LumberFlow
Understand how we protect and use your personal data on our platform.
This Privacy Policy describes how LumberFlow LLC (“LumberFlow,” “we,” “our,” “us”) collects, uses, and shares information when you access or use our Co-Pilot software, shared inbox integrations, AI features, websites, and related services (collectively, the "Service").
We are committed to protecting your privacy and handling data in accordance with applicable laws.
By using the Service, you agree to the practices described in this Privacy Policy.
We collect information in the following categories:
When you register or are onboarded as a user, we may collect:
name, email address, password
job title and role
organization name
billing details (if applicable)
“Customer Data” refers to any data you submit to or route through the Service. This includes:
email messages, attachments, RFQs, documents, supplier quotes
purchase history and sourcing workflows
PDF files, spreadsheets, product specifications, pricing details
messages routed through shared email inboxes (e.g., rfq@lumberflow.com)
Important: If you use or route communications through a shared inbox we operate or host, you acknowledge that LumberFlow will have access to all messages, purchase details, and supplier/buyer interactions transmitted via that inbox.
We process Customer Data solely on your behalf, except where anonymized or aggregated.
We automatically collect system-level data, including:
IP address, device type, browser type
operating system, timestamps, pages viewed
performance metrics, error logs, debugging information
This helps us maintain security, ensure uptime, and improve reliability.
We gather information about how you and your team interact with the Service:
features used, workflows invoked, frequency of activity
AI model usage metrics
operational and performance analytics
If you connect third-party tools (email providers, cloud drives, internal systems), we may receive:
metadata
message contents
file attachments
integration log data
This data remains Customer Data that we process on your behalf.
We use collected information for the following purposes:
Including:
parsing emails and documents
extracting structured data
routing communications
generating AI-driven insights, pricing comparisons, and summaries
maintaining account access, authentication, and security
We analyze usage and technical data to:
detect issues and optimize performance
train and refine AI models
develop new features
enhance accuracy, speed, and usability
We may send:
service-related messages (required)
updates, alerts, and security notices
marketing or promotional messages (optional; can opt out anytime)
We may de-identify or aggregate Customer Data to generate analytics, benchmark data, or market insights that do not identify you or your organization.
These insights may be used internally or shared externally in anonymized form.
We may use or disclose information as required to:
comply with legal obligations
prevent fraud or misuse
protect safety, rights, or property
respond to law enforcement or regulatory requests
LumberFlow does not sell personal information.
We may share information with:
Trusted vendors who help us operate the Service, including:
Cloud Infrastructure: Vercel Inc., Neon, Inc.
AI Processing: Google LLC (Gemini models)
Payment Processing: Stripe, Inc.
Email Delivery: Resend, Inc.
Analytics & Monitoring: PostHog, Inc., Sentry (Functional Software, Inc.)
All sub-processors are contractually required to:
protect your data,
follow privacy and security requirements, and
use Customer Data only to provide services to us.
A full list of sub-processors is available upon request.
If you enable integrations (email, cloud storage, CRM), we may share or receive data at your direction, per the integration’s functionality.
We may disclose information when legally required, subject to notifying you where allowed.
We use robust administrative, technical, and physical safeguards to protect your data, including:
encryption in transit (TLS 1.2+)
encryption at rest (AES-256)
strict internal access controls
audit logging, monitoring, and intrusion detection
regular security testing and vulnerability scanning
Despite these measures, no system can guarantee absolute security.
We retain Customer Data for:
the duration of your subscription, and
a reasonable period thereafter for backup, audit, or legal compliance purposes.
You may request deletion of Customer Data at any time (subject to legal obligations).
Depending on your jurisdiction (e.g., GDPR, CCPA, state privacy laws), you may have the right to:
access your personal information
correct inaccurate information
request deletion of your information
request a copy of your data
restrict or object to certain processing
designate an authorized agent to make requests on your behalf
To submit a request, contact us at support@lumberflow.com.
We will verify your identity before fulfilling requests.
You are responsible for:
obtaining appropriate consents from your users, suppliers, buyers, or contacts whose data flows into the Service
compliance with your own contractual obligations and privacy requirements
securing any third-party accounts or integrations you use with the Service
If you route supplier or buyer communications through a shared inbox, you must ensure you have lawful rights and permissions to do so.
We may transfer, store, or process information in the United States or other countries where our sub-processors operate. Where required, we use Standard Contractual Clauses (SCCs) or other approved safeguards for international transfers.
Our Service is not intended for individuals under 18. We do not knowingly collect personal information from children.
We may update this Privacy Policy periodically. If changes are material, we will notify you via email or through the Service.
Continued use after changes take effect constitutes acceptance.
If you have questions or concerns about this Privacy Policy, please contact us:
support@lumberflow.com LumberFlow LLC