MalcolmAI MalcolmAI
Home Features Integrations Request Demo

Privacy Policy

Effective Date: July 4, 2026

1. Introduction

MalcolmAI LLC ("MalcolmAI," "we," "us," or "our") is committed to protecting the privacy of our customers and the individuals whose data is processed through our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our AI-powered container inspection platform, mobile application, web admin dashboard, and related services (collectively, the "Service").

MalcolmAI provides a business-to-business (B2B) SaaS platform. Our customers are intermodal shipping terminals, container depots, and logistics companies ("Customers"). This policy applies to Customer employees and authorized users who interact with the Service, as well as individuals whose information may be captured during the container inspection process (such as truck drivers).

2. Information We Collect

2.1 Account and User Information

When Customers register for the Service, we collect:

  • Organization name, address, and business contact information
  • Individual user names, email addresses, and job titles
  • Account credentials (passwords are stored in hashed form only)
  • Billing and payment information (processed by our payment provider; we do not store full payment card numbers)

2.2 Container Inspection Data

During the container inspection workflow, the Service captures:

  • Container door photographs. images of container markings including owner codes, serial numbers, check digits, size/type codes, and operational markings (weights, dimensions)
  • Chassis number photographs. images of chassis identification numbers
  • License plate photographs. images of vehicle license plates including state or province identifiers
  • Container seal photographs. images of security seals including seal numbers and condition
  • AI-extracted data. structured data extracted from the above photographs by our AI processing pipeline, including container IDs, chassis numbers, plate numbers, seal numbers, weights, and confidence scores

2.3 Driver Credential Data

The Service captures photographs of driver's licenses or commercial driver's licenses (CDLs) for operator verification purposes. This may include:

  • Driver name, license number, and issuing state
  • License class, endorsements, and expiration date
  • Photograph of the physical license document

Important: Driver credential data is collected by the Customer as part of their gate operations. MalcolmAI processes this data on behalf of the Customer. The Customer is responsible for ensuring that appropriate notice is given to drivers and that collection complies with applicable law.

2.4 Yard, Booking, and Invoicing Data

Customers using the yard management and invoicing modules may store additional business records in the Service:

  • Yard operations data. container yard locations, placement and retrieval history, dwell times, and gate in/out events
  • Shipping-customer records. business contact and billing information for the Customer's own shipping customers (company names, contact names, email addresses, phone numbers, billing addresses, tax identifiers) used to generate bookings and storage invoices
  • Booking and invoice records. capacity bookings, rate cards, invoices, and related confirmation emails sent at the Customer's direction to the Customer's own shipping customers

Important: This data is collected and controlled by the Customer as part of its own business operations. MalcolmAI processes it on behalf of the Customer.

2.5 Gate Payment Data

Customers using the payments module can collect card payments from drivers for yard services. In connection with these payments, the Service processes:

  • Payer contact information. an email address (for the payment receipt) and optionally a phone number provided by the payer at the time of the charge
  • Transaction records. itemized charges, amounts, payment status, refunds, and operator/device attribution

Card data never touches MalcolmAI systems. Card numbers are entered directly into payment surfaces hosted by Stripe, our payment infrastructure provider (see Section 4.2). We store only the transaction outcome and non-sensitive metadata returned by Stripe.

2.6 Device and Location Data

When using the mobile application, we collect:

  • GPS coordinates. location data associated with each inspection transaction, providing a verifiable record of where the inspection occurred
  • Device information. device model, operating system version, app version, and unique device identifiers
  • Network information. connection type (WiFi/cellular) and network status for offline queue management

2.7 Usage and Analytics Data

We automatically collect information about how the Service is used, including:

  • Feature usage patterns, screen views, and navigation paths
  • Inspection completion times, upload statistics, and processing metrics
  • Error logs, crash reports, and performance data
  • Login timestamps, session duration, and access patterns

3. How We Use Information

We use the information we collect for the following purposes:

PurposeData Used
Providing the Service. processing container images, extracting data, delivering results to CustomersInspection data, driver credentials, device/location data
AI Processing. analyzing images using multimodal AI models to extract container, chassis, plate, seal, and driver informationPhotographs submitted through the inspection workflow
Quality Assurance. confidence scoring, review queue management, and accuracy improvementExtracted data, confidence scores, manual correction history
Account Management. user authentication, access control, and subscription managementAccount information, credentials, billing data
Customer Support. responding to inquiries, troubleshooting issues, and providing technical assistanceAccount information, usage data, error logs
Service Improvement. analyzing usage patterns, optimizing performance, and developing new featuresAggregated usage and analytics data
Security and Compliance. detecting fraud, preventing unauthorized access, and maintaining audit trailsAccess logs, device information, usage patterns
Gate Payments. creating payment charges, delivering receipts, processing refunds, and reconciling transactions on behalf of the CustomerPayment transaction records, payer contact information
Yard, Booking & Invoicing. tracking yard inventory, managing bookings, and generating storage invoices on behalf of the CustomerYard operations data, shipping-customer records, booking and invoice records
Communications. sending service notifications, maintenance alerts, and product updatesAccount contact information

4. Data Sharing and Disclosure

4.1 With the Customer Organization

All inspection data, extracted results, and associated metadata are accessible to the Customer organization that initiated the inspection. Customers control access through their own user management and role-based permissions.

