HauLens Privacy Policy
- HauLens reads the Gmail page you are looking at, inside your browser, to spot carrier MC and DOT numbers, phone numbers, and lanes. The text of your emails never leaves your browser.
- We do not use the Gmail API and we never ask for permission to read, send, or manage your mail. Sign-in only asks Google for your name and email address.
- What our servers receive: your Google sign-in identity, the MC or DOT numbers you look up, the sender's email domain, the loads you enter, and your team settings.
- Loads are stored encrypted. Carrier, domain, and phone lookups are cached without any link to who asked.
- You can delete everything from the Account tab in the extension. We do not sell data, run ads, or use analytics trackers.
Who we are
HauLens is operated by Haris Rasidagic ("we", "us"). Questions and requests about your data: contact@haulens.ai.
What HauLens does in Gmail
The extension runs only on mail.google.com. It adds a side panel and small buttons to Gmail's own page. To do that it reads the page content of the thread you have open: message text, sender addresses, and the subject line. From that text it detects carrier identifiers (MC and DOT numbers), phone numbers, and lane mentions, and it compares them against the loads you have saved. All of this reading and matching happens on your computer, in the browser.
HauLens does not use the Gmail API. It does not request any Google permission that covers your mail. The only Google permission it uses is sign-in (OpenID Connect with the openid, email, and profile scopes), which tells us your Google account ID, email address, and name so we can create your account and, if you join a team, show your teammates who you are.
The Gmail integration library the extension uses runs locally with its error reporting and usage tracking switched off.
Information that stays on your device
The extension keeps working data in Chrome's extension storage and, as a backup that survives reinstalls, in the browser's local storage for mail.google.com. This includes your saved loads and offers, carrier groups, reply templates, settings, the onboarding tour state, and your sign-in session token. None of this is sent anywhere except the load, team, and template data described below, which syncs to our servers so it follows you across devices.
Uninstalling the extension removes its extension storage. To remove the backup copy as well, clear site data for mail.google.com in Chrome, or use Delete account in the extension, which also signs you out.
Information sent to our servers
Our service runs on Cloudflare Workers with a Cloudflare D1 database. Every request is over HTTPS and, apart from sign-in and this page, requires your session. Here is everything that reaches us, why, and for how long we keep it.
| Data | Why | Kept |
|---|---|---|
| Google account ID, email address, name | Creating and signing in to your account; showing you to teammates | Until you delete your account |
| Session token | Keeping you signed in | 30 days, then renewed silently through Google |
| MC or DOT numbers you look up | Fetching the carrier's public FMCSA record | The carrier record is cached for 24 hours, keyed by the DOT number. We do not keep a per-user history of lookups. |
The sender's email domain (for example carrier.com), never the full address | Checking how old the domain is, a fraud signal | Cached by domain for up to one year |
| Loads you enter or import: lanes, dates, equipment, weight, commodity, rates, reference numbers, notes, status | Syncing your board across devices and sharing it with your team | Encrypted at rest (AES-GCM) with a key held by the service. Kept until you delete the load or your account. |
| Team name, membership, and the email addresses you invite | Running your team | Until the team is dissolved or you leave |
| Your reply templates and settings, including your brokerage's own MC number if you enter it | Syncing them across devices | Until you delete your account |
| Your private blacklist entries (a carrier's DOT number, a reason, a note) | Remembering carriers you flagged | Private to you, never aggregated or shared. Until you delete them or your account. |
| Your IP address and user ID in rate-limit counters | Preventing abuse of paid lookups | Rolling 24-hour counters |
Never sent to us: the text of your emails, subject lines, attachments, your contacts, or any Gmail message. Lane matching and reply drafting happen in the browser; a drafted reply goes only where you send it, through Gmail.
Third parties that receive data
- FMCSA QCMobile (
mobile.fmcsa.dot.gov, US Department of Transportation). Called directly from your browser with the MC or DOT number, so FMCSA sees your IP address like any visitor to their site. - US DOT open data (
data.transportation.gov). Called from our servers with the MC or DOT number. - Domain registries via RDAP (directory published by IANA). Called from our servers with the sender's domain name.
- Google. Sign-in only. We verify the token Google issues; we do not access any Google service on your behalf.
- Cloudflare. Hosts the service and the database and keeps short-lived operational logs (request metadata such as IP address, path, and timestamps) that we use to diagnose errors.
There are no advertising networks, analytics SDKs, or data brokers. We do not sell or rent personal data.
Google user data
HauLens's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The only Google data we receive is your basic profile at sign-in.
Security
All traffic uses HTTPS. Sessions are signed tokens. Load data is encrypted at rest with a service-held key. Lookups that cost money sit behind per-user rate limits so an exposed session cannot be used to run up a bill. The extension ships no remotely loaded code, as Chrome's Manifest V3 requires.
Coming soon
Phone-number checks (whether a number in a carrier's signature is a VoIP line) are not active yet. The extension detects phone numbers in your browser and lists them, but sends none to us or to anyone else. When the check launches we will name the provider and the retention here, and update the effective date, before it is switched on.
Your choices
- Delete everything: Account tab, Delete account. This removes your user record, loads, templates, blacklist, team membership, and rate-limit counters immediately. If you created a team, the team is dissolved and teammates' loads return to their own accounts.
- Stop using it: uninstall the extension from
chrome://extensions. - Access or export: email us and we will send you what we hold about your account.
- Domain checks only run when you click them.
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with data protection rights, you can exercise access, correction, deletion, portability, and objection rights by emailing us. We process your data to provide the service you signed up for and, for rate limiting and error logs, in our legitimate interest of keeping it secure.
Children
HauLens is a business tool for freight brokers and is not directed to anyone under 18.
Changes
When this policy changes we update the effective date at the top of this page. Material changes are also announced in the extension's release notes.
HauLens · Effective 2026-09-25 · Terms of Service · contact@haulens.ai