Your Data
This page explains in plain language how Haul Monitor handles customer data — what we collect, what we intentionally do not store, and how we protect what we do hold. It's a summary of our internal security policy, written for customers.
What we store
Haul Monitor stores only the data that you create or provide directly:
- Your account — email address and authentication credentials
- Fleet profiles — equipment type, home base location, driver records, and rate configuration
- Open requests — your saved search parameters for ongoing backhaul monitoring
- Completed haul records — loads you've confirmed through the "Haul This Load" workflow, including revenue outcomes
- AI preference signals — anonymized feedback on load recommendations used to improve your matching results over time
- Billing records — credit bundle purchases (payment card data is handled entirely by Stripe — we never see or store it)
What we do not store
Haul Monitor is a real-time intelligence layer, not a data aggregator.
Load board data from DAT, Truckstop, and similar sources is queried live through authorized API partnerships when you run a search. It exists only in memory for the duration of your session — roughly 15 to 30 minutes — and is never written to our database.
This means:
- No load listings are persisted. The loads you see in search results live on the load board's platform, not ours. We're providing the matching intelligence applied to that data.
- No route geometry is permanently stored. Driving directions from our routing provider (PC*MILER) are returned to your browser in real-time. We maintain a shared distance cache — origin/destination city pairs only, no personal information — to reduce redundant API calls.
Why? Load data lives authoritatively on load board platforms. Copying it doesn't make the matching better — it just increases our data footprint and your risk exposure. We keep only what's ours to keep.
How we protect your data
- Encryption in transit: All data between your browser and Haul Monitor is encrypted via TLS 1.2 or higher
- Encryption at rest: All data stored in our database is encrypted at rest (AES-256) by our database provider, Supabase
- Tenant isolation: Row-Level Security on every database table ensures your data is accessible only to your authenticated account — not to other customers
- Credential management: API keys and service credentials are stored as server-side environment variables and are never exposed to the browser or included in client-side code
- Administrative access: All production system access is restricted to a single named administrator, protected by strong passwords and multi-factor authentication
Third-party service providers
We share your data only with the vendors necessary to deliver the service:
| Provider | Purpose | What is shared |
|---|---|---|
| Supabase | Database and authentication | All application data (fleet profiles, requests, completed hauls) |
| Vercel | Application hosting and serverless compute | API request data in transit; server logs |
| Trimble (PC*MILER) | Driving distance calculations for load matching | Origin and destination city/state pairs only — no account or fleet identifiers |
| Stripe | Payment processing | Name and email for billing; payment card data never touches our servers |
| Anthropic (Claude) | AI-powered load analysis and Co-driver assistant | Load and fleet context for the current session; Anthropic does not train on customer inputs |
Supabase and Vercel are SOC 2 Type 2 certified. Stripe is SOC 2 Type 2 certified and PCI DSS Level 1 compliant.
We do not sell your data. We do not share it with advertisers or use it for behavioral profiling.
Service availability
Haul Monitor is monitored continuously. You can check current service status and incident history at our public status page: haul-monitor.betteruptime.com.
In the event of a security incident that affects your personal data, we will notify you within 72 hours of confirming the breach.
Your rights
- Access: You can request a copy of the data we hold about you
- Correction: You can update your fleet profile, driver records, and account details directly within the application
- Deletion: You can request full deletion of your account and all associated data
- Portability: You can request an export of your data in a machine-readable format
To exercise any of these rights, email support@haulmonitor.cloud. We'll respond within 5 business days.
Questions
For any questions about how your data is handled, contact us at support@haulmonitor.cloud.
The full Privacy Policy is available at haulmonitor.cloud/privacy.