Security & Trust

Privacy Policy

What Ultimate Recycling Inc. collects, why, who else processes it, how long we keep it, and what you can ask us to do about it.

Section 1

1. Scope

This policy covers personal information handled by Ultimate Recycling Inc. (the “Platform”) through this website, the marketplace, the operations tools, the driver portal, and our transactional email.

The Platform is a business-to-business service, but much of what it handles is still personal information about individuals — the people who hold accounts, make offers, drive, and work at the companies that use it. This policy treats it as such.

Companies using the operations tools decide what employee data they enter. For that data we act as a processor on their instructions; they are responsible for their own notices to their staff.

Section 2

2. What We Collect

Categories of personal information collected
CategoryExamplesApplies to
Account and contactName, work email, phone number, company name and role, password hash.All users
Business verificationRegistered business address and its geocoded coordinates, uploaded business license document.Sellers
Tax identifierAn Employer Identification Number is validated for format at registration and is not stored.Sellers
Marketplace activityListings, offers and proxy maximums, watchlists, standing contracts, wins, orders, and messages to support.Buyers and sellers
PaymentPayment-processor customer and account identifiers, the last four digits and brand of a saved card, invoices and settlement records. We never receive or store full card numbers.Buyers and sellers
Offline payment and payout detailsBank account and routing numbers, Zelle contact, Cash App cashtag — encrypted at rest and masked on display.Buyers and sellers who choose these methods
Employment recordsDate of birth, driver licence number, emergency contact, shift and time-clock records, certifications, and encrypted payroll bank details.Staff of a company using the operations platform
Precise locationSee Section 3.Drivers and shipments
PhotographsListing, ticket, and shipment photographs, which may carry embedded capture metadata.Sellers and staff
Enquiries from visitorsYour name, email address, subject, and the message you write in our contact form, together with the IP address and browser the submission came from. We keep the submission itself, not only the notification we send ourselves.Anyone who uses the contact form, including visitors with no account
Technical and securityIP address and user agent recorded with each offer and each audited action, request identifiers, sign-in events, and rate-limit counters.All users

We do not knowingly collect government identity documents, credit reports, or biometric data, and we do not buy personal information from data brokers.

Section 3

3. Precise Location Data

We collect precise geolocation. Some jurisdictions treat this as sensitive personal information, so we describe it separately rather than folding it into a general list.
  • Driver location. While a driver is signed in to the driver portal with location sharing on, we store their most recent position, heading, and accuracy so dispatch can route work. This is a current-position record, not a stored history.
  • Shipment breadcrumbs. During an active shipment we store a trail of timestamped coordinates, speed, and heading, retained against that shipment as a delivery record. The whole trail is deleted automatically 90 days after the shipment finishes — see Section 9.
  • Address coordinates. Business and pickup addresses are geocoded to coordinates for routing.
  • Photograph metadata. Photographs uploaded from a phone may contain embedded location metadata.

Coordinates are stored to roughly sub-meter precision. They are visible to dispatch and administrative staff at the company operating the shipment, and to the driver themselves. Precise coordinates are never included in public listing or tracking payloads.

Section 4

4. Why We Use It

  • To create and secure accounts, and to authenticate you.
  • To run the marketplace: accepting offers, resolving proxies, closing lots, and determining winners.
  • To take payment, calculate fees, invoice, and settle seller payouts.
  • To verify seller eligibility and to meet scrap-industry record-keeping obligations.
  • To schedule pickups, route drivers, and produce shipping documents.
  • To detect and investigate fraud, shill offering, ceiling evasion, and abuse — which is the reason an offer is stored with an IP address and user agent.
  • To maintain a tamper-evident audit record of consequential actions, which we are not able to alter after the fact.
  • To send transactional email about your account, lots, and shipments.
  • To meet tax, accounting, and legal obligations.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not run advertising networks, advertising pixels, or third-party analytics on this site.

Section 5

5. Service Providers

We use the following providers to operate the Platform. Each receives only what it needs for its function.

