Terms of Service
These terms govern your use of Haul IQ, operated by NovaTrans LLC ("we", "us"). By creating an account, signing in, or using the service, you agree to these terms.
How you agree, and what you are agreeing to
When you create an account you tick a box that says you agree to these Terms of Service and the Privacy Policy. That tick, together with the account it creates, is your agreement. The Data Processing Addendum (the DPA tab) is part of these terms and applies to the data your company puts in Haul IQ; no separate signature is needed. We keep a record of the agreement with your account: the date and time, the version of these documents you saw, and the address it came from. A customer who needs a countersigned copy of the DPA for its own records can ask, and we will sign one.
If we change these terms in a way that matters, we will say so on this page with a new "Last updated" date and tell account owners by email before the change takes effect.
1. The service
Haul IQ is an operations system for trucking companies: dispatch, documents, invoicing, settlements, compliance, a driver app and a customer portal, with AI assistants that read paperwork, draft work and make recommendations. Your data lives in a multi-tenant database hosted on Cloudflare; the Privacy Policy and the DPA say exactly where and with whom.
2. Your account
You are responsible for keeping your login credentials and API keys secret, and for what people you invite do inside your company's account. AI assistants act within the autonomy tier you set; a company-wide stop switch turns all AI off at any time. Choosing not to use those controls does not transfer responsibility for your operation to us.
3. Pricing
- Pilot — free for the first 30 days, then $199/mo for 1 truck.
- Carrier — $149/truck/month, billed monthly.
- Enterprise — custom pricing for fleets above 100 trucks. Talk to us.
We don't charge per-seat. We don't charge for storage. AI usage is included in your plan; each plan carries a daily AI-spend ceiling, set well above normal use, that stops runaway work rather than billing you for it.
4. Acceptable use
Don't use Haul IQ to do anything illegal, defraud anyone, or violate the laws that apply to your operation (FMCSA, DOT, IRS, OFAC and the rest). The service refuses certain categories of automated action by design; don't try to work around those refusals.
5. Cancellation and termination
You can cancel at any time by writing to us at the address at the bottom of this page; we confirm within one business day, and your access continues to the end of the period you have paid for. We can suspend your account if you violate these terms, fail to pay, or do anything that puts the platform or other customers at risk; we will tell you why. After cancellation we keep your data for 30 days so you can export it (see the Privacy Policy for how), and we delete it after that, except for records the law requires someone to keep for longer.
6. Disclaimer
Haul IQ provides tools and recommendations, but you are still the carrier of record. We are not your dispatcher of record, your safety officer, your compliance lawyer, or your tax preparer. Nothing an AI assistant proposes is carried out without a person in your company approving it, and the responsibility for that approval is yours.
The service is provided "as is." We work to keep it up; outages at our hosting provider, at data publishers and bugs happen, and we do not promise a specific uptime percentage.
7. Limitation of liability
To the maximum extent allowed by law, our total liability for any claim is limited to the amount you paid us in the 12 months before the claim arose. We're not liable for indirect, incidental, or consequential damages.
8. Governing law
These terms are governed by the laws of Florida, USA. Disputes go to arbitration before they go to court.
9. Operator information
Haul IQ is operated by NovaTrans LLC, a Florida limited-liability company. References in this document and across the product to "we", "us", "Haul IQ" or "the service" all refer to NovaTrans LLC unless otherwise noted. For service of process, billing questions, data requests, or any legal matter, write to lamborghinidaniil@gmail.com.
Privacy Policy
This describes what we collect, why, who receives it, where it lives, how long we keep it, and your rights over it. It is written to match what the software actually does; where something is not built yet, it says so.
Two roles we play
For the data you give us to open and run your account (your name, email, company, billing, sign-in records) we are the data controller: this policy governs it. For the data your company puts into Haul IQ to run its operation (loads, customers, drivers, documents, invoices, payroll) your company is the controller and we are the data processor, acting on your instructions under the Data Processing Addendum. If you are a driver or a customer's contact reading this, the company that gave you access decides how that data is used; we help them honor your requests.
