Privacy Policy
This Privacy Policy describes how HaulBook Inc. (“HaulBook,” “we,” “us,” or “our”), collects, uses, discloses, and protects information in connection with the HaulBook mobile applications — HaulBook, HaulBook Driver, and HaulBook Maintenance — and the HaulBook web TMS (together, the “App”), and the website at haulbookapp.com (the “Site,” and together with the App, the “Services”). By using the Services you agree to this Policy. If you do not agree, do not use the Services.
1. Who this applies to
The Services are intended for businesses and self-employed professionals in the trucking industry located in the United States. They are not directed to children, and we do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
2. Information we collect
Information you provide:
- Account & profile — name, email address, password (stored only in hashed form), and the business details you enter (company, MC/DOT numbers, trucks, drivers, fuel cards, insurance policies and agents).
- Content you add — loads, trips, expenses, mileage, and the documents you upload or share (rate confirmations, BOLs, PODs, fuel and IFTA statements, receipts, insurance certificates), plus the data our AI extracts from them.
- Driver qualification information — for the drivers a carrier employs: Social Security number, date of birth, home address, driver’s license / CDL number and expiry, medical examiner’s certificate, motor vehicle record (MVR), and the employment, accident, and drug-and-alcohol history collected on a driver application. This is sensitive information and it is covered in detail in Section 4.
- Communications — messages you send us (e.g., support requests), messages between a carrier’s office and its drivers inside the App, and information you submit through forms on the Site.
Information collected automatically:
- Precise location — the separate HaulBook Driver app collects continuous, high-accuracy GPS location from a driver’s phone, including while the app is closed. This is covered in detail in Section 3. The main HaulBook app, the Maintenance app, the web TMS, and the Site do not track your location.
- Usage & device data — app/site interactions, features used, approximate device and browser type, app version, crash and diagnostic data, and IP address (used for security and approximate location only).
- Cookies & similar technologies — see Section 11. On the Site, analytics cookies load only after you consent via the cookie banner.
Information from third parties: if you sign in with Apple or Google, we receive the basic profile information you authorize (such as name and email). Subscription and payment processing is handled by our payment processor, Stripe; we receive your subscription and billing status from Stripe but do not receive or store your full payment-card details. If you choose to connect your email mailbox, your bank, your ELD, or QuickBooks, we receive information from those accounts — see Section 5.
To be plain about two things: HaulBook does collect precise geolocation (from the Driver app), and it does collect sensitive personal information (driver Social Security numbers and related qualification records). Sections 3 and 4 explain exactly what we collect, why, and how long we keep it.
3. Precise location from the HaulBook Driver app
What we collect. HaulBook Driver is the app a carrier’s drivers install. Once a driver grants location permission, the app streams high-accuracy GPS readings — latitude, longitude, speed, and heading — to their carrier’s HaulBook account. If the driver grants “Always” permission, this keeps running with the app closed and the phone locked, which is what makes the truck visible to dispatch on a long run. Location sharing is not an optional extra inside the Driver app; it is what the app is for, and the permission prompt says so. A driver can turn location off in their phone’s settings at any time, which stops the sharing and stops automatic arrival and departure stamping.
What we use it for. Showing the carrier’s office where their trucks and loads are; calculating ETA to the next stop; automatically stamping arrival and departure at pickups and deliveries using a geofence around each stop — those stamps are what detention time is measured from; and the alerts and broker updates the office sends about a load.
What we do not use it for. We do not use driver location for advertising, and we do not sell it. It is not used to calculate IFTA or state mileage tax — those come from your ELD import or from the mileage you enter yourself.
How long we keep it. We keep only each driver’s most recent position — every new reading replaces the one before it. HaulBook does not build a location history or a breadcrumb trail you can scroll back through. What lasts is the arrival and departure times stamped on the load’s stops, not the coordinates. If a driver stops sharing, the last position stays as it was until it is overwritten or removed; it is deleted when the account is deleted (Section 13).
Who sees it. The carrier the driver works for. Drivers do not see each other’s location. Location may also be used by our AI features to answer a carrier’s question like “where is truck 12” or to draft an ETA update to a broker (Section 7).
