Cypress Authority Services LLC
Privacy Policy
Effective June 16, 2026
The short version
You give us sensitive information to get your authority running: your legal name, your SSN or ITIN, your address, your driver roster, your vehicles. We encrypt the sensitive fields, restrict access by role, log every read, and we never sell your data. If we share your information with an affiliated company, we disclose it and you control the consent in your portal.
1. What we collect
In plain English: The information the government and our regulated partners require to issue your authority, formation, EIN, BOC-3, and recurring compliance filings.
- Identity: legal name (as it must appear on government filings), date of birth, SSN or ITIN, residential address, ownership percentages, prior FMCSA authorities.
- Business: entity name, EIN, state of formation, principal office address, mailing address, operating commodity, vehicle inventory, driver roster.
- Operations: filing history, compliance events, FMCSA inspection records, IRP / IFTA quarterly activity, drug-and-alcohol consortium roster (where you enroll), MVR pulls (where you enroll).
- Account: email, phone, password hash, billing details (card or ACH; PCI scope is delegated to our payment processor Stripe), login history.
- Operational telemetry: dashboard activity, IP address, device fingerprint, browser metadata. Used for fraud prevention and abuse mitigation.
2. How we store and secure sensitive identifiers
In plain English: SSN, ITIN, EIN, and driver license numbers are encrypted on disk and again in our database. Only the small set of staff who need them to file your paperwork can read them, and every access is logged.
- Encryption at rest: SSN, ITIN, EIN, driver license number, and date of birth are stored as ciphertext using AES-256-GCM with envelope keys held in a managed Key Management Service. Plaintext never sits on application disk.
- Encryption in transit: TLS 1.2+ for every customer-facing connection. Internal service-to-service calls run over mutually-authenticated TLS within a private network.
- Access control: role-based access control (RBAC). Only staff in the Filing Operations, Customer Resolution, and Compliance roles can request sensitive-field decryption, and only against accounts assigned to their queue. Engineering and finance roles cannot read sensitive fields without an approved support escalation.
- Audit log: every decryption request, every customer-data export, and every administrative action is logged with actor, timestamp, justification, and the affected account. Audit logs are immutable for 7 years.
- Background checks: staff with sensitive-field access pass a background check at hire and are re-attested annually.
3. How we use your information
We use your information to (a) prepare and submit the filings you ordered; (b) maintain your active filings (renewals, biennial updates, quarterly reports); (c) operate your dashboard and respond to your support requests; (d) bill you for service fees and remit pass-through fees to the underlying agency or partner; (e) detect and prevent fraud, abuse, and regulatory violations on the platform; (f) comply with our own legal and regulatory obligations. We do not sell your information.
4. Who we share it with
In plain English: The government agencies and regulated partners required to complete your filings, and a small number of operational vendors who power our platform. Nobody else, unless you tell us to.
- Government agencies: FMCSA (URS, MCS-150, OP-1), IRS (Form 2290 e-file, EIN application), state Secretaries of State (LLC formation), state DOTs (UCR, IRP, IFTA), state DMVs (MVR, with permissible-purpose credentials).
- Regulated partners: BOC-3 process-agent firms (49 CFR §366 designation), registered-agent firms (state-required), insurance carriers (for insurance filings you authorize), drug-and-alcohol consortium administrator (where you enroll).
- Operational vendors: Stripe (payment processing, PCI scope), DocuSign (e-signature on engagement and FMCSA attestations), our infrastructure provider (encrypted storage and compute), our customer support tooling. Each operates under a data-processing agreement.
- Affiliated companies: Cypress Authority Services LLC is affiliated with Dispatch Rail Logistics LLC and Northridge Risk Group LLC under common ownership. Per our internal architecture decision ADR-CP-004 v2, sharing your information with one affiliated company does not automatically share it with another. If we propose to share your information across affiliated entities, we will ask you in your portal and the share is gated on your explicit consent.
- Compelled disclosure: if we receive a subpoena, court order, or government demand for your information, we will produce only the information legally required, and we will notify you unless legally prohibited from doing so.
5. Retention
In plain English: We keep your filing records for as long as the law requires (usually 7 years after closure). We delete or de-identify what we no longer need.
- Active accounts: retained while the account is open plus the active-filing window.
- Closed accounts — filing record: retained 7 years after account closure to satisfy IRS recordkeeping (HVUT and EIN), FMCSA recordkeeping (49 CFR §379), and state Secretary-of-State recordkeeping. After 7 years, identifying fields are deleted or de-identified.
- Audit logs: immutable retention for 7 years.
- Operational telemetry: rolling 13-month window for fraud and abuse review, then deleted.
6. Your rights
You may at any time, from your dashboard or by writing to ops@cypressauthority.com:
- Access a copy of the information we hold about you.
- Correct information that is inaccurate. Note that some fields (legal name, EIN) drive active filings and require a regulator-side amendment to change.
- Delete your account. We will delete or de-identify information not subject to the retention obligations described in Section 5.
- Manage your affiliated-company consent preferences (see Section 4).
- Export your filing record in a portable format.
Residents of California, Virginia, Colorado, Connecticut, and other states with comprehensive privacy statutes have additional rights (including non-discrimination for exercising privacy rights). Contact us to exercise them.
7. Children
Our service is intended for commercial motor carriers and is not directed to children under 18. We do not knowingly collect information from anyone under 18.
8. Changes
We may update this policy. Material changes will be announced at least 14 days in advance via email and on this page.
9. Contact
Cypress Authority Services LLC
Privacy questions: ops@cypressauthority.com