Privacy Policy
Effective August 20, 2026
Who we are
TruckDesk is operated by The Truck Desk LLC, a Georgia limited liability company (“TruckDesk”, “we”, “us”). We provide accounting software for small trucking fleets at thetruckdesk.com (driver settlements, bookkeeping, and IFTA filings). This policy explains what information we collect, why, who touches it, and what you can ask us to do with it. For anything this page doesn’t answer, write to support@thetruckdesk.com.
It covers three groups: visitors to our website, the trucking companies that use TruckDesk (“customers”) and their staff, and the drivers and other people whose information a customer stores in TruckDesk.
Information we collect
Account information. Your name, email address, and password (stored as a hash by our authentication provider, Supabase). If you sign in with Google, we receive your name, email, and profile picture from Google, nothing else.
Company information. Business details you enter: company name, entity type, EIN, address, phone, MC/USDOT numbers, insurance details, and pay-period settings.
Driver records your company enters. TruckDesk is a back-office tool, and carriers keep driver qualification records in it: name and contact details, date of birth, hire date, CDL number and expiry, DOT medical certificate (including the document itself), drug and alcohol test dates and results, employment attributes such as felony-record, citizenship, and military-base-access flags, emergency contact details, pay arrangements, and language preference. Several of these are sensitive categories, we treat all driver records with the protections described under Security, and we never use them for anything except providing the service to your company.
Financial information. If you connect a bank or card through Plaid: institution name, account names, types, and last-four masks, and transaction history (dates, amounts, merchants). If you upload statements: the statement PDF and the transactions extracted from it, including cardholder names printed on fleet-card statements. Plus the settlements, advances, and deductions you create in the product.
Business documents and operations data.Rate confirmations, proof-of-delivery and related documents, load details including your customers’ names and pickup/delivery addresses, invoices, and (when you connect an ELD such as Motive) per-vehicle, per-state mileage and fuel purchase records.
Automatically. Only what sign-in requires: authentication cookies (strictly necessary, they keep you logged in). We run no analytics, no advertising trackers, no session recording, and no third-party marketing pixels. Your theme preference is stored in your own browser.
How we use information
- To provide the service: computing settlements, keeping books, preparing IFTA figures, generating invoices and statements.
- To operate accounts: sign-in, security, support, and service emails (we send no marketing email).
- To protect the service: enforcing tenant isolation and investigating abuse.
Document processing with AI
When you upload a bank or fuel-card statement, the PDF is sent to Anthropic’s Claude API, which reads it and returns the transactions for your review before anything is saved. Rate confirmation PDFs are processed the same way to pre-fill load details, and transaction descriptions are sent for expense categorization. Under Anthropic’s commercial terms this data is not used to train models. You always review extracted data before it enters your books. In the product this assistant is called Truckie.
Service providers
We use a small set of providers to run TruckDesk, each receiving only what its job requires:
- Supabase: database, authentication, and file storage (hosted in the United States).
- Vercel: application hosting.
- Plaid: bank and card connections (see below).
- Anthropic: document extraction and transaction categorization, as described above.
- Mapbox: geocoding and routing of load pickup/delivery addresses for maps and mileage.
- Motive (if you connect it): we retrieve your fleet’s mileage and fuel data from your Motive account; we send Motive no personal data.
- Google (if you choose Google sign-in): authentication only.
Bank connections and Plaid
TruckDesk uses Plaid Inc. to connect your financial accounts. When you connect an account, you grant TruckDesk and Plaid the right, power, and authority to access and transmit your information as reasonably necessary to provide the service, and you acknowledge that information you provide through Plaid will be treated in accordance with Plaid’s End User Privacy Policy. Plaid access tokens are encrypted (AES-256-GCM) before storage, and disconnecting a bank revokes the connection at Plaid and destroys the stored token.
Driver data: whose responsibility is what
Driver records in TruckDesk are entered and controlled by the trucking company that employs or contracts the driver. For that data, the company is the data controller and TruckDesk processes it on the company’s behalf and instructions. Companies are responsible for their own legal obligations to their drivers including notice, consent where required, and federal record-keeping rules (for example, DOT drug-and-alcohol testing and driver qualification file requirements). Drivers with a portal login can see only their own settlements, loads, and documents. They never see another driver’s data, the company’s financials, or any credentials. If you are a driver with questions about your data, start with your carrier; you can also contact us at support@thetruckdesk.com.
Security
All traffic is encrypted in transit (TLS) and stored data is encrypted at rest by our infrastructure providers. Bank access tokens and connector API keys carry an additional layer of application-level AES-256-GCM encryption. Every customer’s data is isolated by row-level security enforced in the database itself; documents live in private storage accessible only through short-lived signed links; and secrets never reach the browser. No method of transmission or storage is 100% secure, but if we learn of a breach affecting your data we will notify you without undue delay.
Retention and deletion
We keep your data for as long as your account is active. In the product you can delete individual records, undo a statement import, remove uploaded accounts, delete loads, invoices, and driver records (deleting a driver also deletes their medical certificate document). Disconnecting a bank stops syncing and revokes access but keeps the imported history in your books until you delete it.
To delete your account and its data entirely, email support@thetruckdesk.com and we will complete the deletion without undue delay. Two honest caveats: records that the law requires your business to keep (tax records, DOT driver files) are yours to export and retain before deletion, and finalized settlement statements already issued to drivers may be retained where required for legal compliance.
Your rights
Regardless of whether a specific privacy statute applies to your state, we honor the same baseline for everyone: you can request access to the personal information we hold about you, correct it, receive a copy (the product exports transactions, settlements, reports, and IFTA data as CSV, and we will provide a fuller export on request), or delete it. Email support@thetruckdesk.com; we will verify the request and respond within 30 days. We never sell personal information, so there is nothing to opt out of.
Other things you should know
- TruckDesk is a business tool for people 18 and over; we do not knowingly collect information from children.
- Data is stored and processed in the United States.
- Emergency contacts entered by your company are stored solely so your company can reach them; we never contact them.
- If we make material changes to this policy we will update the date above and notify account owners by email or in the product.
Contact
The Truck Desk LLC (dba TruckDesk) · support@thetruckdesk.com