Privacy Policy
X3 DOT Audit · Effective August 13, 2026 · Operated by X3 Fleet Safety LLC
X3 Fleet Safety LLC ("X3," "we," "us") provides fleet-safety and U.S. Department of Transportation (DOT) compliance software, including X3 Compass and the related X3 products (the "Services"). This Policy explains how we handle personal information in connection with the Services and our websites.
Because our customers are motor carriers and employers, most personal information we process is driver and applicant data that a customer submits to run its own compliance program. For that data the customer is the controller (or "business"), and X3 acts as a processor / service provider under the customer's instructions and our Data Processing Addendum (DPA). For account, billing, and website data, X3 is the controller.
1. Scope and roles
Customer-submitted data (drivers, applicants): customer is controller/business; X3 processes on its behalf under the DPA.
Account, billing, marketing, and website data: X3 is the controller.
2. Information we collect
Account and billing: name, business email, company, role, and payment information (processed by our payment processor; we do not store full card numbers).
Regulated driver / applicant data submitted by customers, which may include: identifiers (name, date of birth, Social Security number, driver-license number, state, and class); background and consumer-report information governed by the Fair Credit Reporting Act (FCRA); motor-vehicle-record (MVR) data governed by the Driver's Privacy Protection Act (DPPA); DOT drug-and-alcohol testing information governed by 49 CFR Part 40 Subpart P; medical-examiner certification status; hours-of-service (HOS) and electronic-logging-device (ELD) records; and driver-qualification (DQ) file documents.
Integration data: records X3 receives, at the customer's direction, from third-party ELD, applicant-tracking, screening, and MVR providers connected by the customer.
Website and usage data: privacy-focused, cookieless analytics and server logs; support communications.
3. How we use information
Provide, operate, secure, and support the Services and perform compliance monitoring the customer configures.
Billing, account administration, and customer communications.
Legal, regulatory, and safety obligations, and to enforce our terms.
We do not sell personal information. We do not use customer, driver, or applicant data to train artificial-intelligence models, and we contractually require the same of our AI sub-processor.
4. Artificial-intelligence processing
Certain features use a third-party large-language-model provider to extract, classify, and analyze documents (for example, background and MVR review). We are implementing data-minimization so that regulated identifiers and Part 40 testing content are minimized or redacted before any external processing, and we process regulated data with this provider only under a written agreement providing zero data retention with the G4 determination (redaction-first Option A/B/C).]
5. Sub-processors and disclosure
We share personal information with vetted service providers who process it on our behalf under written contracts. Categories include cloud hosting and storage, database and vector storage, the AI provider described above, background and MVR providers, carrier-data providers, payment processing, and privacy-focused analytics, plus the ELD / applicant-tracking / screening integrations a customer connects. Our current Sub-processor List is maintained in, and incorporated by reference from, our DPA.
6. Regulated-data commitments
FCRA. Background information is consumer-report data used only for permissible purposes; the customer is responsible for obtaining the standalone disclosure and written authorization and for following adverse-action procedures.
DPPA. MVR data is used only for a permitted use under 18 U.S.C. 2721(b); we maintain records of redisclosure as required by 2721(c).
49 CFR Part 40 Subpart P. DOT testing information is treated as confidential and released only to authorized recipients consistent with specific written consent requirements.
7. Retention and disposal
We retain personal information only as long as necessary to provide the Services and to meet legal obligations. Where the FTC Safeguards Rule applies, we securely dispose of customer information no later than two years after the last date it was used, unless a longer period is required by law (for example, DQ-file and testing-record retention rules) or reasonably necessary for a legitimate business purpose. bases.]
8. Security
We maintain administrative, technical, and physical safeguards including encryption in transit and at rest, access controls, multi-factor authentication, logging and monitoring, and vendor oversight. See our Trust & Security Overview for detail.
9. Your choices and rights
Driver and applicant requests to access, correct, or delete regulated data are generally directed to the customer that submitted it (the controller); we assist customers in responding. Depending on your state, you may have rights under laws such as the CCPA/CPRA and other U.S. state privacy laws. We do not sell or share personal information for analysis and any required "Do Not Sell or Share" mechanism; state-law rights matrix (TX, VA, CO, and others).]
10. International transfers
The Services are intended for U.S. motor carriers and their data. 27 representative and named transfer mechanism (EU SCCs 2021 / UK IDTA).]
11. Children
The Services are for business use and are not directed to children under 13, and we do not knowingly collect their personal information.
12. Changes
We may update this Policy and will revise the "last updated" date; material changes will be communicated through the Services.
13. Contact
← Back to X3 DOT Audit · Questions? joshua@x3fleetsafety.com