Skip to content
Annex Orbis

Legal

Privacy Policy

Last updated September 16, 2026

How ANNEX ORBIS Inc. ("ANNEX ORBIS", "we", "us") collects, uses, shares and protects personal information when you use app.annexorbis.com, annexorbis.com, Routes for Android and our related services (the "Services"). We do not sell personal information.

Contents

  1. 1. Who is responsible for your information
  2. 2. Information we collect
  3. 3. How we use information
  4. 4. How we share information
  5. 5. Artificial intelligence
  6. 6. Bank connections through Plaid
  7. 7. The public motor carrier directory
  8. 8. Cookies and browser storage
  9. 9. How long we keep information
  10. 10. Security
  11. 11. Your choices and rights
  12. 12. Children
  13. 13. Changes to this Policy
  14. 14. Contact us

1. Who is responsible for your information

ANNEX ORBIS Inc., doing business as "ANNEX ORBIS", 30 N Gould St #68044, Sheridan, WY 82801, provides a business operating platform to organizations ("Customers"). Customers use the Services to run their operations, and in doing so they put information about their employees, drivers, applicants, contractors, customers and contacts into the Services ("Customer Content").

  • For Customer Content, we are a service provider (processor). We process it on the Customer's behalf and under its instructions, as described in our Data Processing Addendum. The Customer decides what is collected and why, and its own privacy notice governs. If you are an employee, driver, applicant or contact of one of our Customers, please send requests about your information to that Customer first; we will help them respond.
  • We are responsible (controller) for account and sign-in information, security and audit records, visitors to annexorbis.com and contact-form submissions, the public motor carrier directory described in section 7, and the de-identified operational data we use to improve arrival-time predictions described in section 5.

This Policy is part of our Terms of Service.

2. Information we collect

Account and sign-in information. Name, work email address, phone number, profile photo, time zone, language and display preferences; organization memberships, roles and permissions; passkey public keys and credential identifiers (we never receive your private key or biometrics); and one-time sign-in codes and recovery codes, which we store only as irreversible hashes.

Session, device and security records. IP address, browser user agent, device name, platform and app version, when a session or device was first and last seen, and records of sign-ins, failed attempts, lockouts, passkey and device changes, step-up verifications and actions taken in the Services, each with IP address and user agent.

Customer Content. Depending on the features a Customer uses:

  • Email: messages, attachments, headers and participants for mailboxes hosted on the Services.
  • Phone and text: phone numbers, call details, SMS and MMS content, voicemail, call recordings and transcripts, and text-message consent records.
  • Chat and meetings: messages and attachments; meeting participants; and, where enabled with every participant's consent, meeting recordings, transcripts and summaries.
  • Files and e-signature: documents and their extracted text; for e-signature, each signer's name, email address, IP address, user agent, time zone and the times they viewed, consented and signed, kept in a tamper-evident audit trail.
  • Workforce and HR records: employment and assignment details; credentials and their expiry; compensation, pay stubs, deductions and benefits imported from payroll providers such as Gusto, Rippling or ADP; leave, accommodation, injury and workers' compensation records; voluntary EEO information; Form I-9 and E-Verify case status; conduct and performance records; time and attendance; and, where the employer enables it with notice and consent, presence and location samples.
  • Background screening: disclosures and consent records, screening requests and results returned by the consumer reporting agency the employer engages.
  • Routes and fleet: stops, addresses, schedules, vehicles, proof-of-delivery and inspection photos, compliance records, hours-of-service records and driver location.
  • Accounting: ledgers, invoices, documents and bank data (see section 6).
  • CRM: contacts, companies and form submissions, including the submitter's IP address and user agent.

Location from Routes for Android. While a driver is on duty or has an active route, the app collects precise location (latitude, longitude, accuracy, heading and speed) including while the app is closed or in the background, and sends it to the Services so the Customer can dispatch, track shipments, estimate arrival times and keep required records. Android shows an ongoing notification while this happens. Positions are sent from about every 5 seconds, while a customer is watching a delivery, to about once a minute when idle; during hours-of-service logging a position is recorded about once per second. Background location is requested with an in-app disclosure and can be turned off in Android settings, which stops tracking features from working.

Assistant ("HAL") information. Your requests, HAL's replies, the conversation thread, and memory notes HAL saves about your preferences. If you speak to HAL, your voice is converted to text by a speech provider and replies may be converted to speech.

Website visitors. When you submit the contact form on annexorbis.com we collect your name, email address, your consent to be contacted, and the IP address and user agent of the submission. Our hosting provider records standard request logs.

