FreightPaperwork

Last updated 11 August 2026

Privacy Policy

The document generators run inside your web browser. If you are not signed in, shipper names, consignee addresses, freight descriptions, weights and every other value you type are never transmitted to us and never stored — close the tab and the data is gone. If you create an account and subscribe, that changes deliberately and only for you: saved addresses and the documents you generate are then kept on our server, because that is the feature being paid for. Both situations are set out below.

Who runs this site

FreightPaperwork publishes free freight document generators and reference guides for shippers, carriers, brokers and owner-operators. If you have a question about this policy or about how anything here works, write to hello@freightpaperwork.com.

What the document generators do with your data

Used without an account, nothing leaves your device. The bill of lading form is ordinary HTML, and the PDF is assembled by JavaScript running in your browser using a library called jsPDF. There is no server-side step, no upload and no queue. That applies to the bill of lading generator on the homepage and to every other document tool published here.

That is an architectural fact rather than a promise about our intentions. For anonymous use there is no store of shipment data to be breached, subpoenaed, sold or leaked, because none is created. You can verify it: open your browser's network tab and generate a document. No request carries what you typed.

The practical consequence is that we cannot help you recover a document generated that way. If you made a bill of lading last Tuesday and lost the PDF, we have no copy, no record that you visited, and no way to rebuild it. Save your downloads.

The paid plan exists precisely because some companies want the opposite of that, and it is covered next.

What an account stores

Accounts are optional. Every generator works fully without one. If you create an account, the following is held on our server, and the company — not the individual — is the unit that owns it. Everyone you invite can see all of it.

Data held in an account
WhatWhyKept until
Your name, email address and a hash of your password To sign you in and to send account email — verification, password resets, invitations. Passwords are stored as a one-way hash and cannot be read back, by us or by anyone with the database. You delete the account
Your company name, and the plan and its status To know what the subscription entitles the company to. You delete the account
Sign-in sessions To keep you signed in. Each one records the device's browser string and IP address so you can spot a session you do not recognise and sign it out. The session expires or is signed out
Saved parties — the shippers, consignees, carriers, facilities and brokers you save So your team stops retyping the same addresses. This is the paid feature. You delete them, or you delete the account
Document history — the field values behind every document generated while signed in on a paid plan, and who generated it So a document can be reopened, and so numbering can run in sequence. The PDF is not stored; the values it was built from are, which is what makes a reopened document editable. You delete the document, or you delete the account
Your logo, if an owner uploads one So it prints on the documents your company generates. The file you send is decoded and re-saved as a new PNG, so camera EXIF data — including the GPS coordinates a phone photo carries — is discarded rather than stored. It is kept outside the public part of the server and has no public address. You remove it, or you delete the account
An audit log of account actions Sign-ins, invitations, plan changes, logo changes and deletions, so an owner can see what happened to the company account. You delete the account

Documents generated before you signed in, or while signed out in a different browser, are not in the history. Nothing is retroactively collected.

We do not sell, rent or share any of it. We do not use the contents of your documents to train anything, to build a shipper directory, to benchmark rates, or for any purpose other than showing it back to your own company. Account data is not passed to the advertising described below.

Card numbers never reach this site. Payment is taken by Paddle as the seller of record, on their own checkout, and what comes back to us is a customer reference, the plan status and the renewal date.

Deleting a saved party or a document removes it from every view immediately and marks it deleted in the database, where it is purged on a routine cycle.

Three stronger options are self-serve, and none needs to go through us. An owner can download everything the account holds at any time, on any plan. Anyone can remove themselves from a company from their account page, which deletes their user, their password and their sign-ins while leaving the company's shared records for the colleagues still using them. An owner can close the whole account, which deletes everything in the table above — the rows are removed, not flagged, and the logo file is deleted from the server. There is no grace period and we cannot restore it afterwards.

One thing survives a closure, and it is not about you: the record that a payment message arrived. Those rows are kept with the company reference removed and the contents emptied, because their unique key is what stops Paddle re-processing a repeated message. They hold no personal data once an account is closed. Paddle keeps its own invoice records as the seller of record, under its terms rather than ours.

