Privacy Policy

Last Updated: February 16, 2026

CORPORACIÓN OTIF LOGÍSTICA INTEGRADA, S.A. DE C.V. ("OTIF," "we," "us," or "our") respects your right to privacy, and we are dedicated to securing and protecting any information we have about you. This Privacy Policy describes the ways we collect, use, and share information that relates to an identifiable individual ("Personal Data") and also how you can exercise your rights under applicable privacy and data protection laws.

If you have any questions or concerns about our use of your Personal Data, or if you wish to exercise any of your privacy rights including the right to object (where applicable), then please contact us using the contact details under 'How to Contact us' at section 14 below.

OTIF is headquartered in Mexico. For jurisdiction specific provisions of this Privacy Policy see the 'Jurisdiction Specific Provisions' at section 9 below.

We recommend that you read this Privacy Policy in full to ensure you are completely informed about OTIF's collection and use of your Personal Data.

By downloading, installing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the terms of this Privacy Policy, you must not use the App.

Table of Contents

1. Applicability of this Privacy Policy

This Privacy Policy describes how OTIF collects, uses, discloses, and otherwise processes Personal Data in connection with the OTIF Driver mobile application (the "App") and related services (collectively, the "Services").

This Privacy Policy applies to all users of the App, including professional drivers with commercial driver's licenses who are employed by or contracted with transportation and logistics companies that use OTIF's Services (hereinafter referred to as "Contracting Companies"). The App is a business-to-business ("B2B") logistics and transportation monitoring application designed to optimize logistics operations, ensure road safety, and facilitate compliance with transportation contracts through the monitoring of assets and shipments.

Your use of the Services is governed by separate Terms and Conditions available at https://otif.mx/otif-driver/terms-conditions (the "Service Terms"). This Privacy Policy governs only where OTIF is the data controller responsible for the processing of Personal Data.

2. Minors' Data

The App is intended solely for use by adult professional drivers holding commercial driver's licenses. The App is not directed at individuals under the age of eighteen (18) years, and we do not knowingly collect Personal Data from individuals under eighteen (18) years of age.

If you have reason to believe that a minor under the age of 18 has provided Personal Data to OTIF, please email us at privacy@otif.mx and we will take steps to remove that information from our servers.

3. Personal Data We Collect and Process

OTIF collects and processes Personal Data in connection with the provision of the Services. The App is designed to minimize the collection of personally identifiable information ("PII") by associating collected data with shipments rather than individual drivers. However, certain data elements may constitute Personal Data under applicable law. Below is a description of the categories of data we collect:

3.1 No Account Registration

Account registration is not required for the use of the App. The app uses One-Time Password (OTP) authentication. This method ensures that only the intended device is transmitting telemetry, without capturing Personal Data from the user such as name, email address, phone number, physical address, and other user-level identifiers.

3.2 Location Data

3.2.1 Precise Geolocation Data. The App captures precise geolocation data (GPS coordinates with latitude and longitude to three or more decimal places) continuously during the execution of an active trip. This data is critical for logistics optimization, road safety monitoring, and contract compliance.

3.2.2 Coarse Location Data. The App may collect coarse or approximate location data when precise location data is unavailable.

3.2.3 Background Location Tracking. The App collects location data in the background while a trip is active to ensure accurate and continuous location streams necessary for safety, reliability, and observability guarantees. Location tracking occurs only while a "Trip" is active, respecting drivers' right to disconnect when not engaged in an active trip.

3.3 Device Identifiers

The App collects unique device identifiers. These identifiers are used to link the One-Time Password ("OTP") authentication to a specific device, prevent multiple devices from servicing the same shipment, and ensure the integrity of telemetry reports.

By using the App, you represent and warrant that you have the legal authority to permit the collection of device identifiers from the mobile device on which the App is installed. If you are using a device owned by a Contracting Company, or any third party, you represent that you have obtained all necessary permissions to use the App on such device. OTIF is not responsible for any disputes arising from your use of the App on a device for which you lack appropriate authority.

