Legal

Privacy Policy

Last updated: July 31, 2026

This page describes Moonora Lab's current product practices for launch review. It is not legal advice and has not been approved by counsel. Material processing of contributed Payment Pulse data remains subject to legal sign-off.

Overview

Moonora Lab ("Moonora," "we," "us") is a freight intelligence platform operated from Canada. This Privacy Policy explains what information we collect, how we use it, and the choices available to you.

Whether PIPEDA, provincial privacy statutes, or other laws apply to a particular request depends on the facts and is subject to counsel review. We describe our practices factually; we do not claim compliance merely because this page exists.

Information We Collect

Account

  • Email address, authentication and security data.
  • Profile details such as role and company association when you provide them.

Community reports

  • Payment experiences, comments, ratings, and related fields you submit for review and possible publication.
  • Dispute and claim communications about published reports.

Private Payment Vault

  • Uploaded file contents processed for import (for example Excel/CSV exports).
  • Broker/customer/company names, invoice/due/payment dates, invoice or receipt identifiers or protected commitments, amounts/currency where stored privately, source system, matching selections/preferences, and import/job metadata.

Contribution (opt-in)

  • Affirmative consent record, version, and time.
  • Selected import/records, derived timing, matched company, validation outcome, anomaly/integrity signals, observation status, and audit decisions.

Operational

  • Integrity alerts, processing jobs, notification delivery status, administrative corrections, and security/abuse logs.
  • Usage data such as company searches, pages viewed, watchlist activity, and technical data needed to secure the Service.

Public company surfaces

  • Company identity (name, MC/USDOT when available, location/type/status when shown).
  • Approved community reports and company-level aggregate counts/scores, including severe-overdue and confirmed-unpaid aggregate counts and month-coarsened evidence recency.

Private by Default

Uploading to Payment Vault does not publish the upload. Raw private Vault rows are not public company evidence.

Contribution to company-level Payment Pulse aggregates requires a separate, unchecked affirmative action with a versioned consent record. Only qualifying derived observations may affect public aggregates.

Public output excludes raw invoice numbers, amounts, filenames, uploader identity, import IDs, HMAC/dedupe commitments, and exact private event dates. Public evidence recency, when shown, is coarsened to month level.

Restricted Moonora personnel or processors may access private data only as reasonably needed to operate the Service, provide support, investigate fraud/abuse, or meet legal obligations. We do not claim that employees can never access private data.

How We Use Information

  • Provide private Vault features (parse, match, organize payment records).
  • Validate, deduplicate, and process opted-in contribution requests.
  • Calculate company-level Payment Pulse aggregates and related metrics.
  • Prevent manipulation and maintain integrity alerts and audit records.
  • Display approved community reports and public aggregates.
  • Resolve disputes, corrections, rematches, and observation revocations.
  • Send requested or operational communications (for example payment reminders or integrity admin email when configured).
  • Protect security and investigate abuse.
  • Improve reliability using appropriately limited operational data.

We do not use this data for unrelated advertising purposes.

Automated Validation

Qualifying trusted observations may be validated automatically using checks such as ownership/consent, trusted company identity matching, date integrity, duplication, and anomaly signals. Clean qualifying records may affect company aggregates without prior manual approval.

Ambiguous records may be quarantined for review. Administrators may review, correct, rematch, revoke, or reprocess evidence. Automated validation is not human verification and is not an endorsement of any company.

Public Aggregates and Payment Pulse

Payment Pulse is an informational 0–100 company payment-pattern metric. It is not a guarantee of payment, not legal or financial advice, and not a consumer credit report. Trusted observations and community reports are distinct evidence sources.

Aggregates may include score/counts, evidence and confidence thresholds, month-coarsened recency, and contributor influence controls. There is no public page of raw private observations. Aggregates may change after new evidence, correction, revocation, or recalculation.

Severely overdue means more than 30 days past a known due date, or at least 60 days from invoice when no due date is available. Confirmed unpaid is a separate, stronger state and is not synonymous with every severely overdue item.

Consent and Withdrawal

  • Contribution is opt-in; the consent checkbox starts unchecked.
  • Consent is versioned; material policy changes require a new version.
  • Revoking contribution consent stops future processing under the implemented rule.
  • Revocation does not automatically remove already-qualified aggregate influence.
  • A separate correction or removal request is required for already-processed evidence.
  • Legal, fraud, audit, and security retention may still apply.

Withdrawal is available subject to applicable law and legitimate retention requirements. Withdrawal does not automatically erase all audit records.

Access, Correction, Deletion, and Removal

Depending on applicable law, you may request access to, correction of, or deletion of personal information we hold about you, subject to legal and operational limitations.

  • Personal information access/correction/deletion requests.
  • Company identity fact corrections.
  • Community report disputes (verified company representatives).
  • Challenges to trusted severe-overdue or confirmed-unpaid signals.
  • Correction/removal of contributed trusted evidence.
  • Revocation of future contribution consent.
  • Account deletion requests.

See Data Correction & Challenges for process paths. We may verify identity or authority before acting. We do not promise a fixed response deadline unless operations can meet it and counsel approves it.

Retention

Exact retention periods for each data category are subject to counsel/operations decisions before production activation. Until those periods are approved, we retain information only as reasonably necessary for the purposes described here, legal obligations, disputes, security, and audit. We do not claim indefinite retention by default.

Categories include account data; private Vault data; consent records; qualified, quarantined, and rejected observations; audit decisions; alerts/jobs; notification delivery records; community reports and disputes; and security logs.

Service Providers and Transfers

We use service providers in categories such as hosting/database and authentication (for example Supabase), email delivery (for example Resend when configured), and infrastructure monitoring. We do not list vendors we do not use.

Processing may involve cross-border transfers. We do not claim Canadian-only processing. Cross-border handling is a counsel review item.

We do not sell your personal information. We may share information with processors under contractual obligations, when required by law, or to protect rights and safety.

Cookies and Local Storage

We use session and authentication mechanisms needed to keep you signed in and secure. We may store recent searches and recently viewed companies in browser local storage. You can clear this data in your browser settings.

Security

We use reasonable administrative, technical, and organizational safeguards. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children's Privacy

Moonora Lab is intended for business users in the freight industry and is not directed to children under 16. We do not knowingly collect personal information from children.

Changes

We may update this Privacy Policy. Material changes will be posted here with an updated date. Material contribution-processing changes require a new consent version before new contribution processing.

Contact

Privacy and data requests: privacy@moonoralab.com (mailbox monitoring must be confirmed before launch).

Corrections and challenges: /data-correction. Legal questions: legal@moonoralab.com.