1. The short version
- Hostler is software for carriers that haul Amazon Relay freight. Carriers (our customers) use it to schedule drivers, track safety and compliance, keep driver files, check timecards and message drivers.
- Most of the personal information in Hostler is about a customer’s own drivers, staff and job applicants. The customer is in charge of that information. We hold and process it for the customer, under our contract, only to run Hostler for them.
- We do not sell personal information. We do not share it for advertising. We do not use it to train AI models.
- Our website sets no cookies and runs no analytics.
- The driver app does not use your location, camera, photos, contacts or microphone. You can delete your login inside the app.
- Some Hostler features use AI from Anthropic. Messages that drivers write in the Hostler driver app are not sent to AI. Messages in a carrier’s Slack channels can be.
- Questions or requests: info@gethostler.com.
2. Who we are
Hostler (“Hostler”, “we”, “us”, “our”) is a small business based in Fresno County, California. One person owns and runs it, as a sole proprietorship, under the name Hostler.
Hostler was built at United Interstate Group LLC (“UIG”), an Amazon Relay carrier in Fresno County, California, which still uses it every day. UIG is a customer. Some features work only for UIG today, and some of UIG’s records are kept as files on a computer (section 14).
Hostler’s owner also works at UIG. UIG never sees another customer’s data. We never use another customer’s data for UIG, including for hiring, pay or bidding for freight, and we never use one customer’s data to help another customer.
You can reach us at the contact details in section 20.
3. What this policy covers
This policy covers personal information we handle through:
- gethostler.com, our public website;
- the Hostler office app, which a carrier’s office staff use in a web browser;
- Hostler Assistant, our Chrome extension, which works inside the office user’s own browser;
- the Hostler driver app for iPhone and Android;
- email and demo calls with us.
It does not cover:
- The other systems a carrier connects to Hostler, such as Amazon Relay, Netradyne, J.J. Keller, Geotab, ADP, Fountain and Slack. Each of those companies has its own privacy policy, and the carrier’s own agreement with each of them applies.
- How a carrier, as an employer, handles its workers’ information outside Hostler. If you drive or work for a carrier, your employer’s own privacy notice tells you what it collects about you and why.
4. Who is in charge of what
Privacy laws treat two roles differently, so we explain both.
The carrier is in charge of information about its drivers, employees and job applicants, and of everything its staff put into Hostler or connect to it. We call this Customer Data. The carrier decides what goes in, which of its staff can see it, and how long it is kept. We are the carrier’s service provider (in some laws, its processor). We use Customer Data only to provide Hostler to that carrier, as our Terms of Service and any data processing addendum we sign with the carrier say.
If you are a driver or an employee and you want to see, fix or delete information about you, ask your employer first. If you ask us, we will pass your request to your employer and help them answer it (section 16.6).
We are in charge of information about:
- people who visit our website, email us or book a demo;
- office users’ account details (name, work email, role and company), as far as we need them to run accounts, keep the service secure and bill;
- billing contacts.
5. What we collect
5.1 Website visitors
- Nothing in your browser. gethostler.com sets no cookies. It runs no analytics, no advertising trackers and no forms, and it loads nothing from other websites.
- Server logs. Vercel, which hosts the website, keeps short-lived logs of each request: your IP address, browser type, the page you asked for and the time. We use them only to keep the site running and safe, and we do not combine them with anything else.
5.2 People who book a demo or email us
- Book a demo opens a Google Calendar booking page. What you type there (your name, your email and any answers the page asks for) goes to Google, and then to us as a calendar booking. Google’s privacy policy covers what Google does with it.
- Email. Our email runs on Google Workspace. If you email us, we receive your email address, what you write and anything in your signature, such as your company and phone number.
- Why. We use this to answer you, hold the demo, set up a trial and follow up about Hostler.
- Marketing email. We do not send marketing email today. If we start:
- we will send it only to people at businesses who have dealt with us or asked for it, and never to bought lists;
- every message will say honestly who it is from and what it is about, and will include our mailing address;
- every message will have an unsubscribe link that keeps working for at least 30 days, and we will honor an unsubscribe within 10 business days;
- we will keep the list of people who unsubscribed only to make sure they get nothing more, and we will never sell or share it;
- we will not send marketing text messages without your written consent.
Emails about your account, billing, security, or changes to our terms or this policy are not marketing. They still reach you after you unsubscribe from marketing.
5.3 Office users (a carrier’s staff)
- Your account: your name, work email, role (Owner, Operations Manager or Driver Team Lead) and company. Your password is stored only as a scrambled hash by our sign-in provider, Supabase. Nobody at Hostler can read it.
- Sign-in records: when you sign in, from which IP address and which browser. Supabase keeps these for security.
