Privacy & Data Security

Privacy & Data Security Policy

Last Updated: September 20, 2026 • Operated by Linehaul (trylinehaul.com)

1. Information We Collect

Linehaul collects information needed to provide, secure, support, and improve the freight-invoice workflow.

  • Account and team information: work email address, company/workspace information, authentication records, password hashes, workspace role/ownership status, and team-invitation metadata such as invited email, role, status, inviter, and timestamps. Linehaul does not store your plaintext password, and active invitation bearer tokens are stored in the application database only as cryptographic hashes.
  • Invoice and shipment information: uploaded PDFs or EDI documents and the text, metadata, charges, identifiers, addresses, references, and other structured information extracted from them. This can include files submitted through the public audit workflow as well as authenticated workspaces.
  • Workspace configuration: review decisions, corrections, duplicate/rebill decisions, carrier alias rules, ERP/GL mappings, export preferences, team roles, billing state, and other settings required to provide the Service.
  • Security and operational information: IP address, browser/request information, timestamps, request identifiers, security events, and application logs used for authentication, rate limiting, troubleshooting, abuse prevention, and reliability.

2. Document Retention & Privacy Mode

Invoice source files may be retained so authorized workspace users can review the original document and so interrupted processing can resume. Linehaul also provides an optional Privacy Mode for workspaces that prefer shorter source-document retention.

  • When Privacy Mode applies to an invoice, Linehaul removes the retained source PDF and raw extracted text from active application storage after processing, while preserving the structured invoice record required for the workspace and audit trail.
  • Multi-invoice workflows may temporarily stage source files so interrupted or capacity-paused work can continue. Staging records have an expiry period and are removed by automated maintenance after they are no longer eligible for processing.
  • Deletion from active application storage does not necessarily mean instantaneous erasure from every backup, security log, or provider system. Backup copies, where present, follow the applicable backup-retention cycle and are not used as active workspace data.
  • Archived invoice records are subject to Linehaul's configured retention process unless restored or removed earlier through an available workspace action.
  • Public-audit source files are kept under a separate bounded retention setting and are removed from active storage by maintenance after that period. They are not converted into a customer workspace unless a separate account workflow does so.

3. How We Use Information

We use information to provide and operate Linehaul, including document extraction, supported freight-charge and tariff-math review, duplicate/rebill review, workspace invitations and access control, ownership transfer, exports, billing, customer support, security, reliability, and product improvement.

  • No sale of invoice data: Linehaul does not sell or rent customer invoice documents or proprietary freight-rate information to data brokers, freight brokers, or advertising networks.
  • Automated processing: Linehaul's production PDF parser uses deterministic document-processing and OCR components inside a network-isolated parser boundary. The untrusted PDF process does not receive model-provider credentials or outbound network access.
  • AI-assisted fallback: when Linehaul's optional production fallback is enabled, a trusted application process may send bounded extracted invoice text and, for image-only rescue, safe rasterized page previews produced inside the parser sandbox to the configured AI extraction provider. The raw PDF is not handed directly to that provider by the sandboxed parser.
  • Support diagnostics: authenticated support and feedback forms can optionally include extracted fields or parser diagnostics. The interface identifies when extracted invoice text or other business data will be included; those details are not attached unless the user selects the corresponding option.
  • Aggregated and de-identified information: Linehaul may derive statistics from Service usage for product analytics, reliability, capacity planning, product improvement, and business-to-business marketing. These statistics are intended not to identify a customer or user and not to disclose customer-specific invoices, freight rates, carrier relationships, or other confidential business information.
  • Feedback: Linehaul may use feedback, suggestions, and feature requests voluntarily submitted to improve the Service and may summarize or use that feedback in business-to-business marketing without identifying the source. Linehaul does not attribute a testimonial or quote to a customer without separate approval.

4. Public-Site Analytics & Browser Storage

When optional public-site analytics is configured, Linehaul uses Microsoft Clarity only on selected low-sensitivity public marketing and calculator pages. It is excluded from sign-in, registration, team-invitation acceptance, password-reset, checkout, support/contact, enterprise-contact, demo-upload, and authenticated workspace pages. Where Clarity requires consent, analytics is not loaded until the visitor allows it. In other regions, analytics may load automatically on those public pages.

