How Tow Defender handles your data
Last updated: July 6, 2026
Tow Defender helps heavy-recovery tow operators assemble an insurer-ready defense packet for a disputed invoice. To do that we handle two kinds of information: the details you share when you join our founding list, and the case evidence you upload once you start a packet. This page explains what we collect, who processes it, how long we keep it, and the choices you have. We keep it plain on purpose.
What we collect
- Founding-list details. When you use the deposit form, we store your work email, and — only if you provide them — your business name and roughly how many invoice disputes you handle a month.
- Site analytics. First-party page-view and form-open events, tied to a random per-visit id. We store a salted hash of your IP address for rate-limiting and rough counts — never the raw IP. No third-party advertising or tracking pixels.
- Account details. Your work email is your sign-in identity; we also store the business name and contact you give during intake.
- Case evidence you upload. Scene photos, your invoice, the carrier's short-pay letter, authorization records, police/incident reports, storage notices, and the facts you type in — wreck details, carriers, claim numbers, adjuster contacts, and amounts. Photos may carry embedded time and location (EXIF) data, which we read to build the photo log.
How we use it
We use your information to build and deliver your defense packet, to keep you signed in, and to email you about your case (sign-in links, status updates, and your founding-list welcome). We do not sell your data, and we do not use it for third-party advertising.
Who processes it
We keep our vendor list short. Each of these handles part of the service on our behalf:
- Railway — application hosting and our PostgreSQL database.
- Cloudflare — R2 private object storage for your evidence and generated packet files, plus content delivery for the website.
- Stripe — payments (the $49 refundable founding deposit and the $249 packet charge). Stripe handles your card details directly; we never receive your full card number.
- Resend — transactional email (sign-in links, confirmations, status notices).
- Anthropic (Claude) — AI processing, described next.
AI processing disclosure
How it is stored and secured
Evidence and packet files live in a private storage bucket, reached only through short-lived server-signed links — there is no public URL to your files. Data is encrypted in transit, database access is limited, and internal secrets never appear in our code or logs.
How long we keep it
- Case files (evidence and generated packets). Kept while your case is active. After a case is closed, its files are deleted from storage 90 days later. The case's summary records may remain in our database for our own reconciliation and history.
- Payment records. Retained by Stripe under its own policy; our records note the charge, the refund, and the deposit credit applied.
- Founding-list details. Kept until you ask us to remove you.
Your choices
- Ask for a copy of the information we hold about you, or ask us to correct it.
- Ask us to delete your case files or remove you from the founding list.
- Your $49 deposit is refundable the same day you ask — just email us.
Cookies
We use a single, strictly-necessary sign-in cookie to keep you logged into the portal. It is HttpOnly and, in production, secure. We do not use third-party advertising or cross-site tracking cookies. If we ever run an ad test that adds a tracking pixel, we will update this page first.
Changes and contact
If our data practices change, we update this page and its date. Questions, access requests, or deletion requests: email [email protected] and a real person will handle it.