What we collect
Account data
- Email, first name, last name, company name, and if you give them your MC and USDOT numbers
- Your password, stored only as a salted hash — we never see or store the plaintext
- IP address and browser identification at sign-up and at each sign-in, for security and to stop brute-force attempts
- The record of your agreement to the Terms: the date, the version you saw and the address it came from
Your company's operational data
- What you enter or upload: loads, customers, carriers, drivers and their qualification documents, trucks, documents (rate confirmations, bills of lading, proofs of delivery, receipts), invoices, settlements, and payroll details including Social Security numbers when you use payroll
- What your people do inside the account: who created, approved, voided or paid what, kept as an audit trail
- What the AI assistants read and produced for you, kept so you can see why a document was filed or a suggestion made
Services you connect
Only when you connect them, and only what that connection needs: mail from a connected mailbox, files from a connected drive, positions from a connected ELD, transactions from a connected bank feed, messages through a connected phone number. The list of these services is in "Who receives it" below; disconnecting stops the flow.
Driver app data
Location and paperwork the driver app collects are described in their own sections below ("Driver location", "Driver evidence record"); nothing there is collected before the driver has seen and accepted what is being asked.
Public-world data
Diesel prices, weather alerts, economic releases, regulatory filings and similar public feeds are ingested once under a shared record (tenant_id='_global') and shown to every customer; none of it is about you.
How we use it
- To run the service for you: dispatch, documents, invoicing, settlements, the driver app and the customer portal
- To keep accounts safe: sign-in checks, rate limits, audit trails
- To bill you and to send you the emails the service needs to send (verification, password reset, notifications you turn on)
- To let AI assistants read your paperwork and draft work for a person in your company to approve
We do not sell your data, we do not use it for advertising, and there are no analytics trackers or advertising pixels on any page of the service.
Who receives it
Sub-processors we use for every customer
- Cloudflare, Inc. — hosting, database and file storage, and the fallback AI models that run inside Cloudflare's network when Anthropic is unavailable
- Anthropic, PBC — AI reading and drafting. The prompt (which can include your operational data and document contents) goes to Anthropic's API under its commercial terms, which do not permit Anthropic to train its models on it. Anthropic's privacy policy applies to their handling.
- Resend, Inc. — the email the service sends (verification, password reset, notices, invoices you send by email)
- Stripe, Inc. — payment processing for paid plans, and the banking features where you enable them. We never see or store your card number.
Services you connect yourself
These receive data only when you connect them, and only for what you connected them to do. Each has its own privacy policy.
- Google (sign-in, Gmail, Google Drive), Microsoft (Outlook, OneDrive), Dropbox and Box — mail and file intake
- Samsara, Motive and OnTime Logs — ELD positions and hours of service, read from your account with them
- Twilio, OpenPhone and RingCentral — text messages and calls you send from the service
- Plaid — bank feeds, if you link a bank account
- Truckstop — load board, if you connect your account
- Slack — notifications to your own workspace, if you connect it
Not enabled
The software can also be configured to use other AI providers and an alternate email provider. None of them is enabled on the live service. If that changes, we will add them to this list and tell account owners before any of your data reaches them.
Email you connect (Gmail and other mailboxes)
If you connect a mailbox — by signing in with Google, or by forwarding mail to your Haul IQ intake address — we read the messages and attachments that arrive there for one purpose: turning your freight paperwork (rate confirmations, bills of lading, proofs of delivery, invoices, receipts, driver documents) into loads, documents and records inside your account.
- What we access: message headers, bodies and attachments of the connected mailbox. With Google sign-in we request the
gmail.modifyscope so we can read mail, file it, and send replies you approve; we never send anything you have not clicked to send. - What we do with it: classify, extract and file it into your tenant. Extraction may be performed by an AI provider listed above (Anthropic, or Cloudflare Workers AI) acting as our processor.
- What we never do: sell it, use it for advertising, share it with data brokers, use it to train general-purpose AI models, or let a person read it except with your permission, for security, or to comply with the law.
- Disconnecting: Integrations → Disconnect revokes our Google access token with Google and stops all reading; mail already filed stays in your account until you delete it.
