01Who this applies to
This is the privacy notice for Brunel Shipping, a last-mile pickup and delivery service built by Brunel Momentum (“we”, “us”). It covers this website, the merchant portal, the dispatch and admin portals, and the Brunel driver mobile app on iOS and Android.
Brunel is a business-to-business platform. The people whose data flows through it usually fall into one of these groups:
- Operators — dispatchers, warehouse staff, and admins at the company that runs Brunel.
- Merchants — businesses that hand parcels to Brunel and use the merchant portal to watch their shipments.
- Drivers — couriers who use the Brunel mobile app to pick up and deliver parcels.
- Recipients — the end customers receiving a delivery, who interact with the public tracking page and may receive SMS or email updates.
What we collect, why, and for how long depends on which group you are in.
02What we collect
From operators (dispatchers, admins)
- Name, work email, phone number.
- Authentication details (hashed password, session tokens).
- Audit logs of actions taken in the platform — who dispatched which route, who edited which stop, who reassigned which driver.
From merchants
- Business name, contact email, address.
- API keys and OAuth credentials for connected commerce platforms.
- Order data forwarded from the merchant’s store: recipient name, address, contact info, parcel contents (description only — never product price unless the merchant chooses to send it).
- Billing information processed by our payment provider (we do not store full card numbers).
From drivers (mobile app)
- Identity: name, phone number, photo, government-issued ID (driver’s licence), insurance certificate, vehicle inspection report.
- Location: precise GPS coordinates, but only while you are signed into an active route. The app does not collect location when you are off-shift, even if it has permission.
- Photos: proof-of-delivery photos you take inside the app, and any photos you choose to attach to a support message.
- Voice: audio is captured only while you press the microphone button for hands-free commands. It is transcribed on-device and the audio is discarded immediately.
- Device data: iOS/Android version, app version, device model, crash logs, and a per-install token used to send push notifications.
- Pay records: stops completed, miles driven, hours worked, tips received, fuel reimbursements claimed.
From recipients (the people receiving a delivery)
- Name, delivery address, and one of: phone number, email address — whichever the merchant included with the order.
- Optionally a one-time PIN (OTP) you typed at the door, a wet signature, or a delivery photo, when the delivery protocol requires one.
- If you visit the public tracking page: standard web logs (IP, user agent, page accessed). No advertising trackers.
03Why we collect each kind of data
| Data | Why | Legal basis |
|---|---|---|
| Driver location during active route | Live ETAs, on-site verification, progress for dispatch and the recipient. | Performance of contract |
| Driver photos / signature at delivery | Proof of delivery, dispute resolution, anti-fraud. | Performance of contract; legitimate interest |
| Recipient phone / email | “Out for delivery” and “delivered” notifications; OTP for high-value parcels. | Performance of contract |
| Operator audit logs | Security, compliance, debugging support tickets. | Legitimate interest; legal obligation |
| Crash and device logs | Fix bugs, harden the app. | Legitimate interest |
| Voice commands | Convert speech to a command. Audio discarded immediately. | Consent (you press the button) |
| Billing information | Charge for service; tax and accounting compliance. | Performance of contract; legal obligation |
04How long we keep it
- Live operational data (today’s routes, active stops, driver positions): retained while the route is active, then archived.
- Completed deliveries (PoD photos, signatures, GPS pin at delivery): kept for 2 years for dispute resolution and audit. Merchants can request earlier deletion of specific records.
- Driver pay records: kept for 7 years to comply with payroll record-keeping rules.
- Recipient contact info from a single delivery: deleted 90 days after the delivery completes, unless the recipient subscribed to ongoing tracking notifications, in which case it is kept until they unsubscribe.
- Crash / debug logs: 30 days.
- Voice audio: never stored. Discarded after on-device transcription.
- Account closure: when an operator, merchant, or driver account is closed, we delete personal data within 30 days, except records we are legally required to keep (e.g. payroll, tax invoices).
06Where data lives & international transfers
Brunel processes personal data primarily in Canada. Some service providers — for transactional email, SMS, mapping, and push notifications — operate from servers in the United States or other jurisdictions. If you are located outside Canada, your data may be transferred to and processed in Canada or the United States.
When personal data is transferred from regions with comprehensive data-protection laws (such as the European Economic Area, the United Kingdom, or Switzerland) to a country without an adequacy decision, we rely on appropriate safeguards — typically the European Commission’s Standard Contractual Clauses — together with supplementary technical and organizational measures.
07How we protect data
- Encryption — all data in transit is encrypted using industry-standard TLS; data at rest is encrypted with AES-256.
