Privacy Policy

Last Updated October 23, 2023

This Straightaway Privacy Policy (“Policy”) applies to use of a mobile application offered by Straightaway LLC, with its principle place of business at 1133 15th St NW, Suite 825, Washington DC, 20005 (“Straightaway”) and branded as Straightaway Powered by Mapbox (the “App”), which is available both to individual independent drivers(“Independent Drivers”) who use the App to manage their own delivery routes and to drivers who use the App in connection with performing delivery services for Fleets (“Managed Drivers”) that have more than one ManagedDriver (“Fleets”), unless the Mapbox Data Processing Addendum (“DPA”) otherwise applies.

California Residents See Section 10 "California Notice At Collection" 

1. Personal Data Straightaway May Receive 

Identifiers. For example, Internet protocol address (“IP”), name, home address, email, phone number, Straightaway account username. 

Commercial information. For example, account creation data, including name, phone number, email, and professional title. Please note, to have access to all features, an Independent Driver must create their own account through the App. Managed Drivers may either create their own accounts through the App or a Fleet may create their accounts for them. 

Financial data. For example, 

Independent Drivers. When applicable, subscriptions to the App are processed through the Google Play store or the AppStore, and payments for the App are processed through such applicable service and RevenueCat. Straightaway does not receive payment card information but does receive confirmation of the transaction and subscription reports from RevenueCat. 

Fleet/Managed Drivers. Straightaway requires payment by Fleet of a fee for use of the services (or certain portions thereof), and thus requires its third-party PCI-certified payment provider, Stripe (and any information provided to Stripe is governed by its privacy policy) to collect credit card information, such as credit card number, expiration date and email and mailing addresses for billing and notification purposes, which is not processed by Straightaway. Payment information is encrypted and transmitted directly and securely to Stripe via HTTPS, and is not stored on Straightaway systems.‍ Payment information can be updated through a Straightaway account. 

Internet or other network or device activity. For example, 

○ When visiting or interacting with Straightaway’s website, certain information is automatically collected, including details about the visitor’s browser, operating system or device, pages visited, and information about clicked links. Straightaway’s website cookie policy is available here. 

○ When using the App, IP, device and browser information, operating system, the content of an API request, the date and time of the request, certain usage data, along with an ephemeral ID. 

● Employment data. For example, Fleet/Managed Drivers’ employer name and contact information. 

● Location information. For example, real-time and precise location data to provide an accurate route.

Other information that identifies or can be reasonably associated with an individual. For example, any information entered or uploaded to the App, including route information, delivery photos and notes, questions or feedback when information is requested about Straightaway services or register to receive information, requests for customer or technical support, or other communication with Straightaway. 

2. How Straightaway Uses Personal Data 

● Communicate with Fleet, Managed Driver, or Independent Driver; 

● Provide, test, maintain, secure and improve Straightaway products and services; 

● Provide requested support, including applying knowledge gained from individual customer support requests to benefit all Straightaway customers, to the extent such information is de-identified,

● Prevent fraud, misuse and cyberattacks; 

● Administer account & billing; 

● Calculate de-identified aggregate statistics; 

● Marketing purposes including analytics such as understanding when an email is opened or links/banners/content are clicked; 

● Anonymize data so it is no longer considered personal data; 

● Cooperate with public and government authorities, courts or regulators in accordance with Straightaway’slegal obligations; and 

● Comply with applicable law. 

Straightaway processes de-identified data only in de-identified form and does not permit attempts to re-identify such data or associate it with a natural person. 

3. To Whom Straightaway May Disclose Personal Data 

Straightaway does not sell personal data. Instead, Straightaway may disclose your personal data to the following parties: 

Fleet. Straightaway may disclose personal data, including real-time location of a Managed Driver with its Fleet who shall have access to certain of its Managed Driver’s personal data. All Managed Drivers should carefully read the applicable Fleet’s privacy policy to understand the Fleet’s privacy practices and the Managed Driver’s rights in that regard; 

Service Providers. Straightaway may disclose any personal data it collects with its service providers and sub-processors in accordance with the use cases outlined in Section 2 above (“How Straightaway Uses Personal Data”); 

Affiliates. Straightaway may share personal data with its affiliated companies; 

Disclosures to Protect Straightaway or Others. Straightaway may access, preserve, and disclose any information to external parties if Straightaway, in good faith, believes that doing so is required or appropriate to: 

● comply with law enforcement or national security requests and legal process, such as a court order or subpoena; 

● comply with law; 

● protect an individual’s, Straightaway or others’ rights, property, or safety; 

● enforce Straightaway policies or contracts; 

● collect amounts owed to Straightaway; and 

● assist with an investigation or prosecution of suspected or actual illegal activity. 

