Privacy policy
Last updated 2026-08-20
Anvil holds the details of your freight, which means your customers' addresses and your shipping costs. This is what happens to it.
The short version
- Anvil collects what it needs to move freight and bill for it. Nothing else.
- Anvil does not sell your data, does not share it for advertising, and runs no analytics, advertising, or tracking scripts. There is one cookie and it keeps you signed in.
- Card numbers never reach Anvil. The payment processor holds them.
- Carriers get what they need to pick up and deliver, which is unavoidable: the driver needs the address.
- Your rates and your shipping volumes are never shown to another customer.
What Anvil collects
- Account and company details. Your name, work email, and password; your company name, legal name, EIN, phone, entity type, years trading, and the volume and spend ranges you report on the credit application.
- Freight details. Origin and destination addresses, contact names and phone numbers at those addresses, dock hours, commodity descriptions, weights, dimensions, classes, and any notes you add for the driver.
- Shipment and pricing history. Quotes requested, every carrier option returned, what you booked, what you were charged, tracking events, exceptions, and documents.
- Payment details. The card brand, last four digits, and expiry, plus a token from the payment processor. Not the card number. Card numbers go from your browser to the processor and never touch Anvil’s systems.
- An audit trail. Who did what and when: account changes, credit decisions, document uploads, disputes. Defending a damage claim or a rebill depends on proving what was known and when.
Anvil does not ask for and has no use for government identification numbers belonging to individuals, financial account credentials, or any special category of personal data.
Cookies and tracking
Anvil sets one cookie, anvil_session. It holds a random token and nothing else, it is httpOnly so scripts cannot read it, and it expires after 30 days or when you sign out. It exists to keep you signed in and there is no way to use the app without it.
One thing lives in your browser’s local storage: a Rate & book draft, saved only when you press Save and finish later and removed when the shipment books. It stays on your machine and is never sent anywhere.
There is no analytics, no tag manager, no advertising pixel, and no third-party script anywhere in the product. This is why Anvil has no cookie banner: there is nothing to consent to. If that ever changes, this page changes first.
Who else sees it
- The carrier you book. They receive the bill of lading: shipper and consignee names, addresses, contacts, commodity, weight, class, and your special instructions. A driver cannot deliver freight to an address they were not given.
- Anyone you send a tracking link to. The public tracking page shows status, carrier, and city-level movement. It deliberately withholds your rate, the full addresses, and the contact names.
- Service providers, each for one job and none for their own purposes: the database and file storage host [Supabase], the application host [hosting provider], the payment processor [Stripe], and the email provider [Resend].
- Anvil staff, when operating the service: reviewing a credit application, working an exception, or answering a question you raised.
Anvil will disclose data if required by law, and will tell you unless legally prevented. If Anvil is ever acquired, data moves with the business and this policy travels with it until you are told otherwise.
What Anvil does not do
- Sell your data. Not to carriers, not to data brokers, not to anyone.
- Show your pricing to another customer. Every query is scoped to your organization and that boundary is tested by attack on every change, not checked by hand once.
- Use your shipment history to advertise to you or to anyone else.
- Tell a carrier what a competing carrier quoted.
Anvil does use aggregate, de-identified information about lanes and volumes to negotiate carrier pricing and improve rating. That work never identifies a customer to a carrier or to another customer.
How long it is kept
Shipment records, charges, and the audit trail are kept for [retention period, at least the statute of limitations for freight claims], because a cargo claim or a carrier rebill can surface long after delivery and the record is the only defense. Account details are kept while the account is open and for that same period after it closes. Uploaded documents are deleted when you delete them.
Security
Passwords are stored as scrypt hashes and never in a form Anvil can read back. Sessions are server-side records rather than tokens, so removing someone from a team ends their access immediately instead of at the next expiry. Uploaded documents are never given a public URL; they are served only to a signed-in member of the organization that owns them.
No system is perfectly secure. If Anvil discovers a breach affecting your data you will be notified without undue delay, with what happened and what to do.
Your choices
You can see and edit your company profile, addresses, commodities, and documents in the app at any time, and you can choose which emails Anvil sends you in settings. Ask at [privacy contact address] for a copy of your data, a correction, or deletion. Anvil will keep what it must for the reasons in the retention section, and will tell you what it kept and why.
Anvil is a business service and is not directed at children. Anvil does not knowingly collect data from anyone under 18.
Changes and contact
Changes are posted here with a new date, and material ones are emailed to account owners.
Questions: [privacy contact address]. The terms of service cover the rest of the relationship.