Hayes Recruiting Hub

    Privacy Policy

    Last updated: August 21, 2026

    This Privacy Policy explains how Hayes Recruiting Hub LLC ("Hayes Recruiting Hub", "we", "us", "our") collects, uses, discloses, and safeguards personal information when you visit our website, when CDL drivers and other applicants apply for jobs through our platform, when carrier and recruiting-agency customers use our marketing and applicant-tracking tools, and when prior employers or background-check vendors interact with us for verification purposes.

    Summary

    • We collect the personal information needed to evaluate driver applications, run DOT-required verifications, operate the platform, and market our services.
    • Sensitive identifiers (date of birth, SSN, license number, medical card, drug-test history) are encrypted, role-restricted, and audit-logged on every access.
    • We do not sell personal information and we do not share it for cross-context behavioral advertising.
    • AI voice and chat agents identify themselves as artificial. No fully-automated adverse hiring decisions are made without human review.
    • You have rights to access, correct, delete, port, and limit use of your data. Submit a request at our data-subject request page.

    1. Who this applies to

    This policy covers four audiences:

    • Applicants & drivers who submit applications, complete consents, or speak with our AI agents.
    • Carrier and recruiting-agency customers who license the platform.
    • Recruiter, vendor, and client-portal users who hold an account.
    • Website visitors who browse our marketing pages.

    It does not cover the independent privacy practices of the carriers, background-check vendors, DMV agencies, or job boards (e.g., ZipRecruiter, Indeed) we interact with. Their own privacy notices apply to data they collect directly.

    2. Our role — controller and service provider

    For our marketing site, our own staff accounts, and information we collect directly from website visitors, we act as a business / controller.

    For applicant data submitted to a specific carrier or recruiting agency through our platform, we act as a service provider / processor under CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA and similar laws. We process that data only on the documented instructions of the carrier or agency (the "Customer"), under contractual obligations restricting our use, retention, sale, and sharing of personal information. The Customer is the controller for that data and is responsible for the lawful basis to collect it, applicant-facing notices specific to the Customer, and adverse-action decisions. We support the Customer in responding to data-subject requests they receive.

    3. Information we collect

    3.1 Application & driver-qualification data

    • Name, contact information, mailing and physical addresses.
    • Work history, prior employers (DOT-regulated and non-regulated), positions, dates, equipment operated, accidents, terminations.
    • CDL information — class, endorsements, restrictions, issuing state, expiration, license number.
    • Driving record (MVR), Pre-Employment Screening Program (PSP) data, Drug & Alcohol Clearinghouse query results.
    • Medical examiner's certificate, exemption letters, SPE certificates.
    • Education, military service, references.

    3.2 Sensitive personal information

    • Date of birth.
    • Social Security Number (in full only when handed off to a background-check provider; otherwise last four digits).
    • Government-issued ID and driver-license numbers.
    • Drug- and alcohol-testing history.
    • Criminal-history information disclosed for FCRA-permissible employment purposes only and subject to state ban-the-box and fair-chance laws.
    • Limited health information necessary for DOT medical certification.

    3.3 Communications & consent records

    • SMS, voice, and email messages exchanged with our AI agents and human recruiters.
    • Call recordings and AI transcripts where consent has been obtained.
    • TCPA, FCRA, DPPA, drug-testing, and other written authorizations, with timestamps, IP, and user-agent for evidentiary purposes.

    3.4 Account & identity data (staff and customer users)

    • Email, full name, employer, role, multi-factor-authentication factors.
    • Authentication metadata, MFA enrollment, session and login history, trusted-device tokens.

    3.5 Marketing & technical data

    • IP address, device, browser, language, referring URL, pages viewed, clicks, time on page.
    • Strictly necessary, functional, and analytics cookies and similar technologies.
    • UTM parameters and source-attribution data (including ZipRecruiter click identifiers) used to measure ad performance.

    4. Where we get it

    • Directly from you — through application forms, consent flows, account signup, voice and chat conversations, or support requests.
    • From our Customer (the carrier or recruiting agency) — account provisioning data, applicant referrals, hiring outcomes.
    • From background-screening vendors — consumer reports and investigative consumer reports we order on the Customer's behalf with your written authorization.
    • From government sources — State DMVs (under DPPA), the FMCSA Pre-Employment Screening Program, the FMCSA Drug & Alcohol Clearinghouse.
    • From prior employers — DOT-required safety performance history under 49 CFR §391.23.
    • From job boards — ZipRecruiter, Indeed, TheTruckReport, and other syndication partners forward applications and click data.
    • From integration platforms — e.g., Gmail when a recruiter connects an inbox to the platform.
    • From cookies and analytics on our marketing site.