Service providers and what they process
ProviderPurposeWhat it receives
StripeCard payments, subscriptions, billing portal, payout infrastructureName, email, payment method, transaction amounts; where you connect a bank account, balance and ownership information
NeonManaged PostgreSQL databaseAll application data
Google Cloud — Firebase App Hosting / Cloud RunApplication hostingRequest data in transit, server logs
Google Cloud StorageFile and photograph storageUploaded documents and images
Google Secret ManagerCredential storageApplication secrets only, no user data
Google (OAuth)Optional sign-in with a Google accountEmail, name, and profile image from your Google account, if you choose this method
Google Address ValidationValidating and geocoding business and pickup addressesAddress strings
MapboxMap rendering for dispatch and shipment trackingCoordinates rendered in the map view
ResendTransactional email deliveryRecipient email address and message content
SentryError monitoring, when enabledError reports with payment, authentication, and secret values scrubbed before transmission

Stripe is our payment processor and is PCI-DSS compliant. Card details are entered directly into Stripe's hosted fields and never reach our servers.

Section 6

6. When We Disclose

We disclose personal information only:

  • to the service providers listed in Section 5, for the stated purpose;
  • to the company that operates your account, where you are its staff member;
  • operationally, to the extent a transaction requires it — a driver and dispatch staff receive the pickup address and site contact in order to collect;
  • to professional advisers, auditors, and insurers under confidentiality obligations;
  • where required by law, subpoena, or a lawful government request, or to establish or defend legal claims; and
  • to an acquirer in a merger, acquisition, or sale of assets, subject to this policy continuing to apply.

We do not disclose a buyer's identity to a seller, or a seller's identity to a buyer, as part of a transaction.

Section 7

7. What Is Publicly Visible

Public listing pages show material descriptions, photographs, quantities, the approximate pickup region, and the current price. They are stripped of contact details and precise coordinates, and bidder identities are not published.

Shipment tracking links are unauthenticated. A tracking link contains a long random token and shows shipment status to anyone who has the link, without signing in. Treat a tracking link as shareable, and do not forward it to anyone you do not want to see that shipment's status.
Section 8

8. Job Applicants

If you apply for a job through our careers pages, this section is the one that applies to you. You do not need an account to apply, and applying does not create one.

What we collect. Your name, email address, phone number, and mailing address; whether you are legally authorized to work in the United States, whether you would need sponsorship, and whether you are 18 or older; the date you could start and any pay expectation you tell us; your work history and education as you enter it; your answers to the screening questions on the posting; how you heard about us; and the resume you upload, if you upload one. We also record the IP address and browser the application was submitted from, to defend the form against abuse.

Why. To decide whether to interview and hire you, to contact you about it, and to keep the record of that decision that federal record-keeping rules require. We do not sell applicant information, and we do not use it for advertising.

Who sees it. The people at Ultimate Recycling Inc. who review applications for the role you applied to. Your resume is served only to a signed-in reviewer, as a download, never through a public link.

What we deliberately do not ask. We do not ask for your race, sex, veteran status, or disability status on the application. We do not ask for a Social Security number, a date of birth, or a background-check authorization at this stage — a background-check disclosure is a separate, standalone document under federal law, and it belongs after an offer, not inside an application.

How long we keep it. At least 1 year, and no more than 2 years, measured from whichever is later: the day you applied, or the day we decided. Both halves of that sentence are enforced — the minimum because federal rules require applicant records to be kept and we do not delete them earlier on request, the maximum because a scheduled job deletes the record and the resume file at the end of it.

Your link. We email you a private link that shows the status of your application and lets you withdraw it. Withdrawing stops us considering you; it does not delete the record, for the record-keeping reason above.

If you used the same email address as an existing account here, we associate the application with that account so you can see it when signed in. We do not tell an applicant whether an account exists.

Section 9

9. How Long We Keep It

Retention periods
DataKept for
Account recordsFor as long as your account exists. We do not delete accounts automatically; you can ask us to delete yours under Section 11, subject to the limits set out there
Transaction, invoice, and settlement recordsAt least 7 years, to meet tax and accounting obligations. These are kept rather than deleted on request — see Section 11
Seller verification documentsWhile the seller account exists, and at least 7 years after the last transaction they support, for tax and anti-fraud purposes
Shipment GPS breadcrumbs90 days after the shipment completes, then automatically deleted
Driver current positionOverwritten by each update; not kept as a history
Audit logRetained as an append-only record and not deleted on request — see Section 11
Consent recordsKept for as long as needed to evidence the agreement
Contact-form enquiries365 days after you submit them, then automatically deleted
Job applications and resumesAt least 1 year and no more than 2 years, measured from the later of when you applied and when we decided — then the record and the resume file are automatically deleted. See Section 8

Where this table says data is deleted automatically, a scheduled job performs the deletion — the period is not a statement of intent. Where it gives a minimum, we are committing to keep the records for at least that long, not to erase them at the end of it.