- Access control — least privilege. Only team members who need a particular dataset to do their job can access it. Access is logged.
- Application secrets are stored in dedicated secrets-management systems, never in source code or logs.
- Network isolation — production databases are not directly reachable from the public internet.
- Application security — public endpoints sit behind a managed web-application firewall. Authentication and OTP endpoints are rate-limited.
- Sensitive documents — government IDs and other identity documents are stored encrypted with restricted access.
- Vulnerability management — dependencies are continuously scanned and production systems are patched on a defined cadence.
- Incident response — we notify affected users and regulators within the timeframes required by applicable law.
No system is perfectly secure. If you believe an account has been compromised or you discover a vulnerability, contact us at the email below.
08Your rights
Subject to applicable law, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Correct — fix anything inaccurate or out of date.
- Delete — ask us to remove your data, subject to legal retention requirements (e.g. payroll, tax records).
- Export / portability — receive your data in a structured, commonly used, machine-readable format.
- Restrict or object — limit how we process specific kinds of data, including the right to object to processing based on legitimate interests.
- Withdraw consent — for anything we process on the basis of consent, without affecting the lawfulness of processing already carried out.
- Complain — to your local data-protection authority.
- Non-discrimination — we will not deny you service, charge you a different price, or provide a lesser quality of service for exercising any of these rights.
To exercise any of these rights, email privacy@brunelmomentum.ai. We respond within 30 days and may verify your identity before acting.
09Region-specific notices
California residents (CCPA / CPRA)
In addition to the rights in section 08, California residents have the right to know, delete, and correct personal information, to opt out of the “sale” or “sharing” of personal information, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined under the CCPA, and we do not engage in cross-context behavioural advertising. We honour Global Privacy Control (GPC) signals as a valid opt-out request.
European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP)
Brunel Momentum is the controller for personal data we collect directly. For data we process on a merchant’s behalf (such as recipient contact details supplied by a merchant’s store), the merchant is the controller and Brunel is the processor. Legal bases for processing are listed in section 03. You have the right to lodge a complaint with your local supervisory authority.
Quebec residents (Law 25)
- We have appointed a privacy officer responsible for the protection of personal information at Brunel Momentum, reachable at the email below.
- We do not currently engage in automated decision-making with legal or significantly similar effects on individuals.
- A privacy impact assessment is conducted before any new project that involves the collection, use, or disclosure of personal information at scale.
- Personal information transferred outside Quebec is subject to a written agreement and a privacy impact assessment.
Canada generally (PIPEDA)
You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
10Driver mobile app — specifics
The Brunel driver app uses sensitive iOS and Android permissions. Here is why each one exists, and how to turn them off.
- Location (Always) — required to track your live position while a route is active. You can revoke at any time in your phone’s settings; without it the app cannot dispatch you to stops.
- Camera — for barcode scanning and proof-of-delivery photos.
- Photo library — only used when you tap “attach photo” in support; we do not scan or upload your library otherwise.
- Microphone & speech recognition — only active when you tap the mic button; speech is converted to text on-device, and the audio itself is never sent to our servers.
- Background audio mode — used to play turn-by-turn voice navigation while the screen is off.
- Push notifications — for new route assignments, dispatcher messages, and customer reschedule events.
We do not use any third-party advertising identifiers (IDFA / AAID), analytics SDKs that track across apps, or session-replay tooling.
11Cookies & website analytics
This marketing website uses essential cookies and, where configured, first-party analytics to understand how pages are used. The dispatch, merchant, and platform portals use a single session cookie to keep you signed in. We do not deploy advertising trackers, cross-site identifiers, or session-replay tools on customer-facing surfaces.
If we add a product analytics tool to better understand how the portals are used, we will disclose it in this notice before the tool goes live, use a tool that does not engage in cross-site tracking, and provide a way to opt out where required by law.
12Children
Brunel is a B2B logistics platform. None of our services are intended for or directed at people under 16. We do not knowingly collect data from anyone under 16; if you believe we have, contact us and we will delete it.
13Changes to this notice
When we change this notice in a material way, we will update the effective date at the top of this page, notify operators and drivers in their respective apps, and email merchant administrators at the address on file. For non-material changes (typo fixes, restructuring), only the date changes.
14Get in touch
Brunel Momentum is the controller of personal data processed through Brunel Shipping, except where expressly identified otherwise (for example, where we process personal data on a merchant’s behalf). For privacy questions, rights requests, or complaints:
- Email: privacy@brunelmomentum.ai
- Mail: Brunel Momentum, Toronto, Ontario, Canada
See also our Merchant Terms of Service.