Versioned notice
Privacy
Version R1.2.1-2026-08-20. Content hash a446c5d04856aeca239e20eadf9fea68e2f0bcb82f6cd6c5e2ed715d57701e0b.
TollCover privacy baseline R1.2.1-2026-08-20 This notice describes how TollCover handles information in the current pre-deployment product. It is a product baseline, not attorney-approved legal advice. Public study TollCover's public study may collect: company or business name; role and budget authority; city or relevant toll corridor; a structured incident type and, for nonmedical respondents only, an optional nonidentifying incident note; current parking or transport benefit; preferred fixed-credit range and maximum bounded self-funded-pilot range; optional contact name and email when the respondent consents; and follow-up consent and preference. The study is collected to understand destination-access problems, qualify interest in a bounded merchant-applied credit, and — only when the respondent consents — to contact that person about a synthetic or future pilot. TollCover uses study answers for product research and for requested follow-up. TollCover does not use study answers for advertising pixels, session replay, or behavioral tracking. If the respondent does not consent to contact, TollCover does not store a contact name or email. Follow-up preference is treated as no contact. Study rows are retained until an operator deletes them for a recorded purpose. Automatic deletion is not promised. To request access or deletion, email privacy@tollcover.com. An operator may also delete a study submission when a purpose is recorded in the audit log. STANDARD merchants STANDARD merchants may collect only minimal visitor information needed to issue and verify a promotional credit: an optional given name and an optional contact handle, plus consent and visit-state timestamps. HEALTHCARE_NO_PHI HEALTHCARE_NO_PHI merchants provide campaign configuration and aggregate campaign totals only. TollCover does not receive patient-level information and must not be sent patient names, appointment details, plate numbers, or other individual healthcare data. TollCover does not collect license plates, toll accounts, GPS, payment cards, medical records, government IDs, or healthcare patient-level data. Infrastructure may process limited technical logs (path, status, redacted error class). Raw access tokens, session secrets, visitor contact handles, and full form payloads are not written to logs. STANDARD supports export and deletion of visitor-linked offer fields where implemented. HEALTHCARE_NO_PHI supports campaign, packet-batch, and aggregate-closeout export, plus organization-level deletion or anonymization. TollCover does not promise patient deletion in HEALTHCARE_NO_PHI because it must not possess patient data. Automatic deletion is not promised beyond the implemented operator and merchant controls above. Contact: privacy@tollcover.com