Loadout · Privacy

The short version

Loadout runs in the dispatcher's own browser. Driver names, emails, mobile numbers and photos stay on that computer. What this server keeps is who our customer is (the DSP owner's contact details and the company's), a credential for each computer, the DSP's Sling sign-in, encrypted, and, if backup is on, an already-pseudonymised copy of the dispatcher's own working notes. The week it passes along to be compared with Sling is pseudonymised too; the one exception is described under Reconciling with Sling. For the Driver portal, it also keeps each current driver's first name and last initial — "Juan P." — and nothing longer.

What this server stores

What this server never receives

The assistant

Questions are relayed to a language model to be answered. Because the context is pseudonymised before it leaves the browser, the model sees P07, not a person. Answers come back with the same identifiers and the extension puts the names back on screen, locally.

So it can follow a conversation from one question to the next, the assistant keeps a thread, held under an identifier derived from the licence — never from a person. That thread is the one thing tied to a DSP that lives outside the database described above, which also means that deleting the database does not remove it. It is removed separately, on the same request. We would rather write that here than leave it for someone to find.

Reconciling with Sling

To compare the Amazon week with the Sling schedule and propose fixes, the browser sends the week with every person already replaced by a one-way code. This server adds the DSP's Sling sign-in, for that request only, and passes both to Loadout's reconciliation engine, on a server we run. The engine reads the schedule through Sling's official API, replaces each Sling email with the same kind of code, and answers with what doesn't match. It stores none of it, and its log records failures only. It cannot write to Amazon: it never receives the identifiers a change in Amazon needs, so every change there is made by the dispatcher's browser after the dispatcher confirms it.

One exception, written here on purpose: so that someone who is in Sling but not on the Amazon roster shows up with a name, the engine answers with the names of the DSP's Sling users, their emails already replaced by the code. Those names cross this server on their way to the browser, and neither server keeps them.

The driver portal

Each DSP's drivers can open the driver portal on their own phone, at drivers.load.lat, and sign in with the email they use for Amazon. This server uses that email twice and keeps it neither time: to work out the same one-way hash the backup uses, so it can find that driver, and to send a six-digit code from Loadout's own email account. Someone whose email is not on any DSP's list gets the same answer and no email. Codes are stored only as a keyed hash, work once and expire after 10 minutes; a session lasts 30 days on a phone where the driver chose to stay signed in, 12 hours otherwise, and ends when the driver signs out or leaves the DSP's list.

Signed in, a driver sees their own record, worked out from the backup with the same rules the dispatcher's screen uses: their company score, their attendance week by week and overall, their Amazon scorecard week by week with where the points went, and any van incident that took points off. Nothing about the DSP itself is shown. Of other drivers they see only this week's top 10 — first name, last initial, rank, Amazon score, standing and packages delivered that week, which break ties — and never anyone else's attendance, metrics or incidents. It is read-only: nothing a driver does in the portal changes the DSP's records, and the portal never contacts Amazon.

Other services, and what leaves the browser for them

Amazon

Loadout reads and writes only inside the DSP's own authenticated session, with the DSP's consent, and every write is confirmed by the dispatcher first — nothing is sent to Amazon automatically. The extension does not attempt to disguise itself or evade detection of any kind.

The associate list. When it syncs, Loadout reads the DSP's own associate list from Amazon's DA Console, inside the same session: names, work emails, Transporter IDs, status, qualifications and licence expiry, to show the roster and the Employees list, and each driver's mobile number — the personal one, or the work one if there is no other — so that a dispatcher can text a write-up. The mobile numbers are taken out of the list before it leaves that page and kept apart, on that computer only: they are not backed up, never sent to this server, and used only when the dispatcher presses Send text. A number the dispatcher types in Loadout takes the place of Amazon's.

Live routes listens to the DSP's own Amazon operations page while the computer has an active licence: the extension keeps a copy of what that page already loads — route progress, the plan, shift times and each driver's last reported position, plus the stops of a route the dispatcher opens there — so it can show which routes are at risk. It makes no requests of its own, and it opens, navigates or clicks nothing on that page: routes and stops are opened by the dispatcher. Drivers' names, initials and phone numbers, customers' names, phone numbers and streets, door codes and delivery notes are dropped as the data arrives; a customer's address is reduced to a map point, and a package's ID to a code. That copy stays in the browser's session memory: it is not backed up, not sent to this server, and is cleared when the browser closes or the licence stops being active. Only the bare coordinates described under Mapbox ever leave it.

Rivian FleetOS

Loadout reads Rivian FleetOS while the computer has an active licence, with the access to rivian.com that Chrome grants when the extension is installed: once a minute it copies five columns of the vehicle list that the DSP's own FleetOS tab already shows — VIN, distance to empty, charging status, state of charge and mileage — to know each electric van's battery. It sends Rivian no requests, clicks nothing and reads no cookies. The latest reading of each van is kept on that computer, next to its fleet records; it is not backed up, and removing Loadout's access to rivian.com in Chrome stops it.

Dispatch: what runs on its own, and what doesn't

Since version 0.74.0 (October 5, 2026) Dispatch has no switches: it works the same way on every computer with an active licence. Nothing runs with the browser closed.

Keeping and deleting

Usage counts are kept for 12 months. The backup is kept while the licence is active.

On the dispatcher's computer, someone who leaves both Amazon's associate list and Sling stays in Employees, with the date they left, for the one, two, three or five years the DSP chooses (three by default); then they are forgotten on their own, mobile number included. The DSP can also forget someone sooner, from their profile.

A DSP can ask for everything tied to its licence to be deleted — the backup, the usage counts, the list of computers, the owner's account, the stored settings, the Sling sign-in, the driver portal list and its sessions, and the licence record itself — and it is removed. What remains is one line in our own admin record: that it was deleted, when, by whom at Loadout and for which company, without the owner's email or mobile. The procedure is written down, step by step, so that the request is answered the same day instead of improvised, and so that anyone can check it was done. The assistant's thread, described above, is removed in the same pass.

Contact

Questions about this policy, or a request to delete a DSP's data: dspagentus@gmail.com.

Loadout · Last updated 2026-10-05