Privacy Policy
Version 1.2 · Effective 2026-08-18
RateMyDOT is operated by HahaTech LLC at ratemydot.com. Questions about this policy or your data go to support@hahatech.team or by mail to 4640 Lucerne Lakes Blvd W, Apt 101, Lake Worth, FL 33467. We do not operate a phone line for privacy requests, deliberately. See “How to reach us” below.
Two things we can't do, and why.
We can’t show you your own reviews. We do not store an account identifier, email address, or user ID on a review. The capability token shown after submission is the only route back to that review, and it is not attached to your account. Your account data export therefore will not contain your reviews.
Deleting your account doesn’t delete your reviews. For the same reason: we don’t know which ones are yours. Deleting your account removes the active account record. A deleted record may remain temporarily in encrypted backups until those backups rotate out, as described in our privacy policy. Your reviews stay published without an account link.
The only key is the one we show you once. When you submit a review we give you a one-time capability token. Save it. If you lose it, that review can never be edited or withdrawn, by you, by us, or by anyone claiming to be you. That’s the trade: the lookup that would let us recover it is the same lookup a court could compel.
How to reach us about your data
You can make a privacy request three ways. This covers access, deletion, correction, portability, opt-out, limiting sensitive data use, and appeals. The three are our webform, email to support@hahatech.team, or written request to our postal address above. We do not publish or operate a phone number for privacy requests. RateMyDOT is an online-only business with a direct relationship to the drivers whose data it holds; under the CCPA regulations (Cal. Code Regs. tit. 11, § 7020(c)) that combination lets us satisfy the statutory intake obligation with an email address alone. A staffed phone line would also be an uncontrolled re-identification surface. A caller’s number, voice, and volunteered details are exactly the kind of identity data this policy exists to never collect. We acknowledge webform creates an auditable reference but does not collect contact details; send that reference by email or mail if you need a response. We acknowledge every request that includes a response channel within 10 business days and substantively respond within 45 days (extendable once, by 45 days, with written notice). Every denial or partial denial names the specific legal exception we relied on.
Product analytics
RateMyDOT uses PostHog to measure, anonymously, how the site is used. It counts which pages are visited, which searches run, and how many people complete actions like filing a report. Your IP address is discarded at ingestion and never stored with analytics events. We never connect analytics to your account or email, never record your screen or keystrokes, and never sell or share analytics data. On account, report, and letter pages, analytics events are stripped of the referring page and any query string. No analytics event contains report content, letter content, or the carrier number a report names. We do not use analytics to trace a report back to a person. If your browser sends the Global Privacy Control or Do Not Track signal, analytics does not load at all.
Global Privacy Control
We honor the Global Privacy Control (GPC) signal nationally, not only in states that require it. RateMyDOT does not sell or share personal information for targeted advertising. If your browser exposes GPC, product analytics is disabled entirely. If your browser exposes GPC while you are signed in, the preference is also recorded against the account and cannot be downgraded by a later session without the signal.
Cookies and browser storage
RateMyDOT uses no advertising cookies, tracking pixels, or social-media embeds. PostHog analytics stores an anonymous identifier in your browser. It is not tied to your account, and it is never set when your browser sends GPC or Do Not Track. The pre-launch preview gate uses one strictly necessary HTTP-only cookie. Account sessions and one-time review capability tokens are stored locally in your browser so the site can provide the function you requested. The names, purposes, lifetimes, and controls are listed in our Cookie and Browser Storage Notice.
How long we keep things
RateMyDOT does not request or store employment documents, payroll records, or banking information. Privacy-request and consent records are kept for 24 months unless a legal hold applies. RateMyDOT does not enable web access logs. Anonymous product analytics (see “Product analytics” above) is held by PostHog under its retention schedule and contains no account identity, review content, or letter content. Infrastructure providers may keep limited security and operational records under their own controlled retention schedules; they are listed on the subprocessor page. A deleted account may remain in an encrypted backup until that backup rotates out. A restored backup must be re-purged before ordinary production use. We do not shorten an established schedule while a dispute is reasonably anticipated.
What this policy will never say
This policy does not contain, and will never contain, a clause broadly reserving our right to disclose your information at our discretion. We can only disclose what we hold, and by design we do not hold a link between your account and anything you’ve written. We also don’t use the words “verified,” “anonymous,” or “deleted” to describe anything this system doesn’t literally do.
See also our no-reidentification commitment and the list of vendors who process data on our behalf.
