Privacy Policy
Last updated: [EFFECTIVE DATE]
[Company Legal Name], a [State of formation] [entity type, e.g. LLC] doing business as DirectHaul ("DirectHaul," "we," "us"), operates this platform. This policy covers what we collect, why we collect it, and who can see it.
1. What we collect
- Account information: name, email, phone, password (stored as a salted scrypt hash — we never store or can recover your actual password).
- Carrier business information: legal name, USDOT and MC numbers, truck VINs and the vehicle details decoded from them, trailer type and capacity.
- Identity and compliance documents: driver's license or CDL, certificate of insurance, W-9, MC authority letter — whatever you upload for review. These are stored privately and are never shown to other users.
- Shipper business information: company name, city, state, and the loads you post (origin, destination, commodity, weight, rate).
- Location data: GPS coordinates, heading and speed, sent from a carrier's device while a truck is hauling a booked load. See section 3 — this is the most sensitive data we hold, and it's the most tightly scoped.
- FMCSA records: operating-authority status, safety rating, and related snapshot data we pull from FMCSA's public QCMobile API using your USDOT number.
2. Why we collect it
To run the marketplace: to decide whether a carrier is cleared to book freight, to match loads to equipment, to let a shipper track a load they've booked, and to let an admin review the documents that clear a carrier for booking. We don't use your data for advertising, and we don't build behavioral profiles beyond what's needed to run the product.
3. Location data — the part that matters most
A shipper can see a carrier's location only while that carrier has an accepted or in-transit booking with that shipper. Visibility is granted the moment a booking is accepted and revoked the moment the load is marked delivered or the booking is cancelled — automatically, not by request. There is no directory of carrier positions and no view that shows "all carriers" to anyone. Every time a shipper's view of a location succeeds or is denied, that read is logged with the viewer, the carrier, and the outcome, so there is a full audit trail of who looked at whose position and when.
Raw GPS history is kept for a limited time — [currently 30 days by default, configurable] — and then deleted. See the standalone location tracking notice for the plain-language version of this section, including where state law requires separate disclosure.
4. Who we share data with
- FMCSA: we query FMCSA's QCMobile API with a carrier's USDOT number to check operating authority. This is a lookup against a public regulatory database, not a disclosure of the carrier's private data to FMCSA.
- Identity/insurance verification vendor: if and when we contract with a licensed verification vendor, identity documents are sent to that vendor for a pass/fail decision. Until that contract exists, review is manual and internal — [name the vendor here once contracted, and confirm their DPA terms with counsel].
- The other party to a booking: a shipper and carrier see each other's company name and relevant load/location details needed to complete that specific booking.
- We do not sell personal information, and we do not share it with anyone else for their own marketing purposes.
5. Data retention
- Location pings: deleted after a limited retention window (see section 3).
- Session tokens: expire automatically and are purged once expired.
- Account, document, and booking records: kept for as long as the account is active and for [retention period — counsel to set based on statute-of-limitations and DOT recordkeeping requirements] after closure.
6. Security
We use administrative and technical safeguards designed to protect your information, including password hashing and access controls limiting who can view uploaded documents. [This section must be reconciled with the actual production setup before publishing — do not claim a specific security measure, such as encryption in transit, that isn't actually in place yet. Counsel and engineering should review together.]
7. Your choices and rights
You can review and update your account information in the app. You can ask us to delete your account and associated data, subject to what we're required to keep for compliance or legal reasons. [Depending on where your users are located, state privacy laws (e.g. California, Colorado, Virginia, and others) may grant additional rights — access, deletion, correction, opt-out of sale/sharing, and a non-discrimination guarantee. Counsel should confirm which apply and add the required disclosures and request mechanism.]
8. Children
This platform is for commercial carriers and shippers. It isn't directed at, and we don't knowingly collect information from, anyone under 18.
9. Changes to this policy
We'll post updates here with a new "last updated" date. [Counsel to confirm notice requirements for material changes, especially to the location-data section.]
10. Contact
[Company Legal Name]
[Notice address]
[Notice email]