← jalopermit.com
Privacy Policy
Effective 2026-09-16 · Applies to jalopermit.com and the JaloPermit app.
Short version: we collect what it takes to read your permit and show your route,
payments go through Stripe so we never see your card number, and we don’t sell your
information.
What we collect
- Your permit. The PDF you upload and the text extracted from it. Permits often include names, addresses, vehicle details, and USDOT numbers — upload only documents you’re authorized to share.
- Email address — if you type one, sign in with one, or provide one at checkout. Used to send your result, sign-in codes, and messages about a problem with a paid analysis.
- Payment records. Payments are processed by Stripe. We receive a payment reference and status, never your card number.
- Technical basics. IP address, browser type, and request logs — used for security, rate limiting, and abuse prevention.
- Feedback. Anything you send through “Something look wrong?” or by email.
- Location — browser and mobile app. With your permission, location features show your position on a map. In browser Bridges, choosing My location starts a nearby bridge search and can follow your position while the page is visible. The search center is sent to our API, saved in this browser and included in the page URL; sharing that URL shares the searched area. Later position updates move the map without automatically sending another bridge search. Google Maps processes the map areas you view. Search requests can appear in service logs. You can stop location tracking or revoke permission in your browser or device settings.
- A device identifier — mobile app only. A random identifier created on your device when you install the app, used to count free analyses per day. It is not your advertising ID and it does not follow you to other apps.
How we use it
- To produce your analysis: reading the permit, drawing the route, checking escorts and limits.
- To run the service safely: preventing abuse, debugging failures, keeping the lights on.
- To improve accuracy: uploaded permits and your feedback are how reading mistakes get found and fixed.
- To reach you when it matters: your result is ready, a sign-in code, or a paid analysis hit a problem.
- To show your position and help find nearby bridges when you enable location features. Native route guidance uses device location; browser Bridges follows your position while you use the page.
We do not sell your information, and we don’t send marketing email.
Services that process data for us
Producing your result involves a few processors, each receiving only what its job requires, under its own terms:
- Stripe — payment processing.
- Google — AI text extraction (Gemini), geocoding, maps, and translation. Permit text is sent to produce your result.
- Netlify and Google Cloud — current website, API and data-hosting infrastructure. Amazon Web Services was used for previous hosting.
- Email delivery providers — the transactional emails above.
- Error reporting and analytics (e.g., Sentry, Google Analytics) — crash reports and usage statistics, where enabled.
Cookies & local storage
The app uses local storage and cookies for what you’d expect: remembering that you accepted the Terms, keeping you signed in, and remembering your recent permits, map preferences and last bridge-search area on your device. Where analytics is enabled, its cookies measure page usage.
Your choices
You can use the free tier without an account or card. The email field on upload is optional. Questions or requests about your information: support@jalopermit.org.
Changes to this policy
If this policy changes materially, the effective date above changes with it.