Google API Services User Data Policy. Haul IQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Where it lives
The service is hosted by Cloudflare, Inc., a United States company, on its global network: the database and file storage are Cloudflare's, encrypted at rest by Cloudflare, and every connection to the service uses HTTPS. We keep no separate data warehouse and no copies with anyone else.
How long we keep it
- While your account is active: for as long as you use the service. You decide what to delete inside it.
- After cancellation: we keep your company's data for 30 days so you can export it, then delete it within a further 30 days. Deletion is done by us, on request or on that schedule; it is not a self-serve button yet, and this page will say when it is.
- Sign-in and security records: kept for security only, and never used for anything else.
- Records federal rules make carriers keep: driver qualification files, medical examiner's certificates, drug and alcohol testing records, inspection reports and hours-of-service records have retention periods set by the FMCSA. Your company decides how long those stay, within the rules that bind it; a driver's deletion request goes to the company, and we help the company answer it.
Your rights
Whatever state you are in, you can ask us to:
- Tell you what personal data we hold about you and where it came from
- Correct it (most of it you can correct yourself inside the account)
- Export it. Your account record and AI activity can be exported today through the API; a complete export of your company's operational records (loads, drivers, invoices, documents) is prepared by us on request within 10 business days
- Delete your account and your company's data. We do it within 30 days of the request, except for records the law requires your company to keep
- Stop AI processing of your company's data at any time: the stop switch in Settings turns off every AI assistant, and the rest of the service keeps working
Write to the address at the bottom of this page. We confirm who you are before acting, answer within 30 days, and never charge for a request. If you are a driver or a customer's contact, the company that gave you access is the controller of that data; ask them first, and we will help them.
Driver location
If you're a driver using the Haul IQ Drive portal (the phone link your dispatcher sends you), your location is only ever collected because you chose to share it — never by default, and never before you've seen and accepted the consent screen in the app.
- What we collect: precise GPS (latitude, longitude, and when available heading, speed and accuracy) each time your phone reports a position while you have sharing turned on and the app is open on your screen.
- Between loads (changed 2026-09-15): while sharing is on, your position is reported whether or not you are running a load. When you are on a load, each position is stored as part of that load's trip record. When you are not — deadheading, waiting, parked — your dispatcher sees your latest position: where you are now, kept as the current location on your driver and truck record. Each position you report between loads is also kept as a record on the company audit log, and those records are not deleted automatically either. So there is no route line drawn for you between loads, but there is a dated record of each position that was reported. This page previously said every position was tied to a specific load; that stopped being true on 2026-09-15 and this is what replaced it.
- Why: so your dispatcher can see your truck's live position and route while that load is in transit, and can see where their trucks are between loads — the same reason a carrier watches an ELD or a tracking link today.
- Speed: your dispatcher can see how fast you are travelling — either the speed your phone or ELD reports, or a speed worked out from the distance between your last two positions. Your company may set its own fleet speed threshold; if a position is at or above it, that is recorded and shown to your dispatcher. It is compared only against the number your own company set — Haul IQ does not hold posted speed limits and makes no claim about the legal limit on any road.
- What we don't offer yet: background tracking. The consent screen shows an "Always" option (location while your phone is locked or the app isn't open) locked with the reason why — this build has no background-location capability, in the browser or in the Haul IQ mobile app. Only "while using the app" is available, and only after you turn it on.
- Retention: location pings stay with the load — there is no automatic deletion today. Each position you report between loads is also kept as a record on the company audit log, and those records are not deleted automatically either. That is a deliberate choice by Haul IQ's operator, not a technical limit, and it may change; this page will be updated first if it does.
- Who sees it: only your own dispatcher's company (the tenant that sent you the portal link) — never another driver, another carrier, or anyone outside your dispatcher's team.
- How to stop: turn location sharing off from the app (Profile → Location sharing, or the toggle on the Loads tab) — this stops new location reports immediately. Your dispatcher can also revoke your portal link at any time, which signs you out and stops sharing the same way.
- Session cookie: the portal sets one cookie,
hauliq_driver_session, so it can recognize your phone between visits. HttpOnly, Secure, SameSite=Lax, 30-day rolling TTL (refreshed while you're active; it expires on its own if you stop opening the app). It identifies your driver session only — it is not used for tracking or advertising.
