01Who we are
Haulium LLC builds software for trucking companies. This policy covers Haulium TMS (transportation management), Hail (a browser extension for contacting freight brokers), Haulium Driver (a mobile app for drivers), and haulium.com.
Our customers are businesses. Most of the information we handle is business information about loads, brokers, and equipment, together with work-related information about the people who use the software.
02Our role
For most data, we act as a service provider to the trucking company that subscribes: they decide what goes in and why, and we process it on their instructions. If you are a driver or dispatcher using Haulium because your employer subscribes, direct questions about their practices to your employer; we will refer such requests to them.
We act as a controller for our own account, billing, support, and website data.
03What we collect
| Category | Examples |
|---|---|
| Account | Name, work email, company, role, password hash, and for paid plans billing contact and payment records (card data is handled by our payment processor, not stored by us). |
| Operational | Loads, lanes, rates, stops, equipment, documents, invoices, and related records you enter or that we ingest on your behalf. |
| Broker and carrier | Company names, MC and DOT numbers, business contact names, email addresses and phone numbers, and public regulatory data such as operating authority and surety bond status. |
| Outreach | The emails you send through Hail, the responses matched back to them, and the notes and status marks your team records about a broker. |
| Connected accounts | The address of a mailbox you connect, and an access credential we store to send on your behalf. See section 5. |
| Load board context | Load details visible on a load board page you have open, used to fill in a message and record which posting an email referred to. |
| Driver app | Device location while on duty, photos and documents captured, messages sent, device and push token, as described in section 13. |
| Technical | IP address, timestamps, browser or device type, and error and performance logs. |
04How we use it
- To provide the features you asked for — dispatching loads, sending an email you composed, matching a reply back to it, showing a broker's history with your company.
- To keep the Services secure, enforce limits, prevent abuse, and diagnose problems.
- To provide support you request.
- To bill you and keep business records.
- To meet legal obligations and respond to lawful requests.
- To improve the Services using aggregated or de-identified information that does not identify you, your company, or your counterparties.
We do not use Customer Data to build advertising profiles, and we do not sell it.
05Google user data
Hail can send broker emails from a Google account you connect. This section describes exactly what that involves.
What we request
One permission: https://www.googleapis.com/auth/gmail.send — the ability to send email as you. We also receive your email address and basic profile identifier through standard sign-in scopes, which we use only to confirm you connected the mailbox you intended to.
What we do with it
- We send the individual messages you compose and submit in the product, one at a time, at your direction.
- We store a copy of each message we send for you, so your team can see what was already sent to a broker.
- We store the refresh credential Google issues, encrypted, so you do not have to reconnect before every send.
What this permission does not allow
The gmail.send scope does not permit reading, searching, listing, modifying, or deleting anything in your mailbox — and we do not request any scope that would. We cannot see your inbox, your existing messages, your drafts, your labels, or your contacts. We have deliberately designed the product to avoid needing that access: broker replies reach us through a tracking reply address or through mail you choose to forward, never by reading your mailbox.
Limited Use disclosure
Haulium's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described here.
- We do not transfer Google user data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition in which we give notice.
- We do not use Google user data for advertising, and we do not sell it.
- We do not allow humans to read Google user data except with your explicit consent for a specific support request, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and de-identified.
Revoking access
You can disconnect a mailbox in Hail at any time, or revoke access directly at myaccount.google.com/permissions. On disconnection we delete the stored credential promptly. Records of messages already sent remain in your account history unless you delete them or close your account.
06Email we send for you
When you send a broker email through Hail, it is sent from your own mailbox and appears in your Sent folder as your own mail. We add a reply address we control so that responses can be matched back to the load and shown to your team; the broker's reply reaches both you and us. You can also forward rate confirmations to an intake address, in which case we parse the message and any attachment to identify the broker, lane, and rate, and attach it to the right record.
Correspondence handled this way is stored as part of your account's records and is available to the users in your organization who have access to that broker or load.
07What we never do
- We do not sell personal information or Customer Data.
- We do not read your mailbox, and we do not request permission that would let us.
- We do not use your data to train advertising models or share it with data brokers.
- We do not send email on your behalf that you did not compose and submit.
- We do not disclose your broker relationships, marks, notes, or sending history to another customer.
08Sharing
We share information only in these situations:
- Within your organization. Other authorized users of your account can see the records you create.
- Recipients you choose. A broker you email receives the message you wrote.
- Service providers who process data on our behalf under contract and only on our instructions — hosting and database infrastructure, email and document processing, error monitoring, mapping and geocoding, and payment processing. They are not permitted to use it for their own purposes.
- Integrations you enable, such as a telematics provider, factoring company, or load board — data flows only as needed for that integration, and their handling is governed by their own terms.
- Legal and safety — when required by law, subpoena, or court order, or where necessary to protect rights, safety, or the integrity of the Services.
- Business transfer — in a merger, acquisition, or sale of assets, with notice to affected customers.
09Separation between customers
Each customer's records are isolated at the database level and access is enforced per organization and per user. One customer cannot see another's loads, brokers, notes, marks, credit information, or sent mail.
The exception is publicly sourced regulatory information keyed to an MC or DOT number — such as whether a broker's operating authority is active and whether a surety bond is on file. That data comes from public federal sources, is not specific to any customer, and is shared across the product.
10Security
We encrypt data in transit and at rest. Mailbox credentials are held in a dedicated encrypted secret store, not in the application database, and are accessible only to the server-side function that sends mail. Access to production systems is limited to personnel who need it. Sending happens only through an authenticated server-side path that verifies the user's membership in the organization before acting.
No system is perfectly secure. If a breach affects your information, we will notify you as required by law and without undue delay. Report a vulnerability to security@haulium.com.
11Retention
We keep Customer Data while your account is active and for 30 days after termination so you can export it, then delete or de-identify it, subject to routine backups (purged on their own cycle) and to any longer period the law requires. Mailbox credentials are deleted promptly on disconnection. Billing records are kept as long as tax and accounting rules require. Security and audit logs are kept for a limited period.
12Your choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, or to object to or restrict certain processing. Because we usually act as a service provider, send requests to the company whose account you use; if you contact us directly we will route it to them and assist as required.
For information we control, write to privacy@haulium.com. We will verify your identity and respond within the period the law requires. We do not discriminate against you for exercising a privacy right.
We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under California law.
13Location and driver data
Haulium Driver may collect a device's location while a driver is on duty, to support dispatch, stop arrivals, and load tracking. Location is collected in connection with work and is visible to the driver's employer. Photos, documents, and messages sent through the app are records of the employing company and may be reviewed by it. Employers are responsible for notifying their drivers and obtaining any consent their jurisdiction requires.
Vehicle and trailer telematics data comes from the equipment providers a carrier uses and is governed by the carrier's agreement with those providers.
14Children
The Services are for business use by adults. They are not directed to anyone under 18, and we do not knowingly collect information from children. If we learn we have, we will delete it.
15Changes and contact
We may update this policy. For material changes we will give notice by email or in-product before they take effect, and update the date at the top. Continued use after that means you accept the update.
Questions, requests, or complaints:
Haulium LLC · 1095 Sugarview Dr, STE 1200, Sheridan, WY 82801
Privacy: privacy@haulium.com · Security: security@haulium.com