HaulinCars HaulinCars

Privacy Policy

Last updated · Version 2026-08-02

What HaulinCars collects, why, who else sees it, and how long we keep it. We do not sell personal information and we do not track anyone across other companies' apps or websites for advertising.

1. Who this covers

HaulinCars (“we”, “us”) provides a transportation management system for auto-transport carriers. This policy covers the HaulinCars web console, the HaulinCars driver mobile app, our public marketing pages, and the APIs behind them.

Two different relationships run through this product, and they matter for your rights:

  • Carriers — the trucking companies that sign up. A carrier is our customer. The carrier is responsible for its own business records and for what it tells its drivers and its customers.
  • Drivers, dispatchers, and shipping customers — people whose information enters the platform because a carrier put it there or because they use the driver app. For most of that information we act on the carrier's instructions. If you are a driver and want your information corrected or removed, start with your employer; you can also contact us directly at privacy@haulincars.com.

2. What we collect

Account and identity

  • Name, email address, phone number, and a hashed password (we never store your password in readable form).
  • Profile photo, if you upload one, and your time zone.
  • Your role on a company (owner, dispatcher, driver) and which company you belong to.
  • Two-factor authentication secrets and recovery codes, if you enable 2FA. These are encrypted at rest.
  • One-time verification codes we send by email or SMS when you sign up or sign in.

Company and regulatory information

When a carrier signs up we look up the USDOT or MC number they enter against the FMCSA's public carrier registry and store what it returns — legal name, operating authority status, and related public registration details — so we can confirm the company is a real, authorized motor carrier. We re-check that record periodically while the account is open. This is public government data, not information you give us.

Social sign-in

If you sign in with Google or Apple (the only two providers we support), we receive and store the provider name, the account identifier that provider assigns you, your name, your email address, and a link to your avatar image. We also store the access and refresh tokens the provider issues, encrypted at rest, so the connection keeps working. We do not receive your password from Google or Apple, and we do not use these tokens to read anything from your Google or Apple account beyond confirming who you are.

Load and business data

The operating record of the carrier's business: orders and loads, vehicle details including VINs, pickup and delivery addresses, shipper and customer contact names, phone numbers and email addresses, pricing and payment terms, notes, invoices, expenses, fuel purchases, and driver pay periods. Carriers enter this themselves, import it from a load board or dispatch sheet, or receive it through a connected integration.

Vehicle and driver location

This is the most sensitive category we handle, so it is described precisely in section 3 rather than summarized here.

Photos, documents, and signatures

  • Inspection photos — the condition photos a driver takes at pickup and delivery, including damage photos, and any documents attached to a load or vehicle.
  • Signatures — the e-signature captured at pickup or delivery, stored together with the signer's name, the phone number they give, any notes, the time of signing, and the device location at the moment of signing (both the driver's and the signing customer's). This is what makes a bill of lading defensible in a damage dispute.
  • Payment photos — photos of cash or checks a driver collects, used to verify the amount against what is later deposited.
  • Uploaded dispatch sheets and PDFs, which frequently contain customer names, addresses, and phone numbers.

Payment information

  • For the carrier's subscription to us: Stripe processes the card. We store the Stripe customer identifier, the card brand, the last four digits, and the trial/subscription status. We never receive, see, or store full card numbers, expiry dates, or security codes — card entry happens on Stripe's own hosted pages.
  • For payments a carrier collects from its own customers: the amount, the payment method as a label (cash, check, credit card, and so on), a reference or transaction number the carrier types in, who collected it, notes, and any payment photo. We do not store bank account numbers, routing numbers, tax identification numbers, or Social Security numbers anywhere in the platform.

Product analytics

We use Google Analytics 4 to understand how the product is used — which screens people reach, where flows are abandoned, which features are worth building on. When analytics is configured for a deployment, we send Google:

  • a pseudonymous client identifier (from a Google Analytics cookie on the web, or the Firebase app instance identifier in the mobile app);
  • your internal HaulinCars user ID (a random UUID — not your name or email) when you are signed in;
  • your role, your company's internal ID, your company's subscription plan state, the month your company signed up, and which feature flags are on for you;
  • the name of the action taken and a small set of parameters describing it.

What we deliberately do not send: names, email addresses, phone numbers, VINs, street addresses, license plates, or exact dollar amounts. Order values are sent as coarse ranges rather than precise figures. Event names and parameters come from a fixed allowlist in our source code, and an automated test fails our build if a parameter that looks like personal information is ever added. Google's own handling of this data is governed by Google's privacy policy.

