DRAFT — not yet legal advice. Have a solicitor review before publishing — especially the limitation of liability and governing law clauses. Related: Privacy Policy.
1. Who these terms are between
These terms are an agreement between Pipim Ltd (company number 16852516, registered in England and Wales, registered office 128 City Road, London, EC1V 2NX, United Kingdom) — "we", "us" — and the company subscribing to DQTrack — "you".
By creating an account you agree to these terms and to the Data Processing Agreement at Schedule A, which forms part of them.
2. What DQTrack is — and what it is not
DQTrack tracks dates and stores documents. It tells you which records exist, which are missing, and which are due to expire.
DQTrack does not certify that you are compliant with any regulation. It is not legal advice. It does not replace your own judgement, your safety manager, or your attorney.
Compliance with the Federal Motor Carrier Safety Regulations remains entirely your responsibility. We make no representation that using DQTrack will prevent a violation, a fine, a downgraded safety rating, or an adverse audit finding.
Federal rules on record retention (49 CFR 390.31) permit legible copies in place of originals. You are responsible for satisfying yourself that your use of electronic records meets your own regulatory obligations.
3. Who may use it
DQTrack is offered to motor carriers and their staff operating in the United States. You must be at least 18 and authorised to act for your company.
You are responsible for everything done under your account, for keeping credentials secure, and for telling us promptly if you think someone has gained access they should not have.
4. Your data belongs to you
You keep all rights in the data and documents you put into DQTrack. We claim no ownership of it. We use it only to provide the service to you, as set out in the Privacy Policy and Schedule A.
You can export everything, at any time, in one click — including after you cancel. We will never withhold your compliance records to pressure you into paying.
5. Subscriptions, trials and payment
Plans. $39/month for up to 8 active drivers, $89/month for up to 30, $149/month for up to 75. Every plan includes every feature. Fleets above 75 drivers should contact [email protected]. Prices are in US dollars and exclude any tax that may apply.
Active drivers only count. Archived and terminated drivers whose records you must retain do not count toward your limit, ever.
Trial. New accounts get 14 days free. A payment card is required to start the trial. We will email you before the trial ends, telling you the exact amount and date, with a way to cancel inside the app.
Cancelling. One click inside the app. No phone call, no email to us, no retention process.
If you forget to cancel and are charged, email us and we will refund it. We mean this and we do not ask questions.
Renewal. Subscriptions renew automatically each month until cancelled. Cancelling stops the next renewal; it does not refund the current period, except under the promise above.
Annual plans. If we offer annual billing, it is billed yearly at ten months' price and is refundable on a pro-rata basis for whole unused months.
Going over your plan limit. We will never block you from entering compliance data because of a plan limit. We will show you that you have passed it and ask you to upgrade. If you do not, we may move you to the correct plan after 30 days' notice.
Price changes. We may change prices with 30 days' notice. Existing customers keep their current price for at least 12 months from the date of any increase.
Failed payments. We will retry and email you. We will never delete or lock your documents over a failed payment; only writing new data is suspended.
6. What we promise about the service
We will provide DQTrack with reasonable skill and care, and take reasonable steps to keep it available and secure.
We do not promise uninterrupted or error-free operation. We do not guarantee that alert emails will be delivered — email delivery depends on systems outside our control, and you remain responsible for monitoring your own compliance dates. Alerts are shown in the application as well as by email; treat email as a convenience, not as the system of record.
We may change or remove features. If we remove something you depend on, we will give you 30 days' notice and a refund of any unused prepaid period if you choose to leave.
7. What you must not do
Do not use DQTrack to store data you have no right to hold; upload malware; attempt to access another customer's data; scrape, resell or white-label the service without our written agreement; or reverse engineer it.
We may suspend an account that is causing harm to the service or to others. We will tell you why, and where possible give you a chance to fix it first.
8. Limitation of liability
Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be limited.
Subject to that:
We are not liable for any fine, penalty, out-of-service order, downgraded safety rating, lost freight, increased insurance cost, or other consequence of a regulatory violation. DQTrack is a record-keeping and reminder tool. Meeting your obligations is your responsibility.