Driver evidence record
The Haul IQ Drive portal (the same phone link covered under "Driver location" above) also asks you for things your dispatcher's compliance record needs — a photo of your pre-trip, a signed bill of lading, your medical card — and records, per driver, per day, what was asked and what came back.
- What we record: that the OS asked you for something on a given day, and what came back — that a photo or a document arrived, and when. We do not record anything about the CONTENT of a photo beyond what you already see it is (the photo or document itself, stored the same as any other document you upload).
- Why: your carrier's own compliance record — the same reason a dispatcher tracks paperwork today, done automatically instead of by hand.
- Who sees it: only your dispatcher's own dispatch and safety staff — never another driver, and never anyone outside your dispatcher's team.
- Retention: kept for as long as the carrier keeps your driver file; the owner sets the horizon. That is a deliberate choice by Haul IQ's operator, not a technical limit, and this page will be updated first if it changes.
- How you see it: the list on your own portal home screen shows exactly what you've been asked and lets you answer from there — the same list this record is built from.
Cookies
We use session cookies to keep you signed in — nothing else, no tracking pixels, no third-party cookies: hauliq_session for dispatchers/admins after they log in, hauliq_customer_session for the customer portal, and hauliq_driver_session for the driver portal (see "Driver location" above). Each is HttpOnly, Secure, SameSite=Lax, with a 30-day TTL.
Children
Haul IQ is for businesses operating commercial trucks. It is not directed to children, and we do not knowingly collect data from anyone under 16.
Changes to this policy
When this policy changes, the "Last updated" date at the top changes with it. For a change that matters — a new sub-processor that receives your operational data, a new purpose, a shorter or longer retention — we tell account owners by email before it takes effect.
Security practices
This page describes, in plain language, what protects your data in Haul IQ. Every statement on it is something the software does today; the things we do not have yet are listed too. The binding commitments are in the Data Processing Addendum; this page is the "how".
Where your data runs
- The service runs on Cloudflare's network. The database and file storage are Cloudflare's and are encrypted at rest by Cloudflare.
- Every connection to
hauliqdrive.comuses HTTPS, with HTTP Strict Transport Security so browsers never fall back. Every response carries a baseline of security headers, and our deploy pipeline checks the live site for them after each release. - Our own connections to the services we use (Anthropic, Resend, Stripe, the services you connect) are HTTPS only.
Signing in
- Passwords are stored as PBKDF2-SHA256 hashes, 100,000 iterations, 16-byte salt — industry-standard hashing. We never see the plaintext.
- You verify your email address before your first sign-in. Password reset is by a code emailed to that address.
- Sessions are cookies marked HttpOnly, Secure and SameSite, valid for 30 days, one for each of the three doors (office, customer portal, driver app).
- Sign-in, sign-up, invitations, password reset and the driver and customer logins are rate-limited per address and per account against guessing.
- Two-factor authentication is not available yet.
Who can see what
- Access inside a company is by role, backed by more than sixty named permissions checked route by route: dispatchers, accounting, safety, mechanics, read-only auditors, drivers and customer contacts each see and do only what their role allows.
- A driver sees only their own loads and paperwork, never another driver's, and never the rate your company negotiated with a broker. A customer's contact sees only their own loads.
- Every read and write is scoped to your company; the database refuses rows without a company on the tables that matter most. Nothing is cached across companies, on the server or in the driver app.
- API keys are shown once at creation and stored only as hashes. Your company's key can be rotated from Settings at any time.
What we record
- Money and people actions leave an audit trail with who, when, and the before-and-after: pay runs, settlements, invoice voids, journal entries, Social Security number reveals, driver terminations.
- Every action an AI assistant takes passes three checks — a company-wide stop switch, the autonomy tier you set, and a policy list — and the decision, allowed or refused, is recorded with its reason. Any past AI decision can be replayed from that record.
AI assistants
- Documents and prompts go to Anthropic's API under its commercial terms (no training on your data), or to models running inside Cloudflare's network when Anthropic is unavailable.
- You can stop every AI assistant at once from Settings; the rest of the service keeps working.
- Each plan has a daily AI-spend ceiling that halts runaway work. If the AI provider fails repeatedly, the service switches to conservative rule-based behavior instead of guessing.
