Legal

Privacy Policy

Last updated: May 2026 ·  Questions? privacy@freightsurf.com

01

Introduction & Scope

This Privacy Policy describes how FreightSurf (“FreightSurf,” “we,” “us,” or “our”) collects, processes, and protects information in connection with the FreightSurf operational intelligence platform (the “Service”). FreightSurf is an AI-powered inbox intelligence platform designed for freight brokers. It connects to your Gmail or Outlook mailbox through Nylas, our email connectivity provider, processes carrier-related email communications, checks carrier information against FMCSA data, and provides load-matching and AI-assisted workflow tools.

This Policy applies to all users of the FreightSurf platform, including individual brokers, brokerage teams, and enterprise customers. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.

Our core commitment: FreightSurf does not sell your data, does not use your data for advertising, and does not use customer data to train general-purpose AI models. Your business intelligence belongs to you.
02

Data We Collect

FreightSurf collects several categories of information to provide and improve the Service:

Account Information

When you create an account, we collect your name, email address, company name, and billing information (processed securely through our payment provider). We do not store full payment card numbers.

Mailbox & Inbox Data

FreightSurf accesses your connected Gmail or Outlook mailbox through Nylas, our email connectivity provider, to identify, classify, and process carrier-related communications. This includes email metadata (such as sender, recipients, subject line, and timestamps), message body content, and the provider authorization credentials used to maintain that connection. See Section 3 for a complete description of email data handling, including which permissions are requested and what actions are taken, and Section 6 for how those credentials are secured.

Freight Intelligence Data

Structured data extracted from carrier email communications, including: carrier names, MC and DOT numbers, lane information (origin/destination), equipment types, offered rates, availability windows, contact information, and thread metadata. This data forms your operational carrier intelligence database within the platform.

FMCSA Verification Records

Results of carrier verification queries made against the FMCSA national database, including authority status, safety ratings, insurance information, and operating history. This is government-sourced public data.

Usage & Platform Data

Information about how you interact with the platform, including features accessed, session duration, actions performed, error events, and performance data. This data is used to maintain service reliability, troubleshoot issues, and improve the platform.

Support & Communication Data

If you contact our support team, we collect the content of your communications, including support tickets, feedback submissions, and email correspondence.

03

Email & Nylas Data Handling

FreightSurf uses Nylas, a third-party email connectivity provider, to connect to and communicate with your Gmail or Outlook mailbox. When you connect your mailbox, you authorize access directly with Google or Microsoft through their own OAuth flow — Nylas provides the unified API and hosted OAuth infrastructure FreightSurf uses to read and send mail on your behalf, rather than FreightSurf implementing a separate, direct integration with each provider. FreightSurf never receives or stores your email password. For Gmail specifically, this section also constitutes FreightSurf's disclosure of Google user data usage as required for Google OAuth verification and Google API Services User Data Policy compliance.

Permissions Requested

FreightSurf requests the minimum mailbox permissions required to operate the Service — no broader account access is requested:

  • Mailbox read access — to monitor your connected inbox and read carrier email content for classification and intelligence extraction. For Gmail, this corresponds to Google's gmail.readonly scope; for Outlook, the equivalent Microsoft Graph mail-read permission.
  • Mailbox send access — requested only when you enable AI-assisted reply and outbound email features. This permission is used solely to send outbound emails that you explicitly compose and authorize within the FreightSurf platform. For Gmail, this corresponds to Google's gmail.send scope.

Mailbox Data FreightSurf Accesses

Under these permissions, FreightSurf's systems — via Nylas — may access the following categories of mailbox data (for Gmail, this is Google user data subject to the Google API Services User Data Policy below):

  • Email metadata — sender, recipient(s), subject line, and timestamps for messages in your connected inbox.
  • Email body content — the text (and, where relevant to freight identification, attachments) of inbound messages.
  • Thread and label/folder metadata used to organize carrier conversations.
  • Provider authorization credentials — the access and refresh tokens issued by Google or Microsoft that authorize Nylas, on FreightSurf's behalf, to act on your connected mailbox. See Section 6 for how these are secured.

