Effective date: August 8, 2026
This policy explains what personal data DO IT ALL SOFT ("we", "us") processes when a company (the "Customer") uses the DO IT ALL SOFT platform, and what rights the people involved have. It covers the web and mobile apps for employees, the customer portal, and our marketing site.
Roles. For workspace account data and billing we act as the data controller. For the operational content a Customer puts into the platform — quotes, shipments, their own customers' contact details, emails, documents — we act as a data processor on the Customer's behalf; the Customer is the controller of that data.
1. Data We Process
Account data (controller): name, work email, phone, position, login and session records (IP address, device/browser info, approximate location derived from IP), profile photo if provided.
Billing data (controller): company name and address, tax/VAT ID, invoice history, subscription state. Payment card data is handled entirely by Stripe — card numbers never reach our servers; we store only non-sensitive references (e.g., a card fingerprint used to prevent trial abuse).
Operational data (processor): the freight business content Customers manage in the platform — inquiries, quotes, shipments and their tracking events, customer company records and contact persons, vendors, documents and files, accounting entries, commissions and payroll figures, notes and comments.
Connected mailboxes (processor): if a Customer connects an email account (Gmail, Microsoft 365/Exchange, or IMAP), we sync and store messages and attachments from that mailbox so they can be used inside the platform (linking emails to quotes, shared visibility per the Customer's own permission settings). Mailbox connection is optional and per-account. The connected user can disconnect a mailbox in the app, or revoke our access in the provider's security settings, at any time — syncing then stops; messages already synced remain part of the Customer's workspace, under the Customer's control, until the Customer deletes them.
AI feature data (processor): text submitted to AI-assisted features (e.g., pasted inquiry text, email content parsed into quote drafts, sensitivity classification of message content) is sent to our AI provider (OpenAI) to produce the result, together with no more context than the feature needs. We record usage metadata (token counts, feature, timestamps) for billing. We do not use Customer content to train models, and our provider agreements prohibit training on it.
Usage telemetry (controller): feature-level usage counters, error logs, and metering records needed to operate limits and billing.
Workplace activity data (processor): for each employee user, the platform records how long the application was open, how long it was actively in use, the kind of device used (desktop browser, mobile browser, or mobile app), a coarse count of interactions, how many changes were saved, and when the person was last active. Records are kept per hour, together with the time-zone offset of the device at that moment so the hours can be shown in the person's own local time.
This measures activity inside the platform only. We do not take screenshots, do not capture keystrokes or their content, and do not observe browsing, applications, or any activity outside this application. The data belongs to the Customer, who decides which of its managers may view it and whether employees may view their own figures; we act as processor. Where required, the Customer — as the employer and controller of this data — is responsible for informing its own staff (see the Terms of Use).
2. Purposes and Legal Bases
We process data to: provide and secure the Service (contract performance); bill subscriptions (contract, legal obligation); prevent abuse and fraud (legitimate interest); send transactional emails such as invoices, trial and payment notices, and usage alerts (contract); improve reliability via aggregate, de-identified statistics (legitimate interest); comply with law (legal obligation). We do not sell personal data and do not use it for third-party advertising.
3. Sub-Processors
We use these providers to run the Service (categories in parentheses):
| Provider | Purpose |
|---|---|
| Amazon Web Services | cloud hosting, storage, authentication, transactional email |
| Stripe | payments, subscription billing, invoices |
| OpenAI | AI-assisted features (text parsing, assistants, classification) |
| Google (Gmail API) | mailbox sync for Customers who connect Gmail |
| Microsoft (Graph API) | mailbox sync for Customers who connect Microsoft 365/Exchange |
| Shipment-tracking data providers | ocean and air shipment tracking — receive container/AWB/BL identifiers only, no personal data |
| Cloudflare (Turnstile) | bot protection on public forms |
| MaxMind (GeoLite2) | approximate IP geolocation for session security |
| Google Firebase | mobile push notifications |
We will update this list when providers change; Customers with a data processing agreement will be notified of additions.
Google API Services note: our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements — Gmail data is used only to provide the mailbox features the user connects, is not used for advertising, is not combined with other data sources for profiling, and is never transferred except as necessary to provide those features or as required by law. We do not allow humans to read Gmail data unless the user has given affirmative agreement, it is necessary for security or abuse investigation, or the law requires it.
Microsoft APIs note: information received via the Microsoft Graph API is handled the same way — used only to provide the mailbox features the user connects, never for advertising or unrelated analytics, and transferred only as necessary to provide those features or as required by law, in accordance with the Microsoft API Terms of Use.
4. Retention
Operational data is retained for as long as the Customer's workspace exists — including after subscription cancellation, so the Customer can return or request an export. Deletion: the Customer's owner can request deletion of the workspace in writing; we delete within a reasonable period except where law requires retention (e.g., invoices). Customer-portal accounts (the logins a Customer's own clients use to view their quotes and shipments) can be deleted on request: we remove the login and the person's identifying details (name, email address, phone number) and anonymize their authorship in the Customer's records; the underlying business records (quotes, shipments, documents, message history) remain with the Customer that owns them. A Customer can also revoke a portal account's access to its workspace at any time, without deleting the account. Session location history and terminated sessions are pruned automatically on a rolling schedule. Workplace activity records are kept at hourly resolution for 13 months and are then deleted automatically; we do not keep a longer-term or finer-grained history of them. Backups roll off on their own cycle after deletion.
5. Security
Data is encrypted in transit (TLS) and at rest (managed AWS encryption). Each Customer's data is logically isolated per workspace: it is never shared with or visible to other Customers, and a person who works with more than one Customer has separate access to each workspace. Access is role-based inside the platform (the Customer controls its own users' permissions) and restricted on our side to personnel who need it to operate the Service; infrastructure access is logged and monitored. Automated backups run regularly to protect against data loss. Authentication is handled by AWS Cognito; sessions can be reviewed and revoked per device. We notify affected Customers without undue delay if a personal data breach affects their data.
6. International Transfers
Our infrastructure runs on AWS. Sub-processors above may process data in the United States and other countries; where GDPR applies, transfers rely on adequacy decisions or standard contractual clauses.
7. Your Rights
Depending on your jurisdiction (e.g., the GDPR, or the CCPA/CPRA for California residents), individuals may have rights to access, rectify, delete, restrict, or port their personal data, and to object to certain processing. We do not sell or "share" personal data as those terms are defined by the CCPA, and we do not discriminate against anyone for exercising privacy rights. If your data is in a Customer's workspace (you are their employee, customer contact, or email correspondent), please contact that company first — they control that data, and we support them in fulfilling requests. If you hold a customer-portal account, you may ask us to delete it (see Retention above for exactly what is removed and what stays with the Customer); because one portal account can be connected to several Customers, we handle these requests directly rather than through any single Customer. For account/billing data we control, contact us directly; we respond within the legally required period. You may lodge a complaint with your supervisory authority.
8. Cookies
The apps use strictly necessary cookies/storage for sign-in sessions and preferences. The marketing site uses no third-party advertising trackers.
9. Children
The Service is a business tool and not directed at children under 16; we do not knowingly process their data.
10. Changes
We may update this policy. Material changes are announced in-app, and workspace owners must review and accept the new version before continuing to use the Service.
11. Contact
DO IT ALL SOFT · 910 Lorinda Dr, Glendale, CA 91206, USA · privacy@doitallsoft.com