Legal
Privacy Policy
Last updated: February 25, 2026
DropHaul ("we," "our," or "us") operates the DropHaul platform, including the web application at app.drophaul.app, the DropHaul mobile application, and the marketing website at drophaul.app (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Account Information
When you create an account, we collect information you provide directly, including:
- Name, email address, and phone number
- Company name and business address
- Team member names, email addresses, and roles
- Payment and billing information (processed securely by Stripe)
Operational Data
When you use the Service to manage your portable sanitation business, we collect:
- Customer names, addresses, and contact information
- Job site locations and service details
- Unit inventory, fleet information, and route data
- Service records, photos, and job completion data
- Invoice and payment history
Usage Data
We automatically collect certain information when you use the Service:
- IP address, browser type, and operating system
- Device information (model, OS version, unique device identifiers)
- Pages visited, features used, and time spent in the application
- Crash reports and performance data
Location Data
With your permission, the DropHaul mobile app collects GPS location data from driver devices to enable route tracking, service verification, and navigation features. You can disable location services at any time through your device settings, though this may limit certain features of the app.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process transactions and send billing-related communications
- Optimize routes and provide navigation for your drivers
- Geocode addresses for mapping and dispatch purposes
- Send you product updates, technical notices, and support messages
- Monitor and analyze usage trends to improve user experience
- Detect, prevent, and address fraud, abuse, and technical issues
- Comply with legal obligations
3. Information Sharing
We do not sell your personal information. We share information only with the following categories of third-party service providers that are essential to operating the Service:
Stripe
Payment processing, subscription management, and invoicing. Stripe processes payment card data directly and is PCI-DSS compliant.
Clerk
Authentication, user management, and organization access control. Clerk handles sign-in credentials and session management.
Mapbox
Address geocoding, route optimization, and map rendering. Mapbox receives addresses and coordinates to provide mapping services.
Convex
Backend infrastructure, database hosting, and real-time data synchronization. Your operational data is stored and processed on Convex's secure infrastructure.
We may also share information when required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets. In such cases, we will provide notice where required and ensure appropriate safeguards are in place.
4. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Secure authentication with JWT tokens and session management
- Role-based access controls and organization-scoped data isolation
- Regular security assessments and monitoring
- Webhook signature verification for all third-party integrations
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Specifically:
- Active accounts: Data is retained for the duration of your subscription
- Cancelled accounts: Data is retained for 90 days after cancellation to allow for reactivation
- Billing records: Retained as required by tax and accounting regulations (typically 7 years)
- Usage logs: Aggregated and anonymized after 12 months
You may request deletion of your data at any time by contacting us. We will process deletion requests within 30 days, except where we are required to retain data for legal or regulatory purposes.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Portability: Request a machine-readable export of your data
- Opt-out: Opt out of marketing communications at any time
- Restriction: Request that we limit how we use your data
To exercise any of these rights, please contact us at privacy@drophaul.app. We will respond to your request within 30 days.
7. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe we have collected information from a child under 13, please contact us at privacy@drophaul.app.
8. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this page. For material changes, we will provide additional notice through the Service or via email. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
9. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
DropHaul
Email: privacy@drophaul.app
Website: drophaul.app/contact