analyze aggregated usage to make product decisions (legitimate interest). Aggregated only; never traced back to identifiable individuals.
  • Communicate optionally — send product updates, feature announcements, or surveys (consent — you opt in, you can opt out anytime).
  • Comply with law — respond to court orders, regulatory inquiries, or fraud investigations (legal obligation).

04 Who we share it with

Broadpath does not sell, rent, or trade personal information. We share data only with:

  • Sub-processors we depend on to run the service. Each is bound by a data processing agreement requiring the same protections we offer.
  • Upstream carrier and AIS providers when we forward your container number or MMSI to fetch tracking data. We never forward billing or account information to them.
  • Law enforcement when required by valid legal process. We push back on overbroad requests and notify affected customers where legally permitted.
  • Successor entities if Broadpath is acquired or merged. Customers will be notified at least 30 days in advance.

4.1 Current sub-processors

ProviderPurposeRegion
Hetzner CloudApplication hosting, databaseGermany (EU)
CloudflareDNS, edge CDN, DDoS protectionGlobal edge
StripePayment processingIreland (EU) / US
Carrier-data aggregatorCarrier API aggregationEU
aisstream.ioAIS feed aggregationEU
Microsoft 365Business email, calendarEU
PostmarkTransactional emailUS

05 Data retention

We hold data only as long as we need it, then delete or anonymize.

  • Account information — kept while your account is active, plus 12 months after deletion for billing/tax compliance.
  • Container tracking events — kept indefinitely as a customer-facing feature (see the historical vessel tracking article). You can request deletion of specific container records at any time.
  • Vessel AIS positions — kept indefinitely. AIS data is not personal information.
  • Usage telemetry — 90 days for raw logs, longer for aggregated metrics.
  • Support emails — 2 years from last contact.
  • Financial records — 7 years, per Canadian tax law.

06 Security

Practical controls we employ:

  • TLS 1.2+ on every connection (HTTPS-only). HSTS enabled.
  • Passwords hashed with bcrypt or argon2 (never stored plaintext).
  • API keys hashed at rest; never logged in plain.
  • Database encrypted at rest (LUKS).
  • Server access via SSH keys only — no passwords, fail2ban-protected.
  • Off-site encrypted backups, daily, retained 30 days.
  • Audit logs for admin actions, 90-day retention.
  • Automatic security patching (unattended-upgrades).

No system is invulnerable. If a breach materially affects your data, we will notify you within 72 hours of discovery, as required by GDPR Article 33 and PIPEDA's mandatory-breach-notification rules.

07 Your rights

Depending on where you live, you have most or all of the following rights over personal information we hold about you. We honor them regardless of where you are based.

  • Access — get a copy of the personal information we have on you.
  • Rectification — fix anything inaccurate.
  • Erasure ("right to be forgotten") — delete your account and associated personal data, subject to legal-retention obligations.
  • Portability — receive your data in a machine-readable format (JSON).
  • Objection — object to processing based on legitimate interest.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Withdrawal of consent — withdraw any consent you previously gave (e.g. marketing emails), without affecting processing already done.
  • Complaint — lodge a complaint with your local data protection authority (e.g. Office of the Privacy Commissioner of Canada, or your EU DPA).

Email [email protected] from your account email to exercise any of these. We respond within 30 days.

08 Cookies & tracking

We use as few cookies as possible.

CookiePurposeDuration
bp_sessionAuth/session — required to stay logged in30 days, sliding
bp_csrfCross-site request forgery protectionSession
bp_prefUI preferences (theme, density)1 year

We do not use Google Analytics, Facebook Pixel, or any advertising/retargeting tracker. The first-party analytics we run (Plausible-style, self-hosted) does not set cookies and does not identify individuals.

09 International transfers

Customer data primarily resides in the EU (Hetzner Cloud, Germany). Some sub-processors are based in the US (Stripe, Postmark). When personal data is transferred between jurisdictions, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for EU→US transfers.
  • Adequacy decisions where they exist (e.g. EU↔Canada under the Canadian commercial adequacy).

If you'd like a copy of the SCCs we use with a specific sub-processor, email [email protected].

10 Children's privacy

Broadpath is a B2B product for logistics professionals. The service is not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact [email protected] and we will delete it.

11 Changes to this policy

We will update this policy as the service evolves. Material changes — anything that affects how we use your data — will be communicated by email or in-product notice at least 30 days in advance. The version history is maintained at /legal/privacy/; old versions are available on request.

12 Privacy contact

For any privacy-related question, exercise of rights, or DPA/GDPR data subject access request:

  • Email: [email protected]
  • Mail: Broadpath Logistics Inc. · Attn: Privacy Officer · Toronto, Ontario, Canada

For EU-based individuals, you can also contact your national supervisory authority — a list is at edpb.europa.eu/members.

For Canadian individuals, the Office of the Privacy Commissioner is at priv.gc.ca.


Broadpath Logistics Inc.
Toronto, Ontario, Canada
Incorporated under the laws of Ontario.