We are not liable for indirect or consequential loss, loss of profit, loss of business, or loss of data where you have not used the export function available to you.
Our total liability to you in any 12-month period is limited to the amount you paid us in the 12 months before the claim arose.
9. Ending the agreement
You may cancel at any time. We may end your subscription on 30 days' notice, or immediately if you seriously breach these terms.
When the agreement ends you keep export access for 30 days. After that, data is deleted on the schedule in the Privacy Policy — except records inside a federal retention window, which we keep available to you unless you instruct us in writing to delete them.
10. Changes to these terms
We may update these terms. For material changes we will email you at least 30 days beforehand. Continuing to use DQTrack after that means you accept them.
11. Governing law
These terms are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
12. Contact
[email protected] — Pipim Ltd, 128 City Road, London, EC1V 2NX, United Kingdom.
Schedule A — Data Processing Agreement
This Schedule forms part of the Terms and applies whenever we process personal data on your behalf. It is written to meet Article 28 of the UK GDPR.
A1. Roles
You are the controller. We are the processor. Your drivers and other staff are the data subjects.
A2. Subject matter, duration, nature and purpose
We process personal data in order to provide DQTrack: storing driver qualification and vehicle records, calculating regulatory due dates, sending reminders, and producing audit export packs. Processing continues for as long as your subscription is active, plus the retention periods set out in the Privacy Policy.
A3. Types of personal data
Driver name and contact details; commercial driving licence number, class, endorsements and expiry; states of licensure; employment dates; motor vehicle records; road test certificates; medical examiner's certificates and medical variances (health data — special category); drug and alcohol testing programme records (special category); Clearinghouse query dates and consent records; and vehicle identification and inspection records.
You must not upload Social Security numbers or payment card details into free-text fields. We provide no field for them and do not want them.
A4. Categories of data subject
Your employed and contracted drivers, and your own staff who use the service.
A5. Our obligations
We will:
- Process only on your documented instructions, including on transfers out of the UK, unless required otherwise by law — in which case we will tell you first, unless the law forbids it.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Implement appropriate technical and organisational security measures (see Annex 1).
- Engage sub-processors only under a written contract imposing equivalent obligations, and give you notice before adding or replacing one so you may object. We remain fully liable for their performance.
- Assist you in responding to data subject rights requests, and with your obligations on security, breach notification and data protection impact assessments.
- Notify you without undue delay after becoming aware of a personal data breach, with the information you need to meet your own obligations.
- On termination, delete or return the personal data as you choose, subject to the federal retention rules described in the Privacy Policy and to any legal requirement to keep it.
- Make available the information needed to demonstrate compliance and allow and contribute to audits by you or an auditor you appoint, on reasonable notice and no more than once a year unless there has been a breach.
A6. Sub-processors
You give general authorisation for the sub-processors listed on our Sub-processors page. We will give at least 30 days' notice before adding a new one. If you reasonably object on data protection grounds and we cannot resolve it, you may terminate and receive a refund of any unused prepaid period.
A7. International transfers
Data is hosted in the United States. Transfers out of the UK rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another approved mechanism.
A8. California
Where the CCPA/CPRA applies, we act as a service provider. We will not retain, use, or disclose personal information for any purpose other than performing the service, and will not sell or share it. We certify that we understand and will comply with these restrictions.
Annex 1 — Security measures
- TLS encryption in transit; encryption at rest for database and document storage.
- Documents held in private storage, accessible only via short-lived signed URLs.
- Database-level isolation between customers (row-level security), so no account can read another's data.
- Multi-factor authentication required on all administrative accounts.
- Append-only audit log recording every change to a compliance record or date, and document uploads and verification.
- Social Security numbers are never requested, extracted or indexed.
- Access to production data limited to personnel who need it, on a least-privilege basis, and logged.
- Regular backups, with restoration tested.
- Documented incident response procedure.
We do not currently hold SOC 2, ISO 27001 or equivalent certification, and we do not claim to. We will tell you honestly what we do and do not have.