1. Introduction
This Privacy Policy describes how Moving & Storage ("we," "us," or "our") collects, uses, stores, and protects information when you use the Pegasus Move Manager mobile application (the "App"), distributed on the Apple App Store and Google Play and previously listed as "Moving & Storage Driver."
The App is a workforce tool for professional long-haul moving drivers. It lets a driver sign in to their company's Pegasus account, review the trips and shipments assigned to them, scan or attach shipment paperwork, and receive notifications when a trip is assigned. It is not a consumer application and is not offered to the general public.
By downloading, installing, or using the App, you agree to the collection and use of information in accordance with this Privacy Policy.
2. Your Employer's Role
The App is used under an account provisioned by your employer — the moving company that licenses the Pegasus platform (the "Company"). This matters for how your information is handled:
- The Company controls the account. It creates your user, assigns your role, links your user to a driver record, and can deactivate your access.
- The Company owns the operational data the App displays. Customer, shipper, consignee, and shipment information shown to you is the Company's business record. We process it on the Company's behalf and under its instructions.
- Requests about that data usually start with the Company. Where we act as a processor (or "service provider") rather than a controller, we will refer rights requests to the Company and support it in responding.
3. Information We Collect
3.1 Account and Authentication Information
To sign you in, the App collects your work email address and password, or routes you through your company's single sign-on (SSO) provider. Credentials are submitted directly to our identity provider (Amazon Cognito) over an encrypted connection; the App does not store your password. Sign-in also involves:
- Company (tenant) selection — where your email is associated with more than one company, the App asks which one you are signing in to.
- Session token — a signed, time-limited token returned after successful authentication, together with your name, email, role, and company identifier.
- Driver mapping — the internal driver identifier your company has linked to your user, which determines which trips you see.
3.2 Trip and Shipment Information Displayed to You
Once signed in, the App retrieves the trips and shipments assigned to you from your company's Pegasus account. This is business data belonging to your employer — it is shown to you by the App, not collected from you. It can include shipper and consignee names, origin and destination addresses (street, city, state), scheduled and actual pickup and delivery dates, shipment weight, order and trip numbers, trip status, assigned driver, booking and sales contacts, and dispatcher notes or comments.
The App does not change trip or shipment status. Trip and shipment information is read-only in the App. Updates to those records are made by dispatchers in the Pegasus web application, not from the driver's device.
3.3 Documents You Capture or Attach
The App lets you attach paperwork to a shipment — for example a bill of lading, proof of delivery, weight ticket, inventory sheet, invoice, receipt, or photo. You can produce that document in two ways:
- Scanning with the device camera, using the built-in document scanner. Scanned pages are combined into a single PDF.
- Selecting an existing file (a PDF or image) that you choose from your device through the system file picker.
Documents you attach are uploaded to our cloud storage and linked to the shipment so your dispatch office can see them. The document, its file name, type, size, and the time it was created are stored on our servers. Anything visible in a page you scan or upload — including customer names, addresses, signatures on a printed delivery receipt, and handwritten notes — is part of that document.
3.4 Push Notification Token
If you allow notifications, the App obtains a push token — an identifier issued by the operating system and the Expo push service that addresses notifications to your specific device installation. The token, together with your device platform (iOS or Android), is sent to our servers and stored against your account so we can notify you when a trip is assigned to you. It is not an advertising identifier and is not used for tracking. When you sign out, the App deactivates the token on our servers and clears it from the device.
3.5 Device Permissions the App Uses
| Permission | Why the App asks |
|---|---|
| Camera | To scan shipment paperwork with the document scanner. The camera is opened only when you start a scan. |
| Files / documents | To let you pick an existing PDF or image to attach. The App receives only the files you select through the system picker — it does not browse your device storage. |
| Notifications | To deliver trip-assignment notifications. Declining is supported; the rest of the App works normally. |
3.6 Information We Do Not Collect
- Location. The App does not request, access, or collect your device location — foreground or background. It contains no GPS or location-tracking feature and does not trace your route or position. Some earlier builds declared operating-system location permissions that were never used; they are being removed.
- Contacts, calendar, microphone, or health data. Never requested.
- Your photo library. The App does not browse or index your photos. It receives only files you explicitly choose in the system picker.
- Advertising identifiers or behavioral tracking. The App shows no advertising, contains no advertising SDK, and does not track you across apps or websites.
- Third-party analytics or crash-reporting. The App integrates no analytics, attribution, or crash-reporting service. Should that change, this policy will be updated first.
- Biometric data. Never collected.
4. How We Use Information
- Authenticating you and maintaining your signed-in session for your company's account.
- Showing you your work — the trips and shipments assigned to your driver record, and the documents attached to them.
- Attaching your paperwork to the correct shipment so dispatch, billing, and claims teams can use it.
- Notifying you when a trip is assigned, and routing the notification to the right screen when you tap it.
- Operating, securing, and supporting the platform — including troubleshooting a reported problem and meeting legal and record-keeping obligations.
We do not use your information to build advertising profiles, and we do not sell or rent it.