- Activity record. Hostler keeps an audit trail of important actions, with who did each one and when. It covers revealing or setting a Social Security number, importing people, saving or clearing the roster or the schedule, updates to J.J. Keller driver files, every step of a timecard correction, and turning modules on or off. Ordinary edits to a person’s record are stamped with who made them and when.
- What you type into Hostler: notes, schedules, messages to drivers and questions to the dispatch desk.
- Your Slack messages. If your company connects Slack, your own messages in the channels Hostler copies are copied too. They can be sent to our AI provider with the rest of the channel (section 9).
- On-call details. If your company lists you as on-call staff, Hostler stores your name, your Slack member ID and your phone number, so it can reach you when a driver needs a person.
- Desk messages through your account. If your company connects your Slack account for the dispatch desk, the desk’s messages post through that account. Every message the desk sends to a driver on its own is marked as coming from the dispatch desk (section 9).
- Billing details, if you start a subscription (section 5.5).
- Your browser also keeps some things on your computer (section 11).
5.4 Drivers, employees and job applicants (Customer Data)
Hostler holds only what the carrier puts in or connects. What applies depends on which modules and connections the carrier uses. Some modules and connections are set up only for our first customer today.
| Kind of information | Examples | Where it comes from |
|---|---|---|
| Identity and contact | Name, phone, email, home address, date of birth, employee code, payroll ID | The carrier’s own records (for example, an employee spreadsheet it imports), its staff, and the Amazon Relay driver list |
| Government ID numbers | Social Security number; driver’s license and commercial driver’s license (CDL) number and state | The carrier’s records; the Relay driver profile (license number); J.J. Keller (last four digits of the SSN and of the license) |
| Employment | Status, position, hire and rehire dates, termination reason, job title, review and training dates and notes, handbook receipt, I-9 and E-Verify status, benefits flag, access to other systems, supervisor, badge and file numbers | The carrier’s records and staff; ADP |
| Pay and time | Hourly pay rate; timecard punches and hours by pay code; timecard corrections, the driver’s answers and the office’s approvals | ADP; the carrier’s staff; the driver app |
| Qualification and compliance | CDL class and endorsements, medical card expiry date, Relay compliance forms and their status, driver qualification file status, motor vehicle record (MVR) dates, results and documents, drug and alcohol random-pool membership and test results, the dates Clearinghouse queries were run | The carrier’s records; Amazon Relay; J.J. Keller |
| Schedule and dispatch | Shifts, start times, truck number, Relay blocks and trips assigned, stops and times, load notes, call-outs and their reasons, outcomes of calls with Amazon’s operations center | The carrier’s staff; Amazon Relay |
| Location and driving | Live truck location (GPS), speed, ignition and fuel level; hours-of-service logs | The carrier’s electronic logging system (Geotab) |
| Safety | Camera-system driver scores and safety alerts; links to alert videos; Relay safety incidents and scorecard; vehicle inspection (DVIR) results | Netradyne; Amazon Relay |
| Messages | Messages between drivers and dispatch in the driver app. If the carrier connects Slack, every message and photo in the channels the connected Slack account belongs to | Drivers and office staff; Slack |
| Job applicants | Name, email, phone, hiring stage, the job applied for, labels and other fields the carrier set up | Fountain |
| Driver app login | See section 6 | The driver |
Drug and alcohol testing. We receive nothing from drug-testing laboratories, and we do not hold medical records (only the date a medical card expires). We do hold the drug and alcohol test history that the carrier’s records and its J.J. Keller account show:
- each test’s date, type, reason (for example random or post-accident), collection method and result (negative, non-negative or pending);
- random-pool membership;
- the dates Clearinghouse queries were run, but not their results.
MVR documents come from the carrier’s own driver files.
What is not saved. Geotab truck locations and hours of service, and applicant reads from Fountain, are held in server memory for a few minutes and are not saved. The exception is what the dispatch desk sends to our AI provider (section 9). ADP timecards are also read into memory and not saved, except for a day the office corrects. For that day, the punches before and after, the correction and ADP’s answer are saved with the correction record. Netradyne’s video links expire about 30 minutes after Netradyne issues them. The extension keeps up to eight in memory and never saves them, and videos play in your browser straight from Netradyne.
Sensitive information. Several of these are “sensitive personal information” under California law: Social Security numbers, driver’s license numbers, citizenship or immigration status (I-9 and E-Verify records), precise location, drug and alcohol testing information, and the content of messages. We use them only to provide Hostler to the carrier. We never use them to infer things about people, and never for advertising.
How Social Security numbers are protected. The full number cannot be read through the app’s normal data access. Only an Owner or Operations Manager can reveal it, one person at a time. Each reveal is written to the audit trail and limited to 20 a minute, and the page hides the number again after 15 seconds. Everyone else sees only the last four digits. Hostler’s administrator can also reach the database directly, to run and repair the service. We do that only for support the carrier asked for, for security, or when the law requires it.
