MalcolmAI
Home Features Integrations Request Demo

Privacy Policy

Effective Date: February 27, 2026

1. Introduction

MalcolmAI LLC ("MalcolmAI," "we," "us," or "our") is committed to protecting the privacy of our customers and the individuals whose data is processed through our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our AI-powered container inspection platform, mobile application, web admin dashboard, and related services (collectively, the "Service").

MalcolmAI provides a business-to-business (B2B) SaaS platform. Our customers are intermodal shipping terminals, container depots, and logistics companies ("Customers"). This policy applies to Customer employees and authorized users who interact with the Service, as well as individuals whose information may be captured during the container inspection process (such as truck drivers).

2. Information We Collect

2.1 Account and User Information

When Customers register for the Service, we collect:

  • Organization name, address, and business contact information
  • Individual user names, email addresses, and job titles
  • Account credentials (passwords are stored in hashed form only)
  • Billing and payment information (processed by our payment provider; we do not store full payment card numbers)

2.2 Container Inspection Data

During the container inspection workflow, the Service captures:

  • Container door photographs — images of container markings including owner codes, serial numbers, check digits, size/type codes, and operational markings (weights, dimensions)
  • Chassis number photographs — images of chassis identification numbers
  • License plate photographs — images of vehicle license plates including state or province identifiers
  • Container seal photographs — images of security seals including seal numbers and condition
  • AI-extracted data — structured data extracted from the above photographs by our AI processing pipeline, including container IDs, chassis numbers, plate numbers, seal numbers, weights, and confidence scores

2.3 Driver Credential Data

The Service captures photographs of driver's licenses or commercial driver's licenses (CDLs) for operator verification purposes. This may include:

  • Driver name, license number, and issuing state
  • License class, endorsements, and expiration date
  • Photograph of the physical license document

Important: Driver credential data is collected by the Customer as part of their gate operations. MalcolmAI processes this data on behalf of the Customer. The Customer is responsible for ensuring that appropriate notice is given to drivers and that collection complies with applicable law.

2.4 Device and Location Data

When using the mobile application, we collect:

  • GPS coordinates — location data associated with each inspection transaction, providing a verifiable record of where the inspection occurred
  • Device information — device model, operating system version, app version, and unique device identifiers
  • Network information — connection type (WiFi/cellular) and network status for offline queue management

2.5 Usage and Analytics Data

We automatically collect information about how the Service is used, including:

  • Feature usage patterns, screen views, and navigation paths
  • Inspection completion times, upload statistics, and processing metrics
  • Error logs, crash reports, and performance data
  • Login timestamps, session duration, and access patterns

3. How We Use Information

We use the information we collect for the following purposes:

PurposeData Used
Providing the Service — processing container images, extracting data, delivering results to CustomersInspection data, driver credentials, device/location data
AI Processing — analyzing images using multimodal AI models to extract container, chassis, plate, seal, and driver informationPhotographs submitted through the inspection workflow
Quality Assurance — confidence scoring, review queue management, and accuracy improvementExtracted data, confidence scores, manual correction history
Account Management — user authentication, access control, and subscription managementAccount information, credentials, billing data
Customer Support — responding to inquiries, troubleshooting issues, and providing technical assistanceAccount information, usage data, error logs
Service Improvement — analyzing usage patterns, optimizing performance, and developing new featuresAggregated usage and analytics data
Security and Compliance — detecting fraud, preventing unauthorized access, and maintaining audit trailsAccess logs, device information, usage patterns
Communications — sending service notifications, maintenance alerts, and product updatesAccount contact information

4. Data Sharing and Disclosure

4.1 With the Customer Organization

All inspection data, extracted results, and associated metadata are accessible to the Customer organization that initiated the inspection. Customers control access through their own user management and role-based permissions.

4.2 Third-Party Service Providers

We share data with the following categories of service providers who assist in delivering the Service:

  • AI Processing (OpenAI) — Container and credential photographs are transmitted to OpenAI's API for AI-powered data extraction. Images are processed under OpenAI's API data usage policies, which prohibit using API inputs for model training.
  • Cloud Infrastructure (Amazon Web Services) — All data is stored and processed on AWS infrastructure, including S3 (image storage), ECS (compute), SQS (message queuing), and MongoDB Atlas (database).
  • Payment Processing — Subscription billing is handled by our payment processor. We do not store full payment card information on our systems.

