Privacy Policy

Last updated 5 August 2026

This policy explains what personal data Yalafleet Freight Broker LLC ("we", "us") collects when you use the Yalafleet customs-documentation service at https://app.yalafleet.com, why we collect it, who we share it with, and the choices and rights you have.

1. Who this policy covers

It covers everyone who uses the service: people who create an account, people invited into someone else's workspace, and visitors to our public pages. Where you use the service through an account created by your employer or another organisation, that organisation controls the workspace and its content; we process that content on their behalf.

2. Data we collect

  • Account data. Your name, email address, and either a hashed password or, if you sign in with Google, the Google account identifier and profile details described in section 3. We never store your Google password.
  • Workspace and membership data. The workspaces you belong to, your role in each, invitations you send or accept, and workspace settings such as document numbering and defaults.
  • Content you create. The commercial invoices, packing lists, consignee and shipper records, goods and templates you build in the service, together with files you upload — including company logos and signature images. This content frequently contains personal data about third parties (for example a consignee contact name, address, phone number or email); you are responsible for having a lawful basis to enter it.
  • Technical and security data. Session records, IP address, browser user agent, request timestamps and rate-limiting counters. We keep an audit log of state-changing actions (who did what, and when) so workspace administrators can review activity on their account.
  • Diagnostic data. Error reports and performance traces generated when something goes wrong, used to fix faults.

We do not collect special-category data, we do not run advertising or cross-site tracking, and we do not buy personal data from third parties.

3. Google sign-in and Google user data

Signing in with Google is optional — you can always use an email address and password instead. If you choose Google sign-in, we request only the basic profile and email scopes, and we receive from Google:

  • your Google account identifier;
  • your email address and whether Google has verified it;
  • your name and profile picture URL, where you have made them available.

We use this data for one purpose only: to create and authenticate your account, and to show your name and picture to you and to other members of your workspace. We store the account identifier, email, name and picture URL alongside your account record, plus the OAuth tokens needed to keep you signed in. We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalised artificial-intelligence or machine-learning models.

Limited Use. Yalafleet Freight Broker LLC's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect the service from your Google account at any time in your Google account settings. Doing so stops future Google sign-ins; to delete the data already held, follow section 9.

4. Why we use your data

  • To provide the service — authenticating you, storing your documents, generating PDFs, and sending the transactional email the service depends on (invitations, verification, password resets).
  • To keep the service secure — detecting and preventing abuse, rate-limiting, and maintaining the audit trail workspace owners rely on.
  • To diagnose faults and improve reliability and performance.
  • To comply with our legal obligations and to establish or defend legal claims.

Where the UK GDPR or EU GDPR applies, our legal bases are: performance of a contract with you (providing the service), our legitimate interests (security, fault diagnosis, service improvement), your consent where we ask for it, and compliance with legal obligations.

5. Who we share data with

We do not sell personal data and we do not share it for anyone else's marketing. We share it only with:

  • Other members of your workspace— content you create in a shared workspace is visible to that workspace's members according to their role.
  • Service providers who process data on our instructions — our cloud hosting and database provider, our transactional email provider, our error-monitoring provider, and, where a paid plan is in use, our payment processor. Each is bound by a contract that limits them to processing data for us.
  • Authorities or advisers — where we are legally required to, or to establish, exercise or defend legal claims.
  • A successor — if the business is reorganised, merged or acquired, under equivalent protections.

6. International transfers

We operate from the United States, and our providers store and process data there, so data you give us is transferred to the United States. Where data leaves the United Kingdom or the European Economic Area we rely on an adequacy decision or on Standard Contractual Clauses, together with encryption in transit and at rest.

7. How long we keep it

Account data is kept while your account is active. Workspace content is kept until you or a workspace administrator deletes it, or until the workspace is closed. Audit and security logs are retained for a limited period for security and accountability, then purged. When you ask us to delete your account we remove or irreversibly anonymise your personal data within 30 days, except where we must keep records to meet a legal obligation.

8. How we protect it

Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. Access to workspace content is scoped to the workspace at the database layer, so one customer's records are not reachable from another's session. Administrative access to production is restricted to the people who need it, and privileged actions are logged. No system is perfectly secure, but we work to a standard appropriate to the sensitivity of the data.

9. Your rights

Depending on where you live, you may have the right to access a copy of your data, to have it corrected, to have it deleted, to restrict or object to how we use it, to portability, and to withdraw consent. The service includes tools to export your data and to request account deletion; you can also exercise any of these rights by writing to support@yalafleet.com. We respond within one month.

Residents of California and other US states with comprehensive privacy laws additionally have the right to know what we collect, to delete it, to correct it, and to opt out of the "sale" or "sharing" of personal information — we do neither, and we do not use your data for targeted advertising or profiling. We will not discriminate against you for exercising any of these rights.

If you are unhappy with our response you may complain to your local data-protection authority — in the UK, the Information Commissioner's Office.

10. Cookies

We set a single strictly necessary cookie to hold your sign-in session. Without it you cannot stay signed in. We do not use advertising, profiling or cross-site tracking cookies, so no cookie banner is required.

11. Children

The service is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the service changes. The "last updated" date at the top always reflects the current version, and we will tell account holders by email before a material change takes effect.

13. Contact us

Privacy questions and data-subject requests go to support@yalafleet.com. Our Terms of Service govern your use of the service.