Who at the carrier sees what. The carrier decides who gets an office seat and which role. Every office seat, Driver Team Leads included, can see people’s records, including dates of birth, home addresses, license numbers, medical card dates, drug and alcohol test results and MVRs. Only Owners and Operations Managers see pay rates, payroll, full Social Security numbers and billing. A driver sees only their own messages and their own timecard corrections.
Slack. If a carrier connects Slack, Hostler copies every message in every public and private channel the connected Slack account belongs to (up to 100 channels), including photos, about every 20 minutes, and keeps the copy for the carrier. It skips Hostler’s own report channel and does not read direct messages. It also reads the workspace’s member list, to show people’s names. The dispatch desk uses these messages to understand what drivers need, and recent messages and photos may go to our AI provider (section 9). A carrier should connect a Slack account that belongs only to the channels it wants Hostler to read, and it must tell its drivers and staff about this copying.
Hostler is not a background-check company. Hostler does not run background checks or prepare consumer reports. It shows the carrier records the carrier already has, or gets from its own providers.
5.5 Billing contacts
- Stripe runs our payment page. Card details go straight to Stripe. We never see or store card numbers.
- We send Stripe the company name, the email of the person who starts checkout and an internal company ID.
- Stripe collects the card, the billing address and, if you give one, a tax ID.
- We keep the Stripe customer ID, the subscription’s status and dates, and a record of billing events.
6. The Hostler driver app
This section is the privacy policy for the Hostler driver app on the App Store and Google Play. It applies whether the app is published in the stores by Hostler or by your employer. The rest of this policy also applies.
Who it is for. Your employer gives you the app so you can message dispatch and check and answer timecard corrections. Anyone can create a login. But only a driver whose employer’s office has linked their login sees a thread with dispatch and the Pay tab. A login that is not linked shows only that it is waiting for the office, and it can still be deleted.
6.1 What the app collects
| Data | What it is | Why | App Store label | Google Play label |
|---|---|---|---|---|
| Name | Your name as your employer’s roster has it, attached when the office links your login | To open your own thread | Name | Personal info: Name |
| Email address | The email you sign in with | To sign you in and link you to your employer’s record | Email Address | Personal info: Email address |
| User ID | The ID our sign-in provider gives your login | To keep your account and thread together | User ID | Personal info: User IDs |
| Device ID | The notification token Apple or Google gives your phone, and whether it is an iPhone or Android | To send you notifications | Device ID | Device or other IDs |
| Messages | What you write to dispatch, when you sent it, and when it was read. If your employer also uses Slack, your Slack messages with dispatch show in the same thread | Your thread with dispatch | Emails or Text Messages | Messages: Other in-app messages |
| Your timecard answers | Whether you accept or decline a correction, when, and any reason you type | To correct your timecard | Other User Content | App activity: Other user-generated content |
| Timecard information | The punches, corrections and paid-time changes shown on the Pay tab, in hours and minutes (never dollar amounts) | To show and correct your timecard | Other Financial Info | Financial info: Other financial info |
All of this is linked to you. It is used only to make the app work. It is not used for tracking, advertising or analytics. The app contains no analytics, advertising or crash-reporting code.
- Your password is stored only as a scrambled hash by our sign-in provider. Nobody can read it.
- Sign-in records (when you signed in, and from which IP address) are kept by our sign-in provider for security.
- What the app does not use: location, camera, photos, contacts, microphone, health data or browsing history. iPhone settings may show a note about the photo library. That note is there because a component built into the app could ask; the app never asks. On Android, the store listing may show storage and “display over other apps” permissions that come with the app’s framework. The app never asks for them or uses them.
- What stays on your phone: your sign-in session only, until you sign out.
- The Pay tab shows timecard information your employer already holds from its payroll and electronic logging systems. The app does not collect that from your phone.
6.2 Notifications
The app asks before it sends notifications. A notification can show the first words of a message from dispatch (up to about 120 characters), or the words of a timecard correction, for example that a day needs a look. Notifications pass through Apple or Google to reach your phone, with a label for the thread made from your name, and they can show on your lock screen. You can turn them off at any time in your phone’s Settings. The app keeps working without them.
6.3 AI and the driver app
- Messages you write in the driver app are not sent to any AI service. Your employer’s staff read them.
- If that ever changes, the app will ask you first, and you will be able to say no.
- If your employer also uses Slack, its dispatch desk may use AI to help answer messages drivers send there, and those Slack messages can be sent to the AI (section 9).
- Messages the desk sends on its own are marked “dispatch desk”, in the app and in Slack, so you can tell a person from the desk.
6.4 Timecard corrections
When you accept a correction and the office approves it, or when the office corrects your timecard directly, the corrected clock times are written to your timecard in your employer’s payroll system (ADP). A direct correction shows under Recent on the Pay tab. A correction can also take a wrong pair of punches off. Hostler changes only clock times. It never changes your pay rate or a pay amount. Hostler keeps a record of each correction, with the times before and after.
