Legal
Privacy Policy
Last updated:
This policy explains what information we collect across buildwithrajan.com and the software products we operate — including RateConHQ (rateconhq.com, app.rateconhq.com) and hosted TMS deployments for individual client companies — how we use it, and the choices you have.
1. Who We Are and What This Policy Covers
The services covered by this policy are operated by Rajan, an independent software developer doing business as Build With Rajan (“we”, “us”, or “our”). This policy applies to:
- the marketing website buildwithrajan.com;
- our product sites and applications, including rateconhq.com and app.rateconhq.com; and
- hosted deployments — TMS and related software instances we operate for individual client companies, such as tms.shmtransport.com.
For data our business customers enter into a product about their own contacts (for example, a broker’s carriers and shippers), we act as a service provider processing that data on the customer’s behalf and under their instructions; the customer is responsible for their own privacy obligations toward those contacts.
2. Information We Collect
- Account data. Name, email address, phone number, and company name, collected when you register, subscribe, or contact us.
- Operational data. The business data customers enter into the TMS in the course of using it: shipments, carriers, customers, facilities, pricing, and documents such as rate confirmations and proofs of delivery. This may incidentally include personal information of the customer’s own contacts (for example, driver or dispatcher names and phone numbers).
- Demo and contact requests. When you submit a contact or demo form we store what you send, together with basic marketing attribution: the page you were on, the referrer, and first-touch and last-touch UTM parameters, so we know how you found us.
- Billing data. Subscription status and invoice history. Payment card details are collected and stored by Stripe, not by us (see Section 5).
- Technical logs. Standard server logs — IP address, browser type, pages requested, and timestamps — used for security and troubleshooting.
3. Cookies and Analytics
Our marketing sites (buildwithrajan.com and product marketing pages such as rateconhq.com) use:
- Google Analytics 4 — aggregate usage statistics: which pages are visited and how visitors arrive;
- Google Ads and Meta advertising tags — these record when a visit that began with one of our ads ends in a message or a booked call, so we can tell which ads are worth paying for. They are also used to show our ads to people who have visited before;
- first-party browser storage that remembers the campaign, referrer or ad click that brought you to the site, so a later message or booking can be credited to it. It is kept for 90 days, stays in your own browser, and is sent to us only if you actually submit the form; and
- Umami — privacy-friendly page analytics that sets no cookie and builds no profile.
If you are in the UK, the EEA or Switzerland, the advertising and analytics tags are set to denied by default under Google Consent Mode: no advertising or analytics identifiers are stored for you, and any reporting we see about your visit is modelled rather than measured.
The logged-in TMS application does not load marketing analytics. Inside the product we use only the cookies required to operate it, such as session authentication. You can control or delete cookies and site data through your browser settings; blocking them does not affect your ability to use the sites, and the contact form works exactly the same either way.
4. Connected Email Accounts and Google User Data
Users of our TMS applications — RateConHQ and hosted deployments such as tms.shmtransport.com — can connect their own Google or Microsoft email account so that the emails they write in the TMS (rate confirmations, invoices, tracking updates and similar messages) are sent from their own email address rather than from ours.
Google accounts
We use your Google account only to send the emails you write, from your own account. We never read your mailbox. When you choose “Sign in with Google” in the Email Center, Google asks you to grant exactly these permissions:
- Send email on your behalf (
gmail.send). This permission can only send messages. It cannot read, search, download, label, or delete anything in your mailbox, and we do not request any permission that could. - Your email address and name (
openid,email,profile). We use these to show which account is connected and to put your name and address on the emails you send.
We do not access your inbox, contacts, calendar, Drive, or any other Google data.
What we store. The access tokens Google issues for your connection, your Google email address and name, and a record of the emails you send through the TMS (recipients, subject, message, attachments and time sent), kept in your organization’s account so you and your team can see what was sent. The message content is what you wrote in the TMS, not anything taken from your mailbox.
How we protect and limit Google user data.
- We use it only to provide the sending feature you turned on, and for nothing else.
