Privacy Policy
X3 SOP · Effective October 5, 2026 · Operated by X3 Fleet Safety LLC
X3 Fleet Safety LLC ("X3," "we," "us") provides fleet-safety and U.S. Department of Transportation (DOT) compliance software, including X3 Compass and the related X3 products (the "Services"). This Policy explains how we handle personal information in connection with the Services and our websites.
Because our customers are motor carriers and employers, most personal information we process is driver and applicant data that a customer submits to run its own compliance program. For that data the customer is the controller (or "business"), and X3 acts as a processor / service provider under the customer's instructions and our Data Processing Addendum (DPA). For account, billing, and website data, X3 is the controller.
1. Scope and roles
Customer-submitted data (drivers, applicants): customer is controller/business; X3 processes on its behalf under the DPA.
Account, billing, marketing, and website data: X3 is the controller.
2. Information we collect
Account and billing: name, business email, company, role, and payment information (processed by our payment processor; we do not store full card numbers).
Regulated driver / applicant data submitted by customers, which may include: identifiers (name, date of birth, Social Security number, driver-license number, state, and class); background and consumer-report information governed by the Fair Credit Reporting Act (FCRA); motor-vehicle-record (MVR) data governed by the Driver's Privacy Protection Act (DPPA); DOT drug-and-alcohol testing information governed by 49 CFR Part 40 Subpart P; medical-examiner certification status; hours-of-service (HOS) and electronic-logging-device (ELD) records; and driver-qualification (DQ) file documents.
Integration data: records X3 receives, at the customer's direction, from third-party ELD, applicant-tracking, screening, and MVR providers connected by the customer.
Website and usage data: privacy-focused, cookieless analytics and server logs; support communications.
3. How we use information
Provide, operate, secure, and support the Services and perform compliance monitoring the customer configures.
Billing, account administration, and customer communications.
Legal, regulatory, and safety obligations, and to enforce our terms.
We do not sell personal information. We do not use customer, driver, or applicant data to train artificial-intelligence models, and we contractually require the same of our AI sub-processor.
4. Artificial-intelligence processing
Certain features use a third-party large-language-model provider to extract, classify, and analyze documents (for example, background and MVR review). We apply data minimization so that regulated identifiers and Part 40 testing content are minimized or redacted before external processing where feasible, and we use this provider only under terms that prohibit it from training its models on our data.
5. Sub-processors and disclosure
We share personal information with vetted service providers who process it on our behalf under written contracts. Categories include cloud hosting and storage, database and vector storage, the AI provider described above, background and MVR providers, carrier-data providers, payment processing, and privacy-focused analytics, plus the ELD / applicant-tracking / screening integrations a customer connects. Our current Sub-processor List is maintained in, and incorporated by reference from, our DPA.
6. Regulated-data commitments
FCRA. Background information is consumer-report data used only for permissible purposes; the customer is responsible for obtaining the standalone disclosure and written authorization and for following adverse-action procedures.
DPPA. MVR data is used only for a permitted use under 18 U.S.C. 2721(b); we maintain records of redisclosure as required by 2721(c).
49 CFR Part 40 Subpart P. DOT testing information is treated as confidential and released only to authorized recipients consistent with specific written consent requirements.
7. Retention and disposal
We retain personal information only as long as necessary to provide the Services and to meet legal obligations. Where the FTC Safeguards Rule applies, we securely dispose of customer information no later than two years after the last date it was used, unless a longer period is required by law (for example, DQ-file and testing-record retention rules) or reasonably necessary for a legitimate business purpose.
8. Security
We maintain administrative, technical, and physical safeguards including encryption in transit and at rest, access controls, multi-factor authentication, logging and monitoring, and vendor oversight. See our Trust & Security Overview for detail.
9. Your choices and rights
Driver and applicant requests to access, correct, or delete regulated data are generally directed to the customer that submitted it (the controller); we assist customers in responding. Depending on your state, you may have rights under laws such as the CCPA/CPRA and other U.S. state privacy laws. We do not sell personal information, and we do not share it for cross-context behavioral advertising. To make a request, email [email protected]. We will not treat you differently for exercising your rights.
10. International transfers
The Services are intended for U.S. motor carriers and are operated from the United States. We do not direct the Services to individuals outside the United States.
11. Children
The Services are for business use and are not directed to children under 13, and we do not knowingly collect their personal information.
12. Changes
We may update this Policy and will revise the "last updated" date. For a material change in how we handle personal data, we will email account owners at least 30 days before it takes effect.
13. Contact
Privacy questions and requests: [email protected] (subject line "Privacy"). A postal address is available on request at that email.
← Back to X3 SOP · Questions? [email protected]