Legal
Privacy policy
Last updated September 6, 2026. This policy explains what personal information 3PL TechFlow handles when warehouses and their clients use our software, why, who we share it with, how long we keep it and the choices you have.
1. Who we are
3PL TechFlow ("we", "us") is a software company based in California, United States. We make ShipFlow (a warehouse management system), RateFlow (quoting and client management for 3PLs, served at rateflow.app) and QualityFlow (a quality management system), together "the Services", and we operate this website, 3pltechflow.com. Our contact for anything in this policy is support@3pltechflow.com.
2. Our role: processor for warehouses, controller for this site
The Services are used by third-party logistics warehouses ("Warehouses") to store and ship goods for their customers ("Clients"). Most personal information in the Services is about the Clients' own customers (the people who ordered the goods) and is put into the Services by the Warehouse or by a Client, or arrives from a sales channel the Client connected. For that information the Warehouse, and through it the Client, decides why and how it is used; we process it on their instructions as a service provider / processor. If you are a shopper whose order was fulfilled through ShipFlow, the merchant you bought from and their warehouse are responsible for your data, and requests about it should go to them first; we help them respond.
For this website, for the accounts of Warehouse and Client staff who sign in, and for support and sales enquiries, we are the controller / business.
3. What we collect
3.1 From Warehouses and Clients using the Services
- Account data: name, work email, role, warehouse or client company, hashed password, sign-in times and IP addresses, and the actions you take (kept in an audit log).
- Order and shipment data: order references, ship-to name, company, address, phone and email, requested shipping method, notes, line items and quantities, carrier, service, tracking numbers, package weights and dimensions, and photos or scans captured during picking and packing.
- Product and inventory data: SKUs, barcodes, descriptions, lots, serial numbers, expiry dates, hazmat details, quantities and locations.
- Receiving data: expected receipts, supplier names, purchase order references and counts.
- Billing data: rate cards, metered charges and invoices between the Warehouse and its Clients. We do not hold card numbers; payments between Warehouses and Clients happen outside the Services.
- Documents: files a Warehouse or Client uploads (purchase orders, bills of lading, packing slips, safety data sheets).
- Integration credentials: store access tokens, marketplace client ids and secrets, SFTP logins and API keys, stored encrypted or hashed.
- Quoting and account data (RateFlow): the Warehouse's rate cards and quotes, its prospects' and clients' company details, contact names, business emails and phone numbers, portal activity including typed acceptances, notes, tasks, emails and calendar entries, and the invoices the Warehouse sends in to be read against its quotes. Where meeting transcription is used, audio is held only until it has been transcribed.
- Quality records (QualityFlow): quality events with photos and the name of the person who reported them, nonconformances and corrective actions, controlled documents and who approved or acknowledged them, safety data sheets, training requirements and records per employee, equipment, supplier, audit and management-review records. These include the names and roles of the Warehouse's employees.
3.2 From connected sales channels
When a Client connects a store or marketplace (for example Shopify or Walmart Marketplace), the channel sends us the orders the Client asks the Warehouse to fulfil, including the customer's name, ship-to address, email and phone, the products ordered and the shipping method, together with product and variant data used to match items. We send back fulfillments, tracking numbers and stock levels. We do not receive payment details from any channel.
3.3 From this website
If you use the contact form we receive the name, email, company, phone and message you give us. Our host records standard web-server logs (IP address, user agent, pages requested) for security and reliability. The site sets no cookies of its own (see section 9).
4. How we use personal information
- To provide the Services: receiving, storing, picking, packing, shipping and proving orders; rating and buying carrier services; keeping inventory accurate; sending shipments and stock levels back to connected channels.
- To run accounts: sign-in, roles and permissions, password recovery, session security and the audit log.
- To support Warehouses and Clients and to answer enquiries from this site.
- To bill between Warehouses and Clients according to their rate cards.
- To keep the Services secure and reliable, investigate abuse and comply with law.
- To improve the Services using aggregated, de-identified usage information.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train models or build profiles of shoppers.
5. Legal bases (where GDPR or UK GDPR applies)
- Performance of a contract with the Warehouse or Client, and processing on their documented instructions, for everything in section 3.1 and 3.2.
- Legitimate interests in securing and improving the Services, keeping audit records and responding to enquiries, balanced against your rights.
- Legal obligation for records we must keep, for example export and hazardous-materials shipping documentation.
- Consent where we ask for it, which you can withdraw at any time.
6. How long we keep information
| Data | Retained |
|---|---|
| Order, shipment, receipt and inventory records | For the life of the Warehouse's agreement with us, then deleted or returned within 90 days of termination unless the Warehouse asks for an export first (see the terms). Warehouses may configure shorter retention per Client. |
| Documents and photos | Same as the records they belong to. |
| Audit log | Life of the agreement plus 12 months, for security and dispute purposes. |
| Integration event and webhook delivery logs | 30 days after processing. |
| API idempotency records | 24 hours. |
| Connected-channel compliance requests (data requests, redactions) and what was done | Life of the agreement plus 12 months, as evidence of compliance. |
| Account data of a deactivated user | Name and email remain on historical audit entries; credentials are removed at deactivation. |
| Website contact-form submissions | Up to 24 months in our support mailbox and form host, then deleted. |
| Web-server logs | Up to 30 days. |
Anonymised or aggregated data that no longer identifies anyone may be kept longer.
