LumberFlow

Back to Home

Privacy Policy

Understand how we protect and use your personal data on our platform.

This Privacy Policy describes how LumberFlow LLC (“LumberFlow,” “we,” “our,” “us”) collects, uses, and shares information when you access or use our Co-Pilot software, shared inbox integrations, AI features, websites, and related services (collectively, the "Service").

We are committed to protecting your privacy and handling data in accordance with applicable laws.

By using the Service, you agree to the practices described in this Privacy Policy.


1. Information We Collect

We collect information in the following categories:

(a) Account & Organization Information

When you register or are onboarded as a user, we may collect:

  • name, email address, password

  • job title and role

  • organization name

  • billing details (if applicable)

(b) Customer Data (Data You Provide or Route Through the Service)

Customer Data” refers to any data you submit to or route through the Service. This includes:

  • email messages, attachments, RFQs, documents, supplier quotes

  • purchase history and sourcing workflows

  • PDF files, spreadsheets, product specifications, pricing details

  • messages routed through shared email inboxes (e.g., rfq@lumberflow.com)

Important: If you use or route communications through a shared inbox we operate or host, you acknowledge that LumberFlow will have access to all messages, purchase details, and supplier/buyer interactions transmitted via that inbox.

We process Customer Data solely on your behalf, except where anonymized or aggregated.

(c) Technical & Log Data

We automatically collect system-level data, including:

  • IP address, device type, browser type

  • operating system, timestamps, pages viewed

  • performance metrics, error logs, debugging information

This helps us maintain security, ensure uptime, and improve reliability.

(d) Usage Information

We gather information about how you and your team interact with the Service:

  • features used, workflows invoked, frequency of activity

  • AI model usage metrics

  • operational and performance analytics

(e) Third-Party Integrations

If you connect third-party tools (email providers, cloud drives, internal systems), we may receive:

  • metadata

  • message contents

  • file attachments

  • integration log data

This data remains Customer Data that we process on your behalf.


2. How We Use Information

We use collected information for the following purposes:

(a) To Provide and Operate the Service

Including:

  • parsing emails and documents

  • extracting structured data

  • routing communications

  • generating AI-driven insights, pricing comparisons, and summaries

  • maintaining account access, authentication, and security

(b) To Improve and Enhance the Service

We analyze usage and technical data to:

  • detect issues and optimize performance

  • train and refine AI models

  • develop new features

  • enhance accuracy, speed, and usability

(c) Communications

We may send:

  • service-related messages (required)

  • updates, alerts, and security notices

  • marketing or promotional messages (optional; can opt out anytime)

(d) Analytics, Benchmarking & De-Identified Insights

We may de-identify or aggregate Customer Data to generate analytics, benchmark data, or market insights that do not identify you or your organization.

These insights may be used internally or shared externally in anonymized form.

(e) Legal, Compliance & Security

We may use or disclose information as required to:

  • comply with legal obligations

  • prevent fraud or misuse

  • protect safety, rights, or property

  • respond to law enforcement or regulatory requests


3. How We Share Information

LumberFlow does not sell personal information.

We may share information with:

(a) Sub-Processors

Trusted vendors who help us operate the Service, including:

  • Cloud Infrastructure: Vercel Inc., Neon, Inc.

  • AI Processing: Google LLC (Gemini models)

  • Payment Processing: Stripe, Inc.

  • Email Delivery: Resend, Inc.

  • Analytics & Monitoring: PostHog, Inc., Sentry (Functional Software, Inc.)

All sub-processors are contractually required to:

  • protect your data,

  • follow privacy and security requirements, and

  • use Customer Data only to provide services to us.

A full list of sub-processors is available upon request.

(b) Connected Third-Party Integrations

If you enable integrations (email, cloud storage, CRM), we may share or receive data at your direction, per the integration’s functionality.

(c) Compliance with Law

We may disclose information when legally required, subject to notifying you where allowed.


4. Data Security

We use robust administrative, technical, and physical safeguards to protect your data, including:

  • encryption in transit (TLS 1.2+)

  • encryption at rest (AES-256)

  • strict internal access controls

  • audit logging, monitoring, and intrusion detection

  • regular security testing and vulnerability scanning

Despite these measures, no system can guarantee absolute security.


5. Data Retention

We retain Customer Data for:

  • the duration of your subscription, and

  • a reasonable period thereafter for backup, audit, or legal compliance purposes.

You may request deletion of Customer Data at any time (subject to legal obligations).


6. Your Rights

Depending on your jurisdiction (e.g., GDPR, CCPA, state privacy laws), you may have the right to:

  • access your personal information

  • correct inaccurate information

  • request deletion of your information

  • request a copy of your data

  • restrict or object to certain processing

  • designate an authorized agent to make requests on your behalf

To submit a request, contact us at support@lumberflow.com.

We will verify your identity before fulfilling requests.


7. Customer Responsibilities

You are responsible for:

  • obtaining appropriate consents from your users, suppliers, buyers, or contacts whose data flows into the Service

  • compliance with your own contractual obligations and privacy requirements

  • securing any third-party accounts or integrations you use with the Service

If you route supplier or buyer communications through a shared inbox, you must ensure you have lawful rights and permissions to do so.


8. International Data Transfers

We may transfer, store, or process information in the United States or other countries where our sub-processors operate. Where required, we use Standard Contractual Clauses (SCCs) or other approved safeguards for international transfers.


9. Children’s Privacy

Our Service is not intended for individuals under 18. We do not knowingly collect personal information from children.


10. Changes to This Policy

We may update this Privacy Policy periodically. If changes are material, we will notify you via email or through the Service.

Continued use after changes take effect constitutes acceptance.


11. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

support@lumberflow.com LumberFlow LLC

Contentful Live