Privacy policy

Fleet data belongs in the correct fleet workspace

This pre-launch policy describes the current HaulVault build and should receive legal review before broad commercial use.

Information HaulVault processes

HaulVault processes account identifiers and login email supplied by the authentication provider, company profiles, memberships and roles, fleet access requests, driver invitations, trips, document metadata and files, mileage, expenses, layover records, notifications and audit events.

Company separation and authorization

New fleet records carry a stable Company ID and, where applicable, Trip ID and Driver ID. Server-side authorization checks limit normal fleet access according to company membership, role and trip assignment. Drivers cannot use the fleet interface to retrieve another driver’s trips.

Platform administration boundary

The Super Admin interface manages fleet approval, complimentary access, plans, status and platform totals. It does not return customer BOL, POD, manifest, border document or complete Trip File content merely because the user is a platform administrator. Authorized company membership is separately required in normal application workflows.

Files, retention and history

Structured metadata is stored in the fleet database and uploaded files are stored in managed object storage. Deactivating a driver or allowing complimentary access to expire does not delete historical trip records. Audit history is retained to explain important record changes.

Exports and deletion

Authorized companies can export appropriate trip and mileage reports. Production retention, backup and deletion procedures require operational and legal review before broad commercial launch; HaulVault does not advertise a backup guarantee in this build.

Earlier encrypted private vault

The original private-vault tables and encrypted records remain preserved as a separate legacy area. Those records continue to use the earlier client-side encryption and recovery-key workflow.