3.4 Telemetry Data

The App collects vehicle telemetry data, including speed and accelerometry data, during active trips. This data is used for road safety monitoring and as evidentiary support for contract compliance.

3.5 Photographic Evidence

The App enables drivers to capture photographs of 1) documents (such as invoices and stamps) and 2) the condition of cargo as delivery evidence. The App requires access to the device camera for this purpose; however, access to the photo or video library is explicitly prohibited to eliminate the possibility of counterfeit evidence. These images are treated as digital assets with metadata indicating time and location to prevent fraud.

3.6 Chat and Communication Data

The App includes a bidirectional chat feature that allows drivers to communicate via text with operations controllers and dispatchers. Chat history is stored as evidence that may be used in disputes regarding delays or incidents.

3.7 Incident Reports

The App allows drivers to submit incident reports providing immediate notifications of accidents, breakdowns, or road blockages. These reports are timestamped with the exact telemetry data from the moment of the incident, providing evidentiary value.

3.8 Free-Form Text Data

Users may enter free form text in two sections of the App: (1) Incident Reporting and (2) Customer Support Chat.

3.9 Data We Do Not Collect

The App does not collect the following categories of Personal Data: names, email addresses, phone numbers, physical addresses, health or medical data, fitness data, payment information, credit information, financial information, contacts or address books, browsing history, search history, user IDs or account identifiers, purchase history, product interaction data (such as app launches, taps, or clicks), advertising data, crash data, performance data, diagnostic data, audio or voice recordings, or scanning data.

Additionally, the App does not collect any sensitive personal information, including racial or ethnic origin, sexual orientation, pregnancy or childbirth information, disability status, religious or philosophical beliefs, trade union membership, political opinions, genetic information, or biometric data.

3.10 Prohibition on Transmission of Personal Information

You are strictly prohibited from transmitting personal information (such as names, addresses, email addresses, phone numbers, identification numbers, or other personally identifiable information about yourself or third parties) through chat messages, incident reports, free-form text fields, photographs, or any other means within the App. The App is not designed to collect or process such information, and OTIF does not request or require such information to provide the Services. If you become aware that personal information has been inadvertently transmitted through the App, you should promptly notify OTIF at privacy@otif.mx so that appropriate measures may be taken.

4. How We Use Personal Data

We process Personal Data exclusively for purposes directly related to the provision of the Services. Specifically, we use data for the following purposes:

4.1 App Functionality and Service Delivery

All data collected through the App is used solely for app functionality. This includes:

  • Logistics Optimization: Using location and telemetry data to track shipments and optimize delivery routes.
  • Road Safety Monitoring: Analyzing telemetry data (speed, accelerometry) to monitor driving behavior and promote road safety.
  • Contract Compliance: Providing verifiable records of delivery progress, checkpoint completion, and cargo condition to satisfy contractual obligations between OTIF and Contracting Companies.
  • Device Verification: Using device identifiers to ensure that only authorized devices transmit telemetry for a given shipment.
  • Operational Communications: Facilitating chat communication between drivers and operations personnel through the in-app chat feature.
  • Incident Management: Recording and processing incident reports to enable rapid response and documentation.

4.2 Evidentiary and Legal Purposes

Data collected through the App is used to create records with evidentiary value for potential legal proceedings, insurance claims, or dispute resolution related to shipments and deliveries. This includes location data, telemetry, photographic evidence, chat records, and incident reports.

4.3 Purposes for Which We Do Not Use Data

We do not use data collected through the App for third-party advertising, first-party advertising or marketing, analytics, product personalization, or any purpose beyond what is necessary to provide the App's core functionality.

5. Who We Share Your Personal Data With

5.1 Contracting Companies

Telemetry data, photographic evidence, and other data generated via the App belongs to OTIF. OTIF Shippers as Contracting Companies have access to real-time shipment data generated by the App only. This data is associated with shipments, not with individual drivers.