Technical and device information

  • Server logs, which include IP address, request path, and timing — used for security, debugging, and abuse prevention.
  • Session and CSRF cookies required to keep you signed in; a Google Analytics cookie when analytics is enabled. We do not use advertising cookies or third-party ad pixels.
  • Push notification device tokens (Firebase Cloud Messaging) if you use the mobile app and allow notifications.
  • API access tokens issued to your devices, which are revoked when idle or when you sign out.

3. Driver and vehicle location — how it actually works

We want to be exact about this, because vague location disclosures are how products lose their drivers' trust.

Where location data comes from

  1. Connected ELD / telematics hardware (the main source). If a carrier connects a Motive (GoMotive) account, that hardware reports its vehicles' position, speed, heading, odometer, engine hours, and fuel level to us as the truck operates. This is truck telemetry from equipment the carrier owns and has connected, but because trucks are assigned to drivers it reveals where the assigned driver is. It reports on the hardware's own schedule — it is not limited to an active load, and we do not control its interval.
  2. Single location fixes from the driver's phone, at two specific moments. When a driver starts a vehicle inspection, the app records one location reading to confirm the driver is actually at the pickup or delivery site. When a signature is captured, the app records one location reading and stores it with that signature. Each is a single point in time tied to a specific action.
  3. Arrival and departure events. We record when a truck enters or leaves a pickup or delivery location, with the coordinates and time, so a load has a checkable timeline.

What we do not do: the driver app does not run continuous background GPS tracking of the phone, and the legacy endpoint that once accepted phone-sourced position pings is disabled and rejects all requests. Location is not collected from a driver's phone when the app is closed.

Who can see it

  • The driver's own carrier — owners, dispatchers, and other authorized staff of that company — can see live truck positions on the console map, the recent path of a truck, and arrival/departure history. One carrier can never see another carrier's data; every record is scoped to a single company.
  • HaulinCars staff, only as needed to operate, support, and debug the service.
  • We do not sell location data, share it with data brokers, or supply it to advertisers or insurers.

How long we keep it

Raw position readings from connected telematics hardware are automatically deleted after 180 days by default. A truck's most recent known position and the arrival/departure events attached to a completed load are retained as part of the load's record, because they are the carrier's proof of service.

4. Notice to drivers: location and electronic monitoring

If you drive for a carrier that uses HaulinCars, read this section.

Your employer or contracting carrier uses this platform to monitor the location and operation of its vehicles, and your activity in the driver app. Specifically, your employer can see:

  • the current and recent location, speed, and heading of the truck you are assigned to, as reported by the truck's telematics hardware while it is operating;
  • when you arrived at and departed from each pickup and delivery;
  • the location recorded at the moment you started an inspection and at the moment a signature was captured;
  • your hours-of-service clocks, if your carrier connects an ELD account;
  • the inspections, photos, notes, signatures, and payment collections you record in the app, with timestamps.

This monitoring exists so loads can be dispatched, customers can be told where their vehicle is, deliveries can be proven, and pay can be calculated correctly. It is not anonymous — it is linked to you as an identified driver.

Several states (including New York, New Jersey, and Connecticut) require employers to give employees notice of electronic and location monitoring. This section is that notice from the platform's side. Your employer remains responsible for providing whatever notice, acknowledgement, or consent the law of your state requires, and for setting its own policy on how location information is used in employment decisions. HaulinCars does not make employment decisions about you.

If you have questions about what your carrier does with this information, ask your carrier first. If you want to know what the platform itself holds about you, email privacy@haulincars.com.

5. Why we use this information

  • To run the service — dispatch loads, route drivers, capture inspections, generate bills of lading and invoices, calculate driver pay, and process subscription billing.
  • To verify identity and eligibility — confirm a signing carrier is FMCSA-authorized, verify email and phone at signup, and authenticate you at sign-in.
  • To prove what happened — condition photos, signatures, timestamps, and arrival records exist so damage claims and payment disputes can be settled with evidence.
  • To communicate — transactional email, SMS, and push notifications about your loads, your account, and your billing. We do not send marketing SMS.
  • To improve the product — aggregate and pseudonymous usage analytics, as described above.
  • To keep the platform safe — rate limiting, abuse detection, fraud prevention, and security logging.
  • To meet legal obligations — respond to lawful requests and retain records we are required to retain.

6. Automated processing and AI features

Some features use third-party AI models: extracting load details from an uploaded dispatch sheet or PDF, suggesting route order, and searching load boards. When you use one of these features, the relevant content — which can include customer names, addresses, and phone numbers printed on the document — is sent to our AI provider's business API for processing and the result is returned to you. We do not build or train any model on your data. These features assist a human; no decision with a legal or similarly significant effect on you is made solely by an automated system.

7. Who we share information with

We share information with service providers that make the product work, and with no one else except as described in this section. Which of these are active depends on what a given carrier has connected.