Disclosure in the Event of Merger, Sale, or Other Asset Transfers. If Straightaway is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, purchase or sale of assets, or transition of service to another provider, then associated personal data may be transferred as part of such a transaction or due diligence related thereto, as permitted by law and/or contract. 

4. International Transfer of Personal Data 

Personal data may be processed by one or more Straightaway affiliates, processors, or service providers in order to operate Straightaway’s business – for example, in the United States for account administration and billing. Therefore, personal data may be processed outside of the location from which it was received. Straightaway ensures that the transfer of personal data offers an adequate level of protection and security, for instance by entering into the appropriate agreements that continuously ensure the same level of protective measures as set forth in applicable data protection laws and regulations and, if required, standard contractual clauses or an 

alternative mechanism for the transfer of data as approved by the European Commission (Art. 46 GDPR) or other applicable regulators or legislators. 

ADDITIONAL INFORMATION FOR INDIVIDUALS OUTSIDE THE UNITED STATES Legal bases for processing personal data: 

Some countries require that companies only process personal data if they have a “legal basis” (or justifiable need) to process personal data. To the extent those laws apply, Straightaway’s legal bases to process personal data are as follows: 

● To comply with a legal obligation to which Straightaway, as a controller, is subject. 

● To protect the vital interests of an individual or of another natural person. 

● For the purposes of the legitimate interests pursued by Straightaway as the controller or by an independent third party controller, except where the individual’s interests or fundamental rights and freedoms override such interests. 

● Performance of the contract. 

● Consent. 

In all cases of data processing on the basis of legitimate interests, Straightaway considers the impact on the rights and freedoms of the individuals whose data may be part of the processing, and ensures that its processing activities do not contradict or place at unreasonable risk any such rights or freedoms. Straightaway has assessed that these legitimate interests are not overridden by the data protection interests or fundamental rights of any individuals. In all cases, Straightaway ensures that such processing is legal, fair, and reasonable. 

5. Retention 

Straightaway stores personal data for so long as Straightaway determines it is needed to fulfill the purposes for which it was collected. In determining how long to retain information, the amount, nature and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure of the data, the purposes for which personal data is processed, applicable legal requirements, and legitimate interests are considered. The purposes for which data is processed may dictate different retention periods for the same types of data. For example, Straightaway retains account information as long as there is an account and an additional period of time after that for legitimate interests, anti-frau, and legal compliance purposes. Additionally, Upon opting out of email marketing, Straightaway maintains email addresses on its suppression list for an extended time to comply with such requests. 

6. Security 

Straightaway takes steps designed to secure personal data in accordance with this Policy. Unfortunately, no system is 100% secure, and Straightaway cannot ensure or warrant the security of any personal data it receives. To the fullest extent permitted by applicable law, Straightaway does not accept liability for unintentional or accidental destruction, loss, alteration, unauthorized disclosure or access. 

7. Children’s Privacy 

The services are not directed to children under the age of 18 (or other age as required by local law), and Straightaway does not knowingly collect personal data from children. If a parent or legal guardian learns that their child has provided personal data to Straightaway without the parent or legal guardian’s consent, they may contact Straightaway as set forth below in Section 12 (“Contact Straightaway”). If Straightaway learns that it has collected personal data in violation of applicable law, it shall promptly take steps to delete such data and terminate the child’s account. 

8. Choices About Personal Data 

To the fullest extent possible, Straightaway shall fulfill data subject rights requests provided it can match a data subject (natural person to whom the personal data in question pertains) to personal data that Straightaway processes. Straightaway does not, and is not required to, collect additional personal data in order to positively identify a data subject. As outlined in Section 1 of this Policy, Straightaway receives only minimal personal data and operates controls designed to promptly de-identify and anonymize such personal data. For example, Straightaway deletes IP addresses within 30 days of receipt (unless required for an investigation), so it is unlikely that Straightaway would have personal data capable of identifying a data subject after 30 days of receiving such data. However, if verifiable and detailed information is available, Straightaway shall work with the data subject to determine if the request can reasonably be met. The data subject shall provide a valid email address so that Straightaway can communicate and support the request, as well as any information that Straightaway determines may be needed to verify whether it holds any applicable personal data. 