4. Sensitive personal information (driver qualification files)
What we collect and why. A motor carrier is required by federal law (49 CFR Part 391) to keep a driver qualification file on every driver it employs. HaulBook is where many carriers keep that file, so we store, on the carrier’s behalf: Social Security number, date of birth, home address, driver’s license / CDL number and expiry, the medical examiner’s certificate and its expiry, motor vehicle records (MVRs), and the employment, accident, and drug-and-alcohol history a driver gives on an application. We collect it because the carrier is legally required to hold it — not to profile anyone.
How Social Security numbers are handled. A full SSN is never stored in plain text and never travels in the data sync to phones. We keep the last four digits for display, and the full number is encrypted with AES-256-GCM. It is decrypted only on the server, only when someone on the carrier’s own office team (owner, manager, dispatch, or safety role) explicitly asks to reveal it for a DQ file or a background check. Full SSNs are never sent to an AI provider.
Credential documents. CDLs, medical cards, MVRs, and signed agreements are stored as files in a private bucket and opened through short-lived signed links, the same as your other documents.
Who sees it. The carrier that employs the driver, and its office team. HaulBook staff access it only when necessary to support or secure the Services. We do not sell it, and we do not use it for advertising or to train AI models.
5. Connected accounts — your mailbox, bank, ELD and accounting
These connections are optional and each one is started by you. You can disconnect any of them at any time, which immediately deletes the stored credential.
Your email mailbox (Gmail or Microsoft Outlook). If you connect your mailbox, you approve the connection on Google’s or Microsoft’s own consent screen. With that permission HaulBook reads messages in your mailbox — recent inbox and sent mail, in a rolling recent window rather than your whole mail history — in order to: find rate confirmations and other load paperwork and file the attachments against the right load; read broker correspondence so it can pull out load, rate, appointment, detention, and status details; and draft replies for you to review. With send permission, HaulBook sends, from your address, the messages you approve (or that you have configured to send automatically). We keep the paperwork we file as documents, the details we extract onto the load, and short excerpts alongside the drafts and activity we produce for you; we do not copy your mailbox into HaulBook. Access and refresh tokens are encrypted before storage and deleted when you disconnect. You can block a sender so HaulBook stops reading their mail.
Your bank (Plaid). If you connect a bank account so HaulBook can match deposits to your invoices, you do so through Plaid. Your bank username and password go directly to Plaid and are never seen or stored by HaulBook. From the day you connect forward — never your history from before it — we store one row per transaction: its date, amount, tidied-up merchant name, whether it was money in or out, which account it came from (that account’s name, last four digits, and type), the category we guessed for it, any invoice we matched it to, and any note you add. That ledger is what the Money screen shows you and what you confirm or dismiss a match against, so it is kept while your account is active. The Plaid access token is encrypted. When you disconnect, the token is deleted and the linked item is also removed at Plaid.
Your ELD (Motive, Samsara, Geotab, TruckX). You supply your own ELD credentials. We use them to import hours-of-service status, vehicle positions, odometer readings, and IFTA miles by jurisdiction. Credentials are deleted the moment you disconnect. Credentials for connections made through the provider's own sign-in are stored encrypted; a provider API key you type in yourself is stored with your company settings and is available only to your office team.
QuickBooks Online. If you connect QuickBooks, we exchange invoice, payment, and expense records with your accounting file. Tokens are encrypted and deleted on disconnect.
6. How we use information
- To provide, operate, maintain, and secure the Services — including reading your documents and connected mail with AI, organizing loads/fuel/expenses, calculating estimates (profit, cost per mile, IFTA), tracking loads, and storing your files so you can access them across devices.
- To keep a carrier’s driver qualification records so the carrier can meet its DOT obligations.
- To authenticate you, process subscriptions, and provide customer support.
- To monitor, debug, prevent fraud and abuse, and improve and develop features.
- To communicate with you about the Services, including service-related notices and push notifications.
- To measure and improve our marketing (Site only, and only with your consent).
- To comply with law and enforce our Terms of Service and other agreements.
7. AI processing
AI is a core part of HaulBook: it reads your paperwork, watches your broker email, drafts replies, and answers questions about your business. To do that, your information is transmitted to and processed by a third-party AI provider acting on our behalf. Today that provider is OpenAI; we also use Anthropic (Claude) as an alternative provider. Which one runs a given request is a configuration choice on our side.
