Privacy Policy
Haul is a family chore tracker. Parents add kids, kids do chores, and Haul keeps the bookkeeping. We collect what we need to make that work — nothing more.
Last updated: August 24, 2026 · Effective date: August 24, 2026
1. The short version
- We don't sell your data. Ever. We don't run ads.
- Kids can't create accounts. A parent creates every kid profile, and the only things a kid can submit are chore activity: a done-tap and an optional preset note picked from fixed messages.
- We never move actual money. Wallet balances are bookkeeping records; parents pay kids out-of-band.
- You can export or delete your data. Email us and we'll handle it within 30 days.
- We never collect photos, video, or any images of kids. There is no camera, upload, or attachment anywhere in Haul.
- AI features send only anonymized stats — never your kids' names — to our AI provider.
2. Who runs Haul
Haul is operated by Trackside Software LLC, a Virginia limited liability company. If you need to reach us about anything in this policy — including data access, correction, or deletion requests — write to support@haul.family.
3. What we collect
From parents
- Account info from Clerk: your name and email when you sign up.
- Household info: name, rooms, pets, and any chore preferences you enter during Smart Start.
- Subscription info from Stripe: if you upgrade to Plus or Family, Stripe holds your payment details. Haul stores only the Stripe customer ID, subscription ID, and current plan tier. We never see or store your card number.
- Chore approval activity: which chores you approve, reject, and when.
About kids (entered by parents)
- First name or nickname (the form asks for no last names)
- Birthday (used to calculate age, set age-appropriate chores, and auto-update over time)
- Avatar color choice
- Optional payout handle (e.g., Venmo username) and method
- A 4-digit PIN the kid sets in person, used only to sign in. It travels only over encrypted connections, is hashed before storage, and is never stored or logged in raw form.
From kids directly
- The PIN they choose during their first sign-in (hashed before storage)
- Chore completion details: timestamp and an optional preset note (kids pick from fixed messages like “Ran out of supplies” — there is no free-text field on kid pages)
- Theme and cosmetic choices for their personal dashboard
- Charity preferences and payout requests
We don't ask kids for email, full name, location, contacts, or any other identifying info. Haul does not collect photos, video, or any other images of children. There is no camera, file upload, or attachment anywhere in the product — not on a kid screen, and not on a parent screen on a kid’s behalf. Chore completion is a tap, optionally accompanied by one of a handful of fixed preset notes.
Kid pages run without analytics. Our product-analytics tool is never loaded on kid-facing pages, so no analytics device identifiers, pageviews, or click events are collected from a kid’s browser session.
Automatically
- Standard request metadata: IP address, user agent, timestamps. Used for security, debugging, and rate limiting.
- Auth session cookies (Clerk for parents; an HMAC-signed cookie for kids).
4. How we use it
- To operate Haul: show your dashboard, track chore status, calculate wallet balances, send notifications.
- To send notifications: push notifications when chores are approved, rejected, or completed. You can disable these per device in Settings → Notifications. Notifications on a kid’s device are off by default for the whole household and only become available after a parent turns them on in Settings → Privacy (with its own recorded consent).
- To generate AI digests and Smart Start suggestions: we send structured, anonymized stats (chore counts, dollar amounts, ages, day-of-week patterns) to our AI provider, Anthropic. Kids are identified only by placeholder labels (“Kid-1”, “Kid-2”) in these requests; your kids' real names are substituted back on our own servers after the response returns. We never send kid names, ids, or notes to the AI provider.
- To process subscription payments: Stripe handles billing; we only see the result (plan tier and renewal status) via webhook.
- To enforce our Terms: investigate abuse, fix bugs, prevent fraud.
5. Who else sees it (sub-processors)
We use a small number of vendors to run Haul. Each handles a specific slice of data and operates under their own privacy policy:
- Clerk — parent authentication. Sees parent email + display name. clerk.com/legal/privacy
- Stripe — subscription billing for Plus / Family tiers. Sees parent payment details. stripe.com/privacy
- Neon — Postgres database hosting. Stores all household data, encrypted at rest. neon.tech/privacy-policy
- Anthropic — AI provider for Smart Start chore generation and the optional Weekly Digest. Receives only anonymized structured stats, never raw user content. anthropic.com/legal/privacy
- Vercel (or our hosting provider) — runs the web servers. Sees request logs.
