Privacy Policy
Effective: January 1, 2026 · Last updated: June 25, 2026
1. Who We Are
Dahlia Strategic Solutions LLC ("DSS," "we," "us," or "our") is a South Florida-based logistics, courier, and supply chain advisory firm. Our principal office is at 200 S Andrews Ave, Suite 504, Fort Lauderdale, FL 33301.
For privacy questions, contact our Data Protection Officer at privacy@dahliastrategy.com.
2. Information We Collect
A. Information you give us
- Account information: name, email, phone, company, address, role.
- Service information: pickup/delivery addresses, contact names, phone numbers, special handling instructions, payment information.
- Communication: emails, calls, SMS messages, support tickets, survey responses.
- Identity verification: government ID for credit customers, beneficial ownership for B2B accounts over a defined threshold.
B. Information collected automatically
- Device & usage: IP address, browser type, operating system, pages viewed, time on page, referring URL.
- Cookies and similar: see Section 6 below.
- GPS tracking: latitude, longitude, speed, heading for DSS vehicles during active assignments. Disabled when vehicle is off-duty.
- Proof of delivery: signature image, recipient name, timestamp, optional photo.
C. Information from third parties
- Credit agencies (for credit decisions).
- Mapping & geocoding providers (to convert addresses to coordinates; no personal data shared back).
- Payment processors (Square, Stripe, ACH — DSS does not store full payment card numbers).
- Public records (business filings, OFAC screening).
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and improve our Services.
- To process payments and fulfill tax/regulatory obligations.
- To communicate with you about Services, including dispatch updates, ETAs, and delivery confirmations.
- To verify identity, prevent fraud, and protect the safety of our personnel, customers, and the public.
- To comply with legal obligations (DOT, FMCSA, HIPAA, IRS, court orders).
- To send marketing communications (with your consent; you can opt out at any time).
- To improve our website, mobile apps, and customer experience through analytics.
4. Legal Bases for Processing (GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, we process your personal data under one or more of the following legal bases:
- Contract: to provide Services you have requested or entered into.
- Legitimate interest: to operate, secure, and improve our business, where your interests do not override ours.
- Consent: for marketing, cookies (where required), and any processing you have explicitly opted into.
- Legal obligation: to comply with applicable laws.
5. How We Share Your Information
We do not sell your personal information. We share information only in the following limited circumstances:
- With your consent: when you direct us to share (for example, sharing a tracking link with a consignee).
- Service providers: vetted vendors who perform services on our behalf (hosting, payment processing, email delivery, SMS, mapping). Each is bound by confidentiality and data-protection obligations.
- Subcontractors: in the event we use a partner carrier for capacity overflow (you will be notified in advance).
- Legal compliance: when required by law, court order, subpoena, or to cooperate with law enforcement. We will notify you of such requests unless legally prohibited.
- Safety: to protect the safety, rights, or property of DSS, our personnel, customers, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, with confidentiality protections.
- Aggregate / de-identified data: we may share aggregated, de-identified statistics with partners or the public (such as "South Florida medical courier market trends").
6. Cookies & Tracking Technologies
We use cookies, web beacons, and similar technologies to:
- Strictly necessary cookies: required for the website to function (session, security, load balancing). These cannot be disabled.
- Analytics cookies: optional, used to understand how visitors use our site (page views, bounce rate, traffic sources). Currently we use first-party analytics only and do not share data with Google Analytics or similar third parties.
- Preference cookies: optional, used to remember your settings (e.g., location preference).
- Marketing cookies: optional, used only with your consent, to deliver relevant ads and measure their effectiveness.
You can manage cookie preferences through your browser settings or our cookie banner. Disabling certain cookies may affect site functionality.
Do Not Track: We honor browser-level "Do Not Track" (DNT) and "Global Privacy Control" (GPC) signals by disabling non-essential cookies.
7. Data Retention
We retain personal data for as long as needed to provide Services, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods:
- Customer accounts: for the life of the account, plus 7 years for tax records (IRS requirement).
- Shipment records: 7 years (IRS, DOT, FMCSA).
- GPS tracking data: 90 days, unless part of an incident investigation or insurance claim.
- HIPAA-related records: 6 years minimum (HIPAA requirement).
- Driver background checks & drug tests: duration of employment plus 3 years.
- Marketing consent records: until consent is withdrawn, plus 3 years.