Integrations
- Credentials for services you connect are stored on the server and never sent to the browser. Disconnecting a Google account revokes our access with Google.
- Webhooks you configure are signed with HMAC-SHA256 so your receiver can verify them, and the service refuses to send to private-network addresses.
Backups and releases
- Our database provider keeps point-in-time recovery for the previous 30 days; file storage is stored redundantly by the provider.
- Every release passes an automated gate before it deploys: a type check, more than 850 behavioral tests including ratchets that refuse a route without an access check or a silent failure on a money path, and size limits. Deploys go through one pipeline that reads the live database schema before and after.
What we do not have yet
We would rather tell you than have you find out.
- No SOC 2 or ISO 27001 certification. When we begin an audit, this page will say so; until then we answer security questionnaires directly.
- No two-factor authentication.
- No self-serve account deletion — deletion is done by us on request (see the Privacy Policy).
- No published incident history. The status page shows the health of the public data feeds we ingest, not uptime.
- No bug bounty program.
Reporting a vulnerability
If you find a security problem, write to lamborghinidaniil@gmail.com with what you found and how to reproduce it. We acknowledge within two business days and tell you when it is fixed. Research done in good faith — no access to data that is not yours, no service disruption, no public disclosure before we have had a reasonable time to fix — will not lead us to pursue legal action.
If something goes wrong
For a suspected security incident involving your data we commit to: acknowledging your report within one business day; investigating and containing it; telling affected customers without undue delay and no later than 72 hours after we confirm a breach of their data, with what happened, what data was involved and what we are doing; and a written summary on request once it is closed.
Data Processing Addendum
This addendum is part of the Terms of Service and applies to the data your company puts in Haul IQ. It takes effect when you create an account; no separate signature is needed. A customer that needs a countersigned copy can ask, and we will sign one.
1. Roles
You (the customer) are the data controller of your company's operational data. NovaTrans LLC ("we") is the data processor, acting on your instructions. The instructions are: run the Haul IQ service for you as described in the Terms and the Privacy Policy, and as configured by you inside the service.
2. What we process, and why
The categories are listed in the Privacy Policy under "Your company's operational data", "Services you connect" and "Driver app data". The people it is about are your employees and contractors (including drivers), your customers' and carriers' contacts, and anyone named in the documents you upload. We process it only to provide the service, to keep it secure, and as the law requires.
3. Confidentiality
The people who work on Haul IQ are bound to confidentiality. Access to production data is limited to what operating and supporting the service requires, and reveals of Social Security numbers are recorded in the audit trail.
4. Security measures
The measures we apply are described on the Security tab of this page, which forms part of this addendum. We keep them at least at that level and improve them over time; a change that lowers protection will not be made.
5. Sub-processors
We use these sub-processors for every customer:
- Cloudflare, Inc. — hosting, database, file storage, fallback AI models
- Anthropic, PBC — AI reading and drafting
- Resend, Inc. — transactional email
- Stripe, Inc. — payments, and banking features where you enable them
Services you connect yourself (mail, file storage, ELD, phone, bank, load board, chat providers — the list is in the Privacy Policy) receive data only because you connected them, under your own agreements with them.
Before we add a sub-processor that will receive your operational data, we list it here and email account owners at least 30 days in advance. If you object, you may cancel before the change takes effect, without penalty, and the cancellation terms of the Terms of Service apply.
6. Helping you with requests
If a person asks you about their data — a driver, a customer's contact — we help you find, correct, export or delete it within the service, and we pass on to you any such request that reaches us directly. We answer within 10 business days.
7. Security incidents
If we confirm a breach of security that affects your company's data, we tell you without undue delay and no later than 72 hours after confirmation, with what we know: what happened, which data and which people were involved, and what we are doing about it. We keep you informed as the investigation continues and give you what you need for your own notifications.
8. Return and deletion
You can export your data while your account is active, as the Privacy Policy describes. After termination we keep your company's data for 30 days so you can export it, then delete it within a further 30 days, and confirm in writing on request. Records that the law requires you to keep are yours to export before then; we do not keep them on your behalf after deletion.
