CargoFlows
Privacy Policy
Effective 7 August 2026Last updated 7 August 2026
Who this policy is about. CargoFlows is a software platform. Freight forwarders, logistics companies and their agencies use it to run their own businesses. This policy describes what CargoFlows does with information as the operator of that platform. It does not describe what any individual business using CargoFlows does with its own customers’ information — those businesses make their own decisions and have their own obligations.
1. Our two roles
It matters which role we are acting in, because it determines who decides what happens to information.
As a provider of software to businesses. When a freight company or agency uses CargoFlows to manage its shipments, customers and conversations, that business decides what information to put into the platform and what to do with it. We process that information on their behalf and under their instructions, in order to provide the service. We do not sell it, and we do not treat it as ours.
As a business ourselves. When someone registers a CargoFlows account, subscribes, contacts us, or uses our own public pages, we decide how that information is handled. That includes account records, billing information, support correspondence and the technical logs we keep to operate the service securely.
A single person can appear in both roles. If you are a customer of a freight agency that uses CargoFlows, your shipment records belong to that agency’s account — but if you also create a login to track your parcels, the account itself is ours to administer.
2. Information we process
Account and access information
- Name, email address and password credentials.
- A record of your acceptance of our terms: which version you accepted, when, and the network address the acceptance came from. We keep this because it is the only evidence that the agreement was entered into.
- Membership and role information determining which company, agency or location a person may access and what they may do there.
- Authentication events, including sign-in attempts, email verification, password resets and invitation acceptance.
- Where a person signs in using an external identity provider, the identifier and basic profile that provider returns.
Business and organisational information
- Company, agency and location records, including trading names, contact details, addresses and configuration.
- Branding assets uploaded by a business for its own use.
- Commercial relationships between companies and their agencies.
Contacts and customer records
- Contact records created by a business: names, company names, email addresses, phone numbers, notes, tags and activity history.
- Customer records, including the identifiers a business uses to recognise its own customers.
- Additional fields a business configures for itself. These are defined by that business, so their content is determined by them rather than by us.
Shipment and package information
- Package records, tracking and reference identifiers, weights, declared values, descriptions, statuses and movement dates.
- Records connecting a package to the customer who claimed it, and how that claim was verified.
- Information received from warehouse and carrier systems a business has connected.
- Delivery addresses and, where a business uses the home-delivery feature, the address and contact details a customer supplies for a delivery.
Proof of delivery
A business may record evidence that a package changed hands: a photograph taken at the point of handover, or a signature captured on screen. This is recorded by that business’s own staff, at three points — a home delivery, a handover from an agency to its customer, and a handover from a consolidating company to an agency.
A photograph taken at a doorstep can show more than a parcel — a person, a home, a vehicle. Proof-of-delivery files are therefore stored privately and are never published, never given a public address, and never included in a tracking page or a shareable link. They are shown only to authenticated staff of the business that recorded them.
The business operating the delivery decides whether to capture this evidence and is responsible for telling the people concerned. If you are a customer and want to know what was recorded at your delivery, ask that business.
Communications
- Conversations and messages exchanged through channels a business has connected, including message content, timestamps, direction and delivery or read status.
- Attachments and media sent or received in those conversations.
- Channel identities — the phone numbers, account identifiers or profile names a messaging provider makes available — used to associate an incoming message with the right conversation and contact.
- Notes, assignments and internal annotations staff add to a conversation.
Email, SMS and telephony channels are handled the same way where a business has enabled them.
Integration credentials
Access tokens and API credentials for services a business connects. These are stored encrypted, are never displayed back in readable form after entry, and are not shared between businesses.
Billing and usage information
- Subscription, module entitlement and invoicing records. Card details are handled by our payment processor and are not stored on our systems.
- Metering and usage counts used to calculate charges and enforce plan limits.
Technical and security information
- Server and application logs, IP addresses, timestamps, user agent information and error diagnostics.
- Administrative and audit records showing which account performed security-relevant actions.
- Session and authentication cookies necessary for signing in and protecting requests. We do not use advertising cookies.
Public page submissions
Information submitted through a public agency page — contact forms, sign-up forms and tracking enquiries — is delivered to the agency operating that page and recorded in its account.
