Effective date: May 31, 2026

This Privacy Policy explains how Haultin Inc., a Delaware corporation ("Haultin," "we," "us," or "our"), collects, uses, and shares information in connection with the Haultin platform and dashboard, our websites, and related services (collectively, the "Service").

This Policy describes how we handle information about the publishers and individuals who use the Service (our customers and their authorized users). It does not govern our processing of end-user data we collect from a customer's own websites on the customer's behalf — that processing is performed as the customer's service provider and is governed by the agreement and Data Processing Addendum between Haultin and that customer.

Information we collect

Account and identity information. When an account is created, we collect a name, email address, and authentication details. Authentication is handled by our identity provider, WorkOS; we receive the resulting user profile and a verification status.

Workspace information. The name of the workspace (organization), membership and role information, and related settings.

Connection credentials. When a Google Ad Manager account is connected, Google returns OAuth tokens that authorize the Service to access that customer's own Ad Manager data on the customer's behalf. These tokens are stored encrypted at rest. We do not receive a Google password.

Usage and product analytics. We collect information about how the Service is used — pages and features accessed, actions taken, session and device metadata, approximate location derived from IP address, and similar diagnostic data — through our analytics provider, PostHog. This is used to operate, secure, and improve the Service.

Communications and marketing preferences. Records of communications sent to or from us, support requests, and a record of whether consent to receive marketing and product-announcement email was given or withdrawn (including the date and version of the terms accepted).

Technical and log data. IP address, browser and device characteristics, request timestamps, and error and performance logs generated when the Service is used.

Cookies and similar technologies. A first-party session cookie is set to keep an account signed in. Our analytics provider may set first-party cookies or use local storage to measure usage. See Cookies and tracking below.

How we use information

We use the information described above to:

  • provide, maintain, authenticate access to, and operate the Service;
  • connect to and retrieve a customer's own advertising data from connected accounts at the customer's direction;
  • understand and improve how the Service is used, and develop new features;
  • communicate about the Service, including service, security, and transactional messages;
  • send marketing and product-announcement email, where consent has been given (consent can be withdrawn at any time);
  • detect, prevent, and respond to fraud, abuse, security incidents, and technical issues; and
  • comply with legal obligations and enforce our agreements.

Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases: performance of a contract (to provide the Service to an account holder); legitimate interests (to secure, operate, analyze, and improve the Service, balanced against individual rights); consent (for marketing email and any non-essential cookies, withdrawable at any time); and legal obligation (to comply with applicable law).

Cookies and tracking

We use a strictly necessary first-party cookie to maintain an authenticated session. We use PostHog for first-party product analytics, which may set cookies or use local storage to distinguish sessions and measure feature usage. Because the dashboard is an authenticated, first-party application, these are used in connection with a logged-in account and the processing described in this Policy. Browser controls can be used to block or delete cookies; blocking the session cookie will prevent sign-in.

How we share information

We do not sell personal information. We share information only as follows:

  • Service providers (sub-processors). We use the following providers to operate the Service. Each processes information only on our instructions and under contractual confidentiality and security obligations:
Provider Purpose
Cloudflare Hosting, edge compute, storage, and email delivery
Neon Managed Postgres database (identity, workspaces, consent records)
WorkOS Authentication and identity management
Google (Ad Manager) Access to a customer's own Ad Manager data via OAuth authorization the customer grants
PostHog Product and usage analytics
Ghost Marketing website, blog, and newsletter/announcement email (for individuals who opt in)
  • At your direction. Information shared with third parties because an account holder configured a connection or instructed us to do so.
  • Legal and safety. Where required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Haultin, our users, or others.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy.

Data retention

We retain account and workspace information for as long as an account is active and for a limited period afterward to satisfy legal, accounting, security, and dispute-resolution needs, after which it is deleted or anonymized. Connection credentials are retained until the connection is removed or the account is closed. Records evidencing marketing consent are retained for as long as needed to demonstrate compliance. Usage analytics and logs are retained for a limited, rolling period consistent with the providers above and our operational needs.

Security

We use technical and organizational measures designed to protect information, including encryption in transit, encryption at rest for sensitive credentials, access controls, and the use of reputable infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

International data transfers

We operate in the United States and use providers that may process information in the United States and other countries. Where information is transferred from the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses where required.

Your rights and choices

Depending on location, individuals may have the right to access, correct, delete, or receive a copy of their personal information, to object to or restrict certain processing, and to withdraw consent. Marketing email can be declined at any time using the unsubscribe link in any marketing message or by contacting us. To exercise any right, contact legal@haultin.com. We will respond as required by applicable law and will not discriminate against anyone for exercising these rights.

Note that for end-user data we process on a customer's behalf, requests should be directed to the relevant customer (the controller); we will assist that customer as required by our agreement with them.

United States state privacy rights

Residents of California and other U.S. states with comprehensive privacy laws have rights to know, access, correct, and delete personal information, and to opt out of the "sale" or "sharing" of personal information and certain targeted advertising. We do not sell personal information and do not share it for cross-context behavioral advertising. To exercise these rights, contact legal@haultin.com.

Children's privacy

The Service is a business tool intended for use by organizations and is not directed to children. We do not knowingly collect personal information from children. If we learn that we have collected such information, we will delete it.

Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice. Continued use of the Service after an update constitutes acceptance of the revised Policy.

Contact us

Haultin Inc. 7980 Michaelis St Greensboro, NC 27455 United States legal@haultin.com