Frexeo

Privacy Policy

Last updated 8 October 2026

Frexeo (“Frexeo”, “we”, “us”) provides email and document automation to freight and logistics companies. This policy explains what information the service handles, why, who else sees it, and the choices you have. It covers the website at frexeo.com and the Frexeo application.

1. Who this applies to

Frexeo is used by companies (“customers”) and the people who work for them (“users”). A customer decides which mailboxes to connect and what is done with the documents inside them. For that mailbox and document content we act as a processor on the customer’s behalf and follow their instructions. For account, security and billing information about users and customers we decide how it is used ourselves.

2. Information we handle

  • Account information: name, work email address, role, sign-in credentials (passwords are stored only as one-way hashes) and multi-factor authentication settings.
  • Connected mailbox content: when a customer connects a mailbox we read its messages, their headers, senders and recipients, dates, and attachments, so they can be shown, searched, sorted and processed.
  • Documents and extracted data: the text, fields and classifications that Frexeo produces from attachments and messages, and the files saved to the customer’s storage destination.
  • Connection credentials: Google access and refresh tokens, or the password or app password for an IMAP mailbox. These are encrypted at rest and are never shown back to anyone.
  • Activity and diagnostic data: audit records of who did what, IP addresses and browser details on sign-in, and error and performance logs.

We do not run advertising or third-party analytics trackers on Frexeo, and we do not buy information about people from anyone.

3. Google user data

If you connect a Google account, Frexeo asks Google for these permissions and no others:

  • Basic sign-in details (openid, email, profile): to identify which Google account has been connected and show its address and name.
  • Gmail, read-only (gmail.readonly): to read the connected mailbox’s messages and attachments so Frexeo can list conversations, find shipping documents and extract their contents. Frexeo does not send, delete, modify or label anything in Gmail.
  • Google Drive, files you choose (drive.file): to create the documents Frexeo files, and to open only the files and folders that a person explicitly selects with the Google file picker. Frexeo cannot browse or read the rest of a Drive.

Google user data is used only to provide and improve the user-facing features described here, on behalf of the person or customer who connected it. We do not use it to show advertising, we do not sell it, and we do not use it to develop or train general-purpose AI or machine-learning models. Our staff do not read it unless the customer asks for help with a specific message, it is needed to investigate abuse or a security problem, or the law requires it.

Frexeo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we use information

  • to show mail and documents to the people the customer has given access to;
  • to recognise document types, read their fields, check them against each other and flag problems;
  • to draft replies and file documents when a user asks for it or approves it;
  • to secure the service, prevent abuse, keep audit records and diagnose faults;
  • to run the account: sign-in, notifications, support and billing;
  • to meet legal obligations.

5. Who we share it with

We do not sell personal information. We share it only with the service providers that help us run Frexeo, who may use it only to perform those services for us:

  • AI providers (currently OpenAI): message and document text is sent to understand, classify and summarise content and to draft replies. Requests are sent with storage turned off, and under the provider’s API terms the content is not used to train its models.
  • Google Cloud Document AI: scanned and image-based documents are sent for text recognition.
  • Google itself, when you connect Gmail or Drive: requests go to Google’s APIs, and files the customer chooses to save are stored in the customer’s own Drive.
  • Hosting and email delivery providers, who run the servers and deliver the messages a customer chooses to send.

We may also disclose information when the law, a court or a government authority requires it, to protect the safety and rights of people or of Frexeo, or as part of a merger or sale of the business, in which case this policy continues to apply to what is transferred unless you are told otherwise.

6. Security

  • All traffic to Frexeo is encrypted in transit.
  • Mailbox credentials and OAuth tokens are encrypted at rest with authenticated encryption.
  • Each customer’s data is separated from every other customer’s at the database level, and access inside a customer follows roles and per-mailbox grants.
  • Sign-in supports multi-factor authentication, and sensitive actions ask people to confirm again.
  • Uploaded files are checked before they are stored, and security-relevant actions are written to an audit log.

No system is perfectly secure. If a breach affects your information we will tell you as the law requires.

7. How long we keep it

We keep a customer’s data while their account is active so that the service keeps working. When a mailbox is disconnected we stop reading it and, for Google accounts, ask Google to revoke Frexeo’s access. When an account closes, or a customer asks us to delete data, we delete it from our systems, except where we must keep a record for legal, security or accounting reasons. Copies in backups are removed as the backups expire. Operational logs are kept for a limited time.

8. Your choices and rights

  • Disconnect a Google account from within Frexeo, or remove Frexeo’s access at any time at myaccount.google.com/permissions.
  • Ask for a copy, correction or deletion of your information, or object to how it is used. If you are a user at a customer, we may direct the request to that customer, who controls the content.
  • Depending on where you live you may have further rights, including to complain to your local data protection authority.

To exercise any of these, write to support@frexeo.com.

9. Cookies

Frexeo sets only the cookies it needs to work: a sign-in session cookie and a security token that protects forms against forgery. Your light or dark theme choice is kept in your browser’s local storage. None of these is used for advertising or tracking.

10. International processing

Frexeo and its providers may process information in countries other than your own. Where the law requires it, we rely on appropriate safeguards for those transfers.

11. Children

Frexeo is a business service and is not intended for anyone under 18. We do not knowingly collect their information.

12. Changes

We will update this page when our practices change and change the date at the top. For significant changes we will also notify customers by email or within the app.

13. Contact

Questions about this policy or your information: support@frexeo.com. See also our Terms of Service.