Skip to main content

Privacy Policy

Freight Friend is a back office for small trucking fleets. This page says what we collect, where it lives, who else touches it, and what you can ask us to do with it. It is written in plain English on purpose. Last updated [date].

What we collect

Your account. Your name, email address, phone number if you give one, and the role you hold in your company (admin, dispatcher, driver). We never see your password; sign-in is handled by Supabase.

Your company. Company name, USDOT and MC numbers, address, and the people, trucks and trailers you add. Driver records can include CDL and medical-card details and pay rules, because that is what settlements and compliance tracking need.

Your loads. Rate confirmations, bills of lading, invoices, factoring packets, settlements, stop times, detention and accessorial entries, and the notes your team writes on them.

Your documents. The PDFs and photos you upload (rate cons, signed BOLs, receipts). We store the files, and we read rate confirmations with an AI model to pre-fill a load — see "Who else processes your data" below.

Driver location. Only when your company turns it on: by connecting an ELD (Motive, Samsara or PEAK) on Admin → ELD, or by sharing a Live Load Link with a broker. ELD positions are polled about every five minutes for the trucks you matched, kept for 30 days, and shown to your dispatch. The driver app does not track a phone's GPS in the background. It asks the phone for one position when a driver taps a stop button (arrived, loaded, delivered) and when a driver taps "Use my location" on a breakdown report; that position is stored with the tap or the report so dispatch and billing can see where and when a stop happened.

Billing. When a company admin saves a card on Settings → Billing, the card is typed into a payment page hosted by Stripe, not into Freight Friend. Card numbers never reach our servers. We keep only the card's brand (for example Visa) and last four digits, the customer and subscription identifiers Stripe gives us, the email address Stripe sends billing receipts to, and the status of your subscription and payments. [Have your lawyer review this clause.]

What the app does. Who did what and when inside your account (for example "invoice sent", "settlement approved"). Your admins can see this log.

Where it lives

Your data is stored in a Postgres database, file storage and sign-in service hosted by Supabase, and the app runs on Vercel. [Confirm the Supabase project region and name it here, or leave as "hosted by Supabase".] Every company's data is separated by row-level security in the database: a login from one company cannot read another company's rows.

Who else processes your data

We use a short list of services to run Freight Friend. Each one gets only what it needs to do its job.

  • Supabase — database, sign-in and file storage.
  • Vercel — hosts the app.
  • Anthropic — the AI model that reads rate confirmations and powers the assistant. Documents are sent to Anthropic's API to be read. [Confirm Anthropic's current commercial API terms state that API inputs and outputs are not used to train models, and cite them here.]
  • Resend — sends email: account emails such as sign-in confirmation, replies to the founding-spot form, and factoring packets to the factor you choose.
  • Stripe — payment processing. Stripe receives the admin's email address, the billing name and address, and the card details you type into Stripe's own pages, and charges the card monthly once billing starts. Stripe's own privacy policy is at stripe.com/privacy. [Have your lawyer review this clause.]
  • Your ELD provider (Motive, Samsara or PEAK) — only if you connect one. We store the API key you paste encrypted, and only use it to read vehicle positions.

We do not sell your data. We do not share it with brokers, factors or other carriers unless you tell the app to — for example, by emailing a packet to your factor or opening a Live Load Link for a broker.

Analytics

On the public pages (the landing page, Resources and the founding-spot form) we count page views and button clicks ourselves. Each event records the event name, the page path, UTM tags from the link you arrived on, the referring site's domain and your language. It does not record your IP address, your browser's user agent, or any cookie or session id. Nothing in it identifies a person. There is no third-party analytics script.

Cookies

Freight Friend sets two kinds of cookie, both needed for the site to work:

  • Sign-in session — set by Supabase when you log in, so you stay logged in.
  • Language (fu-locale) — set only if you pick a language, so we remember it for a year.

There are no advertising or tracking cookies.

The driver app can be installed on a phone as a web app. It keeps a copy of recent pages on the phone so the app opens with no signal. That copy is tied to the signed-in driver and lives only on that phone.

How long we keep it

  • Account and company data — until you delete it or close your account.
  • Truck positions from an ELD — 30 days.
  • Public-page analytics events — [180] days, then deleted.
  • Records we must keep by law (for example invoices) — for the period the law requires, even after you leave.

Your rights

  • Export. Ask us, or use Admin → Export, and you get a full copy of your loads, documents, invoices, settlements and records.
  • Delete. Ask us to close your account and we delete your data within [30] days, except what we must keep by law.
  • Correct. Most records you can fix yourself in the app. Ask us for anything you can't.
  • Drivers. Your company is the one that added your record. Ask your company admin first; if that doesn't work, ask us.

If something goes wrong

If we learn of unauthorised access to your data, we will tell you within [72 hours] of confirming it, say what was affected, and say what we are doing about it.

Children

Freight Friend is for businesses and their staff. It is not for anyone under 18, and we do not knowingly collect data from them.

Changes

If we change this page we will update the date at the top, and tell account admins by email when the change matters to them.

Contact

Reply to any email we have sent you, or use the form at /pilot and say it is a privacy question. [Add a contact email or postal address here.] We answer within [one business day].

Governing law

This policy is governed by the laws of [state].