Back to CargoOS

Privacy Policy

CargoOS by Gasp Maker LLC — Last updated: July 2026

1. Introduction

CargoOS ("we", "our", "us") is a Software-as-a-Service (SaaS) platform operated by Gasp Maker LLC. This Privacy Policy explains how we collect, use, and protect information when you use our platform at cargoos.io.

2. Information We Collect

Operator Information: When a logistics company ("Operator") subscribes to CargoOS, we collect business name, contact information, billing details, and API credentials (EasyPost, Stripe) provided by the Operator.

End-User Information: Operators use CargoOS to manage their own customers ("End Users"). End User data — including names, addresses, shipping details, and payment information — is processed on behalf of the Operator.

Usage Data: We collect technical data such as IP addresses, browser type, pages visited, and actions taken within the platform to improve our service.

3. How We Use Information

  • To provide, maintain, and improve the CargoOS platform
  • To process payments and manage subscriptions
  • To generate shipping labels and rate quotes via integrated carriers
  • To send operational notifications and support communications
  • To comply with legal obligations

4. Data Sharing

We do not sell personal data. We share data only with:

  • Stripe — payment processing. Card numbers are never stored on CargoOS servers. Stripe is PCI DSS Level 1 certified.
  • EasyPost — shipping label generation. End User shipping addresses and package details are shared with EasyPost and transmitted to the selected carrier (FedEx, UPS, DHL, USPS) solely to fulfill the shipment.
  • Supabase — secure SOC 2 Type II certified database hosting.
  • Vercel — SOC 2 Type II certified platform hosting.
  • Resend — transactional email delivery for operational notifications only.

CargoOS does not contact End Users directly for marketing or any purpose other than platform operations. End User data belongs to the Operator.

4B. Identity Documents & USPS Compliance

Operators who offer Virtual Mailbox services are required by U.S. law (USPS Regulation 39 CFR Part 111) to collect a completed USPS Form 1583 from each mailbox holder, including government-issued photo identification.

  • Identity documents uploaded to the platform are transmitted and stored using TLS encryption.
  • Access to identity documents is restricted to the Operator and authorized platform administrators only.
  • CargoOS does not use identity documents for any purpose other than USPS compliance verification.
  • Operators are solely responsible for maintaining USPS Form 1583 compliance for their mailbox customers.

5. Data Security

We implement the following security measures to protect your data:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS.
  • Supabase (Database): SOC 2 Type II certified hosting with encryption at rest.
  • Vercel (Hosting): SOC 2 Type II certified infrastructure.
  • Stripe (Payments): PCI DSS Level 1 certified. We never store raw card numbers.
  • API Credentials: Operator API keys are stored encrypted and never exposed in plaintext or logs.
  • Access Control: Role-based access limits what each user can see and do within the platform.

CargoOS itself does not hold SOC 2 or ISO 27001 certification at this time. We rely on the certified infrastructure of our service providers listed above.

6. Data Retention

Operator and End User data is retained for the duration of the active subscription plus 90 days after cancellation. Operators may request deletion of their data at any time by contacting hello@cargoos.io.

7. Operator Responsibilities

Operators are responsible for obtaining proper consent from their End Users for data collection and processing. CargoOS acts as a data processor on behalf of Operators, who serve as data controllers for their customers' information.

7B. Data Ownership & Portability

Operators are the Data Controllers of their End Users' data. CargoOS acts solely as a Data Processor on behalf of Operators.

  • End User data — including names, addresses, shipping history, and payment records — belongs to the Operator, not to CargoOS.
  • CargoOS will never contact End Users directly for marketing, upselling, or any commercial purpose.
  • Upon cancellation of an Operator's subscription, CargoOS will provide a full data export within 30 days upon written request.
  • After data export delivery, CargoOS will permanently delete the Operator's data from its servers within 90 days.

8. Cookies

We use essential cookies for authentication and session management. We do not use tracking or advertising cookies. Language preferences are stored in a cookie to improve user experience.

9. Your Rights

CargoOS is operated by Gasp Maker LLC, a company registered in Florida, USA. We process data under applicable U.S. law.

  • Florida residents: You have the right to request access to or deletion of your personal data.
  • California residents (CCPA): You have the right to know what data we collect, request deletion, and opt out of sale. We do not sell personal data.
  • International users: We respect data subject rights on a best-effort basis. We do not currently hold GDPR Data Processing Agreements but will cooperate with reasonable requests.

To exercise any of these rights, contact us at hello@cargoos.io.

10. Changes to This Policy

We may update this Privacy Policy periodically. We will notify Operators of material changes via email. Continued use of CargoOS after changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related questions or requests:

Gasp Maker LLC — CargoOS

1861 NW 22nd St, Miami, FL 33142

Email: hello@cargoos.io

Website: cargoos.io

© 2026 CargoOS by Gasp Maker LLC. All rights reserved.