6.5 Encryption
The App Store and Google Play versions of the app talk to Hostler’s hosted service and to our sign-in provider only over encrypted connections (HTTPS).
6.6 Delete your account in the app
- Tap Account.
- Tap Delete my account.
- Confirm.
This takes effect straight away. It deletes your login (your email and password), your profile, and every phone registered for notifications, and it signs you out.
What your employer keeps. These are your employer’s work and payroll records, which the law often requires employers to keep:
- your messages with dispatch;
- your timecard corrections and your answers;
- your record in your employer’s driver files, roster and schedules;
- the office’s invite for your email, with your email and your name as the roster has it.
Hostler does not delete these on a schedule. They stay until your employer deletes them or stops using Hostler, and then section 13 applies. Deleting your login does not change your job, your ADP timecards or your pay. To ask your employer to delete or correct its records about you, contact your employer.
Signing up again. Your employer’s invite for your email stays open unless the office withdraws it. If you sign up again with the same email, you will be linked to your employer’s record again.
6.7 Delete your login without the app
You can also ask us to delete your Hostler driver app login without using the app. Email info@gethostler.com from the email address you sign in with, with the subject “Delete my Hostler login”. Or ask your employer’s office.
We may ask you to confirm from that address that the request is yours. We then:
- delete your login, your profile and your notification tokens within 7 days;
- tell your employer, so the office can withdraw your invite.
The records your employer keeps (section 6.6) stay with your employer.
7. The Hostler Assistant Chrome extension
Who uses it. A carrier’s office staff, in their own Chrome browser, signed in to their own accounts.
Which sites it works on. It works only on these sites:
- Amazon Relay (relay.amazon.com);
- Netradyne (idms.netradyne.com);
- J.J. Keller’s client center (external.jjkellerclientcenter.com and preview.jjkellerclientcenter.com);
- the carrier’s own Hostler page.
It does not read any other website, and it does not collect your browsing history.
What it reads. On those sites it reads the information the site already shows you or loads for you. It keeps a copy of the answers the site sends to your own browser, and it reads the page. On Relay and J.J. Keller it can also ask the site, as you and in your signed-in tab, for more of the same information, such as a trip’s notes, a proof-of-delivery document or a driver’s testing page.
- Amazon Relay: trips, load notes, the scorecard, the driver list, each driver’s profile and compliance file (license number included) and inspection results. It shows documents such as proof of delivery, but does not save them.
- Netradyne: driver scores and safety alerts. It never makes requests of its own to Netradyne; it keeps what the Netradyne console already loaded. To get an alert’s video link, it can open the alert in a background tab, the same as clicking it. Video links are kept in memory only, as section 5.4 describes.
- J.J. Keller: driver qualification files, drug and alcohol testing pools and test results, and MVR documents. It opens each driver’s testing page using your existing sign-in.
What it never handles. It never handles your passwords for those sites. It works inside the session you are already signed in to. It never answers security checks such as CAPTCHAs.
What it writes. It makes changes in Relay when someone presses a button in Hostler:
- assigning drivers to blocks and trip legs (you can watch it fill them in);
- filing delay reports;
- adding trip notes;
- sending a question about a load to Amazon’s Relay Assistant, including a callback phone number the user enters (normally the dispatch office’s line), so Amazon’s operations center can call back.
Two features act on their own, without a click for each action:
- Automatic delay filing. It is off unless the carrier switches it on. It follows strict rules: it never files a reason that blames the carrier, and it never files twice for the same stop.
- The dispatch desk, for a carrier with the Dispatch module, while the desk’s automatic cycle is running. It can send a question about a load to Amazon’s Relay Assistant (up to 6 a day), and it can put an open bobtail leg on a named office user (up to 6 a day). No person clicks first. The desk posts each action in the carrier’s Slack before and after, and an office user can pause the cycle.
Where the data goes. Copies stay in the extension’s storage on your computer and are handed to your company’s Hostler page. From there, some of it goes to Hostler’s servers to be saved for your company: J.J. Keller driver files, the trip board’s history and load notes, and a log of the changes Hostler made in Relay. If your company uses the dispatch desk, what the page holds from Relay and Netradyne also goes with each desk question to our AI provider (section 9), and summaries go to your company’s Slack. Nothing goes to anyone else.
Why it asks for each permission.
- storage: to keep its copies on your computer.
- tabs, activeTab and scripting: to find and work in the Relay, Netradyne and J.J. Keller tabs you have open.
- alarms: to refresh on a timer.
- debugger: to make clicks that Relay accepts as real clicks, and to take screenshots of those pages. Chrome shows a bar at the top of the window while this is in use.
