Privacy Policy
This policy explains what information Virtual Permit Book collects, why we collect it, who we share it with, and the choices you have.
Last updated: August 13, 2026
1. Who we are
Virtual Permit Book is operated by Virtual Permit Book LLC("we", "us", "our"), registered at 2262 Landmaier Rd Ste B, Elk Grove Village, IL 60007, United States. We provide a fleet compliance platform that lets trucking companies store permits and compliance documents digitally, share them with their drivers, and receive alerts before those documents expire.
This policy covers our website, our web application, and our iOS and Android mobile apps (together, the "Service").
2. Our role: controller and processor
Most information in the Service is uploaded by a fleet operator (our customer) about its own business, drivers and equipment. For that information the fleet operator is the data controller and we act as a data processor, handling it on their instructions.
For information we collect directly, such as the account details of the person who signs up and our website analytics, we are the data controller.
If you are a driver and want to know why your employer stores a particular document, please contact your employer first. We will help them respond.
3. Information we collect
Account information
When someone creates an account we collect their name, email address, company name and role. Passwords are stored only as salted hashes by our authentication provider. We never see or store your password in readable form.
Fleet and compliance records
Fleet operators enter records about their business, which commonly include:
- Driver details: name, email address, phone number, commercial driver licence (CDL) number, issuing state, licence expiry date, hire date and employment status
- Vehicle and trailer details: unit number, make, model, year, VIN, licence plate, mileage and service dates
- Company details: business name, DOT number, address and phone
A CDL number is a government issued identifier. We treat it as sensitive and restrict access to it accordingly.
Documents you upload
The core purpose of the Service is storing compliance documents, such as permits, licences, registrations, medical cards and insurance certificates. These files may contain personal information about drivers. We store them so that they can be retrieved by the fleet and shown during inspections.
Camera and photo library (mobile app)
With your permission, the mobile app uses your device camera to scan permit book QR codes and to photograph documents, and can access your photo library so you can upload an existing image. We access these only while you are actively using that feature. We do not scan, index or upload any other content from your camera roll.
Push notifications
If you enable notifications, we store a push token for your device so we can deliver expiry alerts and messages from your fleet manager. You can turn notifications off at any time in your device settings.
Technical and usage information
We record limited technical information needed to operate and secure the Service, including device type and operating system, app version, IP address, and audit logs of significant actions such as sign in, document upload and document deletion. Audit logs exist so fleets can demonstrate compliance and so we can investigate security incidents.
Website analytics and cookies
On vpbapp.com and in the web app at app.vpbapp.com we use Google Tag Manager to load Google Analytics 4. Analytics cookies record which pages you visit, how you reached us, your approximate location from a shortened IP address, and your browser and device type.
We use this only in aggregate, to see which pages help and where people get stuck. We do not use it to build advertising audiences, and we do not combine it with the compliance records a fleet stores in the Service. You can opt out with the Google Analytics opt out browser add on or by blocking cookies in your browser. Blocking them does not affect how the Service works.
Information from connected services
If a fleet connects a telematics provider such as Samsara, Motive or Geotab, we import vehicle and driver records from that provider in order to keep the fleet list in sync. We only import what is needed for compliance records. This connection is optional and can be disconnected at any time.
4. What we do not do
- We do not sell or rent personal information.
- We do not track your location. The mobile app does not request or collect GPS or background location data.
- We do not use advertising or cross app tracking. There are no advertising SDKs, no advertising identifiers and no tracking for marketing purposes in our mobile apps.
- We do not use your documents to train AI models.
5. How we use information
- To provide the Service and keep your records available to you
- To send expiry and renewal alerts, and notifications sent by your fleet manager
- To send necessary service emails, such as invitations and alerts
- To provide support and respond to your requests
- To secure the Service, prevent abuse, and maintain audit trails
- To meet our legal obligations
Where the GDPR applies, we rely on the following legal bases: performance of a contract, our legitimate interests in operating and securing the Service, compliance with a legal obligation, and consent where consent is requested (for example device notifications).
6. How we share information
We share information only with service providers who help us run the Service, and only to the extent needed. Our main providers are:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and file storage hosting |
| Resend | Sending transactional email such as alerts and invitations |
| Expo | Delivering push notifications to mobile devices |
| Vercel | Website and application hosting |
| Telematics providers | Samsara, Motive or Geotab, only if your fleet chooses to connect one |
We may also disclose information if required by law, to protect our legal rights, or in connection with a merger or acquisition, in which case we will give notice before your information becomes subject to a different policy.
7. Sharing documents by QR code and portal link
This section is important, so we state it plainly. The Service lets a fleet generate a QR code or link for a driver, vehicle or trailer. Anyone who scans that code or opens that link can view the compliance documents assigned to it, without signing in. This is deliberate, because it allows a driver to show documents to an inspector in seconds.
It also means that:
- Anyone holding the link or a photograph of the QR code can view those documents
- Links do not expire automatically. A fleet administrator can regenerate a code at any time, which immediately invalidates the previous one
- Documents marked confidential can be protected with a PIN, which we recommend for anything sensitive
Fleets should treat these codes like keys, regenerate them when a driver or vehicle leaves the fleet, and enable a PIN for sensitive records.
8. Data retention
We keep information for as long as the fleet operator maintains an active account, because compliance records must be retained and produced during audits. When an account is closed, we delete or anonymise the associated data within 90 days, unless we are legally required to keep it for longer. Backups are removed on a rolling schedule.
9. Security
We use encryption in transit, encryption at rest, role based access controls, row level database security so one fleet cannot access another fleet's records, and audit logging. No system is perfectly secure, but we work to protect your information and will notify affected customers without undue delay if a breach affects their data.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our use of your personal information, to receive a portable copy, and to withdraw consent. Residents of California additionally have the right not to receive discriminatory treatment for exercising these rights. We do not sell personal information.
To exercise a right, email info@vpbapp.com. If your information was uploaded by your employer, we will forward your request to them and support their response. You may also complain to your local data protection authority.
11. International transfers
We are based in and operate the Service from the United States. If you access the Service from outside the United States, your information will be transferred to and processed there. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
12. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the Service changes. We will update the date at the top of this page, and for material changes we will notify account holders by email or in the app before the change takes effect.
14. Contact us
For any privacy question or request, email info@vpbapp.com or write to Virtual Permit Book LLC, 2262 Landmaier Rd Ste B, Elk Grove Village, IL 60007, United States.