- We do not sell it, and we do not share or transfer it to anyone, except as needed to send your email (the message is delivered through Google’s Gmail API) and to host the service (our infrastructure provider, see Section 5), or when required by law.
- We do not use it for advertising, retargeting, or building profiles, and it is never used to develop, improve, or train artificial intelligence or machine learning models.
- No person at Build With Rajan reads it, unless you ask us to (for example, in a support request), it is needed to investigate security issues or abuse, or the law requires it.
Build With Rajan’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. You can disconnect your Google account at any time from the Email Center in the TMS, or from your Google Account connections page. Either one revokes our access straight away, and we can no longer send from your account. To have your stored tokens, Google email address and name deleted, email hello@buildwithrajan.com and we will delete them within 30 days.
Microsoft accounts
Microsoft (Outlook and Microsoft 365) accounts are connected the same way, through Microsoft’s own sign-in. We store the tokens needed to send (and, where the customer has enabled it, receive) email for the TMS, use the account only to provide those features, never read it for marketing or to build profiles, and never sell it. You can disconnect at any time from the Email Center or from your Microsoft account settings.
5. Third-Party Processors
We share data with a small number of service providers, only as needed to run the services:
- Stripe — payment processing. Card details are entered directly with Stripe and never touch our servers.
- DigitalOcean — cloud infrastructure where the services are hosted.
- Google Maps — geocoding and routing for addresses and lanes.
- Google (Gmail API) and Microsoft — deliver the emails you send from a connected email account (see Section 4).
- Trucker Tools — driver location tracking, used only when a customer initiates tracking for a load.
- FMCSA SAFER — lookups of public carrier safety and authority records.
Each provider receives only the data it needs for its function. We do not sell personal information to anyone, and we do not share it with third parties for their own advertising.
6. How We Use Information
- to provide, operate, secure, and improve the services;
- to respond to demo requests, questions, and support tickets;
- to bill subscriptions and send transactional messages about your account;
- to understand, in aggregate, how the marketing sites are found and used, so we can improve them; and
- to comply with legal obligations and enforce our Terms of Service.
We do not sell personal data, and we do not use customer operational data for advertising.
7. Data Retention
Account and operational data is retained while your organization’s account is active. After a subscription ends, data is kept for a limited wind-down period during which you can request an export (see our Terms of Service), after which it is deleted from active systems in the normal course, subject to routine backup cycles and any legal retention requirements. Contact and demo submissions are kept as long as needed to handle the inquiry and maintain a record of the relationship. Server logs are rotated on a short schedule. Tokens and account details for a connected Google or Microsoft account are kept until you ask us to delete them or your organization’s account is closed (see Section 4).
8. Security and Data Isolation
We protect data with measures appropriate to a business system of record, including:
- encryption in transit (TLS) across all sites and applications;
- per-organization data isolation — each customer organization’s data is logically separated, and one organization cannot access another’s records;
- role-based access controls within each organization’s account;
- routine backups and monitoring; and
- least-privilege access for administration.
No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you as required by applicable law.
9. Your Rights and Choices
You can request access to, correction of, export of, or deletion of your personal information by emailing hello@buildwithrajan.com. We will verify the request and respond within the time required by applicable law.
Depending on where you live, you may have specific legal rights — for example, under the California Consumer Privacy Act (CCPA), California residents can ask what personal information we hold, ask for its deletion, and are entitled not to be discriminated against for exercising those rights. We do not sell personal information, so there is nothing to opt out of on that front. If your data was entered into a product by one of our business customers (for example, your broker uses our TMS), we may refer your request to that customer, who controls that data.
10. Children’s Privacy
The services are business tools and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
11. Changes to This Policy
We may update this policy as the services or the law change. For material changes we will give notice — by email to account holders, a notice in the product, or a prominent note on this page — before the changes take effect. The “Last updated” date above always reflects the current revision.
12. Contact
Privacy questions and requests can be sent to hello@buildwithrajan.com, or by phone for US customers at +1 (206) 944-6897. We reply to most messages within one business day.