How FreightSurf Processes Mailbox Data

  • FreightSurf temporarily analyzes inbound emails in your connected mailbox to identify carrier-related communications.
  • Emails not identified as carrier communications are immediately discarded. They are not retained, indexed, stored, or used in any further processing.
  • Emails identified as carrier communications are processed to extract structured freight intelligence: MC numbers, lanes, rates, equipment, availability, and contact data.
  • Extracted carrier intelligence and associated email metadata are retained in your FreightSurf account as part of your operational database.
  • When you use AI-assisted reply features, FreightSurf may draft outbound email replies for your review. Outbound emails are only sent through Nylas upon your explicit authorization — never automatically.

What FreightSurf Does NOT Do With Mailbox Data

  • Does not sell mailbox data (including Gmail or other Google user data) to any party.
  • Does not license or transfer mailbox data to any third party for their independent use.
  • Does not transfer mailbox data to advertisers or data brokers.
  • Does not use mailbox data for advertising, marketing profiling, or audience targeting.
  • Does not use mailbox data for user profiling unrelated to providing FreightSurf's requested features.
  • Does not use mailbox content to train or fine-tune any generalized AI or machine learning model.
  • Does not store non-carrier email content, message bodies, attachments, or metadata from emails not related to freight operations.
  • Does not access mailbox data except when actively providing the Service to your account.
  • Does not allow employees to read your email content except where required for security investigation, legal compliance, or at your explicit request for technical support — and any such access is logged.

Revoking Access

You can revoke FreightSurf's access to your mailbox at any time through your provider's own account settings — for Gmail at myaccount.google.com/permissions, or for Microsoft 365 / Outlook in your Microsoft account's app permissions — or by disconnecting your mailbox from within your FreightSurf account settings. Revoking access immediately suspends inbox monitoring, and FreightSurf, through Nylas, revokes and deletes the associated authorization credentials from its systems, stopping all further mailbox API calls for your account. Carrier intelligence already extracted and stored in your FreightSurf account will remain available until you request deletion (see Section 8 and Section 12).

Google API Services User Data Policy Compliance

For users who connect Gmail, FreightSurf's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In accordance with that policy, Google user data obtained through the Gmail API — including as accessed via Nylas on FreightSurf's behalf — is never:

  • Sold to any party.
  • Used or transferred for advertising purposes.
  • Transferred to data brokers or other third parties for their own use.
  • Used for profiling unrelated to providing FreightSurf's requested features.
  • Used to train or improve generalized (non-personalized) AI or machine learning models.

Where FreightSurf uses third-party providers — including Nylas for email connectivity and OpenAI for AI processing of email content (see Section 4) — those providers act solely as processors on FreightSurf's behalf, for the sole purpose of delivering the Service to you, and are contractually prohibited from using that data to train their own models.

04

AI-Assisted Processing

FreightSurf uses artificial intelligence and machine learning to provide its core operational intelligence features. This section discloses how AI is used and the limits of that use.

AI Features

  • Email classification — identifying which inbox messages are carrier communications.
  • Data extraction — parsing unstructured carrier email content into structured fields.
  • Risk scoring — analyzing carrier signals to produce a composite risk indicator.
  • Load matching — ranking carrier availability against active load requirements.
  • Reply suggestions — generating draft email responses and counter-offer recommendations based on carrier communication context.

Third-Party AI Processing

FreightSurf uses the OpenAI API to power natural language processing features. When email content — including, for Gmail users, Google user data obtained via the Gmail API — is submitted to OpenAI for classification or extraction, it is transmitted via encrypted API calls under an enterprise API agreement that prohibits OpenAI from using that data to train or improve OpenAI's models. AI providers process this data solely on FreightSurf's behalf, solely to deliver the FreightSurf features you requested, and it is never shared with AI providers for their own model training or any other independent purpose. Your carrier communications and business data are not used to benefit third parties.

