Nexscan — Data Processing Terms
Effective Date: 10/1/2026
These Data Processing Terms ("DPT") form part of the Nexscan Terms of Service between the fleet owner's business (the "Customer") and Verve LLC, a Washington limited liability company ("Nexscan," "we," "us," or "our"). They describe how we process the documents and related records that a Customer's drivers and office staff submit through the Nexscan mobile application and web dashboard (the "Services"). Everything below describes the system as it is built today.
Scope. These DPT govern fleet document data that we process on the Customer's behalf. They do not cover waitlist or marketing contact information submitted on our website: for that data Verve LLC is the controller, and the Privacy Policy governs.
1. Roles
- The Customer is the controller of the documents its drivers submit and of the account records it creates for its fleet. The Customer decides who may join its fleet, which roles they hold, and how long documents are kept.
- Verve LLC is the processor. We store, organize, display, and export that data only to provide the Services to the Customer and only on the Customer's instructions as given through the Services.
2. Data Processed
| Category | What it is |
|---|---|
| Scanned document files | The images or multi-page PDFs a driver captures, plus a first-page thumbnail. |
| Document tag | One of the fixed set of seven: POD, Fuel Receipts, Scale Tickets, Customs Documents, Repair Invoices, Safety / DVIR, Other Expenses. |
| Load and reference numbers | The load number a driver enters at scan time and the confirmation code issued as a receipt. |
| Uploader identity | Which fleet member submitted each document and when. |
| Account and user records | Fleet name and Fleet ID, member names, email addresses, roles, status, phone numbers where given, departments and their notification settings. |
| Office notes | Notes office roles attach to a document. Drivers cannot see them. |
| Audit log entries | Who made each change to a document's metadata, notes, team membership, or fleet settings, and when. |
We do not process payment data (no payment processor is connected) and we do not send document contents to any AI or text-extraction vendor.
3. Security Measures, As Implemented
- Row-level security on every table. Every database table has row-level security enabled, with policies scoped to the fleet. The fleet is derived on the database side from the authenticated user's identity (
auth.uid()), never from a value supplied by a client. - Private file storage. Document files live in a private storage bucket with no public object URLs. Storage access is governed by the same fleet-scoped policies as the database.
- Short-lived signed URLs. Document files are served through signed URLs that expire within one hour and are generated only after the fleet-scoped policy check passes.
- Closed membership. Drivers join by entering the Customer's Fleet ID and must be approved by the fleet owner. Office roles join only through an invitation bound to their email address. There is no open self-signup into an existing fleet.
- Credentials server-side only. Service credentials that can bypass row-level security are held on our servers only and are never shipped to the mobile app or the browser.
- Transport encryption. All traffic between the apps and our servers uses TLS.
4. Access Scope
- Drivers see only the documents they uploaded.
- The fleet owner and the office roles the owner assigns (admin, dispatcher, accountant, viewer) see the fleet's documents according to their role. Viewers are read-only.
- No other fleet can see the Customer's data; the fleet-scoped policies above make cross-fleet access structurally impossible rather than merely prohibited.
- Every metadata edit is attributed. Retags, load-number changes, note edits, deletions and restores are recorded in the audit log with the acting user and time.
- Our staff access Customer data only to operate the Services, investigate a support request from the Customer, or as required by law. Platform-administration actions are themselves audit-logged.
5. Sub-processors
We use the following sub-processors to operate the Services. We do not use any others for Customer data.
| Sub-processor | Role |
|---|---|
| Supabase, Inc. | Database, authentication, and file storage. |
| Vercel, Inc. | Hosting of the web dashboard and its server-side code. |
We will update this list before adding a sub-processor that would process Customer data.
6. Retention, Export, and Deletion
- Retention. Customer data is retained while the Customer's account is active.
- Export. The Customer can export any filtered view of its documents as a CSV file and download the original files as a ZIP archive from the dashboard at any time, without asking us.
- Deletion by the Customer. Owners and admins can delete documents from the dashboard. Deleted documents are held for 30 days, during which they can be restored, and are then permanently removed together with their files.
- Deletion on request or termination. On the Customer's written request, or when the Customer's account is terminated, we delete the Customer's data without undue delay, and in any event within 30 days, except where we are required by law to retain it.
7. International Transfers
The Services run on a Supabase project hosted in the United States. Customer data is stored and processed there. If the Customer or its drivers are located outside the United States, their data is transferred to and processed in the United States.
8. Breach Notification
If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer data, we will notify the fleet owner without undue delay after becoming aware of it, and will share what we know about the nature of the breach and the steps we are taking.
9. Changes
We may update these DPT to reflect changes in the Services. Material changes will be posted at this address with a new effective date.
10. Contact
Questions about these Data Processing Terms:
Verve LLC Email: support@nexscan.app
Last updated: 10/1/2026