7. Sub-processors and other recipients
We use these providers to run the Services. Each is bound by a contract that limits its use of personal information to providing its service to us.
| Provider | Purpose | Location |
|---|---|---|
| Railway | Hosting of the ShipFlow application and API | United States |
| Neon | Managed PostgreSQL database | United States |
| Netlify | Hosting of the dashboard, client portal and this website; contact-form processing | United States |
| Amazon Web Services (S3) | Storage of uploaded documents and photos | United States |
| EasyPost | Carrier rating, label purchase and tracking | United States |
| Resend | Transactional email (password resets, notifications) | United States |
| Anthropic | AI processing: reading uploaded documents (purchase orders, packing lists, safety data sheets, invoices), classifying event photos, and answering questions from the Warehouse's approved documents. Content is processed to return a result and is not used to train models. | United States |
| Supabase | Database and hosting for RateFlow | United States |
| Deepgram | Transcription of meeting audio in RateFlow, where that feature is used | United States |
| Google (Calendar) | Calendar synchronisation in RateFlow, where the Warehouse connects a Google account | United States |
| Carriers (UPS, FedEx, USPS, DHL and freight carriers chosen for a shipment) | Transporting the shipment; they receive the ship-to details on the label | Per carrier |
Sales channels, marketplaces and other systems a Client chooses to connect (for example Shopify, Walmart Marketplace, ShipStation or an EDI network) are not our sub-processors; the Client's agreement with that provider governs the data exchanged with it. We will give Warehouses 30 days' notice by email before adding a sub-processor that handles personal information.
We may also disclose information when the law requires it, to protect the rights and safety of people or the Services, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply.
8. Shopify and connected channels
When a Client connects a Shopify store, ShipFlow receives protected customer data (order ship-to name, address, email and phone) only for orders the merchant asks the Warehouse to fulfil, and only through the access scopes described on ShipFlow for Shopify. That data is used solely to fulfil the order and is shown only to the Warehouse's staff and, through the portal, to the merchant. The store's access token is stored encrypted and refreshed automatically.
We honour Shopify's mandatory compliance webhooks as follows:
customers/data_request— we log the request and compile the warehouse orders that relate to the customer so the merchant can answer their customer; nothing is sent automatically to anyone else.customers/redact— within 30 days, we anonymise the customer's name, address lines, phone, email and notes on the orders named in the request (and any other order of that store with the same email), and strip the ship-to from the intake records. City, state, postal code and country remain, as they are needed for freight reporting and do not identify a person on their own.shop/redact— 48 hours after uninstall Shopify sends this request; we anonymise every order that came from the store in the same way, remove the item links and unmatched-item records for the connection, and delete the stored access token.
Every request is verified against the app secret, recorded with what was done, and visible to the Warehouse and to the merchant. Other channels are handled to the same standard on the Warehouse's or Client's instruction.
9. Cookies and similar technologies
This website uses no cookies, analytics or trackers. The dashboard and client portal keep your sign-in session in browser storage for the duration of the session and remember a few interface preferences (such as a chosen client filter) on your device; these are not used for advertising and are cleared when you sign out or clear site data.
10. Security
Client data is isolated per tenant with row-level security enforced in the database. Connections use TLS. Databases and file storage are encrypted at rest by our providers, and integration credentials are additionally encrypted by us. Access is role-based, sessions are revoked immediately on deactivation or password change, and administrative actions are audit-logged. More on the security page. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify the affected Warehouse without undue delay and as the law requires.
11. Your rights and how to exercise them
If you are a shopper whose order was fulfilled through ShipFlow, please contact the merchant you bought from; they and their warehouse control your data and we act on their instructions. If you contact us directly we will tell you which Warehouse to reach or forward your request with your permission.
California residents (CCPA / CPRA) have the right to know what personal information we collect, use and disclose, to access it, to correct it, to delete it, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we do not use it beyond providing the Services) and not to be discriminated against for exercising these rights. Over the previous twelve months we collected the categories described in section 3 for the purposes in section 4 and disclosed them to the recipients in section 7 for business purposes only.
Residents of the EEA, the United Kingdom and Switzerland (GDPR / UK GDPR) have the right of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent, and the right to complain to their supervisory authority. Where we transfer data from those regions to the United States we rely on standard contractual clauses with the Warehouse and with our sub-processors.
To exercise a right, email support@3pltechflow.com with "Privacy request" in the subject, or ask your Warehouse to raise it. We will verify your identity in proportion to the request, respond within 45 days (California) or one month (GDPR), extendable once where the law allows, and we will not charge a fee unless requests are manifestly unfounded or excessive. You may use an authorised agent; we will ask for proof of authority.
12. Children
The Services and this website are for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us and we will delete it.
13. Changes to this policy
We will post any change here with a new "last updated" date, and for material changes we will email Warehouse administrators at least 30 days before the change takes effect. Continued use of the Services after that date means the updated policy applies.
14. Contact
3PL TechFlow, California, United States. support@3pltechflow.com. We will provide a postal address on request.