3PL TechFlow

Legal

Privacy policy

Last updated September 6, 2026. This policy explains what personal information 3PL TechFlow handles when warehouses and their clients use our software, why, who we share it with, how long we keep it and the choices you have.

1. Who we are

3PL TechFlow ("we", "us") is a software company based in California, United States. We make ShipFlow (a warehouse management system), RateFlow (quoting and client management for 3PLs, served at rateflow.app) and QualityFlow (a quality management system), together "the Services", and we operate this website, 3pltechflow.com. Our contact for anything in this policy is support@3pltechflow.com.

2. Our role: processor for warehouses, controller for this site

The Services are used by third-party logistics warehouses ("Warehouses") to store and ship goods for their customers ("Clients"). Most personal information in the Services is about the Clients' own customers (the people who ordered the goods) and is put into the Services by the Warehouse or by a Client, or arrives from a sales channel the Client connected. For that information the Warehouse, and through it the Client, decides why and how it is used; we process it on their instructions as a service provider / processor. If you are a shopper whose order was fulfilled through ShipFlow, the merchant you bought from and their warehouse are responsible for your data, and requests about it should go to them first; we help them respond.

For this website, for the accounts of Warehouse and Client staff who sign in, and for support and sales enquiries, we are the controller / business.

3. What we collect

3.1 From Warehouses and Clients using the Services

3.2 From connected sales channels

When a Client connects a store or marketplace (for example Shopify or Walmart Marketplace), the channel sends us the orders the Client asks the Warehouse to fulfil, including the customer's name, ship-to address, email and phone, the products ordered and the shipping method, together with product and variant data used to match items. We send back fulfillments, tracking numbers and stock levels. We do not receive payment details from any channel.

3.3 From this website

If you use the contact form we receive the name, email, company, phone and message you give us. Our host records standard web-server logs (IP address, user agent, pages requested) for security and reliability. The site sets no cookies of its own (see section 9).

4. How we use personal information

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train models or build profiles of shoppers.

6. How long we keep information

DataRetained
Order, shipment, receipt and inventory recordsFor the life of the Warehouse's agreement with us, then deleted or returned within 90 days of termination unless the Warehouse asks for an export first (see the terms). Warehouses may configure shorter retention per Client.
Documents and photosSame as the records they belong to.
Audit logLife of the agreement plus 12 months, for security and dispute purposes.
Integration event and webhook delivery logs30 days after processing.
API idempotency records24 hours.
Connected-channel compliance requests (data requests, redactions) and what was doneLife of the agreement plus 12 months, as evidence of compliance.
Account data of a deactivated userName and email remain on historical audit entries; credentials are removed at deactivation.
Website contact-form submissionsUp to 24 months in our support mailbox and form host, then deleted.
Web-server logsUp to 30 days.

Anonymised or aggregated data that no longer identifies anyone may be kept longer.

7. Sub-processors and other recipients

We use these providers to run the Services. Each is bound by a contract that limits its use of personal information to providing its service to us.

ProviderPurposeLocation
RailwayHosting of the ShipFlow application and APIUnited States
NeonManaged PostgreSQL databaseUnited States
NetlifyHosting of the dashboard, client portal and this website; contact-form processingUnited States
Amazon Web Services (S3)Storage of uploaded documents and photosUnited States
EasyPostCarrier rating, label purchase and trackingUnited States
ResendTransactional email (password resets, notifications)United States
AnthropicAI processing: reading uploaded documents (purchase orders, packing lists, safety data sheets, invoices), classifying event photos, and answering questions from the Warehouse's approved documents. Content is processed to return a result and is not used to train models.United States
SupabaseDatabase and hosting for RateFlowUnited States
DeepgramTranscription of meeting audio in RateFlow, where that feature is usedUnited States
Google (Calendar)Calendar synchronisation in RateFlow, where the Warehouse connects a Google accountUnited States
Carriers (UPS, FedEx, USPS, DHL and freight carriers chosen for a shipment)Transporting the shipment; they receive the ship-to details on the labelPer carrier

Sales channels, marketplaces and other systems a Client chooses to connect (for example Shopify, Walmart Marketplace, ShipStation or an EDI network) are not our sub-processors; the Client's agreement with that provider governs the data exchanged with it. We will give Warehouses 30 days' notice by email before adding a sub-processor that handles personal information.

We may also disclose information when the law requires it, to protect the rights and safety of people or the Services, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply.

8. Shopify and connected channels

When a Client connects a Shopify store, ShipFlow receives protected customer data (order ship-to name, address, email and phone) only for orders the merchant asks the Warehouse to fulfil, and only through the access scopes described on ShipFlow for Shopify. That data is used solely to fulfil the order and is shown only to the Warehouse's staff and, through the portal, to the merchant. The store's access token is stored encrypted and refreshed automatically.

We honour Shopify's mandatory compliance webhooks as follows:

Every request is verified against the app secret, recorded with what was done, and visible to the Warehouse and to the merchant. Other channels are handled to the same standard on the Warehouse's or Client's instruction.

9. Cookies and similar technologies

This website uses no cookies, analytics or trackers. The dashboard and client portal keep your sign-in session in browser storage for the duration of the session and remember a few interface preferences (such as a chosen client filter) on your device; these are not used for advertising and are cleared when you sign out or clear site data.

10. Security

Client data is isolated per tenant with row-level security enforced in the database. Connections use TLS. Databases and file storage are encrypted at rest by our providers, and integration credentials are additionally encrypted by us. Access is role-based, sessions are revoked immediately on deactivation or password change, and administrative actions are audit-logged. More on the security page. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify the affected Warehouse without undue delay and as the law requires.

11. Your rights and how to exercise them

If you are a shopper whose order was fulfilled through ShipFlow, please contact the merchant you bought from; they and their warehouse control your data and we act on their instructions. If you contact us directly we will tell you which Warehouse to reach or forward your request with your permission.

California residents (CCPA / CPRA) have the right to know what personal information we collect, use and disclose, to access it, to correct it, to delete it, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we do not use it beyond providing the Services) and not to be discriminated against for exercising these rights. Over the previous twelve months we collected the categories described in section 3 for the purposes in section 4 and disclosed them to the recipients in section 7 for business purposes only.

Residents of the EEA, the United Kingdom and Switzerland (GDPR / UK GDPR) have the right of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent, and the right to complain to their supervisory authority. Where we transfer data from those regions to the United States we rely on standard contractual clauses with the Warehouse and with our sub-processors.

To exercise a right, email support@3pltechflow.com with "Privacy request" in the subject, or ask your Warehouse to raise it. We will verify your identity in proportion to the request, respond within 45 days (California) or one month (GDPR), extendable once where the law allows, and we will not charge a fee unless requests are manifestly unfounded or excessive. You may use an authorised agent; we will ask for proof of authority.

12. Children

The Services and this website are for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us and we will delete it.

13. Changes to this policy

We will post any change here with a new "last updated" date, and for material changes we will email Warehouse administrators at least 30 days before the change takes effect. Continued use of the Services after that date means the updated policy applies.

14. Contact

3PL TechFlow, California, United States. support@3pltechflow.com. We will provide a postal address on request.