The companion program. For some customers, a companion program runs on the office computer that runs Hostler. It uses a saved Relay sign-in to make driver changes the user has already confirmed, without taking over the screen. The saved sign-in stays on that computer.
Chrome Web Store Limited Use. Hostler’s use of information received through the extension follows the Chrome Web Store User Data Policy, including its Limited Use requirements:
- We use it only to provide the extension’s features to the carrier.
- We do not sell it, and we do not use it for advertising, credit or lending.
- We pass it to others only as section 10 describes, to provide those features.
- People at Hostler do not read it unless one of these applies: the carrier asks us to (for example, for support), it is needed for security, the law requires it, or it has been combined and made anonymous for our internal operations.
- Someone who works on Hostler and is also on a carrier’s own staff sees that carrier’s data as that carrier’s staff, not as Hostler.
- When we fix a problem a carrier asked us to fix, our AI coding tools can see that carrier’s data (section 9).
8. How we use information
Customer Data. We use it only on the carrier’s behalf, to:
- run the Hostler features the carrier uses, and show the information to the carrier’s staff by role;
- connect to the systems the carrier links, and make the changes its staff make, approve or switch on;
- send notifications to drivers and staff;
- run the AI dispatch desk, if the carrier uses it (section 9);
- give support when the carrier asks;
- keep Hostler secure, prevent misuse and fix problems;
- meet our legal obligations.
Information we are in charge of. We use it to:
- answer questions, hold demos and set up trials;
- run accounts and billing, and keep tax records;
- keep the service secure;
- tell customers about changes to Hostler or to this policy;
- improve Hostler, based on how the service works and fails, not by mining customer records;
- meet legal obligations and enforce our Terms of Service.
What we never do:
- sell personal information;
- share it for cross-context behavioral advertising, or use it for any advertising;
- train AI models on it;
- use one customer’s data for another customer;
- compare carriers against each other, or build benchmarks across carriers;
- build profiles of drivers for anyone except their own employer.
Suggestions, not decisions. Hostler suggests things: who is eligible for a block, which timecard looks wrong, what a reply to a driver might say. The carrier’s people make the decisions about hiring, firing, discipline, pay and who gets work. In dispatch, the desk can take a few routine actions on its own (sections 7 and 9), and the carrier can pause it.
De-identified information. If we ever use information that has been changed so it cannot identify a person or a customer, we will keep it that way. We will not try to re-identify it.
9. AI
Some Hostler features use Claude, an AI model made by Anthropic, PBC. The main one is the Dispatch module, which is sold separately. Under Anthropic’s Commercial Terms of Service, Anthropic may not train its models on the content we send it, and we keep our rights to what we send and what comes back.
When information goes to Anthropic:
- An office user asks the dispatch desk a question.
- The desk checks new messages in the carrier’s Slack channels, about every 20 minutes, to answer drivers. This runs automatically while the carrier has the Dispatch module and a Hostler office tab is open on the office computer, unless an office user pauses it.
- Once a day, at 5 pm Pacific time, the desk writes the daily report and its review of the day.
- An office user gives the desk an instruction in the carrier’s Slack report channel.
- An office user asks Hostler to redraft the carrier’s dispatch playbook, or to grade the desk against the carrier’s past conversations.
What is sent:
- the question, the instruction, or the driver’s Slack message;
- the last 12 hours of messages in the Slack channels Hostler copies (up to 60), from drivers and office staff alike;
- driver names, phone numbers, home base, notes and eligibility from the roster;
- driver-file problems, such as “medical card expiring”, and problems in drivers’ Relay compliance files;
- trips and the schedule;
- live truck positions and hours-of-service standing;
- safety alerts and the scorecard tier;
- load notes;
- similar past Slack conversations and how they were resolved, and the office’s notes on closed cases;
- the carrier’s dispatch playbook, which includes notes on past cases that can name drivers;
- up to three photos posted in the driver’s Slack channel in the last two hours.
To redraft the playbook or grade the desk, Slack conversations are sent, joined with Relay trip, load-note and Hostler-action history.
What is not sent. Hostler does not add Social Security numbers, dates of birth, home addresses or pay rates. But anything a driver or staff member types or photographs in a copied Slack channel is sent as written. Messages drivers write in the Hostler driver app are not sent.
Where, and for how long. Anthropic stores what we send in the United States, but may run the model on servers in other countries. It deletes what we send and what it returns within 30 days, with two exceptions. If Anthropic’s systems flag content under its Usage Policy, it may keep that content for up to 2 years and its safety scores for up to 7 years. It may also keep content longer where the law requires. We have no zero-retention agreement with Anthropic.
People stay in charge.
- Messages the desk writes to drivers go to a review channel for the office until the carrier switches on live sending. With live sending on, the desk can reply to drivers in Slack on its own, within fixed daily limits.