What is stored on your device

One item if you never sign in, and two more once you do:

Data stored in your browser
NameTypePurposeLifetime
fd-consent Local storage Remembers whether you accepted or declined advertising cookies, so the banner does not reappear on every page. Until you clear your browser storage
fd_session Cookie Keeps you signed in. Set only when you sign in. Marked HttpOnly and SameSite=Lax, so it cannot be read by JavaScript and is not sent from other sites. You sign out, or 30 days
fd_csrf Cookie A security token that proves a form submission came from a page on this site rather than from somewhere else. Contains no information about you. The browser session

We use local storage rather than a cookie for the consent choice deliberately: a cookie would be sent to the server with every single request, and there is no reason for that choice to travel anywhere. The two account cookies are strictly necessary — they exist only to sign you in safely and are not used for measurement or advertising.

Third parties

Three services outside this domain are involved in serving the site. Each of them, by the nature of an internet request, will see your IP address when your browser contacts them. Only one — the PDF library — is involved at all if you never create an account.

Third-party services and what they receive
ServiceWhat it doesWhen it loads
Google AdSense Serves the display advertising on the free tier. Google may set cookies and use them to measure and personalize ads, subject to your consent choice. Only after you accept advertising cookies, and never at all if you are signed in on a paid plan — the tag is not put in the page, so nothing is requested. Declining leaves ad storage, ad personalization and ad user data switched off.
Paddle Takes payment for the paid plan and is the seller of record for it. Card details are entered on Paddle's own checkout and never reach this site. Loaded only on the billing page inside an account. Only when a signed-in account owner opens the billing page. Never on the free generators or the guides.
cdnjs (Cloudflare) Hosts the jsPDF library the generators use to build the PDF. Your browser downloads roughly 400 KB of JavaScript from it. No shipment data is sent — the request only asks for a file. The first time you use a document generator on a page, or shortly after that page finishes loading.

The jsPDF request is loaded with a Subresource Integrity hash, which means your browser refuses to run the file if a single byte of it differs from the version this site expects.

We do not use an analytics platform, a tag manager, embedded video, social media widgets, live chat, heatmaps or session recording. There are no tracking pixels on this site.

Advertising and measurement storage is set to denied by default, before any tag can run, using Google Consent Mode v2. Nothing is granted until you choose to grant it. Declining is a real option — every generator, guide and download on this site works identically either way.

Signed in on a paid plan you will not see the banner at all. No advertising is served to subscribers, so the only cookies left are the session and CSRF pair described above, both strictly necessary and neither requiring consent. A banner asking permission for something that cannot happen would be theatre.

You can change your mind at any time using the Cookie settings link in the footer of every page.

Server logs

Like every website, this one runs on a web server, and that server keeps standard access logs: IP address, the page requested, the time, the browser's user agent string, and the referring page if there is one. Our hosting provider generates these as part of operating and securing the server. We do not use them to build profiles, we do not combine them with anything else, and we do not sell them.

Your rights

If you have never created an account, most data subject requests still have a short answer: there is nothing about you to access, correct, export or delete. The exceptions are the consent value in your own browser storage, which you can clear yourself at any time, and the hosting provider's server logs.

If you do have an account, the data listed under what an account stores is yours. Your name, email and password are editable from your account; saved parties and document history can be deleted from their own pages, whatever plan you are on, and edited while a plan is active; and we can be exported in full by an owner, as a zip with the saved addresses as a spreadsheet — no request to us, no waiting. Deletion is self-serve too: leaving a company removes you, and closing the account removes everything. Note that saved parties and documents belong to the company, so leaving does not take away records colleagues rely on — if you want those gone too, close the account instead.

If you are in the EU or UK, the GDPR gives you rights of access, rectification, erasure, restriction, portability and objection. If you are a California resident, the CCPA and CPRA give you rights to know, delete, correct and opt out of sale or sharing of personal information. We do not sell or share personal information as those terms are defined. To exercise any right, or to ask what we hold, email hello@freightpaperwork.com.

Google's own handling of advertising data is governed by its policies, which you can read at how Google uses information from sites that use its services.

Children

This site is a business tool for the freight industry. It is not directed at children, and we do not knowingly collect information from anyone under 13.

Changes to this policy

If we add a service that changes what leaves your browser, this page gets updated and the date at the top changes with it. The paid plan was the last such change, and it is described in full above rather than buried in a clause. Material changes to how advertising works will also reset the consent banner so you can make a fresh choice.

Contact

Questions, corrections and complaints: hello@freightpaperwork.com. If you want to see how the document generation works rather than take our word for it, the JavaScript is served unminified at /assets/js/pdf-engine.js and you are welcome to read it.