Privacy policy
Draft for owner review — September 30, 2026. Confirm the legal operator, privacy contact, final service providers, retention periods, applicable rights, and international processing arrangements before making this a public policy.
Information processed
HaulBase processes account identifiers and email addresses; carrier, customer, driver and vehicle records; load and mileage details; invoices, expenses and settlements; uploaded documents; and audit events. Driver records can include license and medical-card expiration dates. Connected fleet services may provide vehicle location and mileage information. Only supply information your company is authorized to use.
Why information is used
Information supports sign-in, company access permissions, trucking operations, requested reports, billing, troubleshooting, security, and notifications your company enables. Workspace selection and essential session information help keep requests associated with the correct company.
Who receives information
Authorized members of your carrier can access information according to their permissions. Driver accounts receive a limited view of assigned work and their own settlements. Application operators may need access for support and security.
The current private preview uses ChatGPT Sites and its sign-in service. The application supports Clerk for a separately configured customer login. Cloudflare services support application and data storage. Stripe handles subscription checkout when enabled; HaulBase does not store full payment-card numbers. PC*Miler receives route and location inputs when calculations are requested. When traffic or weather radar overlays are enabled, Trimble Maps also receives the geographic map area requested through our server. Motive and Samsara supply vehicle positions after company authorization. Dispatch maps retrieve last-reported locations while open. Map backgrounds load from OpenStreetMap servers, which receive the map tile areas requested and ordinary browser connection information. Driver names and load details are rendered inside HaulBase, not sent to the map tile service. Resend and Twilio receive recipient details and message content when configured. Rate-confirmation text recognition runs in your browser; original documents are stored after you review and save.
Storage, security, and retention
Company membership checks, role restrictions, private document access, and request limits help protect records. Selected integration credentials are encrypted before database storage. No system can guarantee absolute security. Archiving a record does not delete it, and canceling a subscription does not immediately erase company records.
Before commercial launch, the operator must document retention and deletion schedules for records, files, audit logs, and backups, and test the recovery procedures. Service providers may process information in locations determined by their configuration and contracts.
Your choices and requests
Contact your carrier administrator to correct records, manage access, export available information, or request deletion. Administrators can disconnect integrations and manage notification settings. Identity verification may be required before fulfilling requests. The operator’s direct privacy contact and jurisdiction-specific rights must be supplied in the final policy.
Cookies and updates
Essential sign-in cookies maintain authenticated sessions. Browser storage may retain workspace preferences. This version does not add advertising trackers. Review this notice when services or data practices change; material changes should be communicated before they take effect.