    5. How & why we use it

    We use personal information for the following purposes and on the following legal bases:

    • Application processing — to evaluate fit for a position with the Customer (legitimate interest / performance of a pre-contract request).
    • DOT compliance — driver-qualification files (49 CFR §391.51), drug & alcohol testing (49 CFR Parts 40 & 382), Clearinghouse queries (49 CFR §382.701), safety-history requests (49 CFR §391.23) (legal obligation).
    • FCRA permissible purpose — ordering and using consumer reports for employment purposes (15 U.S.C. §1681b(b)) (consent + legal obligation).
    • DPPA permissible use — obtaining MVRs (18 U.S.C. §2721(b)(1) & (10)) (consent + legitimate interest).
    • Service operation — account management, security, fraud prevention, audit logging, analytics, debugging (legitimate interest).
    • Communications — transactional and operational messaging about your application or account (legitimate interest); marketing calls, AI calls, SMS, and emails (consent under TCPA / CAN-SPAM).
    • Marketing the platform to carrier and agency prospects (legitimate interest, with opt-out).
    • Legal claims and obligations — responding to subpoenas, defending claims, complying with retention rules (legal obligation).

    6. AI processing & automated tools

    The platform uses artificial intelligence in several ways: AI voice agents call applicants for screening and interview booking; AI transcribes and summarizes calls; generative AI helps recruiters draft job descriptions, ad creative, and outbound messages; and AI assists with applicant-pipeline analytics.

    • AI agents identify themselves as artificial at the start of every interaction, in compliance with the FCC's 2024 declaratory ruling treating AI-generated voices as "artificial" under the TCPA, the FTC's Impersonation Rule, and state AI-disclosure laws including California SB 1001 / AB 2013, Utah AI Policy Act (S.B. 149), Colorado AI Act (S.B. 24-205), Texas TRAIGA, and Illinois HB 3773.
    • You may request to speak with a human at any time during an AI interaction.
    • We do not use AI to make a final hiring decision that produces legal or similarly significant effects without meaningful human review by a recruiter or carrier.
    • For AI-assisted employment-decision tools subject to the New York City Automated Employment Decision Tool law (NYC Local Law 144), the Customer is responsible for any required bias audit and candidate notice; we provide tooling and documentation to support compliance.
    • Call recordings and transcripts are used for quality, training, fraud prevention, and compliance, and are protected with the same access controls as other sensitive data.

    7. Communications, TCPA & call recording

    Where we (or our Customer) send marketing or recruiting calls, AI calls, or SMS/MMS to you using an autodialer, an artificial or prerecorded voice, or an AI-generated voice, we obtain your prior express written consent as required by the Telephone Consumer Protection Act (47 U.S.C. §227) and the FCC's implementing rules. Consent is never a condition of employment or of being considered for any position.

    7a. SMS privacy notice

    Applicants may opt in on our public careers and application pages by entering their mobile phone number and actively selecting an optional SMS/calls consent choice that is not selected by default. Applicants can submit the application whether they agree or decline. The disclosure names the carrier and Hayes Recruiting Hub, describes recruiting/application follow-up messages, states that message frequency varies, that message and data rates may apply, that HELP and STOP are supported, and links to this Privacy Policy and our SMS Terms.

    No mobile information, phone numbers, messaging consent records, SMS opt-in data, or text-messaging originator opt-in data will be shared with any third parties or affiliates for marketing or promotional purposes. Mobile opt-in data and consent are not sold, rented, shared, or transferred to any third party or affiliate under any circumstances.

