LEGAL

Privacy Policy

Version 1.0 · Effective August 20, 2026

Short version: we collect what is needed to build your compliance record and nothing else. We never see bank or card numbers. We do not sell data, share it with advertisers, or use it to train models. You can export everything at any time.

1Scope

This policy covers flowerfreight.app, getflowerfreight.com, and the Flower Freight platform (the “Platform”), operated by Flower Freight LLC.

The Platform is a business tool for licensed New Jersey cannabis operators. It is not intended for consumers, and we do not knowingly collect information from anyone under 21.

2What We Collect

Account information. Company name, legal entity name, NJ-CRC license number and class, license expiry, facility address, contact name, email, and phone.

Driver information. Name, email, phone, Cannabis Business Identification Card number and expiry, driver's license state, last four digits, and expiry date. We store the last four digits only — never the full driver's license number.

Vehicle information. Make, model, year, VIN, license plate, registration expiry, and equipment compliance attributes.

Transport records. Load details, Metrc manifest numbers, package tags and quantities, package scan results, lab testing status, cargo temperature readings, receiver signatures and printed names, rejection reports and photographs.

Location data. GPS position, timestamp, and accuracy recorded from a driver's device during an active transport. Location is recorded only while a trip is in progress and only for the assigned driver. We do not track drivers between runs.

Metrc data. Transfers, deliveries, packages, and lab results retrieved through the Metrc API using credentials you provide.

Technical data. IP address, browser type, and timestamps in server logs, retained for security and troubleshooting.

3What We Do Not Collect

  • Bank account or routing numbers
  • Full payment card numbers — card data goes directly to Stripe and never touches our servers
  • Social Security numbers
  • Full driver's license numbers
  • Consumer or patient information
  • Driver location outside an active transport

We do not sell personal information. We do not share it with advertisers. We do not use it to train machine learning models.

4Why We Process It

To provide the Platform: verifying license and insurance status, importing and reconciling Metrc transfers, verifying packages against manifests, recording chain of custody, generating documentation, and alerting you before a credential expires.

To meet legal and contractual obligations, including the daily reconciliation verification required by the NJ CRC Confidentiality and API User Agreement, and record-keeping under N.J.A.C. 17:30.

To operate the business: billing, support, and security monitoring.

Our lawful basis is performance of a contract with you, and our legitimate interest in operating and securing the Platform.

5Metrc Data

You provide a Metrc User API Key issued to your own license. We use it only to read and write data on your behalf as described in this policy and in our agreement with you.

API keys are stored encrypted, are never shared between operators, and are never exposed to browsers or client code. Keys are non-transferable under the NJ CRC API User Agreement, and we treat them accordingly.

We hold a signed NJ CRC Confidentiality and API User Agreement. Data obtained through the Metrc API is confidential. If we receive a subpoena or other legal demand from a third party seeking Metrc-derived data, we will forward it to the Commission's Executive Director as that agreement requires, and will notify you unless prohibited from doing so.

Deleting your Flower Freight account does not delete anything from Metrc. Your records remain in the state system independently.

6Who Else Processes Your Data

We use the following subprocessors. Each is bound by its own contractual obligations, and we do not add subprocessors without updating this list.

SubprocessorPurposeDataLocation
SupabaseDatabase, authentication, file storageAll platform dataUnited States
VercelApplication hostingRequests in transit, server logsUnited States
MetrcState track-and-traceTransfers, packages, lab resultsUnited States
StripeSubscription billingBilling contact, payment method — held by StripeUnited States
ResendTransactional emailRecipient address, message contentUnited States
AnthropicIn-app support assistantYour support messages and account contextUnited States
MapboxGeocoding and route planningFacility addresses, coordinatesUnited States
DocuSignAgreement signingSigner name, email, signatureUnited States
KitMarketing emailEmail address, name, companyUnited States

All data is stored and processed in the United States. We do not transfer data internationally.

7How Long We Keep It

DataRetentionWhy
Account and loginLife of account + 30 daysReversal window if closure was a mistake
Metrc API keyDeleted immediately on closureNo reason to retain a credential
Driver and vehicle recordsLife of account + 30 daysOperational
Transport records, manifests, GPS trails, scans4 years after closureN.J.A.C. 17:30-13.3(a)(1) and 17:30-14.5(a)(1) require licensees to retain secure transport and delivery records for four years. We hold ours for the same period so nothing you are obliged to keep is destroyed on our schedule.
Server logs90 daysSecurity and troubleshooting
Billing records7 yearsTax and accounting

Before anything is deleted, we email you a complete export of your compliance record.

8Your Rights

Export. Account → Data → Export, any time. You receive every load, manifest, GPS trail, package scan, rejection, invoice, and reconciliation report we hold for you.

Correction. Most information is editable in your account. For anything that is not, email us.

Deletion. Account → Data → Delete Account. We export first, then follow the schedule in Section 7. Compliance records are retained for the stated period because the law requires you to keep them.

Access and questions. Email privacy@flowerfreight.app. We respond within 30 days.

9Security

Data is encrypted in transit using TLS and at rest by our database provider. Access is scoped per organization at the database level, so one operator cannot read another's records. Administrative access is limited to personnel who require it and is logged.

Full detail is on our Security page, including our incident notification commitments.

10Changes

If we make a material change to this policy — a new subprocessor, a new category of data, or a change in retention — we will email account holders at least 14 days before it takes effect.

The version and date at the top of this page always reflect the current policy.

Flower Freight LLC
Mount Laurel, New Jersey
privacy@flowerfreight.app

See also our Terms of Service and Security page. Nothing on this page is legal advice.