Version 1.0 · Effective August 20, 2026
This policy covers flowerfreight.app, getflowerfreight.com, and the Flower Freight platform (the “Platform”), operated by Flower Freight LLC.
The Platform is a business tool for licensed New Jersey cannabis operators. It is not intended for consumers, and we do not knowingly collect information from anyone under 21.
Account information. Company name, legal entity name, NJ-CRC license number and class, license expiry, facility address, contact name, email, and phone.
Driver information. Name, email, phone, Cannabis Business Identification Card number and expiry, driver's license state, last four digits, and expiry date. We store the last four digits only — never the full driver's license number.
Vehicle information. Make, model, year, VIN, license plate, registration expiry, and equipment compliance attributes.
Transport records. Load details, Metrc manifest numbers, package tags and quantities, package scan results, lab testing status, cargo temperature readings, receiver signatures and printed names, rejection reports and photographs.
Location data. GPS position, timestamp, and accuracy recorded from a driver's device during an active transport. Location is recorded only while a trip is in progress and only for the assigned driver. We do not track drivers between runs.
Metrc data. Transfers, deliveries, packages, and lab results retrieved through the Metrc API using credentials you provide.
Technical data. IP address, browser type, and timestamps in server logs, retained for security and troubleshooting.
We do not sell personal information. We do not share it with advertisers. We do not use it to train machine learning models.
To provide the Platform: verifying license and insurance status, importing and reconciling Metrc transfers, verifying packages against manifests, recording chain of custody, generating documentation, and alerting you before a credential expires.
To meet legal and contractual obligations, including the daily reconciliation verification required by the NJ CRC Confidentiality and API User Agreement, and record-keeping under N.J.A.C. 17:30.
To operate the business: billing, support, and security monitoring.
Our lawful basis is performance of a contract with you, and our legitimate interest in operating and securing the Platform.
You provide a Metrc User API Key issued to your own license. We use it only to read and write data on your behalf as described in this policy and in our agreement with you.
API keys are stored encrypted, are never shared between operators, and are never exposed to browsers or client code. Keys are non-transferable under the NJ CRC API User Agreement, and we treat them accordingly.
We hold a signed NJ CRC Confidentiality and API User Agreement. Data obtained through the Metrc API is confidential. If we receive a subpoena or other legal demand from a third party seeking Metrc-derived data, we will forward it to the Commission's Executive Director as that agreement requires, and will notify you unless prohibited from doing so.
Deleting your Flower Freight account does not delete anything from Metrc. Your records remain in the state system independently.
We use the following subprocessors. Each is bound by its own contractual obligations, and we do not add subprocessors without updating this list.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All platform data | United States |
| Vercel | Application hosting | Requests in transit, server logs | United States |
| Metrc | State track-and-trace | Transfers, packages, lab results | United States |
| Stripe | Subscription billing | Billing contact, payment method — held by Stripe | United States |
| Resend | Transactional email | Recipient address, message content | United States |
| Anthropic | In-app support assistant | Your support messages and account context | United States |
| Mapbox | Geocoding and route planning | Facility addresses, coordinates | United States |
| DocuSign | Agreement signing | Signer name, email, signature | United States |
| Kit | Marketing email | Email address, name, company | United States |
All data is stored and processed in the United States. We do not transfer data internationally.
| Data | Retention | Why |
|---|---|---|
| Account and login | Life of account + 30 days | Reversal window if closure was a mistake |
| Metrc API key | Deleted immediately on closure | No reason to retain a credential |
| Driver and vehicle records | Life of account + 30 days | Operational |
| Transport records, manifests, GPS trails, scans | 4 years after closure | N.J.A.C. 17:30-13.3(a)(1) and 17:30-14.5(a)(1) require licensees to retain secure transport and delivery records for four years. We hold ours for the same period so nothing you are obliged to keep is destroyed on our schedule. |
| Server logs | 90 days | Security and troubleshooting |
| Billing records | 7 years | Tax and accounting |
Before anything is deleted, we email you a complete export of your compliance record.
Export. Account → Data → Export, any time. You receive every load, manifest, GPS trail, package scan, rejection, invoice, and reconciliation report we hold for you.
Correction. Most information is editable in your account. For anything that is not, email us.
Deletion. Account → Data → Delete Account. We export first, then follow the schedule in Section 7. Compliance records are retained for the stated period because the law requires you to keep them.
Access and questions. Email privacy@flowerfreight.app. We respond within 30 days.
Data is encrypted in transit using TLS and at rest by our database provider. Access is scoped per organization at the database level, so one operator cannot read another's records. Administrative access is limited to personnel who require it and is logged.
Full detail is on our Security page, including our incident notification commitments.
If we make a material change to this policy — a new subprocessor, a new category of data, or a change in retention — we will email account holders at least 14 days before it takes effect.
The version and date at the top of this page always reflect the current policy.