AI Output Limitations

AI-generated outputs — including risk scores, carrier rankings, reply suggestions, and counter-offer recommendations — are operational intelligence tools designed to inform your decisions. They are not determinative, and FreightSurf does not guarantee their accuracy, completeness, or suitability for any specific freight transaction. All final decisions regarding carrier selection, rate negotiation, and load booking remain your responsibility.

FMCSA verification results reflect government-sourced carrier records. A match against those records confirms information available in the FMCSA database — it does not confirm the identity of the individual communicating with you, their authorization to act on behalf of the carrier, or that the carrier will perform as represented.

05

How FreightSurf Uses Your Data

We use the information we collect for the following purposes:

  • To provide, operate, and maintain the FreightSurf platform and its features.
  • To process and classify carrier email communications on your behalf.
  • To verify carriers against the FMCSA national database.
  • To generate risk scores, load matches, and AI-assisted workflow recommendations.
  • To maintain and update your carrier intelligence database.
  • To send transactional communications related to your account, billing, and service status.
  • To provide customer support and respond to technical inquiries.
  • To monitor, diagnose, and improve platform performance and reliability.
  • To comply with applicable legal obligations.
What we never use your data for: advertising, third-party marketing, sale to data brokers, general AI model training, or any purpose unrelated to providing the FreightSurf Service to you.
06

Data Storage & Security

FreightSurf stores and processes data on enterprise-grade cloud infrastructure operated under strict security controls.

  • All data transmitted between your browser and FreightSurf is encrypted using TLS 1.3.
  • All data stored at rest — including carrier intelligence, account information, and extracted freight data — is encrypted using AES-256.
  • Provider authorization tokens used to access your connected Gmail or Outlook mailbox — managed through Nylas — are encrypted at rest and in transit, stored separately from other account data, and are accessible only to the systems and personnel that require them to operate the Service.
  • Access to production systems is restricted to authorized personnel using least-privilege access controls.
  • Infrastructure is monitored continuously for security events and anomalies.
  • Database access is logged and audited.

For a detailed description of our security practices, see our Security page.

07

Third-Party Service Providers

FreightSurf engages the following third-party service providers (“subprocessors”) to deliver the Service. All subprocessors are contractually bound to protect your data in accordance with applicable privacy law.

ProviderPurposeRegionPrivacy Policy
Nylas, Inc.Email connectivity layer — mailbox connection, OAuth infrastructure, and message access for Gmail and OutlookUSAnylas.com/privacy-policy
Google LLCGmail account authorization (OAuth) for users who connect GmailUSA / EUpolicies.google.com/privacy
Microsoft CorporationOutlook / Microsoft 365 account authorization (OAuth) for users who connect OutlookUSA / EUprivacy.microsoft.com
OpenAI, Inc.AI-powered email classification and data extractionUSAopenai.com/privacy
Supabase, Inc.Database infrastructure and data storageUSAsupabase.com/privacy
Cloud infrastructure providersCompute, networking, and hosting servicesUSAVaries by provider
FMCSA (US DOT)Carrier verification — public government databaseUSA (Federal)fmcsa.dot.gov

FreightSurf does not share your data with subprocessors beyond what is necessary to provide the Service. We review subprocessor security practices before engagement.

08

Data Retention

While Your Account Is Active

Account information, carrier intelligence, extracted freight data, and FMCSA verification records are retained for the duration of your active subscription. Historical carrier data is retained according to your plan tier (30 days on Starter, 180 days on Pro, 2 years on Team, unlimited on Enterprise).

Non-Carrier Email Content

Email content from messages not identified as carrier communications is not retained. It is processed temporarily during inbox scanning and immediately discarded.

Mailbox Data & Connection Tokens

Provider authorization tokens are retained only for as long as your Gmail or Outlook mailbox remains connected to FreightSurf through Nylas. When you disconnect your mailbox — whether from your Google or Microsoft account settings or within FreightSurf — those tokens are immediately revoked and deleted from FreightSurf's and Nylas's systems, and no further mailbox API calls are made for your account. This is separate from your carrier intelligence data, which was already extracted from qualifying emails and is retained per the plan-tier schedule above unless you request its deletion. Upon full account deletion, both your connection tokens (if not already removed) and your carrier intelligence data are deleted per the timeline in Section 12.