4.2 Third-Party Service Providers

We share data with the following categories of service providers who assist in delivering the Service:

  • AI Processing (Google Gemini). Container and credential photographs are transmitted to Google's Gemini API for AI-powered data extraction. Images are processed under Google's API data usage policies, which prohibit using API inputs for model training.
  • Cloud Infrastructure (Amazon Web Services). All data is stored and processed on AWS infrastructure, including S3 (image storage), ECS (compute), SQS (message queuing), and Amazon DocumentDB (database).
  • Payment Processing (Stripe). Gate card payments are processed by Stripe, Inc. under the Customer's own Stripe connected account — the Customer, not MalcolmAI, is the merchant of record. Card details are entered directly into Stripe-hosted payment surfaces and are never transmitted to or stored on MalcolmAI systems; Stripe delivers payment receipts to the payer's email address. Stripe's processing is governed by its own privacy policy. Our subscription billing of Customers is likewise handled by our payment processor; we do not store full payment card information on our systems.
  • Email Delivery. Transactional emails (booking confirmations, user invitations, service notifications) are sent through our email delivery provider on the Customer's behalf.

4.3 Customer Integrations

At the Customer's direction, we transmit extracted container data to the Customer's TMS, WMS, or ERP systems via webhooks, REST APIs, or direct database connections configured by the Customer.

4.4 Legal Requirements

We may disclose information when required by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect the rights, safety, or property of MalcolmAI, our Customers, or others.

4.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, Customer data may be transferred to the successor entity, subject to the commitments made in this Privacy Policy.

4.6 No Sale of Data

We do not sell, rent, or trade personal information to third parties for their marketing purposes.

We also do not share personal information for cross context behavioral advertising as defined under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) and effective in its 2026 form. To confirm, update, or revoke your preferences regarding the sale or sharing of personal information, visit our Do Not Sell or Share My Personal Information page. We honor verified opt out requests and Global Privacy Control browser signals on a forward looking basis.

Per the 2026 CCPA opt out confirmation rule, when you submit an opt out request through that page or via the unsubscribe link in any MalcolmAI marketing email, we provide a confirmation that the request has been recorded. If you submit a request from California and we cannot honor it for any reason, we will reply within fifteen business days with the reason and any path to remediation.

5. Data Storage and Security

5.1 Infrastructure

All data is stored on Amazon Web Services (AWS) infrastructure in the US-East-2 (Ohio) region. Our infrastructure includes:

  • Encrypted storage (AES-256) for all data at rest, including S3 buckets and database volumes
  • TLS 1.2+ encryption for all data in transit
  • Virtual private cloud (VPC) network isolation for backend services
  • AWS ECS Fargate for containerized, isolated compute environments

5.2 Access Controls

We implement the following security measures:

  • JWT-based authentication with token expiration
  • Role-based access control for administrative functions
  • CORS protection on all API endpoints
  • Input validation and sanitization to prevent injection attacks
  • Audit logging of all data access and modifications

5.3 Incident Response

In the event of a data breach affecting personal information, we will notify affected Customers without undue delay and in accordance with applicable law. Customers are responsible for notifying their own employees and any affected individuals as required by applicable data breach notification laws.

6. Data Retention

6.1 During Subscription

Customer Data is retained for the duration of the Customer's active subscription. Customers may delete individual records or request bulk deletion at any time through the web admin dashboard or API.

6.2 After Termination

Upon subscription termination, Customer Data remains available for export for thirty (30) days. After the export period, Customer Data is deleted from our active systems within a commercially reasonable timeframe. Backups containing Customer Data are purged within ninety (90) days of deletion from active systems.

6.3 Aggregated Data

Anonymized, aggregated statistical data that does not identify any individual or Customer may be retained indefinitely for analytics and service improvement purposes.

6.4 Legal Obligations

We may retain certain data for longer periods as required by applicable law, regulation, or to establish, exercise, or defend legal claims.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding personal information:

  • Access. Request a copy of the personal information we hold about you
  • Correction. Request correction of inaccurate or incomplete personal information
  • Deletion. Request deletion of personal information, subject to legal retention requirements
  • Data Portability. Request your data in a structured, machine-readable format
  • Restriction. Request restriction of processing in certain circumstances
  • Objection. Object to processing based on legitimate interests

For individuals whose data is captured during the inspection process (such as truck drivers): your employer or the terminal operator is the data controller and is responsible for responding to your rights requests. Please contact them directly. If you contact MalcolmAI, we will direct your request to the appropriate Customer.

To exercise any rights, please contact us at info@malcolm-ai.com.

8. Children's Privacy

The Service is designed for business use by adults in the intermodal shipping industry. We do not knowingly collect personal information from children under 13 years of age. If we become aware that we have inadvertently collected information from a child under 13, we will take steps to delete it promptly.

9. International Data Processing

The Service is hosted and operated in the United States (AWS US-East-2 region, Ohio). If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We process data in accordance with applicable data protection laws, and Customers operating in jurisdictions with specific transfer requirements (such as the EU/EEA) should contact us to discuss appropriate transfer mechanisms.

10. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Effective Date" at the top of this page
  • Notify Customers via email or through the Service at least thirty (30) days before material changes take effect
  • Post the updated policy on our website

Continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

12. Contact Information

For questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:

MalcolmAI LLC
Iowa City, Iowa
Email: info@malcolm-ai.com
Web: malcolm-ai.com

We aim to respond to all privacy inquiries within thirty (30) days.

MalcolmAI MalcolmAI

AI-powered mobile container inspection for intermodal shipping operations. Capture every data point at the gate. no fixed infrastructure required.

Product

  • How It Works
  • Features
  • Comparison
  • Integrations

Resources

  • Privacy Policy
  • Terms of Service
  • Do Not Sell or Share My Personal Information
© 2026 MalcolmAI LLC. All rights reserved. malcolm-ai.com