FreightStow Privacy Policy

Last Updated: September 7, 2026

1. Introduction

Welcome to FreightStow (“we,” “our,” or “us”). FreightStow is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our export documentation application (“FreightStow” or the “App”).

This Privacy Policy has been designed to comply with applicable privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the UK and EU General Data Protection Regulation (GDPR). Please read this Privacy Policy carefully. If you do not agree with its terms, please do not access the App.

2. Information We Collect

2.1 Use Without an Account

The document generators are available without registration. Where you use the App without an account, the information you enter is retained in your browser’s local storage on your own device and is not transmitted to us.

When you generate a document we also record whether its shipment details differ from the starting details, to understand use of the generators. This flag contains none of the text you entered. We record the type of document, the date, and the IP address from which the request was made. We do so in order to detect and prevent misuse of the App, on the basis of our legitimate interests in securing it. That record contains no part of the information you entered and is not linked to any account. IP addresses are erased 30 days after collection, after which the record retains only the document type, the edit flag and the date.

If you select a paid plan we record which plan, the price displayed to you, the page you selected it from, the date, and the IP address from which the request was made. We do so in order to understand which features are worth building, on the basis of our legitimate interests in developing the App. Where you are not signed in, that record is not linked to any account. IP addresses in these records are erased on the same 30-day schedule.

We use product analytics and session replay to understand how the document tools are used: pages visited, clicks, scrolling, use of controls, and a replay of the session. A replay records selected commercial fields of the document you are working on: product descriptions, HS codes, quantities, units, weights, countries, ports, transport mode, Incoterms and currency. Everything else is masked in your browser before a frame is transmitted: the names and addresses of the parties, signatories, bank and payment details, document and reference numbers, prices, notes, and every sign-in field. Recordings never include spreadsheet contents, network request or response bodies, or console output. Replays are deleted 30 days after they are recorded.

2.2 Personal Information

Where you register for an account, we collect the following categories:

  • Identifiers. Name, email address, and IP address.
  • Authentication data. A cryptographic hash of your password, where you set one. We do not store the password itself. Where you authenticate through a federated sign-in provider, we store the identifier that provider supplies in place of a password.
  • Commercial information. The trade records you choose to save, including the parties, ports, container details, and line items you enter, together with the business contacts and product records derived from them.
  • Usage data. A record of the documents you generate, comprising the document type, its reference number, and the date. We also store how many spreadsheet imports you apply in the current calendar month. This is used to enforce the account’s monthly allowance. Product analytics also records pages visited and interactions such as importing, saving, selecting a saved product, and downloading, together with the document type, export format, line count, whether a spreadsheet was imported, and the commercial fields listed in Section 2.1. We do not receive the spreadsheet, its filename, headings, or imported rows.

2.3 Information We Do Not Collect

Documents are assembled and rendered entirely within your browser, in each of the formats we offer — PDF, Excel, and Word. The completed file is not transmitted to us and is not stored on our systems. Spreadsheets selected for line-item import are also read within your browser and are not transmitted to us. We do not collect payment card data, financial account data, or biometric data, and we do not use advertising trackers.

2.4 How We Collect Information

  • Directly from you, when you register, save a trade, or contact us.
  • Automatically, in the form of server log data and the IP address from which you connect, together with product interaction, browser, device, and page information generated when you use the App, whether or not you have an account.
  • From third parties, where you elect to sign in through a federated identity provider that you have authorised to share your name and email address with us.

3. How We Use Your Information

  • To provide and maintain the App, including generating export documentation.
  • To create, authenticate, and manage your account.
  • To retain the trade records, contacts, and products you save, so that they are available to you on subsequent visits.
  • To respond to your enquiries and provide support.
  • To monitor and improve the App and develop new features.
  • To administer and support the App, including where a member of our personnel accesses the records held in your account in order to investigate a fault, respond to a request for support, or verify that the App is operating correctly.
  • To protect against fraudulent, unauthorised, or unlawful activity.
  • To comply with our legal obligations.

4. Disclosure of Your Information

4.1 Service Providers

We disclose personal information to service providers who process it on our behalf and solely to enable us to provide the App. These fall into the following categories:

  • Cloud application hosting and content delivery.
  • Managed database hosting and storage.
  • Transactional email delivery, for account confirmation messages.
  • Federated authentication, where you elect to sign in through such a provider.
  • Error monitoring and product analytics.