- The desk’s actions in Relay (section 7) do not wait for live sending.
- Every message the desk sends to a driver on its own is marked as coming from the dispatch desk, in Slack and in the driver app.
- Hostler refuses to send any message that pressures a driver over hours of service or about disabling safety devices.
- Anything that sounds like an emergency goes to a person.
- An office user can pause the desk at any time.
AI tools we use to build Hostler. We use AI coding tools from Anthropic to write and fix Hostler. When we fix a problem a customer asked us to fix, these tools can see that customer’s data. We use them only under terms that do not let Anthropic train its models on that data.
10. Who we share information with
We share personal information only as this section describes. We do not sell it, and we do not share it for advertising.
10.1 Our service providers (subprocessors)
These companies run parts of Hostler for us. Each one may use the data only to provide its service to us, under its contract or data-processing terms with us, and must protect it at least as well as this policy does.
| Company | What it does for Hostler | What it receives |
|---|---|---|
| Supabase, Inc. (on Amazon Web Services, in the U.S.) | Database, sign-in, and sign-in and password-reset emails | Everything Hostler saves: accounts, Customer Data, sign-in records |
| Vercel Inc. | Hosts our website and Hostler’s hosted service | Every request to them passes through it; request logs (IP address, page, time) |
| Anthropic, PBC | AI for the dispatch desk (section 9), and the AI coding tools we use to build and support Hostler | What section 9 lists; for support, what a fix needs to see |
| Stripe, Inc. | Payments, invoices and sales tax | Company name, buyer’s email, card, billing address, tax ID |
| Apple Inc. (Apple Push Notification service) | Delivers notifications to iPhones | Notification token, notification text and the thread label |
| Google LLC (Firebase Cloud Messaging) | Delivers notifications to Android phones | Notification token, notification text and the thread label |
| Google LLC (Google Workspace and Google Calendar) | Our email and demo bookings | Emails to and from us; demo bookings |
| Twilio Inc. | Text-message alerts to a carrier’s own on-call staff, only if switched on | On-call staff phone numbers, and a short alert naming the driver and the kind of problem (never the driver’s message or phone number) |
| Esri and OpenStreetMap (map images); the U.S. National Weather Service (weather alerts) | The map in the office app | The map area being viewed and truck coordinates, with no driver names. Our server makes these requests, so your IP address is not sent |
We send notifications to phones directly through Apple and Google. No other notification service is used. The driver app is built with Expo, an open-source framework, and Expo receives no Customer Data from us.
We will update this list before a new service provider receives Customer Data. Customers get at least 30 days’ notice by email first, as our Terms of Service say.
10.2 Systems the carrier connects
When a carrier connects one of its own systems, Hostler reads from it, and in some cases writes to it, on the carrier’s behalf. It uses the carrier’s credentials or the carrier’s signed-in browser. These companies are the carrier’s providers, not ours, and the carrier’s agreements with them apply.
| System | What Hostler does with it |
|---|---|
| Amazon Relay | Reads (section 7). Writes driver assignments, delay reports, trip notes, and questions to Amazon’s Relay Assistant with a callback number, normally the dispatch office’s line. The dispatch desk can do some of this on its own (section 7) |
| Netradyne | Reads only |
| J.J. Keller | Reads only |
| Geotab | Reads only |
| ADP Workforce Now | Reads worker and timecard information. Writes corrected clock times that an Owner or Operations Manager approved or entered |
| Fountain | Reads only |
| Slack | Reads every channel the connected account belongs to, except Hostler’s own report channel. Posts the desk’s messages to drivers, a daily report to the carrier’s channel, and alerts to the carrier’s on-call staff |
10.3 Inside the carrier’s own company
The carrier’s office staff see Customer Data according to their role (section 5.4). Drivers see only their own messages and timecard corrections.
10.4 The law and safety
We disclose information if a valid law, subpoena or court order requires it, or if we need to in order to protect someone’s safety, or to protect Hostler and our customers from fraud or abuse. If a request is for Customer Data, we will tell the customer first, unless the law forbids it.
10.5 If Hostler changes hands
If Hostler is sold, merged or transferred, the information may pass to the new owner. The new owner must keep the promises in this policy, or tell you about any change first. Before any such change, customers will be able to export their data (section 15).
10.6 With your permission
We share information in other ways only if you ask us to or agree to it.
11. Cookies and storage on your device
Website. gethostler.com uses no cookies and no browser storage.
Office app cookies. The office app uses two kinds of cookies. Both are needed for the app to work:
- Supabase sign-in cookies (named
sb-…) keep you signed in. hostler-orgremembers which company you are working in, so your browser keeps each company’s stored data apart.
There are no analytics, advertising or third-party cookies.