Managed Drivers. Managed Drivers shall not be able to withdraw their consent to processing of certain personal data collection that is required by Straightaway or their Fleet in connection with the services, and Straightaway shall refer any such inquiries to the applicable Fleet. See the applicable Fleet’s privacy policy for more information. 

Email and Telephone Communications. To unsubscribe from promotional email and telephone communications, click the unsubscribe link found at the bottom of the email and follow the prompts. Note that certain non-promotional communications regarding Straightaway and its services shall continue to be sent and shall not be capable of opting out of (e.g., communications regarding the services or updates to Straightaway Terms or this Policy). Straightaway processes requests to be placed on do-not-mail, do-not-phone and do-not-contact lists as required by applicable law. 

Mobile Devices. Straightaway may send push notifications through the App. Push notifications may be opted-out of at any time by changing the applicable mobile device’s settings. Straightaway also collects location-based information when a Managed Driver or Individual Driver uses the App. Managed Drivers and Individual Drivers may opt-out of such location-based information collection by changing applicable mobile device’s settings. However, the App may not function as intended or as required by the applicable Fleet. 

In accordance with applicable data protection laws and regulations and depending upon the data subject’s residency, the data subject to whom the personal data pertains may have the right to request the following regarding certain of their personal data: 

Access/view/know personal data 

Portability of personal data in a commonly machine readable format 

Correct personal data where it is inaccurate or incomplete 

Deletion of certain personal data 

Restrict or object to processing of personal data 

Opt-out of the “sale” or “share” or processing for “targeted advertising” (each as defined by applicable data protection laws and regulations) of personal data , if applicable, where such requests are permitted by law 

How to make a request. To request deletion of certain personal data, please complete the form here. For any other request to exercise rights, please contact Straightaway at privacy@mapbox.com. The requesting email must come from the data subject to whom the personal data pertains and include the data subject’s name, email address and specific request or question. To protect privacy, Straightaway may take steps to verify the identity of the requestor before fulfilling the request. Straightaway shall process such requests in accordance with applicable data protection laws and regulations. 

To the extent required under applicable data protection laws and regulations in the state where the data subject resides and where Straightaway has denied such data subject’s earlier request, the data subject may file an appeal with Straightaway for reconsideration. To file an appeal, please contact Straightaway at privacy@mapbox.com. The requesting email must come from the data subject to whom the personal data pertains and include the data subject’s name, email address and reference to the specific request and denial. 

Straightaway encourages data subjects to contact Straightaway directly with any questions or complaints. However, Straightaway acknowledges and informs the data subject that they have the right to lodge a complaint in the EU and UK with the appropriate supervisory authority in the applicable jurisdiction; and in select United States states, to contact the respective state’s Attorney General’s Office, whose contact information may be identified here https://www.usa.gov/state-attorney-general (or successor link). In some cases, these rights may be subject to exceptions, as permitted by applicable law. 

9. Third Party Content 

The services may contain links to other websites, and other websites may reference or link to Straightaway’s website or other services. These other websites are not controlled by Straightaway. Straightaway encourages users to read the privacy policies of each service / website / app with which they interact. Straightaway does not endorse, screen or approve and is not responsible for the privacy practices or content of third parties. 

10. Additional Information For California Residents 

10.1 Personal Data Straightaway May Receive 

Identifiers. For example, Internet protocol address (“IP”), name, home address, email, phone number, Straightaway account username. 

Commercial information. For example, account creation data, including name, phone number, email, and professional title. Please note, to have access to all features, an Independent Driver must create their own account through the App. Managed Drivers may either create their own accounts through the App or a Fleet may create their accounts for them. 

Financial data. For example, 

Independent Drivers.When applicable, subscriptions to the App are processed through the Google Play store or the AppStore, and payments for the App are processed through such applicable service and RevenueCat. Straightaway does not receive payment card information but does receive confirmation of the transaction and subscription reports from RevenueCat. 