- PostHog — product analytics on parent surfaces only. Never loaded on kid-facing pages; server-side kid activity counts are anonymized to a household identifier. posthog.com/privacy
- Sentry — error monitoring. Session replays are off, IP/cookie collection is disabled, large payloads are truncated before leaving our servers, and we don't attach kid identifiers to error reports. sentry.io/privacy
Future planned sub-processors (not yet active): Twilio for SMS reminders, Resend for email delivery, and Network for Good for charity payout processing. This policy will be updated and you'll be notified before any of these go live.
We do not use any advertising or social-media trackers in the Haul app, and we never sell data. We do use two operational tools: PostHog (product analytics — which features get used, so we can improve them; it is never loaded on kid-facing pages, kid activity counts are recorded server-side under an anonymous household identifier, never a kid’s name, and session recordings are disabled) and Sentry (error monitoring — crash reports with identifying details and large payloads scrubbed before they leave our servers).
6. Children's privacy (COPPA)
Haul is built with the assumption that kids on the platform are between ~6 and 17 years old, and that a parent is the verifiable adult who creates and manages each kid's profile. This is why our kid auth flow uses a parent-issued sign-in link and a kid-set PIN instead of email-based sign-up.
Kids do use Haul directly — marking chores done, picking an optional preset note — so we treat Haul as a service covered by COPPA and operate with verifiable parental consent: only a parent can create a kid profile, every kid signs in with a PIN set up through a parent-issued invite link, and the parent consents to our collection practices when creating the household (we record the date and policy version of that consent). The profile information itself — first name or nickname, birthday, avatar — is supplied by you, the parent; we ask for a first name or nickname only, never a last name.
Anything that collects more than the basics is off until a parent turns it on. Kid-device push notifications are a household-level opt-in in Settings → Privacy. Each one shows exactly what it collects before it can be enabled, records the date, version, and consenting parent when turned on, and can be turned off again at any time (turning off kid notifications also deletes existing kid-device registrations).
We collect no more information from kids than is reasonably necessary to run the service, we never use kids’ information for advertising or sell it.
As a parent, you can at any time:
- View what information we have about your kid (it's all on the family settings screen and their wallet/activity pages)
- Edit or delete any kid profile from Settings → Family — deletion is immediate and permanent (profile, wallet, badges, device registrations), and the notes on their chore records are scrubbed in the same step
- Note: removing a kid during a Smart Start re-run archives the profile instead (so you can restore it later from Settings → Family). Archived kids can't sign in and their device registrations are deleted; use Settings → Family to delete an archived profile permanently
- Delete your entire household — which removes all kid profiles, wallet history, and chore data — by emailing us
There are no images to worry about. Haul used to offer an optional chore photo-proof feature; it was removed entirely in August 2026, before public launch, along with the database columns that stored it. Haul collects no photos, video, or images of children, and has no facility to do so.
7. We do not move money
Critically: Haul does not transfer, escrow, or hold actual money. Kid "wallets" are bookkeeping records of approved chore earnings. When a kid requests a payout, Haul simply notifies the parent — the parent then sends the actual money via Venmo, PayPal, Zelle, Apple Cash, cash, or whatever method they prefer. Marking a payout "sent" in Haul is just a bookkeeping entry; the underlying transfer happens outside Haul.
Charity donations follow the same pattern: Haul records the kid's intent to donate a portion of their earnings, but the actual donation is currently the parent's responsibility. (A future integration with Network for Good will let parents donate through Haul; we'll update this policy and ask for your consent before that goes live.)