Embedded widgets on a business’s own website
A business can embed a tracking form, a customer sign-up form or an AI chat assistant into its own website. Those widgets are served by us and run inside a frame on that website. When a visitor loads or uses one, we receive what any web request carries — IP address, user agent, timestamp — together with whatever the visitor types into it, and we record which business’s widget it was.
We receive nothing else from the page around the widget. It cannot read the rest of that website, and we do not track visitors across sites or use widget traffic for advertising. The business that embedded it is responsible for disclosing it in its own privacy notice.
3. Information received through Meta services
A business using CargoFlows may connect WhatsApp Business, Facebook Messenger or Instagram messaging. Connecting is a choice that business makes, and it can disconnect at any time.
When connected, we process information Meta’s APIs make available for that channel, which may include:
- Account identifiers: WhatsApp Business account and phone number identifiers, Facebook Page identifiers, and Instagram professional account identifiers.
- Sender identifiers and any display name or profile information the API provides for a person messaging the business.
- Message content, attachments and media sent to or from the connected account.
- Message metadata: timestamps, direction, and delivery or read status.
- The information needed to associate a conversation with the correct business account and contact record.
- Access tokens issued when the business authorises the connection, stored encrypted and used only to operate that connection.
We request the narrowest set of permissions the enabled functionality requires. We do not request access to advertising data, friend lists, or profile information beyond what a connected messaging conversation provides.
Connecting a number already in use (WhatsApp coexistence)
WhatsApp allows a business to keep using its number in the WhatsApp Business app on a phone while also connecting it here. A business that chooses this — and it is a choice, made during setup — should understand that connecting brings existing information across, not only new messages:
- Past conversations. WhatsApp sends us up to six monthsof that number’s chat history when the connection is made. Those conversations then appear in the business’s inbox here, including messages exchanged before the business ever used CargoFlows.
- Contacts saved on the phone. WhatsApp sends us the contacts held in that WhatsApp Business account, including people who have never messaged the business through this platform. We record them as channel identities so a future message is attached to the right person. We do not create marketing lists from them and we do not message them.
- Replies sent from the phone. When staff reply from the WhatsApp Business app rather than from here, WhatsApp copies that reply to us so the conversation stays complete in both places.
A business connecting an existing number is deciding, on behalf of the people in those conversations, to move their history into a new system. Whether that is appropriate — and what those people should be told — is that business’s decision and its responsibility, not ours. The connection can be removed at any time.
Why we process it
Information received through a connected Meta channel is used to provide that channel’s functionality, and for nothing else. Specifically:
- Receiving messages sent to the business.
- Displaying those conversations in the business’s shared inbox.
- Allowing that business’s authorised staff to reply.
- Delivering and displaying attachments.
- Associating a conversation with the correct contact or customer record.
- Maintaining conversation history for the business.
- Generating a reply through an AI assistant, if and only if that business has enabled the feature.
- Operational and security logging needed to run the integration reliably.
We do not use information received through Meta channels for advertising, for profiling unrelated to the conversation, or for any purpose unconnected to providing the messaging functionality the business enabled.
4. Artificial intelligence features
CargoFlows includes optional AI-assisted features. They are off unless a business turns them on.
If a business enables an AI feature, information relevant to the task — typically the recent conversation, and reference material that business has added to its own knowledge base — is sent to the configured AI service so that a response or summary can be produced. Access is limited to the same information the requesting business is already entitled to see; the AI service is not given a broader view of the platform.
The AI service is a configurable component, and today it is an external provider operating in the United States. Information is sent to that provider only to produce the requested output, under API terms that do not permit it to be used to train the provider’s models. It is not retained by us beyond the record of the conversation the feature was used in, and the metering count used to bill it. If we change provider in a way that changes this, we will update this page.
AI output is generated text. It can be wrong, and neither we nor the business using the feature should be read as guaranteeing it. Where a reply is drafted by an AI feature, the business using it remains responsible for what is sent to its customer.
5. Sharing information
We share information in these circumstances, and no others:
- With the business whose account holds the record.A message sent to an agency is visible to that agency’s authorised staff.
- With service providers who operate the platform for us. These fall into categories: infrastructure and hosting, database and storage, email delivery, payment processing, messaging and communications providers a business has connected, error monitoring and logging, and AI processing where enabled. They act on our instructions and may not use the information for their own purposes.
