HaulFinder Privacy Policy
Last updated: September 23, 2026
HaulFinder is a Chrome extension for truckload dispatchers, published by Panaiot Paraskevopulo ("we", "us"). It works on the DAT One load board (one.dat.com) inside the user's own signed-in session. This policy explains what the extension reads, what stays on your computer, what reaches our server, what happens when you connect a Gmail account, who else receives anything, and how to reach us.
Questions or requests: support@haulfinderapp.com.
Summary
- Your loads, notes and settings stay in your browser.
- Our server receives your work email (to sign you in and match you to your company's seat), a sign-in session, the start and end coordinates of loads whose route you open, and short error reports.
- If you connect Gmail, HaulFinder can only send email — never read it. Google's permission for that is stored on our server encrypted; the messages themselves go from your browser straight to Gmail.
- If you connect RTS Pro, your browser asks RTS Pro for the credit of the brokers you look at, with your own RTS Pro session, which stays in your browser's memory. None of it reaches our server.
- Your DAT One sign-in token stays in your browser's memory. It is never saved and never sent to us.
- We do not sell data, show ads, or run analytics or tracking code.
1. What stays in your browser
HaulFinder keeps the following in your browser's extension storage (chrome.storage and IndexedDB). It is not uploaded to us, and Chrome deletes it when you remove the extension.
- Notes you add to loads, the loads you have already seen and when you first saw them (so a re-posted load does not look new), and your saved searches.
- Your settings — columns, filters, highlights, truck costs, fuel price and MPG — and your email templates.
- Your HaulFinder sign-in: your work email, your company and seat identifiers, and a session token. Signing out (the Cabinet's Sign out, or Logout in Settings) removes it from the browser and ends the session on our server.
- The latest signed licence from our server, so a short network outage does not lock you out.
- If you connect Gmail: the list of connected addresses (address, display name, when connected — no tokens) and the history of emails sent from HaulFinder, by you or automatically (recipient, subject, time), which also stops the same load being emailed twice.
- A short log of the load board's recent HTTP status codes, used to slow down or stop when the site is rate-limiting, and a short queue (at most 50 entries) of error reports waiting to be sent to us (section 3).
- Cached road routes for loads you have opened, so an opened route draws again without a request.
2. The load board and your DAT One session
HaulFinder reads the loads shown on the load board — lanes, dates, rates, equipment and the broker's contact details — in your browser, to calculate figures such as rate per mile and estimated profit. This content is not sent to our server (the only exception is a load's start and end coordinates when you open its route, see section 3).
To show your own results, HaulFinder uses the authorization token your browser already sends to DAT One for your session, for the same kinds of requests the page makes for you: place suggestions while you type, the next page of results when you scroll to the end of the list, and a refresh when you ask for one or turn on automatic refresh (off by default, never more often than every 30 seconds, only while the tab is visible). It works at the pace of a person using the page, and it stops at once if the site reports a limit or asks you to sign in again. The token is kept in memory only: it is never written to disk, never logged, and never sent to us or anyone else. HaulFinder never asks for, sees or stores your DAT One password.
3. What reaches our server, and why
Our server is hosted by Railway (railway.com) at api.haulfinderapp.com. It receives:
- Your work email address — to send you a one-time sign-in code and to match you to the seat your company holds. We keep your email, your company and seat identifiers, and your company's plan and number of seats.
- Sign-in codes — six digits, valid for 10 minutes, and at most 5 attempts. We store only a cryptographic hash of the code, never the code itself. The code is delivered to your inbox by our email delivery provider (section 5).
- Your sign-in session — after you sign in, your browser holds a session token and we store only its hash, together with your email and when the session was created and last used. A session ends when you sign out, after 90 days without use, or when your company's administrator revokes it.
- Licence checks — while the extension runs, it presents its session to our server about every five minutes and receives a signed licence (valid for 15 minutes) that unlocks your plan's features.
- Route requests — when you open a load's route, the extension sends that load's start and end coordinates with your session. No load, rate, broker or other personal data is sent. Our server asks a road-routing service for the route (section 5) and keeps the result in a cache, shared by all users and keyed by the coordinates, for up to 14 days.
- Error reports — when something goes wrong that you do not need to act on (for example the load board refusing a request, or an error inside the extension), the extension notes an error code from a fixed list, the HTTP status code if there is one, whether you were in Advanced View or the standard view, the extension version, when it happened and how many times. The notes travel with the licence check above — no separate request — at most every 10 minutes. They never contain load content, your DAT One token, your HaulFinder session, email or web addresses: both the extension and our server accept only short codes from a fixed list. We store them with your company and seat identifiers, use them only to find and fix faults, and delete them after 14 days.
- Gmail, if you connect it — see section 4.
Like any web service, our hosting provider keeps standard technical logs of requests (for example the IP address and time). We do not use them to track you.
4. Sending email through your Gmail
Connecting a Gmail account is optional. When you press Connect Gmail in the HaulFinder Cabinet, Google asks you to grant HaulFinder one permission: to send email on your behalf (the scope gmail.send). HaulFinder cannot read, search, label or delete your mail, and it asks for nothing else in your Google account except your email address, so it knows which mailbox you connected.