5.2 No Third-Party Data Sharing

We do not share data collected through the App with third parties. All API calls made by the App are first-party calls to OTIF's own servers; the App does not integrate any third-party SDKs, analytics tools, advertising networks, or external vendor code.

5.3 No Data Brokers

We do not share any data with data brokers.

5.4 No Advertising Networks

We do not share email lists, advertising IDs, device IDs, or other identifiers with third-party advertising networks for retargeting, lookalike audience purposes, or any other advertising-related purpose.

5.5 Legal and Regulatory Disclosures

We may disclose Personal Data if required to do so by law or in response to valid requests by public authorities, including to meet national security or law enforcement requirements. We may also disclose Personal Data to: (a) conform to the law, comply with legal process, or investigate, prevent, or take action regarding suspected or actual illegal activities; (b) to enforce our Service Terms, this Privacy Policy, to take precautions against liability, to investigate and defend ourselves against any claims or allegations, or to protect the security or integrity of our site; and/or (c) to exercise or protect the rights, property, or personal safety of OTIF, our employees, or others.

5.6 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or other sale of all or a portion of our assets, Personal Data held by us may be among the assets transferred to the acquiring entity. We will provide notice before Personal Data is transferred and becomes subject to a different privacy policy.

6. How We Keep Your Personal Data Secure

OTIF implements appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction. These measures include:

6.1 Encryption in Transit

All data transmitted between the App and our servers is encrypted using Secure Sockets Layer (SSL) encryption.

6.2 Access Controls

We implement per-identity access controls through Google Cloud Platform's Identity and Access Management (IAM) system to ensure that only authorized personnel can access data.

6.3 Data Minimization by Design

The App is designed to associate data with shipments rather than with individual drivers, thereby minimizing the collection of personally identifiable information. Location data is associated with shipments rather than directly with individual drivers, which helps to reduce the identifiability of such data in storage.

6.4 Device Authentication

The OTP authentication mechanism registers a unique device identifier for the duration of a shipment to prevent credential sharing and ensure data integrity.

While we strive to use commercially reasonable means to protect Personal Data, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your data.

6.5 Data Breach Notification

In the event of a data breach that affects your Personal Data, we will notify you and the relevant supervisory authorities in accordance with applicable law.

7. Data Retention

We retain data collected through the App for the following periods:

Data TypeRetention Period
Precise Location Data10 years from shipment completion
Coarse Location Data10 years from shipment completion
Telemetry Data (speed, accelerometry)10 years from shipment completion
Photographic Evidence10 years from shipment completion
Device Identifiers10 years from shipment completion
Chat Messages10 years from shipment completion
Incident Reports10 years from shipment completion

Historical data provides value to the Contracting Companies for logistics analysis, compliance verification, and dispute resolution purposes. Notwithstanding the foregoing, we may retain data beyond the standard retention period in the following circumstances:

  • Pending or Threatened Legal Proceedings: Where data is relevant to pending litigation, arbitration, regulatory investigation, or where we have a reasonable belief that legal proceedings may be commenced.
  • Legal Holds: Where data is subject to a valid legal hold, preservation notice, or similar legal requirement.
  • Regulatory Requirements: Where longer retention is required by applicable law or regulation.
  • Ongoing Contractual Obligations: Where retention is necessary to fulfill ongoing obligations to Contracting Companies.

Early Deletion. Data may be deleted prior to the expiration of the retention period upon receipt of a valid deletion request, subject to applicable legal exceptions.

8. International Data Transfers

8.1 Data Storage Location

Data collected through the App is stored on servers located in the United States of America.

8.2 Transfers from Mexico

For users located in Mexico; by using the App you consent to the transfer of your data to the United States, which may have different data protection laws than Mexico. OTIF will take appropriate measures to ensure that your data is treated securely and in accordance with this Privacy Policy and applicable Mexican law, including the LFPDPPP.

