Privacy Policy
This policy explains how CargoFlow handles account, logistics, security, and Google Workspace data when the application is used for import and freight operations.
1. Scope
CargoFlow is an operations application used to manage logistics work, shipment records, tasks, documents, carrier integrations, and related team activity. The organization that provides your CargoFlow account controls its business records and determines who may access them.
This policy describes CargoFlow's current technical handling of information. Your employer or deploying organization may have additional privacy, retention, security, or records-management requirements.
2. Information CargoFlow processes
- Account and security information. Name, email address, role, account status, authentication and multi-factor authentication information, security events, and account activity needed to protect access.
- Logistics and business records. Shipment references, bills of lading or airway bills, container numbers, purchase orders, customers, carriers, milestones, tracking information, operational notes, tasks, approvals, billing/workflow information, documents, and audit history entered or generated while using CargoFlow.
- Technical information. Request and error information needed for security, troubleshooting, reliability, and system health.
- Appearance preferences. A saved theme preference may be stored for the signed-in CargoFlow user and cached locally in the browser.
3. Google Workspace and Gmail Carrier Inbox
CargoFlow requests only the Gmail read-only scope for the Carrier Inbox feature. CargoFlow cannot send, delete, edit, label, archive, or otherwise modify messages in the connected Gmail mailbox.
When an Administrator connects the shared Gmail inbox, CargoFlow may process the connected Google account email address, OAuth connection status, an encrypted OAuth refresh token, and message data needed to identify likely carrier replies. For likely matches, this may include Gmail message and thread identifiers, sender name and email, subject, received time, a limited text preview, matching confidence/reason, and the Administrator's classification or summary.
Gmail access is used only to provide the Carrier Inbox carrier-reply workflow. A detected message does not automatically change a carrier onboarding status. An authorized CargoFlow Administrator must review and classify it.
Google API data restrictions
- Google user data is not sold.
- Google user data is not used for advertising or ad targeting.
- Google user data is not used to train a general-purpose artificial intelligence or machine-learning model.
- Access is limited to the functionality described above and is designed to follow the Google API Services User Data Policy, including applicable Limited Use requirements.
4. How information is used
CargoFlow uses information to operate shipment and carrier workflows, provide tracking and alerts, support team collaboration, secure accounts, maintain audit history, connect approved carrier or Google services, troubleshoot errors, and improve the reliability of the application.
5. Storage and security
CargoFlow uses role-based access controls and server-side authorization to restrict business data. Administrator access uses multi-factor authentication. Authentication sessions use secure cookies. Sensitive Gmail refresh tokens are encrypted before being stored.
No security measure can guarantee absolute protection. Users should protect their passwords and authentication devices, sign out on shared devices, and report suspected unauthorized access to their CargoFlow Administrator.
6. Sharing and service providers
CargoFlow does not sell user information. Information may be processed by infrastructure and service providers that are necessary to host, store, secure, or operate CargoFlow and its integrations. Authorized users within the deploying organization may access business records according to their assigned CargoFlow role.
When a user intentionally opens or connects an external carrier, Google, or other service, information needed for that requested integration may be transmitted to that provider under its own terms and privacy practices.
7. Retention
- The Gmail OAuth refresh token is retained only while the shared Gmail connection remains configured. Disconnecting Gmail removes the stored token and CargoFlow attempts to revoke it with Google.
- OAuth authorization state records are short-lived and expire after approximately 10 minutes.
- Ignored Carrier Inbox candidates are currently deleted after 180 days.
- Classified carrier communications and other operational records may remain as business and audit history until an authorized Administrator removes them or the deploying organization applies its retention policy.
- Shipment, customer, document, audit, and account records may be retained when needed for operational, contractual, legal, security, or records-management purposes.
8. Cookies and local browser storage
CargoFlow uses essential authentication/session cookies to keep authorized users signed in securely. The application may also use local browser storage for non-sensitive interface preferences such as the selected visual theme. CargoFlow's current configuration does not use advertising cookies.
9. Your choices
- An Administrator can disconnect the shared Gmail account from System Health → Carrier Inbox.
- Google access may also be revoked from the connected Google account's third-party access settings.
- Team accounts can be deactivated by a CargoFlow Administrator.
- Requests to remove historical business, Gmail-derived, shipment, customer, or account records should be directed to the CargoFlow Administrator or the organization that issued the account. Some records may need to be retained under organizational or legal requirements.
See Data & Account Removal for more detail.
10. Children
CargoFlow is a business operations application and is not intended for use by children.
11. Policy changes and contact
This policy may be updated when CargoFlow's features or data practices change. The effective date above will be updated when material revisions are made.
Questions, access concerns, or deletion requests should be directed to the CargoFlow Administrator or the organization that provided your account.