5. Storage and Retention
5.1 On Your Device
The App keeps a deliberately small footprint on the device, stored in the operating system's secure keystore (iOS Keychain / Android Keystore):
- Your session — token, name, email, role, and company — so you stay signed in.
- The push token last registered for your account, and the outcome of that registration.
Trip and shipment details are not written to device storage; they are held in memory for the current session and re-fetched from the server. Pages you scan are written to the App's temporary cache directory only long enough to be assembled into a PDF and uploaded, and are managed by the operating system thereafter.
5.2 On Our Servers
Documents you upload are stored in encrypted cloud object storage (Amazon S3) and are reachable only through short-lived, signed links issued to authorized users of your company's account. Your user record and registered device tokens are stored in our platform database, segregated by company.
Server-side data is retained for as long as your company maintains its Pegasus account and as long as its own record-retention and legal obligations require — shipment paperwork in particular is a business record your employer may be required to keep for years. When retention ends, or on a valid deletion request, data is deleted or de-identified.
5.3 Signing Out and Uninstalling
Uninstalling the App does not delete server-side data. Signing out clears your session from the device and deactivates that device's push token. Uninstalling removes what the App stored locally. Neither removes documents you have already uploaded, nor your user record — those live in your company's Pegasus account. To have them deleted, use the contacts in Section 10.
6. Diagnostic Logging
The App writes operational messages — sign-in and sign-out events, notification registration outcomes, and upload failures — to the local development console. In production builds this logging is disabled: the messages are not written to a file, not retained, and not transmitted anywhere. There is no remote logging or crash-reporting pipeline in the App.
7. Service Providers
We rely on the following providers to operate the App. Each processes only what its function requires, under contractual confidentiality and security obligations.
| Provider | Role | What it handles |
|---|---|---|
| Amazon Web Services | Hosting, identity, storage | Sign-in (Amazon Cognito), the Pegasus API, and encrypted document storage (S3). Data is hosted in the United States. |
| Expo | App framework, build, push relay | Builds and distributes the App (EAS), and relays push notifications to Apple and Google. See expo.dev/privacy. |
| Apple | Push delivery, distribution | Apple Push Notification service; App Store and TestFlight distribution. |
| Push delivery, distribution | Firebase Cloud Messaging for Android notifications; Google Play distribution. |
8. Sharing and Disclosure
We do not sell, rent, or trade personal information. We share it only:
- With your employer. The documents you upload, and the record of your activity in your company's account, are visible to authorized users of that company — dispatchers, billing, and administrators.
- With the service providers listed in Section 7, strictly to operate the App.
- When required by law — to comply with a subpoena, court order, or lawful request from a public authority, or to establish, exercise, or defend legal claims.
- In a business transfer. If we are involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We will give notice before your information becomes subject to a different privacy policy.
- With your consent, for any other purpose you explicitly agree to.
9. Security
- All communication between the App and our services uses HTTPS/TLS encryption.
- Session and push tokens are held in the operating system's hardware-backed secure keystore, not in general application storage.
- Your password is never stored by the App and never transits our own API.
- Uploaded documents are encrypted at rest and reachable only via short-lived signed links.
- Each company's data is segregated, and access is enforced by role on every request.
- Signing out revokes the session locally and deactivates the device's push token.
No system is perfectly secure. We implement measures appropriate to the sensitivity of the information, but cannot guarantee absolute security.
10. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of, or receive a portable copy of your personal information, and to withdraw consent you have given. You will not be discriminated against for exercising these rights.
Because your account and its data belong to your employer, the fastest route is usually your company's Pegasus administrator. You may also contact us directly using Section 12 and we will respond, or coordinate with your employer, within the period the applicable law requires.
Managing Permissions on Your Device
- iOS: Settings → Pegasus Move Manager → Camera / Notifications
- Android: Settings → Apps → Pegasus Move Manager → Permissions
Turning off the camera permission prevents document scanning; turning off notifications means you will not be alerted to new trip assignments. Everything else continues to work.
11. Additional Disclosures
California (CCPA/CPRA)
In the past twelve months the App has collected the following categories of personal information: identifiers (name, work email, company and driver identifiers, device push token) and the professional information described in Sections 3.1–3.4. It is collected for the business purposes in Section 4 and disclosed only as described in Sections 7 and 8.
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use sensitive personal information to infer characteristics. California residents may exercise the rights to know, delete, correct, and opt out; see Section 10.
Children's Privacy
The App is a workplace tool intended solely for employed or contracted commercial drivers and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a minor has provided information through the App, contact us and we will delete it.
International Users
The App and its supporting infrastructure are operated in the United States. If you use the App from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data-protection laws may differ from those in your country.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date above and, where the change is material, provide additional notice. The current version is always available at this address, which is also linked from within the App. Continued use of the App after an update constitutes acceptance of the revised policy.
13. Contact Us
If you have questions, concerns, or requests about this Privacy Policy or our data practices, contact us at:
Email: admin@dolas.devMailing Address:
Moving & Storage
5840 Kingston Avenue
Lisle, IL 60532
United States