8.3 Transfers from the European Economic Area, United Kingdom, and Switzerland

If you are located in the EEA, United Kingdom, or Switzerland, please note that data collected through the App will be transferred to and processed in the United States. The United States may not provide the same level of data protection as your home jurisdiction. When we transfer Personal Data outside of the EEA, United Kingdom, or Switzerland, we will implement appropriate safeguards to ensure that such data receives an adequate level of protection, which may include: (a) transfers to countries that have been deemed to provide an adequate level of data protection by the European Commission; (b) the use of Standard Contractual Clauses approved by the European Commission; or (c) other lawful transfer mechanisms. You may request a copy of the relevant safeguards by contacting us at the contact details provided below.

9. Jurisdiction-Specific Provisions

This Section 9 provides additional information for users located in specific jurisdictions regarding how we collect, use, and disclose Personal Data, and describes certain rights you may have under applicable law. These jurisdiction-specific provisions supplement the other sections of this Privacy Policy. In the event of a conflict between this Section 9 and other provisions of this Privacy Policy, this Section 9 shall control with respect to users located in the applicable jurisdiction.

9.1 Mexico (LFPDPPP)

If you are a data subject located in Mexico, the following provisions apply in accordance with the LFPDPPP and its Regulations:

Responsible Party. CORPORACIÓN OTIF LOGÍSTICA INTEGRADA, S.A. DE C.V. is the responsible party ("Responsable") for the processing of your Personal Data under the LFPDPPP.

Purposes of Processing. Your Personal Data is processed for the primary purposes described in Section 4 of this Privacy Policy, which are necessary for the provision of the Services. We do not process your Personal Data for secondary purposes such as marketing, advertising, or analytics.

Sensitive Personal Data. We do not collect sensitive Personal Data ("datos personales sensibles") as defined under Article 3, Section VI of the LFPDPPP, including data revealing racial or ethnic origin, present or future health status, genetic information, religious, philosophical or moral beliefs, union membership, political opinions, or sexual preference.

ARCO Rights. Under the LFPDPPP, you have the right to access, rectify, cancel, or oppose (collectively, "ARCO Rights") the processing of your Personal Data. To exercise your ARCO Rights, please submit a written request to privacy@otif.mx containing:

  • (a) your name and contact information;
  • (b) a clear description of the Personal Data with respect to which you seek to exercise any of your ARCO Rights;
  • (c) any other element that facilitates the location of your Personal Data; and
  • (d) in the case of rectification requests, indication of the modifications to be made and documentation supporting your request.

Consent. By using the App, you consent to the processing of your data as described in this Privacy Policy. Consent to GPS tracking for work and logistics security purposes is obtained through in-app prompts requesting location data access.

Limitation on Use or Disclosure. You may limit the use or disclosure of your Personal Data by contacting us at privacy@otif.mx.

Revocation of Consent. You may revoke consent to the processing of your Personal Data at any time by contacting us at privacy@otif.mx. Please note that revocation of consent may affect your ability to use the App.

Transfer of Personal Data. By using the App, you consent to the transfer of your Personal Data to servers located in the United States for the purposes described in this Privacy Policy.

Changes to Privacy Policy. Any changes to this Privacy Policy will be published at https://otif.mx/otif-driver/privacy-policy.

9.2 United States

If you are a consumer located in the United States ("US"), we process your Personal Data in accordance with US privacy laws, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA").

Categories of Personal Information Collected. In the preceding twelve (12) months, we have collected the following categories of personal information as defined under the CCPA/CPRA:

  • Geolocation data (precise and coarse location)
  • Identifiers (device identifiers)
  • Internet or other electronic network activity information (telemetry data, chat messages)
  • Visual information (photographs of documents and cargo)

Sources of Personal Information. We collect personal information directly from you through your use of the App and automatically from your device during active trips.