Office app browser storage. To load quickly, the office page keeps copies of what it read from Relay, Netradyne and J.J. Keller in your browser. Most of it is deleted when you sign out. Some of it stays on that computer on purpose:
- the roster, with its backups and any copy not yet saved;
- the scheduler’s current week, with its backups;
- earlier People edits;
- Relay load notes for the last 200 trips, including notes on calls with Amazon’s operations center;
- color and layout settings, and Relay’s list of domiciles;
- dispatch-desk bookkeeping.
The dispatch desk’s chat is kept only until you close the tab.
Use Hostler on computers your company controls. On a shared computer, sign out and clear the site’s data when you finish.
Extension storage. The extension keeps its copies on your computer until the extension is removed or its storage is cleared. Signing out of Hostler does not clear it.
Driver app. The app keeps only your sign-in session on your phone, until you sign out or delete your account.
12. Do Not Track and Global Privacy Control
- Do Not Track. Some browsers send a “Do Not Track” signal. There is no common standard for responding to it. Hostler does not track you across other websites or apps, and we do not let anyone else do so through our website or apps. So there is nothing for the signal to switch off, and we do not change anything when we receive it.
- Global Privacy Control. We do not sell or share personal information, so a Global Privacy Control signal has nothing to turn off. If your browser sends one, we treat it as a valid request to opt out of sale and sharing anyway.
13. How long we keep information
Hostler does not delete records on a timer. This table says what happens instead.
| Information | How long |
|---|---|
| Customer Data (people records, roster, schedules, messages, timecard records, compliance files, the audit trail) | While the customer’s account is open. Archiving a person keeps their record. If a customer wants records deleted, they ask us, and we delete them unless the law requires us to keep them. After a customer leaves, they have 30 days to export their data. We then delete it within 30 more days. Copies in backups expire within 7 days after that |
| Slack copies, Relay trip-board history, load notes and the log of Relay changes | The same as Customer Data |
| Geotab truck locations and hours of service, Fountain reads and ADP timecard reads | A few minutes, in server memory. Not saved, except as section 5.4 describes |
| Office user accounts | Until the customer asks us to close them, or the account ends |
| Driver app login and profile | Until you delete it (section 6) |
| Notification tokens | Until you sign out, delete your account, or Apple or Google reports the token is no longer valid |
| What Anthropic receives | Up to 30 days, with the exceptions in section 9 |
| Office page storage | Most of it is deleted at sign-out. Section 11 lists what stays |
| Extension storage | Until the extension is removed. Signing out of Hostler does not clear it |
| Website logs | The short period Vercel keeps them |
| Emails and demo bookings | As long as the conversation is useful, and no longer than 2 years after our last contact, unless you become a customer |
| Billing records | As long as tax law requires, generally 7 years |
14. Security
What we do:
- Each customer is walled off in the database. Every row of data belongs to one company, and the database itself refuses to show it to anyone signed in to another company.
- Every page and request in the app needs a signed-in user with the right role. The only exceptions are the sign-in, password-reset and email-confirmation pages, the public privacy and help pages, the map library’s files, and Stripe’s notification address, which checks Stripe’s signature first. Your identity comes from your sign-in, never from what a request claims.
- The most sensitive fields are locked down further. Full Social Security numbers and pay rates are restricted as section 5.4 describes. Revealing a Social Security number is logged. Hostler’s administrator can reach the database directly to run and repair the service, and does so only as section 5.4 describes.
- Important actions are recorded in an audit trail that cannot be edited.
- Limits on repeated tries. For example, sign-in allows five attempts per 15 minutes.
- Encryption. Our website, Hostler’s hosted service and the store versions of the driver app use encrypted connections (HTTPS). Our database provider encrypts stored data (AES-256).
- Card numbers never reach us. Stripe handles them.
- Secret keys stay on the server. They are never sent to a browser or a phone.
What we do not have yet. We want you to know:
- Sign-in uses an email and a password. Two-step sign-in is planned for account owners but is not available yet.
- Hostler has not had an independent security audit, such as SOC 2.
Our first customer. For our first customer, Hostler also runs on a computer in that customer’s office, reached over the customer’s own office network. Some of that customer’s records are kept as files on that computer, not in the database:
- copies of Slack channels and their photos;
- trip-board and load-note history;
- a log of the changes Hostler made in Relay;
- the desk’s sends, escalations and on-call pages;
- case notes and the dispatch playbook;
- raw J.J. Keller reads.
A saved Relay sign-in for the companion program is kept there too. No other customer’s data is kept on that computer.
What you can do:
- Use a strong password that you use nowhere else.
- Give office seats only to people who need them, at the lowest role that works.
- Tell us when someone leaves, so we can close their login.
- Sign out on shared computers.
If something goes wrong. No system is perfectly secure. If a security incident affects Customer Data, we will tell the affected customer without unreasonable delay, and in any case within 72 hours of discovering it. We will help them notify the people affected, as the law requires. If an incident exposes sign-in details (an email address with a password) or other information we are in charge of, we will also tell the people affected directly, as the law requires.