What is sent to the AI provider:
- Documents you upload or that arrive as email attachments — rate confirmations, BOLs, PODs, receipts, fuel and IFTA statements.
- The subject, body text, and attachments of messages in a connected mailbox that relate to your freight (Section 5).
- Load, rate, and broker details — broker and dispatcher names and email addresses, rates, lanes, stops, appointment times, detention, and invoice status.
- Driver-identifying operating data where the task needs it — driver names and phone numbers, truck and trailer numbers, hours-of-service status, and current truck position — so a draft can tell a broker who is on the load and when the truck will arrive.
- The questions you ask the in-app assistant, and the records from your own account needed to answer them.
What is not sent: driver Social Security numbers, your password, your bank credentials, and your payment-card details are never sent to an AI provider.
We send this under commercial API agreements that do not permit the provider to use your content to train their general models, and we instruct them to use it only to perform the processing we request. AI output is an estimate and may contain errors — you are responsible for reviewing it before relying on it, and messages HaulBook drafts are held for your approval unless you have turned on automatic sending.
8. How we share information
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under applicable law. We disclose information only as follows:
- Service providers / processors — the companies listed by name in Section 9, each only to the extent needed to perform services for us and under obligations to protect the data.
- Within your company — a carrier’s office team sees the records of the carrier, including its drivers’ qualification files, pay, and current location. A driver sees only their own loads, pay, and documents.
- At your direction — e.g., when you generate and send an email (such as a POD to a broker or a loss-run request to your agent), that content goes to the recipient you choose.
- Legal & safety — to comply with law, legal process, or governmental request; to enforce our Terms; or to protect the rights, property, or safety of HaulBook, our users, or the public.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
- With your consent — for any other purpose disclosed at the time.
9. Companies that process data for us
These are the third parties that handle your information so HaulBook can work. Several are used only if you turn on the feature that needs them.
- Render — hosts our application servers (United States).
- Supabase — our Postgres database and the private bucket that stores your uploaded files (United States).
- Stripe, Inc. — subscription billing and payment processing.
- Resend — delivery of transactional email we send you (verification codes and notices).
- OpenAI — our current AI provider (Section 7).
- Anthropic — our alternative AI provider (Section 7).
- Plaid — bank connections and deposit data, if you link a bank account.
- Google — Gmail, if you connect your mailbox; Google Maps Platform for address lookup and driving distance; Sign in with Google; and Google Analytics on the Site after you consent.
- Microsoft — Outlook / Microsoft 365 mail, if you connect that mailbox.
- Apple — App Store distribution and Sign in with Apple.
- Expo — delivery of push notifications to your phone.
- Intuit (QuickBooks Online) — accounting sync, if you connect it.
- Twilio — text messages to drivers, where we have that channel enabled.
- Motive, Samsara, Geotab, and TruckX — ELD data (hours of service, vehicle position, odometer, IFTA miles), only for the provider whose credentials you enter.
- FMCSA (U.S. Department of Transportation) — we look up DOT and MC numbers in the FMCSA’s public carrier database to verify authority and insurance. Only the DOT/MC number being checked is sent; no personal information goes with the query.
- National Weather Service (weather.gov) — public weather alerts for the coordinates along a route. No account or personal information is sent.
- Meta — the Meta Pixel for marketing measurement on the Site, if we have it switched on and only after you consent (Section 11). It is never used in the App.
We update this list as our vendors change; the “Last updated” date above tells you when it was last revised.
10. Your data is yours
The business records and documents you put into HaulBook belong to you. We act as a custodian to provide the Services. We do not sell them, and we do not share your business data with brokers, carriers, lenders, or advertisers.
11. Cookies, analytics & your choices
The Site uses privacy-friendly analytics (such as Google Analytics and the Meta Pixel) to understand traffic and measure marketing. These load only after you click “Accept” on our consent banner; if you decline, they are not loaded. You can also block or delete cookies in your browser. Because there is no industry consensus on “Do Not Track” signals, we do not currently respond to them, but our default is to load no analytics until you consent. The App uses limited diagnostic/usage data to operate and improve.
12. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy (portability) of your personal information, and to opt out of the “sale” or “sharing” of personal information or certain profiling. We do not sell or share personal information as those terms are defined under U.S. state privacy laws. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, limit the use of sensitive personal information, and to non-discrimination for exercising these rights. The sensitive personal information we collect (Section 4) is used only to provide the Services and to keep the driver qualification records a carrier is legally required to hold — not to infer characteristics about anyone. To exercise any right, email support@haulbookapp.com; we will verify your request (typically by confirming control of your account email) and respond within the time required by law. You may use an authorized agent where permitted.
If you are a driver, note that some of the records about you belong to the carrier that employs you — its DQ file, your pay history, and its load records are the carrier’s business records. We will refer requests about those to your carrier.
13. Getting your data out, and deleting your account
Retention. We retain personal information for as long as your account is active and as needed to provide the Services, then for a limited period as required to comply with legal, tax, accounting, dispute-resolution, and backup obligations, after which it is deleted or de-identified. Credentials for connected accounts (mailbox, bank, ELD, accounting) are kept only while that connection is active and are deleted the moment you disconnect it.
Export. You can download your records at any time, from the App or the web: HaulBook builds one zip containing spreadsheets of your loads (with their stops, charges and relay legs), drivers, trucks, expenses, fuel, invoices, settlements and the rest of your synced records, plus your company settings — your whole business, on demand, downloaded directly to your device. Documents you uploaded (rate confirmations, PODs, receipts) remain downloadable individually from their loads.
Deleting your account. You can delete your account in the App (More → Account → Delete account). When you confirm, and if you are the last remaining member of your company, HaulBook does the following, in this order:
- Disconnects your connected accounts first, so nothing keeps reading your data while the deletion runs — the Gmail and QuickBooks tokens are revoked with Google and Intuit, the linked bank item is removed at Plaid, and every stored credential is deleted from our database. If the credentials cannot be deleted, nothing is deleted and you are asked to try again.
- Cancels your subscription with Stripe. If the cancellation cannot be confirmed, the deletion is stopped and nothing is removed — we will not delete an account while a card could still be charged.
- Removes your uploaded files from our storage bucket — rate confirmations, BOLs, PODs, receipts, signed agreements, and driver qualification documents. Any file we could not remove is reported so it can be cleared by hand.
- Deletes your records — loads, stops, invoices, settlements, expenses, fuel, drivers, equipment, documents, messages, chat history, automations, push tokens, saved driver locations, and settings.
- We keep a log entry recording that the account was deleted, when, and from where. It is not linked to your deleted records and exists so we can answer a later question about the deletion itself.
Two honest caveats. First, if other people are still members of your company, deleting your login removes your login only — the company’s records, subscription, and connections stay with the remaining members. Second, if you are a driver deleting your personal HaulBook login, the carrier keeps its own driver record for you: its DQ file, your pay history, and its load records are the carrier’s business records, not your login’s. Your app access ends.
Backups held by our hosting provider roll over on a schedule, so deleted data leaves those backups as the window passes. Where law requires (for example, tax records), minimal records may be kept for the legally mandated period. To request deletion by email instead, write to support@haulbookapp.com; we honor requests without undue delay and in any case within 30 days.
14. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal information (including encryption in transit, access controls, and storage in private, access-restricted buckets). In addition, the most sensitive values we hold — driver Social Security numbers, and the access tokens for your connected mailbox, bank, and ELD — are encrypted with AES-256-GCM at the application layer before they reach the database, so the database alone does not expose them. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for maintaining your own copies of records important to your business.
15. Data location & international users
We operate in the United States and process and store information there. The Services are intended for U.S. users. If you access them from outside the U.S., you consent to processing in the U.S., which may have different data-protection laws than your jurisdiction.
16. Third-party services & links
Beyond the processors named in Section 9, the Services link to sites and services we do not control (for example, a broker’s portal, or a recipient you email). Their handling of your information is governed by their own privacy policies, which we do not control and are not responsible for.
17. Changes to this Policy
We may update this Policy from time to time. We will revise the “Last updated” date and, for material changes, provide additional notice where required. Your continued use of the Services after an update means you accept the revised Policy.
18. Contact
Questions or requests: support@haulbookapp.com · HaulBook Inc., Roseville, California, USA.