Fleet/Managed Drivers. Straightaway requires payment by Fleet of a fee for use of the services (or certain portions thereof), and thus requires its third-party PCI-certified payment provider, Stripe (and any information provided to Stripe is governed by its privacy policy) to collect credit card information, such as credit card number, expiration date and email and mailing addresses for billing and notification purposes, which is not processed by Straightaway. Payment information is encrypted and transmitted directly and securely to Stripe via HTTPS, and is not stored on Straightaway systems.‍ Payment information can be updated through a Straightaway account. 

Internet or other network or device activity. For example, 

○ When visiting or interacting with Straightaway’s website, certain information is automatically collected, including details about the visitor’s browser, operating system or device, pages visited, and information about clicked links. Straightaway’s website cookie policy is available here. 

○ When using the App, IP, device and browser information, operating system, the content of an API request, the date and time of the request, certain usage data, along with an ephemeral ID. 

● Employment data. For example, Fleet/Managed Drivers’ employer name and contact information. 

● Location information. For example, real-time and precise location data to provide an accurate route. 

Other information that identifies or can be reasonably associated with an individual. For example, any information entered or uploaded to the App, including route information, delivery photos and notes, questions or feedback when information is requested about Straightaway services or register to receive information, requests for customer or technical support, or other communication with Straightaway. 

10.2 How Straightaway Uses Personal Data 

● Communicate with Fleet, Managed Driver, or Independent Driver; 

● Provide, test, maintain, secure and improve Straightaway products and services; 

● Provide requested support, including applying knowledge gained from individual customer support requests to benefit all Straightaway customers, to the extent such information is de-identified, 

● Prevent fraud, misuse and cyberattacks; 

● Administer account & billing; 

● Calculate de-identified aggregate statistics; 

● Marketing purposes including analytics such as understanding when an email is opened or links / banners / content are clicked; 

● Anonymize data so it is no longer considered personal data; 

● Cooperate with public and government authorities, courts or regulators in accordance with Straightaway’s legal obligations; and 

● Comply with applicable law. 

Straightaway processes de-identified data only in de-identified form and does not permit attempts to re-identify such data or associate it with a natural person. 

10.3 To Whom Straightaway May Disclose Personal Data 

Straightaway does not sell personal data. Instead, Straightaway may disclose your personal data to the following parties: 

Fleet. Straightaway may disclose personal data, including real-time location of a Managed Driver with its Fleet who shall have access to certain of its Managed Driver’s personal data. All Managed Drivers should carefully read the applicable Fleet’s privacy policy to understand the Fleet’s privacy practices and the Managed Driver’s rights in that regard; 

Service Providers. Straightaway may disclose any personal data it collects with its service providers and sub-processors in accordance with the use cases outlined in Section 2 above (“How Straightaway Uses Personal Data”); 

Affiliates. Straightaway may share personal data with its affiliated companies; 

Disclosures to Protect Straightaway or Others. Straightaway may access, preserve, and disclose any information to external parties if Straightaway, in good faith, believes that doing so is required or appropriate to: 

● comply with law enforcement or national security requests and legal process, such as a court order or subpoena; 

● comply with law; 

● protect an individual’s, Straightaway or others’ rights, property, or safety; 

● enforce Straightaway policies or contracts; 

● collect amounts owed to Straightaway; and 

● assist with an investigation or prosecution of suspected or actual illegal activity. 

Disclosure in the Event of Merger, Sale, or Other Asset Transfers. If Straightaway is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, purchase or sale of assets, or transition of service to another provider, then associated personal data may be transferred as part of such a transaction or due diligence related thereto, as permitted by law and/or contract. 

10.4 Retention 

Straightaway stores personal data for so long as Straightaway determines it is needed to fulfill the purposes for which it was collected. In determining how long to retain information, the amount, nature and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure of the data, the purposes for which personal data is processed, applicable legal requirements, and legitimate interests are considered. The purposes for which data is processed may dictate different retention periods for the same types of data. For example, Straightaway retains account information as long as there is an account and an additional period of time after that for legitimate interests, anti-frau, and legal compliance purposes. Additionally, Upon opting out of email marketing, Straightaway maintains email addresses on its suppression list for an extended time to comply with such requests. 

11. Changes To This Privacy Policy 

Straightaway may update this Policy at its own discretion from time to time to reflect changes in Straightaway’s practices, technologies, legal requirements, and other factors. 

12. Contact Straightaway 

Straightaway would love to hear any questions, concerns, or feedback about this Policy or Straightaway’s data protection practices. Please contact Straightaway at privacy@mapbox.com.