Section 10

10. Security

  • Tenant isolation at the database. Row-level security is enforced by PostgreSQL itself, under an application role that cannot bypass it. A query that fails to scope returns nothing rather than another company's data.
  • Encryption in transit and at rest. Traffic is served over TLS. Bank, routing, Zelle, Cash App, and payroll details are encrypted with AES-256-GCM before storage and are masked when displayed.
  • No card data. Card numbers are entered directly into our payment processor and never reach our systems.
  • Tamper-evident audit log. Consequential actions are recorded in a hash-chained append-only log.
  • Upload validation. Uploads are checked by file signature rather than by extension and are served as forced downloads.
  • Abuse controls. CSRF protection, rate limiting, and sanitization of seller-authored listing content.

No system is perfectly secure. These measures reduce risk; they do not eliminate it.

Section 11

11. Your Rights

Subject to your jurisdiction and to verification of your identity, you may ask us to:

  • confirm what personal information we hold about you and give you a copy;
  • correct information that is inaccurate;
  • delete information we no longer have a lawful basis to keep;
  • provide your information in a portable, machine-readable format;
  • restrict or object to a particular use; and
  • withdraw a consent you previously gave, without affecting past processing.
Limits on deletion. We cannot delete transaction, invoice, tax, or audit records we are required to keep, and the audit log is append-only by design — it exists precisely so that it cannot be rewritten. Where we cannot delete, we will tell you why and restrict the data instead.

Send requests to ultimaterecyclinginfo@gmail.com, or by post to Ultimate Recycling Inc., 317 Elm St, Benton, KY 42025. We respond within [RESPONSE PERIOD] and will tell you if we need longer. We do not charge for a request, and we will not treat you differently for making one.

Section 12

12. California Residents

Under the California Consumer Privacy Act as amended, California residents have the rights to know, delete, correct, and opt out, and the right not to be discriminated against for exercising them.

In the preceding twelve months we collected the categories in Section 2 and disclosed them for the business purposes in Section 4 to the providers in Section 5. We have not sold personal information and have not shared it for cross-context behavioural advertising.

We collect precise geolocation, which the CCPA classifies as sensitive personal information. We use it only to route and record work, which is a permitted purpose that does not trigger a right to limit its use — we do not use it to infer characteristics about you.

You may use an authorised agent, with proof of authorisation. Contact us at the address in Section 11.

Section 13

13. EEA and UK Users

Where the GDPR or UK GDPR applies, our lawful bases are:

  • Contract — operating your account, running the marketplace, taking payment, and arranging fulfillment.
  • Legal obligation — tax, accounting, and scrap-industry record-keeping.
  • Legitimate interests — securing the Platform, preventing fraud and offer abuse, and keeping an audit record. We have weighed these against your interests and consider them proportionate.
  • Consent — where we ask for it, such as location sharing in the driver portal.

You may lodge a complaint with your supervisory authority. Our [EU/UK REPRESENTATIVE, IF REQUIRED] and [DATA PROTECTION OFFICER, IF REQUIRED] are to be confirmed.

Section 14

14. Breach Notification

If we determine that a breach has affected your personal information, we will notify you and any required regulator without undue delay and within the period the applicable law requires. Our notice will describe what happened, what data was involved, what we are doing, and what you can do.

Section 15

15. Children

The Platform is for business use by adults. We do not direct it to children and do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it.

Section 16

16. International Transfers

We operate from the United States and our providers process data there. If you use the Platform from outside the United States, your information is transferred to and processed in the United States, which may not offer the same protections as your home jurisdiction.

Where a transfer from the EEA or UK requires a safeguard, we rely on [TRANSFER MECHANISM — SCCs / UK ADDENDUM].

Section 17

17. Changes to This Policy

This policy is versioned. Each version has an identifier and an effective date, shown at the top of this page, and we record which version each account has accepted. When we make a material change we will ask you to review the new version.

See also our Cookie & Tracking Notice.

Version 2026-09-01, effective September 1, 2026. Added a section covering job applicants: what a careers application collects, why we keep it, and how long. Applicant records are kept for at least a year and no more than two, as federal record-keeping rules require. Nothing changed for buyers, sellers, or staff.

Prior versions are retained. When we publish a new version we record which version each account accepted and when. See our Terms of Service, Marketplace Agreement, Privacy Policy, and Cookie & Tracking Notice.