Privacy Policy
Effective date: 30 August 2026
Last updated: 30 August 2026
1. Who we are
This policy describes how IRP Express Inc ("we", "us") handles information in the app.irpexpressinc.com compliance platform (the "Service").
Contact: info@irpexpressinc.com
Address: 7263 Harlem Avenue, Bridgeview, IL 60455
2. Who uses this Service
The Service is a private, internal business application used by IRP Express Inc staff to manage IFTA, IRP and related motor-carrier compliance work on behalf of client carriers. It is not offered to the general public and does not accept public registration.
Where this policy refers to "your information", it means information about client carriers, their vehicles and their personnel, which our staff enter or import in the course of providing compliance services.
3. Information in the Service
Business and contact information. Carrier and customer names, business addresses, telephone and mobile numbers, email addresses, website addresses, and internal notes.
Compliance identifiers. IFTA account numbers, IRP account numbers, USDOT numbers, motor carrier (MC) numbers, and legal filing names.
Vehicle information. Vehicle identification numbers, registration details, fuel type, weight, and mileage by jurisdiction.
Personnel information. Driver names, licence details, and — where required for a filing or registration — government identification numbers.
Filing and document records. Prepared returns, supporting calculations, submitted filings, and stored documents.
Account information. Names, email addresses and access credentials for staff who use the Service.
Operational records. A log of actions taken in the Service, so that changes to a compliance record can be attributed and reviewed.
4. QuickBooks Online
The Service can connect to a QuickBooks Online company at the account owner's direction. This section describes that connection specifically.
What we access. Customer records only: customer and company name, contact name fields, email address, telephone, mobile, fax and other telephone numbers, website, billing address, the name printed on cheques, whether the record is a sub-customer, and whether QuickBooks marks the record active or inactive.
What we do not access. We do not read invoices, payments, balances, transactions, journal entries, payroll, or any other financial record. The Service is built so that this is a property of the software rather than a policy: the QuickBooks component contains no code capable of retrieving them.
The connection is read-only. The Service cannot create, modify, delete or deactivate anything in a connected QuickBooks company. It contains no function that writes to QuickBooks, and an automated check verifies this on every build.
Why we access it. So that carrier contact information maintained in QuickBooks does not have to be re-entered, and so that the two records do not diverge.
Access credentials. Authorisation tokens issued by Intuit are encrypted at rest using a key held separately from all other application secrets, and are never displayed, logged, or transmitted anywhere other than to Intuit.
Disconnecting. The account owner may disconnect QuickBooks at any time from within the Service, or revoke access from within QuickBooks itself. On disconnection we delete the stored authorisation tokens. Customer information already imported remains in the Service as part of the compliance record, and can be deleted on request under section 8.
5. How information is protected
Encryption in transit. All connections to the Service use TLS.
Encryption at rest. Government identification numbers and other sensitive personal identifiers are encrypted in the database using AES-256-GCM with a dedicated key. Authorisation credentials for third-party services are encrypted separately, each under its own key, so that rotating one does not affect another.
Access control. The Service requires authentication for every request. Staff accounts carry roles that determine what each person may see and do.
Retention of sensitive identifiers. Where a value is displayed for recognition rather than use, only the final digits are shown.
We take these measures seriously, and we also state plainly that no system is perfectly secure.
6. Who we share information with
We do not sell information, and we do not share it for advertising.
Information is disclosed only:
- To the relevant authority, where disclosure is the purpose — a return filed with a state or federal tax authority contains the information that return requires.
- To service providers who operate parts of the Service on our behalf, limited to what each needs: our email delivery provider, our SMS delivery provider, and our hosting provider.
- Where the law requires it, including in response to a valid legal process.
- To the client carrier the information concerns, or to someone they authorise.
7. Text messaging
IRP Express Inc sends text messages to customers who have provided a mobile number and consented to receive them, for the purpose of notifying them about filing deadlines and their account. Consent is given in person at our office or by telephone, and is recorded against the customer's account.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile numbers are used solely to deliver the messages described above and are not sold, rented or shared for any other purpose.
Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe at any time, or HELP for assistance.
See our Messaging Terms for the full programme description.
8. Other notifications
The Service also sends deadline reminders and related messages by email to contact details held for a carrier. Recipients may ask to stop receiving them by contacting us at info@irpexpressinc.com.
9. Retention, correction and deletion
We keep compliance records for as long as we provide services to a carrier, and afterwards for the period required by applicable tax and transport regulations, which in some cases exceeds four years.
A carrier may ask us to correct information we hold about them, or to provide a copy of it, by contacting us at info@irpexpressinc.com. We will honour deletion requests except where a record must be retained to meet a legal or regulatory obligation, and we will say which records those are and why.
10. Children
The Service is a business application and is not directed to anyone under 18. We do not knowingly collect information from children.
11. Changes
We will update this policy when the Service changes in a way that affects it, and revise the "last updated" date above. Material changes will be communicated to affected clients directly rather than only by posting.
12. Contact
Questions about this policy, or about information we hold:
IRP Express Inc7263 Harlem Avenue, Bridgeview, IL 60455
info@irpexpressinc.com