After Account Termination

Upon account cancellation or termination, your data is retained for 30 days to allow for data export or reactivation. After 30 days, all personal account data and carrier intelligence is permanently deleted from active systems. Anonymized, aggregated operational metrics not attributable to any individual may be retained for service improvement purposes.

Legal Hold

Notwithstanding the above, FreightSurf may retain data for longer periods where required by applicable law, legal process, or to establish, exercise, or defend legal claims.

09

Your Rights

Depending on your location, you may have the following rights with respect to your personal data. To exercise any of these rights, contact privacy@freightsurf.com.

Access

You may request a copy of all personal data FreightSurf holds about you, including your account information and extracted carrier intelligence.

Correction

You may request correction of inaccurate or incomplete personal data associated with your account.

Deletion (Right to Be Forgotten)

You may request deletion of your account and all associated personal data. See Section 12 for account deletion procedures.

Data Portability

You may request an export of your carrier intelligence data in a standard machine-readable format (JSON or CSV).

Restriction of Processing

You may request that FreightSurf restrict processing of your personal data in certain circumstances, such as while a correction request is being assessed.

Objection

Where processing is based on legitimate interests, you may object to that processing. FreightSurf will assess whether its legitimate interests override your objection.

California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected, the right to opt out of the sale of personal information (FreightSurf does not sell personal information), and the right to non-discrimination for exercising CCPA rights. To submit a CCPA request, contact privacy@freightsurf.com.

EEA, UK & Swiss Residents (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) including those listed above, plus the right to lodge a complaint with your local supervisory authority if you believe your rights have been violated.

10

International Data Transfers

FreightSurf's infrastructure is primarily operated in the United States. If you access the Service from outside the United States, your data may be transferred to, stored in, and processed in the United States, which may have different data protection laws than your country of residence.

For users in the European Economic Area, United Kingdom, or Switzerland, FreightSurf relies on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for transferring personal data outside the EEA. Copies of applicable SCCs are available upon request at privacy@freightsurf.com.

11

Cookies & Analytics

FreightSurf uses cookies and similar technologies to operate the platform and maintain session state. We do not use advertising cookies or cross-site tracking technologies.

  • Strictly necessary cookies — required for authentication, session management, and core platform functionality. These cannot be disabled without impairing the Service.
  • Analytics cookies — used to understand how the platform is used in aggregate, to improve reliability and feature design. These collect no personally identifiable information beyond what is necessary for session analysis.

FreightSurf does not use cookies to build advertising profiles, retarget users across other websites, or share behavioral data with third-party ad networks.

12

Account Deletion

To delete your FreightSurf account and associated data:

  • Submit a deletion request to support@freightsurf.com from your registered account email address, or
  • Use the account deletion option within your FreightSurf account settings, if available.

We will process your deletion request within 10 business days. You will receive a confirmation when deletion is complete. Following deletion, your data will be permanently removed from active systems within 30 days, subject to any legal hold obligations described in Section 8.

Before requesting deletion, you may wish to export your carrier data (see Section 9). Data export requests are processed within 5 business days.

13

Policy Updates

FreightSurf may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational factors. When we make material changes, we will notify you via email to your registered address and post a notice on the platform at least 30 days before the changes take effect.

Your continued use of the Service after the effective date of an updated Privacy Policy constitutes acceptance of the updated terms. If you do not agree with the changes, you may cancel your subscription and request account deletion before the effective date.

14

Contact Information

For privacy-related questions, data requests, or concerns about this Privacy Policy, please contact us:

Privacy inquiries: privacy@freightsurf.com

General support: support@freightsurf.com

Legal matters: legal@freightsurf.com

Business address: Available upon request.

We aim to respond to all privacy inquiries within 5 business days.