Privacy Policy
Last updated: June 18, 2026
This document is provided by Ironhorse Logic LLC (doing business as Shield Carriers) and is pending attorney review.
Ironhorse Logic LLC (doing business as Shield Carriers) ("Shield Carriers," "we," or "us") is the company that operates Shield Carriers and the data controller responsible for the personal information described in this policy. We collect only what we need to operate the shield: your business name, USDOT number, real phone and email, signup attestation, classifications you select (e.g. hazmat), an optional profile photo you choose to upload, inbound traffic details (caller, timestamp, decision), and billing identifiers.
How we use it
Account data is used to set up and operate your shield. Inbound details are used to show your inbox and surface allow/block decisions. Billing identifiers are used to operate your subscription with Stripe. Ironhorse Logic LLC (doing business as Shield Carriers) does not sell your data and does not use it for targeted advertising.
Analytics & cookies
Our public website uses Google Analytics (GA4), a web-analytics service provided by Google, to understand how visitors find and use the site. When analytics is active, Google sets cookies in your browser and receives the pages you view (page paths and page titles), your approximate location (derived from your IP address), basic device and browser information, and a cross-domain session identifier that lets us recognize a single visit as it moves between Shield Carriers's marketing site and the app. We use this only for product and usage analytics — to see which pages and features carriers use. Ironhorse Logic LLC (doing business as Shield Carriers) does not sell this data and does not use it for targeted advertising; Google acts as our subprocessor for this purpose (see the Subprocessors page).
Analytics is off until you choose to allow it. The first time you visit, a banner lets you accept or decline analytics cookies, and we remember your choice on your device. If you decline — or simply ignore the banner — Google Analytics never loads and no analytics cookies are set or analytics data collected. You can change your choice at any time using the “Cookie preferences” link in the site footer.
Staff access
Our staff have no routine access to stored content; any access requires authorization and is logged in an audit trail.
Voice calls and voicemail
By default Shield Carriers does not record voice calls — for an ordinary screened call we capture only caller ID, time, duration, and our routing decision.
When a caller does not pass your shield's spoken screen, instead of simply being turned away they may be invited to leave a voicemail. The caller is told the line is filtered and asked to leave a message; if they choose to, the call may be recorded so you can hear what they wanted.
When a voicemail is recorded, we store the audio recording and, where available, a written transcript so you can review the message; the transcript is encrypted at rest and the recording is held in restricted storage. If a caller leaves no message, we keep only the call metadata. To produce the transcript, the voicemail audio is processed by our AI subprocessor (OpenAI, via the Replit AI proxy) — see the Subprocessors page. Recordings and transcripts are kept for your content-retention window (by default 7 days, configurable per carrier — see the Data Retention page) and then permanently deleted.
Inspection Mode
By default we store only metadata for inbound text and email (sender, timestamp, and our allow/block decision) — not the contents. If you turn on Inspection Mode for a channel, we begin capturing the contents (such as message subject and body) of inbound texts or emails for that channel so you can review what was filtered. Inspection Mode is off until you enable it, and you control it per channel from your settings.
Captured contents are encrypted at rest and automatically deleted after your content-retention window — by default 7 days after capture, which you can change per carrier (1, 3, 7, 14, or 30 days) in Settings → Privacy. The same window applies to voicemail recordings and transcripts. Inspection Mode applies only to text and email; it never records voice calls — voice is recorded only when a caller leaves a voicemail, described above. Ironhorse Logic LLC keeps captured contents only for as long as that window allows.
Separately, when your shield blocks a text or email as suspected spam, we keep that message's encrypted contents for 30 days so you can review it and recover a false positive (for example, a real load confirmation a keyword caught). This spam-quarantine window is independent of your content-retention window above and may be longer than the window you chose — see the Data Retention page.
Fraud prevention and consent records
To enforce our one-free-trial limit and detect abuse, we record a few signals when you sign up: a device fingerprint (a normalized identifier from your browser or mobile device), plus signals derived from your network and your business name. We do not store your raw IP address — we coarsen it to a network range and keep only a one-way hash, and your business name is likewise reduced to a one-way hash for this purpose. These signals can flag a signup for review but do not by themselves block you.
If you opt in to text reminders, we record your consent — the phone number, the time, and the version of the consent language you agreed to — and we honor STOP, HELP, and START replies as A2P 10DLC rules require. Mobile phone numbers and SMS opt-in and consent information are never shared with or sold to third parties or affiliates for marketing or promotional purposes. At onboarding we also look up your public FMCSA record (legal and DBA name, address, and insurance status and underwriter) to set up your safe-sender rules, and you may provide insurance details such as your renewal date.
Retention
See the Data Retention page for specific retention windows. You can export your account data or request deletion of your account yourself, any time, from Settings → Privacy — no email required. If you'd rather we help, you can still reach us at contact@shieldcarriers.net.
Subprocessors
Ironhorse Logic LLC (doing business as Shield Carriers) uses Twilio for telephony, Postmark for email, Clerk for authentication, Stripe for billing, OpenAI (via the Replit AI proxy) for voicemail transcription, Google (Google Analytics) for website analytics, Apple for in-app purchases on iOS, object storage for recordings and exports, and a managed Postgres database, among others. See the Subprocessors page for the current list and what each receives.