Security & Trust

Privacy Policy

What Ultimate Recycling Inc. collects, why, who else processes it, how long we keep it, and what you can ask us to do about it.

Section 1

1. Scope

This policy covers personal information handled by Ultimate Recycling Inc.(the “Platform”) through this website, the marketplace, the operations tools, the driver portal, and our transactional email.

The Platform is a business-to-business service, but much of what it handles is still personal information about individuals — the people who hold accounts, make offers, drive, and work at the companies that use it. This policy treats it as such.

Companies using the operations tools decide what employee data they enter. For that data we act as a processor on their instructions; they are responsible for their own notices to their staff.

Section 2

2. What We Collect

Categories of personal information collected
CategoryExamplesApplies to
Account and contactName, work email, phone number, company name and role, password hash.All users
Business verificationRegistered business address and its geocoded coordinates, uploaded business license document.Sellers
Tax identifierAn Employer Identification Number is validated for format at registration and is not stored.Sellers
Marketplace activityListings, offers and proxy maximums, watchlists, standing contracts, wins, orders, and messages to support.Buyers and sellers
PaymentPayment-processor customer and account identifiers, the last four digits and brand of a saved card, invoices and settlement records. We never receive or store full card numbers.Buyers and sellers
Offline payment and payout detailsBank account and routing numbers, Zelle contact, Cash App cashtag — encrypted at rest and masked on display.Buyers and sellers who choose these methods
Employment recordsDate of birth, driver licence number, emergency contact, shift and time-clock records, certifications, and encrypted payroll bank details.Staff of a company using the operations platform
Precise locationSee Section 3.Drivers and shipments
PhotographsListing, ticket, and shipment photographs, which may carry embedded capture metadata.Sellers and staff
Enquiries from visitorsYour name, email address, subject, and the message you write in our contact form, together with the IP address and browser the submission came from. We keep the submission itself, not only the notification we send ourselves.Anyone who uses the contact form, including visitors with no account
Technical and securityIP address and user agent recorded with each offer and each audited action, request identifiers, sign-in events, and rate-limit counters.All users

We do not knowingly collect government identity documents, credit reports, or biometric data, and we do not buy personal information from data brokers.

Section 3

3. Precise Location Data

We collect precise geolocation. Some jurisdictions treat this as sensitive personal information, so we describe it separately rather than folding it into a general list.
  • Driver location. While a driver is signed in to the driver portal with location sharing on, we store their most recent position, heading, and accuracy so dispatch can route work. This is a current-position record, not a stored history.
  • Shipment breadcrumbs. During an active shipment we store a trail of timestamped coordinates, speed, and heading, retained against that shipment as a delivery record. The whole trail is deleted automatically 90 days after the shipment finishes — see Section 8.
  • Address coordinates. Business and pickup addresses are geocoded to coordinates for routing.
  • Photograph metadata. Photographs uploaded from a phone may contain embedded location metadata.

Coordinates are stored to roughly sub-meter precision. They are visible to dispatch and administrative staff at the company operating the shipment, and to the driver themselves. Precise coordinates are never included in public listing or tracking payloads.

Section 4

4. Why We Use It

  • To create and secure accounts, and to authenticate you.
  • To run the marketplace: accepting offers, resolving proxies, closing lots, and determining winners.
  • To take payment, calculate fees, invoice, and settle seller payouts.
  • To verify seller eligibility and to meet scrap-industry record-keeping obligations.
  • To schedule pickups, route drivers, and produce shipping documents.
  • To detect and investigate fraud, shill offering, ceiling evasion, and abuse — which is the reason an offer is stored with an IP address and user agent.
  • To maintain a tamper-evident audit record of consequential actions, which we are not able to alter after the fact.
  • To send transactional email about your account, lots, and shipments.
  • To meet tax, accounting, and legal obligations.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not run advertising networks, advertising pixels, or third-party analytics on this site.

Section 5

5. Service Providers

We use the following providers to operate the Platform. Each receives only what it needs for its function.

Service providers and what they process
ProviderPurposeWhat it receives
StripeCard payments, subscriptions, billing portal, payout infrastructureName, email, payment method, transaction amounts; where you connect a bank account, balance and ownership information
NeonManaged PostgreSQL databaseAll application data
Google Cloud — Firebase App Hosting / Cloud RunApplication hostingRequest data in transit, server logs
Google Cloud StorageFile and photograph storageUploaded documents and images
Google Secret ManagerCredential storageApplication secrets only, no user data
Google (OAuth)Optional sign-in with a Google accountEmail, name, and profile image from your Google account, if you choose this method
Google Address ValidationValidating and geocoding business and pickup addressesAddress strings
MapboxMap rendering for dispatch and shipment trackingCoordinates rendered in the map view
ResendTransactional email deliveryRecipient email address and message content
SentryError monitoring, when enabledError reports with payment, authentication, and secret values scrubbed before transmission

Stripe is our payment processor and is PCI-DSS compliant. Card details are entered directly into Stripe's hosted fields and never reach our servers.

Section 6

6. When We Disclose

We disclose personal information only:

  • to the service providers listed in Section 5, for the stated purpose;
  • to the company that operates your account, where you are its staff member;
  • operationally, to the extent a transaction requires it — a driver and dispatch staff receive the pickup address and site contact in order to collect;
  • to professional advisers, auditors, and insurers under confidentiality obligations;
  • where required by law, subpoena, or a lawful government request, or to establish or defend legal claims; and
  • to an acquirer in a merger, acquisition, or sale of assets, subject to this policy continuing to apply.

We do not disclose a buyer's identity to a seller, or a seller's identity to a buyer, as part of a transaction.

