Privacy Policy
Last Updated: October 4, 2026
1. Information We Collect
We collect information in the following categories:
- Account Information — name, email, phone, company details, DOT/MC numbers
- Transaction Data — load details, offers, payments, shipping history
- Location Data — GPS coordinates for tracking shipments and matching carriers
- Usage Data — pages visited, features used, session duration, device information
- Communications — in-app messages, support tickets, feedback
- Identity and compliance documents — if you verify your identity or upload carrier paperwork: photographs of a government-issued ID (driver’s licence or passport, front and back), the short sequence of selfie frames captured during the liveness check, and documents such as certificates of insurance, W-9s, medical cards and vehicle registrations
2. How We Use Your Information
- Provide, maintain, and improve our freight platform
- Match shippers with verified carriers
- Process transactions and payments securely
- Send notifications about loads, offers, and shipment status
- Verify carrier credentials (FMCSA, insurance)
- Prevent fraud and enforce our Terms of Service
- Generate analytics and market insights
- Communicate platform updates and promotional offers
3. Information Sharing
We may share your information in the following situations:
- Between shippers and carriers involved in the same transaction
- With payment processors (Stripe) to complete transactions
- With FMCSA and insurance verification services
- When required by law or legal process
- With your consent for other purposes
- With advertising and measurement providers — see section 7
- With the services that actually deliver our messages: Resend sends every email (it receives your address, the subject and the body — a verification code, an offer, a delivery confirmation), and Twilio sends every SMS (it receives your phone number and the message text). Both report back whether a message bounced or was rejected, and we record that so we stop writing to an address or number that does not work.
- With mapping providers, to turn an address into a point on a map: the pickup and delivery locations you type, and a carrier’s truck coordinates while a shipment is moving, are looked up against OpenStreetMap’s Nominatim service. Those lookups are made by our server, not your browser, so your IP address is not part of them. Route calculation runs on our own infrastructure.
- With Anthropic, whose Claude model performs the first automated review of identity and compliance documents. The ID photographs, the liveness selfie frames and the document images described in section 1 are sent to Anthropic’s API for that review, which includes judging whether the ID photo and the selfie frames show the same person. When that review is confident, the check is approved automatically after five minutes unless an administrator overrides it; otherwise an administrator decides. The head-movement tracking during the liveness check runs in your own browser.
We do not sell your personal data to third parties.
4. Data Security
We implement industry-standard security measures including TLS encryption, PCI-DSS compliance for payments, regular security audits, and strict access controls to protect your information.
5. Data Retention
We retain your data for as long as your account is active. Transaction records are kept for 7 years for legal and accounting purposes.
ID photographs and liveness selfie frames are stored encrypted alongside your verification record and are deleted automatically 365 days after your verification is decided — a daily routine removes the images while keeping the decision itself for the audit trail. If you start a check and never submit it, its images are deleted 90 days after you started. You do not have to wait for that: email privacy@gethauldirect.com and we will delete them sooner.
Broker Record Retention
As an FMCSA-authorized property broker (MC-123033), we retain records of every brokered transaction for at least three (3) years per 49 CFR § 371.3, including shipper and carrier identification, shipment dates, compensation amounts, and any volume discounts. These records are available to either party to the transaction upon written request to broker-records@gethauldirect.com.
6. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate information
- Delete your account and data
- Export your data in a portable format
- Opt out of marketing communications
- Restrict processing of your data
Contact privacy@gethauldirect.com to exercise these rights.
7. Cookies and Tracking
We use an essential cookie for authentication and session management, and browser session storage to remember which campaign brought you here.
We also load two third-party advertising tags on every page of this site, including pages you can view without an account:
- Google Ads (gtag.js, tag AW-18133202272) — measures which ads lead to sign-ups. Sets Google advertising cookies (e.g.
_gcl_au) and sends Google your IP address, page URL, and referrer. - Meta Pixel (ID 1307475041481709) — the same for Facebook and Instagram ads. Sets Meta cookies (e.g.
_fbp) and sends Meta your IP address and page URL, plus thefbclidvalue if you arrived from a Meta ad.
Both tags load automatically. We do not currently show a cookie-consent banner and we have no in-product opt-out switch — if we add one this section will say so. To stop this collection today, block third-party tags in your browser or an extension, and adjust your ad settings directly with Google and Meta. We do not run Google Analytics or any other analytics product; the usage data in section 1 is recorded by our own servers.
Separately from any tag: when a page shows a map, your browser fetches the map images directly from Esri (server.arcgisonline.com), which therefore sees your IP address and which area of the map you are looking at. The dark basemap used elsewhere is proxied through our own server, so that one does not expose your address.
Blocking the tags does not stop everything. When you complete registration our server sends Meta a Lead event directly (Meta Conversions API, pixel 1292588732890467) containing a SHA-256 hash of your email address, your IP address, your browser user-agent, whether you signed up as a shipper or a carrier, the landing page you arrived on, and the click identifier if you came from a Meta ad. It fires once, as the account is created, so there is nothing to switch off in advance and a browser blocker cannot prevent it. Write to privacy@gethauldirect.comand we will delete our copy of the attribution data; deletion on Meta’s side is requested through your Meta account settings.
8. California Privacy Rights (CCPA)
California residents have additional rights under the CCPA/CPRA, including the right to know what data we collect and the right to request deletion.
We do not sell personal information for money. However, the advertising tags described in section 7 disclose identifiers and browsing activity to Google and Meta for advertising measurement, and California law treats that as “sharing” for cross-context behavioral advertising. We would rather say so plainly than hide behind “we don’t sell data.” To opt out, email privacy@gethauldirect.com and we will delete the records we hold about you; to stop the tags themselves, use the browser and ad-platform controls in section 7. We do not currently detect the Global Privacy Control signal.
9. Children's Privacy
Our services are intended for users 18 years and older. We do not knowingly collect information from minors.
10. Changes to This Policy
We may update this policy periodically. Material changes will be communicated via email or platform notification.
11. Contact Us
For privacy-related inquiries: privacy@gethauldirect.com