    • Reply STOP to any text to opt out, or tell the agent or recruiter to stop. Reply HELP for help. Standard message and data rates may apply.
    • Email opt-outs are honored per the CAN-SPAM Act (15 U.S.C. §7701). Every marketing email includes the sender's identity and physical postal address and a working unsubscribe link.
    • State do-not-call and mini-TCPA statutes are honored, including the Florida Telephone Solicitation Act §501.059, Oklahoma Title 15 §775C.1, Maryland §14-3201, and Washington §80.36.400.
    • Calls and AI voice interactions may be recorded and transcribed where you have given consent. Recording is conducted in compliance with both one-party and two-party / all-party consent state laws, including California Penal Code §632, Florida §934.03, Illinois 720 ILCS 5/14-2, Maryland Cts. & Jud. Proc. §10-402, Massachusetts Ch. 272 §99, Pennsylvania 18 Pa.C.S. §5703, and Washington RCW 9.73.030.

    8. Sharing & disclosure

    We share personal information only as described below:

    • With the Customer you applied to (the carrier or recruiting agency) and its authorized recruiters.
    • With prior employers contacted for DOT safety-history verification, after your written authorization.
    • With background-check providers we order reports from on the Customer's behalf, including the full Social Security Number where required for the consumer-reporting agency to identify you. We do not retain the full SSN after the order is placed.
    • With government agencies — state DMVs, the FMCSA PSP, and the FMCSA Drug & Alcohol Clearinghouse, for the regulated purposes described above.
    • With sub-processors that operate the platform — cloud hosting, transactional email and SMS delivery, AI inference, error monitoring, analytics. Sub-processors are bound by written contracts limiting their use of the data to providing services to us.
    • For legal reasons — to comply with valid legal process, to enforce our Terms, to protect rights, property, and safety, and in connection with a corporate transaction (merger, acquisition, financing, asset sale) under appropriate confidentiality obligations.

    We do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioral advertising, in any sense those terms are defined under CCPA/CPRA, CTDPA, CPA, VCDPA, UCPA, TDPSA, OCPA, or similar laws.

    SMS / mobile opt-in data: No mobile information, phone numbers, SMS opt-in records, messaging consent records, or text-messaging originator opt-in data is shared with any third parties or affiliates for marketing or promotional purposes. Mobile opt-in data and consent are not sold, rented, shared, or transferred to any third party or affiliate under any circumstances. Mobile numbers are used only to deliver the recruiting messages the applicant requested, through messaging infrastructure sub-processors (e.g., Twilio) acting on our behalf under written contracts that prohibit any other use.

    9. Sub-processors

    Current categories of sub-processors include:

    • Cloud infrastructure & database — managed Postgres, object storage, and edge compute provider (U.S. region).
    • Authentication — identity provider for sign-in, MFA enrollment, and session management.
    • AI inference — third-party large-language-model and voice providers used through our AI gateway (no training of public models on your data).
    • Email & SMS delivery — transactional and recruiter-initiated messaging providers.
    • Background screening — consumer-reporting agencies engaged at the Customer's direction.
    • Job-board syndication — ZipRecruiter, Indeed, TheTruckReport, and similar platforms when the Customer enables them.
    • Analytics & error monitoring — first-party analytics for product usage and reliability.

    A current sub-processor list is available on request to privacy@hayesrecruitinghub.com.

    10. International transfers

    The platform is designed for U.S. operations and we process and store personal information in the United States. We do not knowingly accept applications from drivers outside the United States. If you access the platform from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different data-protection laws than your country.

    11. Cookies & tracking

    We use a small number of categories of cookies and similar technologies:

    • Strictly necessary — authentication, session, security (cannot be disabled).
    • Functional — remembering preferences, MFA trusted-device tokens.
    • Analytics — anonymized product-usage and reliability metrics.

    We do not set advertising or cross-site tracking cookies. We honor browser Global Privacy Control (GPC) signals as a valid opt-out of any sale or sharing of personal information for residents of states that recognize them.

    12. Retention

    • Driver-qualification files — for the duration of employment plus three years after the driver leaves the carrier's employ, as required by 49 CFR §391.51.
    • Drug- and alcohol-testing records — one to five years, per the schedule in 49 CFR §382.401.
    • Rejected applications — one year from the date of the application or as long as required by applicable EEO recordkeeping rules and state law (whichever is longer).
    • Consent and audit logs — at least the period of the underlying record they relate to.
    • Marketing data — until you opt out or for two years of inactivity, whichever is sooner.
    • Account data — for the term of the Customer's subscription plus a reasonable wind-down period for export.