- What we store. Google gives our server a refresh token for that permission. We store it encrypted (AES-256-GCM) on our server, together with the address, the permission Google granted and when you connected it. Our server uses it for one thing only: to issue a short-lived access token to your own signed-in extension when it sends an email, which keeps it in memory and never saves it.
- Where your messages go. You write each email and press Send yourself — unless you turn on automatic emails (below). Either way the message — its text and recipients — goes directly from your browser to Gmail; it does not pass through our server, and we do not keep a copy. Your browser keeps the sent history described in section 1.
- Disconnecting. Remove a mailbox with × in the HaulFinder Cabinet: our server deletes the stored token and revokes HaulFinder's access with Google in the same step. You can also remove access in your Google Account (Security → Third-party connections); when Google tells us the token no longer works, we delete it.
- Automatic emails (optional, off by default). HaulFinder sends nothing on its own until you turn automatic emails on in the HaulFinder Cabinet: you choose a default mailbox and a default template, then confirm. While they are on, each new load that appears in your load board search gets one email to its broker, built from your template and sent from your default mailbox — never twice to the same broker about the same load, never to brokers or states you exclude, and no more than your hourly limit (30 by default). You can turn them off at any time.
4a. Broker credit from your RTS Pro account (optional)
Connecting RTS Pro is optional and needs your own RTS Pro account. When you press Connect RTS in the HaulFinder Cabinet, Chrome asks you to allow HaulFinder to access rtspro.com (and to add a small script there); then you sign in to RTS Pro yourself, in your own tab.
- HaulFinder picks up your RTS Pro sign-in session from that tab and keeps it in memory only — it is never saved, never logged and never sent to us. HaulFinder never sees your RTS Pro password.
- To show a broker's credit, your browser sends RTS Pro that broker's MC or DOT number, with your session. The answer is shown to you and kept in memory; it is not sent to our server.
- Disconnect in the Cabinet removes the scripts, forgets the session and gives Chrome's access back; you can also remove the access in Chrome's extension settings.
Limited Use. HaulFinder's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. The use of information received from Google APIs will also adhere to the Chrome Web Store User Data Policy (https://developer.chrome.com/docs/webstore/program-policies/limited-use), including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not use it to train AI or machine-learning models, and no person at HaulFinder reads your email.
5. Service providers
| Provider | What it receives | Why |
|---|---|---|
| Railway | everything in section 3 and the encrypted Gmail token from section 4, as our host | runs our server |
| Resend | your work email and the sign-in code | delivers the sign-in email |
| Road-routing services we use | pairs of coordinates, sent by our server — never your identity or IP address | road routes and miles |
| Google (Gmail API and Google sign-in) — only if you connect Gmail | the permission you grant; the messages you send and their recipients, from your browser | sends your email |
| RTS Pro — only if you connect it | the MC or DOT numbers of the brokers you look up, from your browser, with your own RTS Pro session | the factoring company's credit answer |
| Cloudflare | standard request logs when you visit haulfinderapp.com, and email you send to our addresses | hosts our website and our domain, forwards our email to our mailbox |
| Stripe — only if your company pays by card online | billing details your company gives Stripe directly | payments — the extension never sees card data |
We do not sell or rent personal information, and we do not share it for advertising. Route geometry is computed from OpenStreetMap data (© OpenStreetMap contributors, https://www.openstreetmap.org/copyright).
6. Links you click
Some buttons open other websites in a new tab — Google Maps directions, the FMCSA SAFER carrier lookup, a factoring company's site (only if you turn that column on), or your phone app for a call. Those sites receive what your browser sends when you visit them; their own privacy policies apply.
7. Do Not Track
HaulFinder does not track you across websites, so it behaves the same whether or not your browser sends a Do Not Track signal.
8. Security
Sign-in codes and session tokens are stored only as hashes; Gmail refresh tokens are stored encrypted; all traffic to our server uses HTTPS; your DAT One token never leaves your browser's memory. No system is perfectly secure; if we learn of a breach affecting your information, we will notify you and your company as the law requires.
9. Retention and deletion
- In your browser: until you delete it, sign out (for the sign-in record and licence), or remove the extension.
- On our server: your seat record for as long as your company keeps your seat; sessions until you sign out, they expire, are revoked, or your seat is removed; route cache up to 14 days; error reports up to 14 days; Gmail tokens until you disconnect the mailbox or Google revokes them.
- Deletion on request: write to support@haulfinderapp.com or ask your company's administrator. We will delete the records tied to your email — including any stored Gmail token, which we also revoke with Google — and confirm by email.
10. Your choices and rights
You can sign out, disconnect a mailbox or RTS Pro, delete your notes, or remove the extension at any time. You can ask us what we hold about you, ask us to correct or delete it, or ask us to stop taking error reports from your seat, at support@haulfinderapp.com.
11. Business customers
HaulFinder is sold to companies. We process your dispatchers' seat data on your behalf to provide the service. A data processing addendum is available on request.
12. Children
HaulFinder is a business tool for freight dispatchers. It is not directed to children under 13, and we do not knowingly collect their information.
13. Changes to this policy
We will post any change here with a new "Last updated" date. For a material change, we will also email your company's administrator before it takes effect.
14. Contact
Panaiot Paraskevopulo · support@haulfinderapp.com