4.3 Customer Integrations

At the Customer's direction, we transmit extracted container data to the Customer's TMS, WMS, or ERP systems via webhooks, REST APIs, or direct database connections configured by the Customer.

4.4 Legal Requirements

We may disclose information when required by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect the rights, safety, or property of MalcolmAI, our Customers, or others.

4.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, Customer data may be transferred to the successor entity, subject to the commitments made in this Privacy Policy.

4.6 No Sale of Data

We do not sell, rent, or trade personal information to third parties for their marketing purposes.

5. Data Storage and Security

5.1 Infrastructure

All data is stored on Amazon Web Services (AWS) infrastructure in the US-East-2 (Ohio) region. Our infrastructure includes:

  • Encrypted storage (AES-256) for all data at rest, including S3 buckets and database volumes
  • TLS 1.2+ encryption for all data in transit
  • Virtual private cloud (VPC) network isolation for backend services
  • AWS ECS Fargate for containerized, isolated compute environments

5.2 Access Controls

We implement the following security measures:

  • JWT-based authentication with token expiration
  • Role-based access control for administrative functions
  • CORS protection on all API endpoints
  • Input validation and sanitization to prevent injection attacks
  • Audit logging of all data access and modifications

5.3 Incident Response

In the event of a data breach affecting personal information, we will notify affected Customers without undue delay and in accordance with applicable law. Customers are responsible for notifying their own employees and any affected individuals as required by applicable data breach notification laws.

6. Data Retention

6.1 During Subscription

Customer Data is retained for the duration of the Customer's active subscription. Customers may delete individual records or request bulk deletion at any time through the web admin dashboard or API.

6.2 After Termination

Upon subscription termination, Customer Data remains available for export for thirty (30) days. After the export period, Customer Data is deleted from our active systems within a commercially reasonable timeframe. Backups containing Customer Data are purged within ninety (90) days of deletion from active systems.

6.3 Aggregated Data

Anonymized, aggregated statistical data that does not identify any individual or Customer may be retained indefinitely for analytics and service improvement purposes.

6.4 Legal Obligations

We may retain certain data for longer periods as required by applicable law, regulation, or to establish, exercise, or defend legal claims.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding personal information:

  • Access — Request a copy of the personal information we hold about you
  • Correction — Request correction of inaccurate or incomplete personal information
  • Deletion — Request deletion of personal information, subject to legal retention requirements
  • Data Portability — Request your data in a structured, machine-readable format
  • Restriction — Request restriction of processing in certain circumstances
  • Objection — Object to processing based on legitimate interests

For individuals whose data is captured during the inspection process (such as truck drivers): your employer or the terminal operator is the data controller and is responsible for responding to your rights requests. Please contact them directly. If you contact MalcolmAI, we will direct your request to the appropriate Customer.

To exercise any rights, please contact us at info@malcolm-ai.com.

8. Children's Privacy

The Service is designed for business use by adults in the intermodal shipping industry. We do not knowingly collect personal information from children under 13 years of age. If we become aware that we have inadvertently collected information from a child under 13, we will take steps to delete it promptly.

9. International Data Processing

The Service is hosted and operated in the United States (AWS US-East-2 region, Ohio). If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We process data in accordance with applicable data protection laws, and Customers operating in jurisdictions with specific transfer requirements (such as the EU/EEA) should contact us to discuss appropriate transfer mechanisms.

10. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Effective Date" at the top of this page
  • Notify Customers via email or through the Service at least thirty (30) days before material changes take effect
  • Post the updated policy on our website

Continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

12. Contact Information

For questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:

MalcolmAI LLC
Iowa City, Iowa
Email: info@malcolm-ai.com
Web: malcolm-ai.com

We aim to respond to all privacy inquiries within thirty (30) days.

MalcolmAI

AI-powered mobile container inspection for intermodal shipping operations. Capture every data point at the gate — no fixed infrastructure required.

Product

  • How It Works
  • Features
  • Comparison
  • Integrations

Resources

  • Privacy Policy
  • Terms of Service
© 2026 MalcolmAI LLC. All rights reserved. malcolm-ai.com