    13. Security

    • All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
    • Sensitive fields (DOB, SSN, license number, government ID) are masked by default and require an explicit reveal action that is audit-logged with user, timestamp, IP, and reason.
    • Documents (resumes, employment-verification files) are stored in private object-storage buckets and served only via short-lived signed URLs.
    • Multi-factor authentication is required for staff and Customer-portal users. Sessions time out after a period of inactivity.
    • Authentication includes leaked-password screening against the Have I Been Pwned database.
    • Role-based access control limits each user to data they need to do their job. Row-level security is enforced at the database tier.
    • We maintain an incident-response plan and will notify affected individuals and applicable regulators where required by state breach-notification laws.

    14. Your privacy rights

    Depending on where you live, you may have one or more of the following rights with respect to your personal information:

    • Right to know / access what personal information we have about you and how we use it.
    • Right to correct inaccurate personal information.
    • Right to delete personal information, subject to legal-retention exceptions (DOT, FCRA, EEO, FMCSA).
    • Right to portability of your data in a structured format.
    • Right to opt out of the sale or sharing of personal information (we do not engage in either) and of targeted advertising (we do not engage in it).
    • Right to limit use of sensitive personal information beyond what is necessary to provide the service.
    • Right to non-discrimination for exercising your rights.
    • Right to appeal our denial of a request.

    These rights are provided under the laws of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Delaware, Iowa, New Jersey, New Hampshire, Minnesota, Tennessee, and Washington (My Health My Data Act), among others.

    To submit a request, use our data-subject request page or email privacy@hayesrecruitinghub.com. We will respond within 45 days (extendable by an additional 45 days where permitted). Authorized agents may submit requests on your behalf with proof of authorization. We may need to verify your identity before fulfilling sensitive requests.

    If we deny your request, you may appeal by replying to our denial. If we deny your appeal, residents of certain states may contact their state attorney general.

    For applicant data held on behalf of a Customer, please direct your request to that carrier or recruiting agency; we will support them in responding.

    15. Children

    The platform is not directed to and is not intended for individuals under 18 years of age (and not under 21 for interstate driving positions). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.

    16. Google API services (Limited Use)

    Hayes Recruiting Hub's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

    When a recruiter connects their Google Account to Hayes Recruiting Hub, we request access to the following Google Calendar scopes:

    • https://www.googleapis.com/auth/calendar.events — to create, read, update, and delete interview and call-back events on the recruiter's calendar so that scheduled driver interviews appear on the same calendar the recruiter already uses.
    • https://www.googleapis.com/auth/calendar.freebusy — to read free/busy windows so the public booking link only offers times the recruiter is actually available.

    How we handle Google user data:

    • We use Google user data only to provide and improve the user-facing scheduling features described above.
    • We do not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
    • We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
    • We do not allow humans to read Google user data unless we have the user's affirmative agreement for specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and used for internal operations in accordance with applicable privacy and other jurisdictional legal requirements.
    • Access tokens and refresh tokens are stored encrypted at rest and are scoped to the individual recruiter who authorized the connection. Recruiters can revoke access at any time from their Google Account permissions page or by disconnecting the calendar from inside Hayes Recruiting Hub.

    Google Ads

    Separately from Calendar, Hayes Recruiting Hub may request authorization to access Google Ads using the scope https://www.googleapis.com/auth/adwords. Google Ads access occurs only where the applicable Google Ads connection has been authorized for a carrier/client account, and we use it only to provide advertising management, reporting, attribution, recruiting-performance measurement, and related Hayes Recruiting Hub functionality. Our use of Google Ads API access is also subject to the applicable Google Ads API terms and policies in addition to the Limited Use commitment above.

    Google Ads data we may read. Where the connected account permits it, we read:

    • Google Ads customer/account identifiers and descriptive account names.
    • Manager (MCC) to client-account relationships and account status.
    • Campaigns, campaign status, and campaign/geographic targeting configuration.
    • Campaign budgets and budget amounts.
    • Ad groups and, where applicable, ad/creative configuration.
    • Keywords and keyword-planning/research results.
    • Search terms that triggered ads.
    • Performance metrics — impressions, clicks, spend/cost, conversions and conversion value — plus Google's own account recommendations.