8. Data retention
We keep children’s personal information only for as long as is reasonably necessary to provide the service it was collected for, and we delete it when it is no longer needed for that purpose — or sooner, if a parent asks us to. We do not retain children’s personal information indefinitely. The table below is our written retention policy, by type of data.
| What we hold | Why we keep it | How long we keep it |
|---|---|---|
| Child profile — first name or nickname (no last names), birthday, avatar, hashed PIN | To run the kid’s account and sign-in | Until the parent deletes the profile or household; then permanently deleted within 30 days. |
| Chore activity & earnings ledger — completions, approvals, balances, streaks, badges, cosmetics | Core bookkeeping and the kid experience | While the household account is active; deleted with the household within 30 days. |
| Optional contact fields — payout handle (e.g. a Venmo username, if you add one) | Payout / reminder features a parent opts into | Until the parent removes them or deletes the profile or household. |
| Parent account info — name, email, Stripe customer/subscription IDs, plan tier | Account, billing, and support | While the account is active; deleted within 30 days of household deletion. Stripe keeps its own billing records as financial-record law requires. |
| Security & request metadata — IP, user agent, auth session cookies, rate-limit counters | Security, abuse prevention, debugging | Session cookies are cleared at sign-out (kid sessions also auto-expire after 30 days at most); operational logs are rotated on a rolling basis (typically within 30–90 days). Device user-agent stored with a push registration follows the push-token row below. |
| Product analytics & error reports — PostHog, Sentry | Reliability and product improvement | Kid-side events are recorded under an anonymous household identifier, never a kid’s name. Retained for each provider’s standard period (see the sub-processor links in Section 5), then deleted or aggregated. |
| Weekly digest snapshots (per-kid stats + AI-written recap) | The Weekly Digest feature (paid plans) | Aged out automatically after ~13 months; a kid's entries are scrubbed from stored digests when their profile is deleted. |
| Marketing waitlist (email address, signup source, browser user-agent) from haul.family | To invite you when access opens | Until you're invited or ask us to remove you (email us). |
| Push-notification tokens | To send the reminders you turned on | Until the device unsubscribes or notifications are turned off, with an automatic sweep of registrations unused for a year (the stored device user-agent goes with them). Kid-device tokens exist only if a parent enabled kid notifications, and are all deleted immediately when that setting is turned off. |
When a parent deletes a child’s profile, or deletes the entire household, every record tied to that child — profile, ledger, streaks, and badges — is permanently deleted within 30 days. A parent can request deletion at any time by emailing support@haul.family, and we respond within 30 days. Some records may be retained longer only where the law requires it (for example, Stripe billing records we don’t control directly).
9. Security
- All traffic is encrypted with HTTPS / TLS.
- Database is encrypted at rest by our hosting provider.
- Kid PINs are hashed with an industry-standard salted key-derivation function (scrypt) — never stored or logged in raw form.
- Kid session cookies are HMAC-signed so they can't be forged.
- We do not store payment card numbers. Stripe handles all payment details.
No system is perfectly secure. If we discover a breach affecting your data, we'll notify you within 72 hours of becoming aware, following the standards required by applicable state laws.
10. Your rights
Depending on where you live, you have some or all of these rights:
- Access — request a copy of the data we have about you and your household
- Correction — fix anything that's wrong
- Deletion — ask us to delete your household and all associated data
- Portability — get your data in a machine-readable format (we'll add a self-serve export in a future release; in the meantime, email us)
- Opt out of sale — we don't sell data, so there's nothing to opt out of, but California residents specifically have this right under CCPA
To exercise any of these rights, email support@haul.family. We'll respond within 30 days.
11. Where Haul operates
Haul is a United States service. It is operated from the US, its hosting and sub-processors are US-based, and all data is stored and processed in the United States.
We offer Haul only to households located in the United States. We do not offer, direct, or market the service to users in the European Union, the United Kingdom, or anywhere else outside the US, and we don't knowingly collect personal information from people outside our service area. If we learn that an account is outside the US, we may close it and delete its data. If we expand to other countries in the future, we'll update this policy and notify account holders before collecting data under different rules.
12. Changes to this policy
We'll post any material changes to this page and bump the "Last updated" date. For substantive changes (new data we collect, new vendors, new uses), we'll notify parent account holders — with an in-app notice, and by email where we have an email channel set up — at least 30 days before changes take effect. Changes that materially expand what we collect from kids trigger a fresh parental-consent prompt.
13. Contact
Questions, requests, complaints, or just wanting to talk to a human: support@haul.family.