Last updated 30 July 2026
Privacy Policy
This policy explains what personal data Alfabolt FZE LLC collects when you use Native Base and Market Tracker (including our free tools and our MCP connector for AI assistants), why we collect it, who we share it with, how long we keep it, and the choices you have.
Who we are
Native Base and Market Tracker are operated by Alfabolt FZE LLC, a company registered in the United Arab Emirates (Business Center, SPC Freezone, Sharjah, United Arab Emirates). Alfabolt FZE LLC is the data controller for the personal data described here.
For any privacy question or to exercise your rights, contact privacy@alfabolt.com. For product support, contact hello@nativebase.ai.
The data we collect
Account data. Your name, email address and a securely hashed password. If you sign in with Google we receive your Google account ID, email address, name and profile picture from Google instead of a password.
Billing data. Subscriptions are processed by Stripe. Stripe collects and holds your card details directly: we never see or store card numbers. We store the Stripe customer and subscription identifiers, your plan, billing interval and subscription status.
Usage data. Pages viewed, features used, searches run and exports requested, together with your IP address, approximate location (country, region, city) derived from it, timezone, browser and device information. This includes product analytics events and, where you have permitted it, session replays and heatmaps.
Free tools data. When you use a tool at /free-tools/ we log the tool used and the values you submitted (for example a USDOT or MC number), along with your IP address, approximate location and browser information. If you unlock a higher daily limit we also store the email address you provide and a verification token.
MCP connector data. If you connect Market Tracker to an AI assistant such as Claude or ChatGPT, we store the OAuth client registration, hashed authorisation codes and hashed refresh tokens, and a log of each tool call: which tool ran, the parameters supplied, whether it succeeded, and how long it took. This log is what enforces free-tier daily limits. We never receive the rest of your conversation with the assistant, only the specific tool requests it sends us.
Documents you upload. Some tools and demos accept files such as insurance declarations pages or ACORD forms, and Market Tracker accepts CSV lists. We process these to extract the data you asked us to extract, and store the resulting files in our hosting provider's object storage.
Email activity. Delivery, open and click events for the emails we send you, and your unsubscribe status.
Motor carrier data from public records
Market Tracker is built on public records published by the U.S. Federal Motor Carrier Safety Administration (FMCSA) and other public sources. These records describe motor carrier businesses, and they can include the names, business telephone numbers, business email addresses and business addresses of company officers.
We did not collect this information from you, and we do not create it: we mirror, index and annotate what the relevant authority publishes. If you appear in these records and want to discuss removal from our index, contact privacy@alfabolt.com. Note that removing a record from our index does not remove it from the underlying government source, which you would need to approach separately.
Scores and estimates we derive from that data, including our ISS estimate and our insurance renewal (X-date) estimate, are our own calculations and are not official FMCSA figures.
Why we use it
- To provide the service: creating and securing your account, running lookups and searches, delivering the MCP connector, and sending transactional email such as verification and password resets.
- To take payment and manage subscriptions, trials and seats.
- To enforce fair use, including free-tier daily limits and rate limits, and to detect abuse or fraud.
- To improve the product: understanding which features get used and where people get stuck.
- To market the service, including product updates, lifecycle email and (where permitted) advertising audiences.
- To meet our legal and accounting obligations.
Where the law requires a legal basis, we rely on performance of our contract with you (to provide and bill for the service), our legitimate interests (to secure, improve and market the service), your consent (for analytics and advertising cookies where consent is required, and for marketing email where required), and compliance with legal obligations.
Who we share it with
We do not sell your personal data. We share it with the service providers below, who process it on our behalf under contract. Our infrastructure and most of these providers are located in the United States, so using the service involves transferring your data internationally.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Hosting, content delivery, file storage | Request logs, IP address, uploaded files |
| Neon | Managed PostgreSQL database (AWS, US East) | All application data |
| Stripe | Payments and subscription billing | Name, email, billing and card data (held by Stripe) |
| Twilio SendGrid | Transactional and product email | Name, email, email engagement |
| Optional Google sign-in | Google account ID, email, name, avatar | |
| OpenAI | Extracting data from documents you upload | Contents of documents you submit for extraction |
| Mixpanel | Product analytics | Usage events, user ID, email |
| Microsoft Clarity | Session replay and heatmaps | Interaction data, IP address |
| Google Analytics | Website analytics | Usage events, IP address |
| Meta, LinkedIn | Advertising and retargeting | Page views, advertising identifiers |
Documents you submit for extraction are sent to OpenAI's API. OpenAI does not use data submitted through its API to train its models by default. We may also disclose data where we are legally required to, or to protect our rights, and to a successor if the business is transferred.
Cookies and tracking
We use a small number of cookies that are strictly necessary to run the site, and analytics and advertising technologies that are not.
| Cookie | Purpose | Lifetime |
|---|---|---|
| nb_session | Keeps you signed in. Strictly necessary. | 30 days |
| nb_consent | Remembers your cookie choice. Strictly necessary. | 6 months |
| nb_ft_unlock | Tracks your free-tool daily allowance after you provide an email. | 12 months |
Microsoft Clarity, Google Analytics, Mixpanel, the Meta Pixel and the LinkedIn Insight Tag set their own cookies and identifiers. If you are in the European Economic Area, the United Kingdom or Switzerland, none of these load until you accept them, and you can change your choice at any time using the "Cookie preferences" link in the footer. Elsewhere they load by default and you can opt out using the same link, your browser settings, or the providers' own opt-out tools.
How long we keep it
We delete your account data within 30 days of you closing your account or asking us to delete it. Two exceptions: we keep invoices and transaction records for as long as tax and accounting law requires, and we keep aggregated or anonymised usage statistics that can no longer identify you.
Free-tool query logs and MCP tool-call logs are retained for up to 24 months so we can enforce limits and investigate abuse. Public motor carrier records are kept for as long as they remain part of the index.
How we protect it
Passwords are hashed with bcrypt and never stored in readable form. Authentication and MCP refresh tokens are stored only as hashes. All traffic is encrypted in transit with TLS, and data at rest is encrypted by our hosting and database providers. See our security page for more detail, including how to report a vulnerability.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to or restrict how we use it, receive a portable copy, and withdraw consent you previously gave. You can exercise any of these by emailing privacy@alfabolt.com. We will respond within 30 days.
You can unsubscribe from marketing email using the link in any such email, without affecting transactional messages about your account. If you are in the EEA or UK you may also complain to your local data protection authority; if you are in the UAE you may contact the UAE Data Office.
Children
Native Base is a business tool and is not intended for anyone under 18. We do not knowingly collect personal data from children.
Changes
If we make a material change to this policy we will update the date at the top and, for significant changes affecting account holders, notify you by email or in the product.