Business or Commercial Purposes. We collect personal information for the business purposes described in Section 4 of this Privacy Policy, specifically for app functionality and evidentiary/legal purposes.

Categories of Third Parties with Whom Personal Information is Shared. We share shipment-related data only with Contracting Companies (our B2B clients). We do not sell personal information and have not sold personal information in the preceding twelve (12) months.

Sale or Sharing of Personal Information. We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.

Sensitive Personal Information. We collect precise geolocation data, which is considered sensitive personal information under the CCPA/CPRA. This data is used solely for the purposes of providing the Services and is not used to infer characteristics about you.

Your California Privacy Rights. Subject to certain exceptions, California residents have the following rights:

  • Right to Know: You have the right to request that we disclose what personal information we have collected, used, disclosed, and sold about you.
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You have the right to request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioral advertising; therefore, there is no need to opt out.
  • Right to Limit Use of Sensitive Personal Information: You have the right to limit the use of sensitive personal information to purposes necessary for performing the Services.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

To exercise your rights, please contact us at driver-privacy-support@otif.mx. We will respond to verifiable consumer requests within forty-five (45) days.

Authorized Agents. You may designate an authorized agent to submit requests on your behalf. To do so, you must provide the authorized agent with written permission to act on your behalf, and we may require you to verify your identity directly with us and confirm that you have authorized the agent. If your authorized agent submits a request, we may require them to submit proof of their authorization to act on your behalf.

Do Not Track Signals. The App is a mobile application and does not respond to "Do Not Track" browser signals. The App does not track users across third-party websites or online services, and therefore Do Not Track signals are not applicable to the App's functionality.

Retention. We retain personal information as described in Section 7 of this Privacy Policy.

9.3 European Economic Area (EEA), United Kingdom, and Switzerland

If you are located in the European Economic Area ("EEA"), United Kingdom ("UK"), or Switzerland, the following provisions apply to the processing of your Personal Data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and the Swiss Federal Act on Data Protection, as applicable.

Data Controller. CORPORACIÓN OTIF LOGÍSTICA INTEGRADA, S.A. DE C.V. is the data controller responsible for your Personal Data.

Legal Bases for Processing. Under the GDPR and UK GDPR, we are required to have a valid legal basis for processing your Personal Data. The legal bases we rely upon are described below:

Contractual Necessity (Article 6(1)(b) GDPR). We process Personal Data necessary to provide the Services, authenticate your device, track shipments, and fulfill our contractual obligations to Contracting Companies.

Legitimate Interests (Article 6(1)(f) GDPR). Our legitimate interests include: (a) ensuring road safety through monitoring of driving behavior; (b) maintaining the integrity and security of logistics operations; (c) creating evidentiary records for dispute resolution, insurance claims, and legal proceedings; (d) preventing fraud, GPS manipulation, and credential sharing; and (e) improving and optimizing our Services. Where we rely on legitimate interests, we have conducted a balancing test and determined that our legitimate interests do not override your rights and freedoms, particularly given the business-to-business nature of the Services and the association of data with shipments rather than individual drivers.

Legal Obligation (Article 6(1)(c) GDPR). We process Personal Data where such processing is necessary for compliance with a legal obligation to which we are subject, including responding to lawful requests from public authorities, meeting transportation regulatory requirements, and complying with applicable tax and accounting obligations.

Consent (Article 6(1)(a) GDPR). In certain limited circumstances, we may process Personal Data based on your consent. Where we rely on consent, you have the right to withdraw your consent at any time by contacting us at privacy@otif.mx. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

The following table sets forth the purposes for which we process Personal Data, the legal bases for such processing, and the categories of Personal Data processed for each purpose:

Data TypeLegal BasisJustification
Precise/Coarse LocationContract performance / Legitimate interestNecessary for logistics optimization, shipment tracking, and contract compliance
Telemetry DataContract performance / Legitimate interestNecessary for road safety monitoring and contract compliance
Photographic EvidenceContract performanceNecessary for delivery verification and proof of condition
Device IdentifiersContract performance / Legitimate interestNecessary for device authentication, security, and data integrity
Chat MessagesContract performance / Legitimate interestNecessary for operational instructions, support requests, and evidentiary purposes
Incident ReportsContract performance / Legitimate interestNecessary for incident management, reporting, and evidentiary purposes

Your Rights Under the GDPR. Subject to applicable law, you have the following rights:

  • Right of Access (Article 15 GDPR): You have the right to obtain confirmation as to whether Personal Data concerning you is being processed and, if so, to access that data.
  • Right to Rectification (Article 16 GDPR): You have the right to request rectification of inaccurate Personal Data.
  • Right to Erasure ("Right to be Forgotten") (Article 17 GDPR): You have the right to request erasure of your Personal Data in certain circumstances.
  • Right to Restriction of Processing (Article 18 GDPR): You have the right to request restriction of processing in certain circumstances.
  • Right to Data Portability (Article 20 GDPR): You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format.
  • Right to Object (Article 21 GDPR): You have the right to object to processing based on legitimate interests.
  • Right to Withdraw Consent (Article 7(3) GDPR): Where processing is based on consent, you have the right to withdraw consent at any time.
  • Right to Lodge a Complaint (Article 77 GDPR): You have the right to lodge a complaint with a supervisory authority in your country of residence.

To exercise your rights, please contact us at privacy@otif.mx.

International Transfers. Please see Section 8 of this Privacy Policy regarding international data transfers.

10. Your Data Protection Rights

10.1 Data Association

As described in this Privacy Policy, the App is designed to associate data with shipments rather than individual drivers, which helps minimize the identifiability of collected data.

10.2 Right to Disconnect

The App is designed so that location tracking and telemetry collection occur only while a "Trip" is active. When no trip is active, the App does not track your location, respecting your right to disconnect.

10.3 Opting Out

No opt-out from data collection is available while a trip is active, as data collection is necessary for the functioning of the App and the fulfillment of contractual obligations. However, data collection automatically ceases when a trip is completed or terminated.

10.4 Accessing, Correcting, or Deleting Your Data

We handle requests for data access, correction, or deletion on a case-by-case basis. To make such a request, please contact driver-privacy-support@otif.mx. We will respond to your request in accordance with applicable law.

10.5 Jurisdiction-Specific Rights

For information about your specific rights under Mexican, California, or EU/UK law, please see Section 9 of this Privacy Policy.

11. Data Ownership

All data generated through use of the OTIF Driver App, including telemetry data, photographic evidence, chat records, and incident reports, belongs to OTIF. Such data is made available to Contracting Companies in connection with their use of OTIF's Services. Drivers do not retain ownership rights in data generated through the App.

12. Prohibited Conduct

The following conduct is prohibited when using the App:

  • GPS Manipulation: Use of "Fake GPS" or any other method to manipulate or falsify location data is strictly prohibited.
  • Credential Sharing: Sharing OTP credentials or allowing multiple devices to service the same shipment is prohibited.
  • Unnecessary Disclosure of Personal Information: Transmitting personal information through any means within the App, except where strictly necessary and directly relevant to a specific shipment, incident, or support request, is prohibited.

Without limiting any other rights or remedies available to OTIF, users found to have been engaged in prohibited conduct may result in: (a) immediate termination of your access to the App; (b) reporting to the Contracting Company; and (c) removal from the OTIF network.

13. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. When we make material changes to this Privacy Policy, we will notify you by posting the updated Privacy Policy at https://otif.mx/otif-driver/privacy-policy and updating the "Last Updated" date at the top of this document.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data. Your continued use of the App following the posting of changes constitutes your acceptance of such changes.

14. How to Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

15. Subprocessors

Subprocessor NamePurposeLocation
Google Cloud PlatformData StorageUnited States

EEA Representative: to be appointed