ProviderWhat it receivesWhy
StripeSubscription billing details and card data entered on Stripe's own pagesProcessing the carrier's subscription payments
Google AnalyticsPseudonymous usage events and the identifiers described in section 2Product analytics
Google & Apple sign-inAuthentication requests, if you use social sign-inSigning you in
Motive / GoMotiveAPI credentials the carrier supplies; returns vehicle telemetry, driver records, and hours-of-service clocksELD and fleet telematics, when a carrier connects it
Super DispatchSession credentials the carrier supplies, stored encrypted; returns the carrier's own load dataImporting loads the carrier already booked
FMCSA (QCMobile)The USDOT or MC number entered at signupVerifying carrier authority against the public registry
AI model providerDocuments and text submitted to AI features (section 6)Dispatch-sheet extraction, routing, load search
Email, SMS, and push providersRecipient address or phone number, device token, message contentsVerification codes and transactional notifications
Mapping and geocoding providersAddresses and coordinates being resolved or displayedMaps, address lookup, distance calculation
Cloud hosting and storageAll platform data at rest and in transitRunning the service

QuickBooks: our QuickBooks feature is an export you download as a CSV file. We are not connected to Intuit and we send nothing to QuickBooks — you decide what to import.

We may also disclose information when required by law, valid legal process, or to protect the rights, safety, and property of HaulinCars, our customers, or the public; and in connection with a merger, acquisition, or sale of assets, in which case this policy continues to apply to the transferred information until it is replaced with notice to you.

8. What we do not do

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • We do not track you across other companies' apps or websites. There are no advertising SDKs, ad pixels, or retargeting tags in this product.
  • We do not sell or license driver location data to data brokers, insurers, or anyone else.
  • We do not use your business data to train AI models.
  • We do not let one carrier see another carrier's loads, drivers, customers, or locations.

9. How long we keep information

  • Raw telematics position readings — deleted automatically after 180 days by default.
  • Loads, inspections, photos, signatures, invoices, and payment records — retained for as long as the carrier's account is active, because they are the carrier's operating and financial records, and afterwards for as long as needed for tax, accounting, and dispute-resolution purposes.
  • Account information — retained while the account is open; see section 10 for deletion.
  • Idle API access tokens — revoked automatically after a period of inactivity.
  • Server and security logs — retained on a rolling short-term basis.

10. Your choices, access, and deletion

  • Access and correction. Most of your information is visible and editable in the app. For anything else, email privacy@haulincars.com and we will respond within the time the applicable law allows.
  • Deleting your account. You can delete your HaulinCars user account from the driver app's settings, or by emailing us. Deleting your account removes your user record, your sign-in sessions, and your device tokens. Records your carrier owns — completed loads, inspections, signed documents, invoices — remain with the carrier, because they are the carrier's business and legal records, not yours to delete. If you want a carrier's whole account and its data removed, the carrier's owner should contact us.
  • Analytics. You can block Google Analytics with a browser setting, extension, or the Google Analytics opt-out add-on. The product works normally with analytics blocked.
  • Notifications. Turn push notifications off in your device settings. Transactional messages about your loads and account are part of the service and cannot be turned off entirely.
  • Location. Location permission for the driver app is controlled in your device settings. Denying it does not stop the truck's own connected telematics hardware from reporting, and it may prevent inspections from verifying you are on site.
  • State privacy rights. Residents of states with comprehensive privacy laws may have rights to know, correct, delete, and appeal, and a right not to be discriminated against for exercising them. Since we do not sell personal information or use it for targeted advertising, there is nothing to opt out of on those fronts. Submit a request to privacy@haulincars.com; we verify requests against the account they concern before acting.

11. Security

Traffic is encrypted in transit. Passwords are hashed and never stored in readable form. Integration credentials, OAuth tokens, and two-factor secrets are encrypted at rest. Every record in the database is scoped to a single company and the platform fails closed if that scope is missing. Two-factor authentication is available for console accounts, and API tokens expire when idle. No system is perfectly secure, and we do not claim otherwise; if a breach affects you, we will notify you as the law requires.

12. Children

HaulinCars is a business tool for commercial motor carriers. It is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a minor has given us information, contact us and we will delete it.

13. Where we operate

HaulinCars is operated from and for the United States, and information is processed in the United States. We do not currently market the service in the European Economic Area or the United Kingdom.

14. Changes to this policy

When we change this policy we update the version and “Last updated” date at the top of this page. For material changes we will give notice in the product before the change takes effect. Continued use after that date means the updated policy applies.

15. Contact

Privacy questions, access requests, and deletion requests: privacy@haulincars.com.

HaulinCars
447 W Watkins St #5, Phoenix, AZ 85003, United States