Section 7

7. What Is Publicly Visible

Public listing pages show material descriptions, photographs, quantities, the approximate pickup region, and the current price. They are stripped of contact details and precise coordinates, and bidder identities are not published.

Shipment tracking links are unauthenticated.A tracking link contains a long random token and shows shipment status to anyone who has the link, without signing in. Treat a tracking link as shareable, and do not forward it to anyone you do not want to see that shipment's status.
Section 8

8. How Long We Keep It

Retention periods
DataKept for
Account recordsFor as long as your account exists. We do not delete accounts automatically; you can ask us to delete yours under Section 10, subject to the limits set out there
Transaction, invoice, and settlement recordsAt least 7 years, to meet tax and accounting obligations. These are kept rather than deleted on request — see Section 10
Seller verification documentsWhile the seller account exists, and at least 7 years after the last transaction they support, for tax and anti-fraud purposes
Shipment GPS breadcrumbs90 days after the shipment completes, then automatically deleted
Driver current positionOverwritten by each update; not kept as a history
Audit logRetained as an append-only record and not deleted on request — see Section 10
Consent recordsKept for as long as needed to evidence the agreement
Contact-form enquiries365 days after you submit them, then automatically deleted

Where this table says data is deleted automatically, a scheduled job performs the deletion — the period is not a statement of intent. Where it gives a minimum, we are committing to keep the records for at least that long, not to erase them at the end of it.

Section 9

9. Security

  • Tenant isolation at the database.Row-level security is enforced by PostgreSQL itself, under an application role that cannot bypass it. A query that fails to scope returns nothing rather than another company's data.
  • Encryption in transit and at rest. Traffic is served over TLS. Bank, routing, Zelle, Cash App, and payroll details are encrypted with AES-256-GCM before storage and are masked when displayed.
  • No card data. Card numbers are entered directly into our payment processor and never reach our systems.
  • Tamper-evident audit log. Consequential actions are recorded in a hash-chained append-only log.
  • Upload validation. Uploads are checked by file signature rather than by extension and are served as forced downloads.
  • Abuse controls. CSRF protection, rate limiting, and sanitization of seller-authored listing content.

No system is perfectly secure. These measures reduce risk; they do not eliminate it.

Section 10

10. Your Rights

Subject to your jurisdiction and to verification of your identity, you may ask us to:

  • confirm what personal information we hold about you and give you a copy;
  • correct information that is inaccurate;
  • delete information we no longer have a lawful basis to keep;
  • provide your information in a portable, machine-readable format;
  • restrict or object to a particular use; and
  • withdraw a consent you previously gave, without affecting past processing.
Limits on deletion. We cannot delete transaction, invoice, tax, or audit records we are required to keep, and the audit log is append-only by design — it exists precisely so that it cannot be rewritten. Where we cannot delete, we will tell you why and restrict the data instead.

Send requests to ultimateelectronicrecycling@gmail.com, or by post to Ultimate Recycling Inc., 317 Elm St, Benton, KY 42025. We respond within [RESPONSE PERIOD] and will tell you if we need longer. We do not charge for a request, and we will not treat you differently for making one.

Section 11

11. California Residents

Under the California Consumer Privacy Act as amended, California residents have the rights to know, delete, correct, and opt out, and the right not to be discriminated against for exercising them.

In the preceding twelve months we collected the categories in Section 2 and disclosed them for the business purposes in Section 4 to the providers in Section 5. We have not sold personal information and have not shared it for cross-context behavioural advertising.

We collect precise geolocation, which the CCPA classifies as sensitive personal information. We use it only to route and record work, which is a permitted purpose that does not trigger a right to limit its use — we do not use it to infer characteristics about you.

You may use an authorised agent, with proof of authorisation. Contact us at the address in Section 10.

Section 12

12. EEA and UK Users

Where the GDPR or UK GDPR applies, our lawful bases are:

  • Contract — operating your account, running the marketplace, taking payment, and arranging fulfillment.
  • Legal obligation — tax, accounting, and scrap-industry record-keeping.
  • Legitimate interests — securing the Platform, preventing fraud and offer abuse, and keeping an audit record. We have weighed these against your interests and consider them proportionate.
  • Consent — where we ask for it, such as location sharing in the driver portal.

You may lodge a complaint with your supervisory authority. Our [EU/UK REPRESENTATIVE, IF REQUIRED] and [DATA PROTECTION OFFICER, IF REQUIRED] are to be confirmed.

Section 13

13. Breach Notification

If we determine that a breach has affected your personal information, we will notify you and any required regulator without undue delay and within the period the applicable law requires. Our notice will describe what happened, what data was involved, what we are doing, and what you can do.

Section 14

14. Children

The Platform is for business use by adults. We do not direct it to children and do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it.

Section 15

15. International Transfers

We operate from the United States and our providers process data there. If you use the Platform from outside the United States, your information is transferred to and processed in the United States, which may not offer the same protections as your home jurisdiction.

Where a transfer from the EEA or UK requires a safeguard, we rely on [TRANSFER MECHANISM — SCCs / UK ADDENDUM].

Section 16

16. Changes to This Policy

This policy is versioned. Each version has an identifier and an effective date, shown at the top of this page, and we record which version each account has accepted. When we make a material change we will ask you to review the new version.

See also our Cookie & Tracking Notice.

Version 2026-08-08, effective August 8, 2026. Replaced the auction/bid terminology with the marketplace Listing/Offer vocabulary. No change to what data we collect, how long we keep it, or who it is shared with.

Prior versions are retained. When we publish a new version we record which version each account accepted and when. See our Terms of Service, Marketplace Agreement, Privacy Policy, and Cookie & Tracking Notice.