A browser-local preference records an analytics choice when one is made. Visitors can reopen Analytics Preferences from the public footer to allow or decline analytics. Necessary session, security, and anti-abuse technologies may operate separately where required to provide or protect the Service.

5. Service Providers, Security & Workspace Isolation

  • Service providers and subprocessors: Linehaul uses third parties for hosting, network/security services, transactional email, billing, encrypted backups, optional inbound-email processing, optional AI-assisted extraction, and selected public-site analytics. The material provider list and the functions/data involved are published on the Linehaul Subprocessors & Service Providers page.
  • Cross-border processing: Linehaul and its providers may process or store information in Canada, the United States, or other jurisdictions where the applicable provider operates. Information processed outside your province, state, or country may be subject to the laws and lawful-access requirements of those jurisdictions. Linehaul limits provider access to the functions reasonably needed to operate the Service and uses contractual, technical, and organizational safeguards appropriate to the service and information involved.
  • Workspace isolation: authenticated application operations are designed to scope customer records to the authorized company/workspace. Teammates in the same company workspace can access shared company records according to their assigned permissions, while administrator-only controls protect billing changes, company settings, team management, Email Ingestion, and ERP mappings. Linehaul also uses signed public-demo references, authorization checks, parameterized database queries, and automated security tests to reduce cross-tenant access risk.
  • Security safeguards: safeguards include password hashing, encrypted HTTPS transport in production, access controls, rate limiting, request validation, security logging, tenant scoping, backups, and ongoing vulnerability and dependency review. No Internet-connected system can be guaranteed to be completely secure.

6. Retention

Linehaul retains personal information and customer records for as long as reasonably needed to provide the Service, maintain security and audit records, meet contractual or legal requirements, resolve disputes, and operate configured retention features. Team-invitation and role-change metadata may be retained where reasonably needed for security, support, and workspace administration. When information is no longer required for an identified purpose, Linehaul aims to delete, anonymize, or otherwise dispose of it using safeguards appropriate to its sensitivity.

7. Privacy Requests

Subject to applicable law, contractual obligations, identity verification, and legitimate retention requirements, you may contact us to request access to or correction of personal information associated with your account, or to request account/data deletion. Workspace administrators can manage teammate access and may also use available in-product export, archive, restore, and deletion tools. Removing a teammate ends that user’s workspace access. Company invoices, settings, and other shared business records remain workspace data subject to the applicable retention and deletion controls.

The workspace owner can also submit a deletion request from Team & Access. That request starts a controlled review; it does not instantly purge the workspace. Linehaul reviews workspace identity, active billing, applicable legal or security holds, retention obligations, and recovery safeguards before scheduling permanent deletion. Data no longer required in active systems is deleted or de-identified according to the applicable process, while backup, security, transaction, or legally required records may remain for their applicable retention period.

Requests can also be sent to [email protected]. We may ask for information needed to verify the requester and the workspace involved before acting on a request.

8. Age & Business Use

Linehaul is a business freight and accounts-payable service and is not directed to children. Account creation and workspace-claim flows require acceptance of Terms that restrict use to people who meet the applicable age requirement and are authorized to use the Service for the relevant organization. Linehaul does not collect date of birth as part of ordinary registration. If you believe personal information was submitted by someone who was not eligible to use the Service, contact the Privacy Officer so the situation can be reviewed and appropriate action taken.

9. Canadian Privacy Principles

Where Canadian private-sector privacy law applies, Linehaul's privacy program is intended to follow applicable requirements concerning accountability, identified purposes, limiting collection, appropriate use/disclosure/retention, safeguards, openness, access, and complaint handling. Applicable privacy rights and obligations can vary by jurisdiction and context.

10. Contact

For privacy, security, data-handling questions, or privacy complaints, contact the Linehaul Privacy Officer at [email protected]. Privacy complaints will be reviewed and escalated as appropriate under applicable law.

© 2026 Linehaul. All rights reserved.