From third parties. Bank account and transaction data from Plaid when a Customer connects a bank account; payroll and benefits records a Customer imports; screening results from a consumer reporting agency a Customer engages; and public records from the U.S. Department of Transportation.

3. How we use information

  • To provide, operate and maintain the Services as the Customer directs.
  • To authenticate users, secure accounts, detect and prevent fraud and abuse, and keep security and audit records.
  • To send service messages such as sign-in codes, invitations, signing requests and security notices.
  • To provide support and respond to requests.
  • To improve arrival-time predictions as described in section 5.
  • To comply with law, respond to lawful requests and enforce our Terms.
  • With your consent, to contact you about ANNEX ORBIS after you submit our contact form.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use Customer Content for advertising.

4. How we share information

Service providers (sub-processors). We use providers for hosting, storage and content delivery, telecommunications, mapping, push notifications and AI. Each receives only what it needs to perform its service for us and is bound to use it only for that purpose. The current list, with what each receives, is on our Sub-processors page.

Plaid. See section 6.

Your organization. Information in an organization's workspace is visible to its members according to the roles and permissions its administrators set. Administrators can see security and activity records for their organization.

Background screening. Screening is performed by a consumer reporting agency the employer engages. We transmit the request and keep the consent record and results on the employer's behalf. ANNEX ORBIS is not a consumer reporting agency.

Legal and safety. We may disclose information if we believe in good faith that the law, a subpoena or other legal process requires it; to protect the rights, property or safety of ANNEX ORBIS, our users or others; or to investigate fraud or security issues. Where the law allows, we will tell the affected Customer first.

Business transfers. If ANNEX ORBIS is involved in a merger, acquisition, financing, reorganization or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

5. Artificial intelligence

Generative AI. HAL uses third-party language and speech models under commercial API terms (listed on our Sub-processors page). What is sent can include your request, recent conversation history, saved memory notes, and Customer Content HAL retrieves to answer you, such as file text, timelines, schedules or your own HR records. We do not use Customer Content to train generative AI models.

Arrival-time predictions. The Services include a machine-learning model, run on our own servers, that predicts trip and stop durations. For carriers that use hours-of-service logging and have a USDOT number, we train it on operational trip data pooled across those Customers: durations, distances, time of day, day of week, stop counts and hours-of-service time remaining. Training records carry internal identifiers but no names, contact details or message content, and the resulting model provides predictions to all Customers. When a Customer, driver profile or vehicle is deleted, its records are removed from future training. A Customer may ask us to exclude its data from training by emailing privacy@annexorbis.com.

AI output can be inaccurate. See the AI terms in our Terms of Service.

6. Bank connections through Plaid

When a Customer connects a bank account, we use Plaid Inc. ("Plaid") to gather the Customer's data from its financial institution. We use Plaid's Transactions product only. We receive and store each account's name, the last four digits of its number and its type; and each transaction's amount, currency, date, pending status, merchant name and category, for up to 24 months of history.

  • We never receive or store bank login credentials, and we do not receive full account or routing numbers.
  • The access token Plaid issues is encrypted before we store it.
  • When a Customer disconnects a bank connection, we ask Plaid to revoke our access and stop importing. Transactions already imported remain part of the Customer's accounting records, as described in our Data Retention and Deletion Policy.

By connecting an account you acknowledge that Plaid's collection, use and sharing of your information is governed by the Plaid End User Privacy Policy.

7. The public motor carrier directory

annexorbis.com includes a directory of motor carriers built from public U.S. Department of Transportation data published at data.transportation.gov. Because many carriers are sole proprietors, those public records can include names, business and mailing addresses, phone numbers and email addresses. We republish what the government publishes and keep earlier versions to show how a record changed. We are not affiliated with the U.S. Department of Transportation or FMCSA and do not guarantee the records are accurate.

To report a problem with a listing, use the report link on the carrier's page or email privacy@annexorbis.com. Changes to the underlying government record must be made with FMCSA. Carrier watch-list emails go only to users who follow a carrier, and every one contains an unsubscribe link.

8. Cookies and browser storage

We use only the cookies needed to run the Services. We do not use advertising or analytics cookies, and we do not load third-party tracking scripts.

CookiePurposeLasts
annexorbis_sessionKeeps you signed inUntil the session ends, up to 30 days
annexorbis_csrfProtects forms against cross-site request forgerySame as the session
annexorbis_deviceRecognizes a device you have signed in from, for securityUp to 400 days
ao_theme, annexorbis_railRemember display preferences1 year
annexorbis_passkey_nudgeHides a reminder you dismissed1 day
ao_portal_session, ao_portal_pendingSecure mail portal sign-inSession
__Host-ao-fmcsa, __Host-ao-fmcsa-handoffCarrier directory access and sign-in handoffUp to 30 days; 2 minutes

The web application also keeps display preferences and unsent drafts in your browser's local and session storage. Pages with maps load map software from HERE or OpenFreeMap, and connecting a bank loads Plaid Link; those providers receive your IP address and browser details when they serve that content.