15. Getting your data out
- People. A customer can export the main fields of its people records as a spreadsheet at any time (People, then Export CSV). The export shows only the last four digits of Social Security numbers, and it includes pay rates only for Owners and Operations Managers. Drug-test entries, notes and J.J. Keller files are not included; ask us for those.
- Trips. A customer can export Relay trips (upcoming, in transit and history) as spreadsheets.
- Everything else. Ask us, and we will provide a copy in a common format (CSV or JSON) within 30 days, at no charge. We are building a fuller self-serve export.
- If Hostler shuts down or is sold, customers will be able to get their data out first.
16. Your privacy rights
16.1 Everyone
Whatever the law where you live, you can ask us:
- what personal information we hold about you;
- to correct it;
- to delete it.
Email info@gethostler.com. If the information is Customer Data, we will pass your request to your employer (section 16.6).
16.2 California
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), gives California residents rights over their personal information. Hostler is a small business and may not meet the size thresholds that make the CCPA apply to it. We honor these rights anyway.
Information we are in charge of, in the last 12 months. We keep each kind as section 13 says.
| CCPA category | Examples | Source | Why we use it | Who receives it |
|---|---|---|---|---|
| Identifiers | Name, email, IP address, account ID | You; your company; your browser | Accounts, demos, support, security | Supabase, Vercel, Google, Stripe |
| Customer records | Name, billing address, phone | You | Billing and support | Stripe, Google |
| Commercial information | Subscriptions and purchases | You; Stripe | Billing | Stripe |
| Internet or network activity | Website and app request logs, sign-in records, audit trail | Your browser; Hostler | Security and running the service | Supabase, Vercel |
| Professional information | Your company and job title | You | Demos, accounts, support | Google, Supabase |
| Sensitive: account sign-in | Email with password (stored as a hash) | You | Signing you in, only | Supabase |
- We have not sold or shared personal information in the last 12 months.
- We do not sell or share the personal information of anyone under 16.
- We use sensitive information only for purposes the CCPA allows, such as providing the service you asked for and keeping it secure. So the right to limit its use does not change anything we do. You can still ask.
Your rights:
- Know and access: what we collect, where it comes from, why, who receives it, and a copy of the specific information.
- Delete it, unless the law lets or requires us to keep it.
- Correct it.
- Opt out of sale or sharing. We do neither.
- Limit the use of sensitive information. See above.
- No retaliation or discrimination for using these rights. That includes employees and job applicants.
16.3 How to make a request
- Email: info@gethostler.com, with the subject “Privacy request”.
Checking it is you. We check that the request comes from you, by matching it with information we already hold. If you have an account, we will reply to its email address. A request for specific pieces of information needs a closer match.
Someone acting for you. An authorized agent can make a request for you. They need your signed permission, and we may check directly with you.
Timing. We confirm we got your request within 10 business days. We answer within 45 days. If we need more time, we will tell you why, and we may take up to 45 more days. Requests are free. We may refuse requests that are clearly unfounded or excessive, and we will tell you why.
16.4 California “Shine the Light”
We do not disclose personal information to other companies for their own direct marketing.
16.5 Other U.S. states
If you live in another state with a privacy law, you may have similar rights. We will honor them as that law requires.
If we turn down your request, you can appeal. Reply to our answer with the word “Appeal”. We will answer within the time your state’s law sets, usually 45 to 60 days. If we still say no, you can contact your state’s attorney general.
16.6 Drivers, employees and job applicants
For Customer Data, your employer is in charge. Send your request to your employer. If you send it to us, we will:
- pass it to your employer within 5 business days and tell you we did;
- help your employer answer it.
If your employer stops using Hostler, it can still answer you from the export it took (section 15).
17. Children
Hostler is a business tool. It is not meant for anyone under 18, and we do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it. If you think a child’s information has reached us, email info@gethostler.com.
18. Where information is kept
Hostler is for carriers in the United States. We store information in the United States. Our AI provider stores what we send in the United States, but may run the model on servers in other countries (section 9). Some service providers, such as Apple and Google, which deliver notifications worldwide, may handle information in other countries under their own safeguards.
Hostler is not offered to people in the European Union, the United Kingdom or elsewhere outside the U.S.
19. Changes to this policy
When we change this policy, we change the “Last updated” date at the top.
Bigger changes. If a change is material, for example a new kind of data or a new use, we will tell customers’ Owners and Operations Managers by email, and in the app, at least 30 days before it takes effect.
Driver app changes. If the driver app starts collecting something new, we will:
- update its App Store and Google Play privacy labels first;
- ask you in the app, where the law or the app stores require it.
20. Contact us
Hostler
Email: info@gethostler.com
Privacy questions and requests go to the same email address. We read every message.