- With connected services, as directed. When a business replies to a WhatsApp message, that reply necessarily goes to Meta for delivery. This is the connected service operating as intended, not an onward transfer of unrelated data.
- Where the law requires it, or to establish, exercise or defend legal claims, or to protect the rights and safety of users and the public.
- In a business transfer, such as a merger or acquisition, in which case this policy continues to apply until replaced by one you are told about.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
6. Keeping information
We keep information for as long as it is reasonably necessary to provide the service, maintain operational and security records, comply with legal and regulatory obligations, resolve disputes, and enforce our agreements.
Different categories are kept for different periods, because they serve different purposes. Shipment, invoicing and audit records may need to be kept after an account closes, where accounting, customs or tax rules require it. When information no longer serves a purpose that justifies keeping it, we delete it or remove its connection to an identifiable person.
Where a business using CargoFlows controls the records, it also controls how long they are kept within the service.
When an account ends we keep its data available for export for 30 days, as our Terms of Service describe, and then delete or de-identify it — except for the records we are required to keep, such as invoices and the audit trail of security-relevant actions.
7. Security
We take appropriate technical and organisational measures to protect information, including:
- Encryption of traffic in transit using current TLS.
- Encryption of stored integration credentials and sensitive fields.
- Separation of each business’s data, enforced in the data layer rather than left to individual features.
- Authentication and role-based authorisation, with access denied unless explicitly granted.
- Audit logging of security-relevant administrative actions.
- Restricted internal access on a need-to-know basis.
No service can promise perfect security, and we do not make that claim. If you believe you have found a security issue, please tell us so we can investigate.
If something goes wrong. If we confirm a security breach affecting personal information, we will notify the affected account holders without undue delay and in any case within 72 hours of confirming it, telling them what we know at that point, what we are doing, and what they should do. We would rather send an incomplete notice on time than a complete one late.
8. International processing
CargoFlows is intended to be used by businesses in more than one country. Information may therefore be processed in a country other than the one you live in, including by the service providers described above.
Where information is transferred from a jurisdiction that restricts international transfers, we will use a transfer mechanism that jurisdiction recognises. Businesses with specific transfer requirements should contact us before relying on the service for regulated data, so the appropriate arrangements can be put in place.
9. Your rights
Depending on where you live, you may have rights to request access to your personal information, correction of it, deletion of it, restriction of or objection to certain processing, and a portable copy of it. These rights vary by jurisdiction and none of them is absolute.
Which route applies to you depends on who holds the record.
- Information we control — your CargoFlows account, billing records, or correspondence with us. Contact us directly and we will act on your request.
- Information a business controls— records held in a freight company’s or agency’s account, such as your shipments, your contact record, or your conversations with them. That business decides those records. Please contact them directly. If you contact us instead, we will help by passing the request on where we can identify the business concerned, and we will support them in responding.
We may need to verify your identity before acting, particularly for deletion requests. This protects you: acting on an unverified request would let someone else erase or obtain your records.
To request deletion specifically, see our data deletion page, which explains what to send and what happens next.
10. Children
CargoFlows is a business-to-business logistics platform. It is designed for and directed to businesses and their staff, not to children. It is not intended for anyone under 13, we do not knowingly collect personal information from anyone under 13, and our Terms of Service require account holders to be at least 18.
If we learn that we hold information collected from a child under 13 without a parent’s consent, we delete it. If you believe a child’s information has been provided to us, please contact us. Some jurisdictions set a higher age threshold for consent; where those apply, we will follow them.
11. Changes to this policy
We may update this policy as the service changes. The effective and last-updated dates at the top of this page show which version you are reading. Where a change materially affects how we handle information, we will take reasonable steps to notify account holders.
12. Contacting us
A dedicated privacy contact address is being finalised and will be published on this page. In the meantime, please contact the business you dealt with, who can pass your request on.
CargoFlows is operated by Print to Succeed, Corp., 12700 SW 96th St, Miami, FL 33186, United States, a company formed in the State of Florida, United States, which is the controller of the information described in this policy as ours.
If your question concerns records held by a freight company or agency using CargoFlows, contacting that business directly will usually be faster, because they control those records.