9. How long we keep information

We keep information for as long as it is needed for the purposes in this Policy and for the periods in our Data Retention and Deletion Policy, which lists them in detail. In summary:

  • Customer Content is kept while the Customer's organization is active, subject to the retention settings the Customer configures and to legal holds, and is deleted after the Customer leaves as that policy describes.
  • Sign-in codes expire after 10 minutes and are deleted within a day; sessions last up to 30 days and their records are deleted 30 days after they end.
  • Security and audit records are kept for up to seven years.
  • Database backups are encrypted and kept for 7 days; deleted information can remain in a backup until that backup expires.

10. Security

  • In transit: every connection to the Services uses TLS 1.2 or higher.
  • At rest: the databases that hold Customer Content run on encrypted disks; database backups are encrypted with AES-256 before they leave our servers; stored files and objects are encrypted at rest by our storage provider; and bank access tokens are additionally encrypted by the application.
  • Secure Mail: mailboxes created as Secure Mail accounts are end-to-end encrypted, so message content is encrypted and decrypted on your approved devices and we hold only ciphertext. Ordinary mailboxes are encrypted at rest but readable by the Services so mail can be delivered and searched.
  • Access: passkeys, step-up verification for sensitive actions, role-based permissions, and database row-level security that keeps each organization's data separate.
  • Operations: restricted key-only server access, firewalls, daily configuration checks, and backups we restore and verify every week.

No system is perfectly secure. If a security incident affects your personal information, we will notify affected Customers and individuals as the law requires. To report a vulnerability, email security@annexorbis.com.

11. Your choices and rights

  • Access and correction: view and edit your profile in the Services.
  • Delete your account: in the web app, in Routes for Android, or at annexorbis.com/account-deletion. Choose immediate deletion or a 7-day scheduled deletion you can cancel.
  • Text messages: reply STOP to stop texts sent through the Services, or HELP for help.
  • Email: marketing and carrier watch-list emails contain an unsubscribe link. Service messages such as sign-in codes continue while you have an account.
  • Location: turn off background location for Routes for Android in Android settings.

U.S. state privacy rights. Depending on where you live, including California, Colorado, Connecticut, Virginia, Utah, Texas and Oregon, you may have the right to know and access the personal information we hold about you, to correct it, to delete it, to receive a portable copy, and to opt out of its sale, targeted advertising or certain profiling. We do not sell personal information or use it for targeted advertising, and we use sensitive personal information only to provide the Services.

To make a request, email privacy@annexorbis.com. We will verify your identity, respond within the time the law requires (generally 45 days), and will not discriminate against you for exercising your rights. You may use an authorized agent, and you may appeal our decision by replying to our response. If the information is Customer Content, we will refer your request to the Customer that controls it and help them respond.

Outside the United States. The Services are hosted in the United States and offered to U.S. businesses. If you use them from elsewhere, your information is transferred to and processed in the United States.

12. Children

The Services are for businesses and are not directed to children. You must be at least 18 years old to create an account. We do not knowingly collect personal information from children for our own purposes. A Customer may keep records about a minor it employs as Customer Content and is responsible for doing so lawfully. If you believe a child has given us personal information, email privacy@annexorbis.com and we will delete it.

13. Changes to this Policy

We may update this Policy. If a change is material, we will give notice by email or in the Services at least 30 days before it takes effect, unless the law requires a shorter period. The date at the top shows when it last changed.

14. Contact us

  • Privacy: privacy@annexorbis.com
  • Security: security@annexorbis.com
  • Support: support@annexorbis.com
  • Mail: ANNEX ORBIS Inc., Attn: Privacy, 30 N Gould St #68044, Sheridan, WY 82801
ANNEX ORBIS
ANNEX ORBIS Inc.
30 N Gould St #68044
Sheridan, WY 82801

Legal

  • Privacy Policy
  • Terms of Service
  • Acceptable Use Policy
  • Data Processing Addendum
  • Sub-processors
  • Data Retention and Deletion
  • Delete your account

Contact

  • Support · support@annexorbis.com
  • Privacy · privacy@annexorbis.com
  • Legal · legal@annexorbis.com
  • Security · security@annexorbis.com
  • Abuse · abuse@annexorbis.com
  • Talk to us
  • Sign in
© 2026 ANNEX ORBIS Inc. All rights reserved.