HauLens Privacy Policy

Effective 2026-09-25. Applies to the HauLens Chrome extension and the HauLens service behind it. See also the Terms of Service.
The short version

Who we are

HauLens is operated by Haris Rasidagic ("we", "us"). Questions and requests about your data: contact@haulens.ai.

What HauLens does in Gmail

The extension runs only on mail.google.com. It adds a side panel and small buttons to Gmail's own page. To do that it reads the page content of the thread you have open: message text, sender addresses, and the subject line. From that text it detects carrier identifiers (MC and DOT numbers), phone numbers, and lane mentions, and it compares them against the loads you have saved. All of this reading and matching happens on your computer, in the browser.

HauLens does not use the Gmail API. It does not request any Google permission that covers your mail. The only Google permission it uses is sign-in (OpenID Connect with the openid, email, and profile scopes), which tells us your Google account ID, email address, and name so we can create your account and, if you join a team, show your teammates who you are.

The Gmail integration library the extension uses runs locally with its error reporting and usage tracking switched off.

Information that stays on your device

The extension keeps working data in Chrome's extension storage and, as a backup that survives reinstalls, in the browser's local storage for mail.google.com. This includes your saved loads and offers, carrier groups, reply templates, settings, the onboarding tour state, and your sign-in session token. None of this is sent anywhere except the load, team, and template data described below, which syncs to our servers so it follows you across devices.

Uninstalling the extension removes its extension storage. To remove the backup copy as well, clear site data for mail.google.com in Chrome, or use Delete account in the extension, which also signs you out.

Information sent to our servers

Our service runs on Cloudflare Workers with a Cloudflare D1 database. Every request is over HTTPS and, apart from sign-in and this page, requires your session. Here is everything that reaches us, why, and for how long we keep it.

DataWhyKept
Google account ID, email address, nameCreating and signing in to your account; showing you to teammatesUntil you delete your account
Session tokenKeeping you signed in30 days, then renewed silently through Google
MC or DOT numbers you look upFetching the carrier's public FMCSA recordThe carrier record is cached for 24 hours, keyed by the DOT number. We do not keep a per-user history of lookups.
The sender's email domain (for example carrier.com), never the full addressChecking how old the domain is, a fraud signalCached by domain for up to one year
Loads you enter or import: lanes, dates, equipment, weight, commodity, rates, reference numbers, notes, statusSyncing your board across devices and sharing it with your teamEncrypted at rest (AES-GCM) with a key held by the service. Kept until you delete the load or your account.
Team name, membership, and the email addresses you inviteRunning your teamUntil the team is dissolved or you leave
Your reply templates and settings, including your brokerage's own MC number if you enter itSyncing them across devicesUntil you delete your account
Your private blacklist entries (a carrier's DOT number, a reason, a note)Remembering carriers you flaggedPrivate to you, never aggregated or shared. Until you delete them or your account.
Your IP address and user ID in rate-limit countersPreventing abuse of paid lookupsRolling 24-hour counters

Never sent to us: the text of your emails, subject lines, attachments, your contacts, or any Gmail message. Lane matching and reply drafting happen in the browser; a drafted reply goes only where you send it, through Gmail.

Third parties that receive data

There are no advertising networks, analytics SDKs, or data brokers. We do not sell or rent personal data.

Google user data

HauLens's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The only Google data we receive is your basic profile at sign-in.

Security

All traffic uses HTTPS. Sessions are signed tokens. Load data is encrypted at rest with a service-held key. Lookups that cost money sit behind per-user rate limits so an exposed session cannot be used to run up a bill. The extension ships no remotely loaded code, as Chrome's Manifest V3 requires.

Coming soon

Phone-number checks (whether a number in a carrier's signature is a VoIP line) are not active yet. The extension detects phone numbers in your browser and lists them, but sends none to us or to anyone else. When the check launches we will name the provider and the retention here, and update the effective date, before it is switched on.

Your choices

If you are in the European Economic Area, the United Kingdom, or another jurisdiction with data protection rights, you can exercise access, correction, deletion, portability, and objection rights by emailing us. We process your data to provide the service you signed up for and, for rate limiting and error logs, in our legitimate interest of keeping it secure.

Children

HauLens is a business tool for freight brokers and is not directed to anyone under 18.

Changes

When this policy changes we update the effective date at the top of this page. Material changes are also announced in the extension's release notes.

HauLens · Effective 2026-09-25 · Terms of Service · contact@haulens.ai