    Actions we may take in the connected account. When explicitly authorized and enabled, Hayes Recruiting Hub may use Google Ads API access to:

    • Create or update advertising campaign configuration.
    • Create or update campaign budgets.
    • Create or update campaign, ad-group, and keyword settings.
    • Retrieve reporting and search-term performance data.
    • Submit recruiting conversion outcomes back to Google.

    Campaign-changing actions are gated by Hayes Recruiting Hub's own approval and spend-authorization controls: a campaign plan must pass our policy checks, be approved in-platform, and the account must be explicitly spend-authorized before anything other than a validation-only request is sent to Google.

    Recruiting conversion outcomes. Where the implemented Google measurement flow is enabled for an account, we send recruiting conversion outcomes to Google — landing-page view, application started, application submitted (measured on the website by the Google tag) and qualified applicant, recruiter transfer, and hired (sent as offline/CRM outcomes through Google's Data Manager API and Enhanced Conversions for Leads). Those uploads carry the Google click identifier where we have one and, where Enhanced Conversions for Leads is enabled for that account, normalized hashed (SHA-256) email and/or phone identifiers for matching. We do not send raw applicant contact details to Google as part of this conversion flow, and we do not send applicant resumes, driving records, or screening answers.

    Storage and retention. To provide reporting, attribution, and audit history we persist in our own database: Google Ads account and manager/client-account identifiers and connection state; campaign plans and their budget/targeting configuration; daily performance metrics; search-term rows; keyword-research runs; landing pages; attribution rows linking an ad click to a Hayes applicant; the conversion-outcome queue and its send status (including hashed identifiers only, never raw contact values in that queue); and an audit log of Google Ads actions taken through the platform. Creative previews and some live account lookups are read-through and shown without being stored. Our code does not define a fixed expiry for Google Ads-derived data: we keep it for as long as needed to provide the service and for legitimate accounting, billing-verification, dispute, and audit purposes, and we delete or de-identify it when it is no longer needed for those purposes or on a valid deletion request, subject to legal retention obligations.

    Credential security. Google OAuth refresh credentials for Google Ads are held server-side in our managed secret storage and are used only by our backend to obtain short-lived access tokens for authorized Google API requests. OAuth client credentials and Google Ads developer credentials are never delivered to browser clients, carrier users, or client-portal users, and are treated as confidential credentials with access limited to the systems and personnel that need them.

    Sharing and account visibility. Google Ads data is used to provide Hayes Recruiting Hub services. Authorized users for the applicable carrier/client can see the reporting, spend, and campaign information associated with their own account; our access controls are designed to keep one carrier's advertising data from being visible to another. We do not sell Google user data, and we do not transfer Google-derived data to unrelated third parties except as necessary to provide the service (for example our hosting and database infrastructure), to comply with applicable law, or as otherwise expressly disclosed in this policy — consistent with the Google API Services User Data Policy and the Limited Use requirements above.

    Revocation, disconnection, and deletion. You can revoke Hayes Recruiting Hub's access to a Google Account at any time from your Google Account permissions page. Where the integration is managed inside Hayes Recruiting Hub, an administrator can also remove the Google Ads account mapping and connection state for a carrier/client, and can ask us to remove the stored authorization credential. Once the credential is revoked or removed, no further Google Ads API requests can be made for that account, and campaign changes and conversion uploads stop. Disconnecting deletes the stored connection credential and account mapping; historical advertising, performance, attribution, conversion-queue, and audit records already written to our database remain, because they document spend and recruiting outcomes for accounting and audit purposes, until deleted under the retention practices described above or on request as permitted by law.

    17. Changes to this policy

    We will update this Privacy Policy from time to time. The "last updated" date at the top reflects the most recent revision. Material changes will be communicated through the platform or by email at least 30 days before they take effect, where reasonably practicable.

    18. Contact

    Privacy questions, data-subject requests, complaints, or requests for the current sub-processor list:

    Hayes Recruiting Hub LLC
    Attn: Privacy
    [Street address], [City], TX [ZIP]
    Email: privacy@hayesrecruitinghub.com
    Support: support@hayesrecruitinghub.com


    This document is a comprehensive starting draft prepared from current federal and state law as of the "last updated" date above. It is not a substitute for legal advice. If you are an enterprise customer, your signed master agreement controls over this online version. Please have qualified counsel review and confirm jurisdiction-specific edits and the corporate / registered-agent address placeholders before launch.