Each such provider is engaged under terms requiring it to process personal information only on our instructions and for the purpose of providing services to us, and prohibiting it from using that information for its own purposes. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.

We currently use PostHog as our product analytics and session replay provider. Signed-in activity is associated with an internal account identifier; we do not send PostHog your email address or display name.

Where you request a list of the specific providers we engage, we will supply it on request to the address in Section 13.

4.2 Legal Requirements

We may disclose your information where required to do so by law, or in response to valid requests by public authorities such as a court or government agency.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.

5. Data Retention

We retain your personal information for as long as your account remains active or as required to provide the App to you. Session records expire seven days after issue. IP addresses recorded when a document is generated are erased 30 days after collection. Session replays are deleted 30 days after they are recorded. Analytics events are kept for as long as they are needed to understand and improve the App. Where you delete an account, the operational records held by FreightStow are removed immediately and permanently, as described in Section 7.

6. Data Security

We implement appropriate technical and organisational measures to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include:

  • Encryption of data in transit using TLS, and of stored data at rest.
  • Storage of passwords using a computationally hardened one-way hashing function, such that the original password cannot be recovered.
  • Session cookies marked HttpOnly, Secure, and SameSite.
  • Rate limiting on authentication endpoints.
  • Access controls restricting personal information to authorised personnel.
  • Use of maintained software dependencies.

Access to the records held in user accounts is restricted to a limited number of authorised personnel, is available only through an administrative interface which requires a separately configured and individually verified account, and is undertaken solely for the purposes described in Section 3.

No method of transmission over the Internet or of electronic storage is entirely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

7. Deletion of Your Account and Data

You may delete your account at any time from Settings within the App. Deletion is immediate and permanent, and removes your account together with all saved trade records, contacts, products, document history, and authentication sessions. We retain no shadow copy of those operational records and the deletion cannot be reversed. Analytics records may remain until their configured retention period expires; you may ask us to delete analytics associated with your former internal account identifier by using the address in Section 13. Documents you have already downloaded are held by you and are unaffected.

You may also delete individual contacts, products, and trade records without closing your account.

8. Your Privacy Rights Under California Law

Under the CCPA/CPRA, California residents have specific rights regarding their personal information.

8.1 Right to Know

You have the right to request information about the personal information we collect, use, and disclose.

8.2 Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions.

8.3 Right to Correct

You have the right to request correction of inaccurate personal information.

8.4 Right to Opt-Out of Sale or Sharing

We do not sell or share personal information. The CCPA/CPRA nonetheless requires us to inform you that you have the right to opt out of such sale or sharing.

8.5 Right to Limit Use of Sensitive Personal Information

You have the right to limit the use and disclosure of sensitive personal information. We do not collect sensitive personal information as that term is defined under the CCPA/CPRA.

8.6 Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights.

9. Your Privacy Rights Under UK and EU Law

Where you are located in the United Kingdom or the European Economic Area, you have the right to access, rectify, erase, restrict the processing of, and port your personal information, and to object to its processing. Our lawful bases for processing are the performance of our contract with you, in respect of operating your account and providing the App, and our legitimate interests in securing the App, preventing misuse, understanding how the App is used, and improving it.

You have the right to lodge a complaint with your supervisory authority. In the United Kingdom this is the Information Commissioner’s Office.

10. Exercising Your Rights

Access, correction, and erasure are available to you directly within the App. For any other request, contact us at the address in Section 13. We will respond within 45 days where the CCPA/CPRA applies, and within one month where the UK or EU GDPR applies.

We may ask you to provide additional information in order to verify your identity before we act on a request. Any information supplied for that purpose is used solely to verify your identity and to process your request.

11. Children's Privacy

The App is not directed to individuals under the age of 18, and we do not knowingly collect personal information from them. If we become aware that we have collected personal information from a person under 18, we will delete it.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the revised policy on this page and updating the “Last Updated” date above. You are advised to review this Privacy Policy periodically.

13. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Email: privacy@freightstow.com

We are the data controller in respect of the personal information described in this policy. You may contact us by email for any request under this policy, including a request for the identities of the service providers referred to in Section 4.1.

Back to FreightStow