Snapshot 39694
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy Policy Last updated: September 11, 2026 Who we are Freightbox is a product of Product Builders Academy, based in Amsterdam, Netherlands. When we refer to “Freightbox,” “we,” “us,” or “our,” we mean Product Builders Academy operating the Freightbox platform at getfreightbox.com. For any privacy-related questions, contact us at hello@getfreightbox.com. What data we collect We collect the following categories of data: Account information — name, email address, organization name, and role when you create an account or book a demo. Communication data — emails, phone calls, voicemails, and conversations processed through the Freightbox platform on behalf of your organization. Connected mailbox data — Gmail or Outlook account identifiers, messages, thread metadata, participants, attachments, labels or categories, drafts, and synchronization activity needed to operate a connected mailbox. Connected calendar data — Google Calendar identifiers, metadata, availability, and events needed to display and manage the calendar features you enable. AI-generated metadata — sentiment analysis, priority classification, categorization, summaries, and recommended actions produced by our AI enrichment features. Derived and aggregated data — reply-needed decisions, generated drafts, provider-action records, and aggregated or anonymized security, reliability, and usage statistics used only to operate, secure, and improve user-facing Freightbox features. Usage data — pages visited, features used, and interactions with the platform, collected via PostHog analytics. Contact and CRM data — contacts, companies, and relationship data you create or that are automatically generated from conversations. Connected Gmail, Outlook, and Google Calendar accounts When you connect a mailbox, Freightbox uses OAuth to access the permissions needed for the features you enable. Google documents gmail.modify as allowing apps to read, compose, and send email. AI Mailbox uses it only to read and synchronize messages, classify logistics workflows, apply Gmail labels, and create reply drafts; it does not call Gmail send endpoints or automatically send messages. Outlook uses delegated Mail.ReadWrite for the same mailbox-scoped functions and does not request Mail.Send. When you connect Google Calendar, calendar.readonly is used to load calendars and availability, and calendar.events is used to create, update, and delete events you request. Freightbox does not currently connect to Microsoft calendars. Freightbox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google mailbox and calendar data and Microsoft mailbox data are used only to provide or improve user-facing Freightbox features, maintain security, investigate failures, and prevent duplicate provider actions. We do not use mailbox or calendar content for advertising, sell it, or allow humans to read it except when necessary for security, legal compliance, or user-requested support with appropriate access controls. How we use your data To provide, maintain, and improve the Freightbox platform and its AI features. To process and enrich conversations with AI-generated metadata (sentiment, priority, categorization, and recommended actions). To generate AI draft replies based on conversation context. To execute automation rules you configure. To provide analytics and reporting on communication performance. To send transactional emails related to your account (e.g., notifications, billing). To understand how the platform is used and improve our product. AI processing Freightbox uses AI to analyze and enrich your communications. This processing happens automatically when conversations arrive. AI-generated metadata (sentiment, priority, category, summaries, and action recommendations) is stored alongside your conversation data within your organization's isolated workspace. Customer data is not used to train third-party AI models. AI providers process the minimum conversation context needed to produce the requested classification, summary, or draft. Freightbox does not opt customer mailbox data into provider model-training programs. Results are stored within the customer's organization workspace and are not exposed to other Freightbox customers. We do not use raw, derived, aggregated, or anonymized Google Workspace data for advertising, credit decisions, data brokerage, or training general-purpose AI models. Data storage and security Mailbox connections use OAuth; stored provider credentials are encrypted server-side and are not exposed in the product. Data is encrypted in transit, and managed infrastructure providers encrypt stored database and file data. Organization- and mailbox-level authorization controls isolate customer workspaces. Sensitive operations and AI Mailbox provider actions are recorded for security and operational auditing. Additional technical and operational controls are described on the public Freightbox security page. Third-party services We use the following third-party services: Google — OAuth identity and connected Gmail mailbox and Google Calendar access. Microsoft — OAuth identity and connected Outlook mailbox access. Supabase — authentication, database, and file storage. Railway — Freightbox application hosting. Anthropic and OpenAI — AI classification, draft generation, and transcription of WhatsApp voice notes (OpenAI Whisper). Relevant message content is transferred only when needed to produce a user-facing classification, summary, draft, or transcript; voice-note audio is not stored. Freightbox does not opt customer mailbox data into their model-training programs. Twilio and Meta (WhatsApp) — delivery of the optional WhatsApp remote-control messages. A team member who pairs their own phone can receive a prompt when a reply draft needs review or when an automation rule forwards an email to them, and can approve, reject, or answer from WhatsApp. Prompts may include the contact name, subject, and a short excerpt, or only a reference tag in minimal mode. Typed replies and transcripts are kept for 30 days; paired numbers are stored only for pairing. Details are in the in-app privacy notice at app.getfreightbox.com/privacy. Sentry — error and reliability monitoring with sensitive provider payloads excluded or redacted. PostHog (EU servers) — product analytics to understand how features are used. No personally identifiable information is shared beyond what is necessary for analytics. Cal.com — demo booking and scheduling. Cloudflare Web Analytics — privacy-first traffic measurement on getfreightbox.com: page views, referrers and page speed. It sets no cookies and does not identify individual visitors. Apollo.io — website visitor analytics on getfreightbox.com only. It identifies the visiting company from network data to help us understand which businesses read our pages; it is not loaded inside the Freightbox application and never sees mailbox data. Vercel — website hosting and delivery. These providers process data only to operate, secure, and support Freightbox under their service terms. We do not sell Google user data or transfer it to advertising platforms, data brokers, or lenders. Your rights under GDPR As a data subject under the General Data Protection Regulation (GDPR), you have the following rights: Right of access — request a copy of the personal data we hold about you. Right to rectification — request correction of inaccurate data. Right to erasure — request deletion of your personal data. Right to restrict processing — request that we limit how we use your data. Right to data portability — receive your data in a structured, machine-readable format. Right to object — object to processing of your data for specific purposes. To exercise any of these rights, contact us at hello@getfreightbox.com. We will respond within 30 days. Data retention We retain your data for as long as your account is active or as needed to provide our services. Disconnecting a mailbox stops new synchronization, removes the stored OAuth credential, and attempts to stop the provider watch or subscription. Existing synchronized history remains until the organization is deleted. Organization administrators can export organization data and schedule deletion in Freightbox. Provider access is removed immediately; active organization data is permanently purged after the 30-day grace period, except where retention is required by law. Limited backup copies may remain for an infrastructure provider's recovery window and are not available in the active product. See the public data deletion guide for the available controls. Cookies Freightbox uses essential cookies required for the platform to function (e.g., authentication sessions). We use PostHog for product analytics, which may set cookies to understand usage patterns. We do not use advertising cookies. Changes to this policy We may update this privacy policy from time to time. When we make material changes, we will notify you via email or through a notice on the platform. Continued use of Freightbox after changes constitutes acceptance of the updated policy. Contact Product Builders Academy Amsterdam, Netherlands hello@getfreightbox.com CASA Tier 2Independently assessed by TAC Security GDPR-readyEU data handling, erasure on request Draft-only AIDrafts replies — never sends on its own No model trainingYour mail never trains third-party AI How we protect your email: security · privacy policy