9. Audits
Once a year, on request, we answer a written security questionnaire within 30 days and share this page's current state and a summary of our own testing. We do not hold third-party certifications today and do not offer on-site audits at our current size; if a regulator with authority over you requires more, we cooperate in good faith.
10. Liability and precedence
Liability under this addendum is subject to the limitation in the Terms of Service. If this addendum and the Terms conflict on the handling of personal data, this addendum governs.
Haul IQ API Terms
The Haul IQ Public API is a first-party REST + Webhook interface owned and operated by NovaTrans LLC. It exposes a stable, versioned subset of the platform — loads, drivers, invoices, quotes, documents, events — so customers and authorized integrators can build on top of it.
1. Base URL + versioning
- Base:
https://hauliqdrive.com/api/v1; the OpenAPI description is at/api/v1/openapi.json - Auth:
Authorization: Bearer hiq_live_… - We maintain backwards-compatibility for the lifetime of a major version. Breaking changes ship behind a new major (
/api/v2) with a minimum 12-month overlap. - Deprecations are announced on this page no less than 6 months before removal.
2. Authentication + scopes
API keys are issued to your company on request; write to the address at the bottom of this page. Each key is tenant-scoped, revocable, and carries one or more scopes:
read— read-only access (loads, drivers, invoices, quotes, status)write— create + update operational recordsfinance— the money-bearing fields of documents, in addition towrite
Keys are hashed at rest (SHA-256). The plaintext is shown exactly once at creation; if you lose it, ask for a new one and we revoke the old.
3. Rate limits
- Default: 120 requests / minute / tenant for read endpoints, 30 / minute / tenant for write endpoints. Higher quotas available on enterprise plans.
- Limit headers on every response:
X-RateLimit-Limit,X-RateLimit-Remaining,X-RateLimit-Reset. - Beyond the limit we return HTTP
429withRetry-After; requests above the limit are refused, never billed.
4. Webhooks
The API can deliver events to your endpoint at POST {your_url}. Every delivery carries webhook-id, webhook-timestamp and webhook-signature: v1,<hmac-sha256> headers, signed with the receiver's secret shown once when you create it in Settings → Webhooks. A delivery that fails is retried six times with increasing delays over 24 hours; after that it is marked dead and you can see it in Settings. We refuse to deliver to private-network addresses.
5. Permissible use
- You may build internal tooling, customer-facing apps, partner integrations, and AI agents on top of the API.
- You may NOT use the API to (a) re-sell raw access to other parties without a written reseller agreement with NovaTrans LLC, (b) scrape, mirror, or rebuild a competing platform, (c) bypass the service's safety controls, (d) impersonate another tenant, (e) violate any applicable law (FMCSA, DOT, IRS, OFAC, etc.).
- API responses contain operational personal data — your handling must comply with the Haul IQ DPA and applicable privacy law.
6. Data ownership
You own your operational data. NovaTrans LLC owns the API surface, schemas, OpenAPI specifications, and the underlying inference layer. Anything you fetch via the API for your own tenant, you may use however you like; anything you fetch from a shared _global table (commodity prices, weather, regulatory filings) remains public-world data and may be re-shared per the original publisher's terms.
7. Availability + support
- We do not publish an uptime guarantee for the API today. Scheduled maintenance is announced at least 48 hours in advance.
- The status page shows the health of the public data feeds the platform ingests.
- Support: email lamborghinidaniil@gmail.com and quote the
X-Haul-Iq-Request-Idheader returned on every response for fastest triage.
8. Pricing
API access is included with all paid Haul IQ subscriptions. Requests above your rate limit are refused with 429, not billed. Higher limits are part of enterprise plans.
9. Suspension + termination
NovaTrans LLC may suspend an API key without notice if we detect abuse, fraud, security risk, or behavior that endangers the platform. We will notify you within one business day of any suspension with the reason. Ask us to revoke a key at any time.
10. Operator
This API is operated by NovaTrans LLC. The full Terms of Service, Privacy Policy, and DPA on the other tabs of this page apply in full to API use; this document supplements but does not replace them. In any conflict between this API Terms doc and the Terms of Service, the Terms of Service governs.