- Website analytics: 26 months (Google's default; we use less).
- Support tickets: 3 years.
- Audit logs (admin actions): 7 years.
After the retention period expires, data is securely deleted or irreversibly anonymized.
8. Your Rights
For all users:
- Access: request a copy of the personal data we hold about you.
- Correction: correct inaccurate or incomplete data.
- Deletion: request deletion of your personal data, subject to legal retention requirements.
- Opt-out of marketing: unsubscribe from our marketing emails via the link in any email, or contact us.
- Object to processing: where we rely on legitimate interest.
California residents (CCPA/CPRA):
- Right to know what categories of personal information we collect, the sources, the business purpose, and the categories of recipients.
- Right to opt out of sale or sharing — we do not sell personal information.
- Right to limit use of sensitive personal information to that necessary to provide the Services.
- Right to non-discrimination for exercising CCPA rights.
EEA / UK / Swiss residents (GDPR):
- All rights above, plus right to data portability and right to lodge a complaint with your supervisory authority.
- Right to withdraw consent at any time, without affecting prior lawful processing.
To exercise any right: email privacy@dahliastrategy.com with your name, account email, and the specific request. We will respond within 45 days (or 30 days under CCPA for verifiable consumer requests). We may need to verify your identity before fulfilling the request.
9. HIPAA Notice
Where DSS handles Protected Health Information (PHI) on behalf of a covered entity or business associate, DSS executes a Business Associate Agreement (BAA) that governs the permitted uses, safeguards, breach notification, and subcontractor obligations required by 45 CFR §§ 164.502(e), 164.504(e), and 164.314.
DSS has implemented administrative, physical, and technical safeguards aligned with the HIPAA Security Rule (45 CFR Part 164, Subpart C), including encryption in transit and at rest, role-based access, audit logging, and workforce training.
10. Data Security
We use industry-standard administrative, technical, and physical safeguards to protect personal data, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls and least-privilege permissions.
- Multi-factor authentication for administrative access.
- Comprehensive audit logging of all data access.
- Background-checked personnel with annual security training.
- Regular vulnerability scanning and annual third-party penetration tests.
- Incident response plan with documented runbooks.
No system is 100% secure. If a security incident affects your personal data, we will notify you in accordance with Section 11 below.
11. Breach Notification
In the event of a data breach affecting your personal information, DSS will:
- Notify affected individuals by email (or postal mail if no email is on file) without unreasonable delay, and in any case within 72 hours of discovery, in line with GDPR Article 33.
- Notify HHS within 60 days for breaches affecting 500 or more individuals (HIPAA Breach Notification Rule, 45 CFR § 164.408).
- Notify state attorneys general as required by state breach-notification laws (e.g., Florida Information Protection Act).
- Provide a description of the breach, the type of data involved, steps you should take to protect yourself, and what we are doing to investigate and mitigate.
- Maintain an incident register documenting the breach, response, and lessons learned.
12. Children's Privacy
DSS Services are intended for adults and businesses. We do not knowingly collect personal information from children under 13 (COPPA), under 16 (GDPR), or under 13 (CCPA). If we learn we have collected such information, we will delete it promptly. Parents or guardians may contact us at privacy@dahliastrategy.com to request deletion.
13. International Data Transfers
DSS is based in the United States and primarily processes data within the United States. Where we transfer personal data from the EEA, UK, or Switzerland to the U.S., we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms.
By using our Services, you acknowledge that your data may be transferred to, stored in, and processed in the United States.
14. Driver & Vehicle Privacy
DSS drivers acknowledge and consent to:
- GPS tracking of DSS vehicles during active assignments (disabled when off-duty).
- Recording of audio/video from in-cab cameras (where installed) for safety and incident investigation.
- Background checks and drug testing as a condition of employment.
- Collection of personal data for payroll, tax, and HR purposes.
Driver personal data is retained per Section 7 (Data Retention) and protected per Section 10 (Data Security).
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to active Customers and posted on this page at least 30 days before the effective date. The "Last updated" date at the top reflects when the most recent change was made.
16. Contact
For privacy questions, data requests, or to exercise your rights:
Data Protection Officer
Dahlia Strategic Solutions LLC
200 S Andrews Ave, Suite 504
Fort Lauderdale, FL 33301
Email: privacy@dahliastrategy.com
Phone: (754) 352-9826
EU/UK representative: available on request for GDPR inquiries.
