Privacy Policy
Last updated: February 6, 2026
1. Introduction
FlagshipRTL ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered purchase order management platform, including our email integration features.
By using FlagshipRTL, you consent to the data practices described in this policy. If you do not agree with our practices, please do not use our services.
2. Information We Collect
2.1 Email Data
When you connect your email account (Gmail, Outlook, or other supported providers), we access and process:
- Email messages related to purchase orders and supply chain communications
- Email metadata (sender, recipient, subject, date, threading information)
- Email attachments (PDFs, spreadsheets, documents) containing purchase order information
- Email content for AI-powered analysis and data extraction
2.2 Account Information
- Name and email address
- Organization/company information
- Authentication credentials (managed securely via OAuth)
- User preferences and settings
2.3 Usage Data
- Log data (IP address, browser type, pages visited)
- Device information
- Feature usage and interaction patterns
- Performance and error data
3. How We Use Your Information
We use the information we collect to:
- Provide Core Services: Process and analyze emails to extract purchase order information, track shipments, and manage your supply chain data
- AI Processing: Use machine learning and artificial intelligence to identify, categorize, and extract relevant information from your emails and documents
- Generate Insights: Create analytics, reports, and actionable insights about your purchase orders
- Improve Our Services: Enhance our AI models, fix bugs, and develop new features
- Communication: Send service-related notifications, updates, and support responses
- Security: Detect, prevent, and address technical issues and security threats
4. AI and Machine Learning
Our platform uses artificial intelligence to process your data. Specifically:
- We use large language models (LLMs) to analyze email content and extract structured information
- AI processes document attachments to identify purchase order details, shipping information, and other relevant data
- Machine learning helps categorize and prioritize your communications
Important: We do not use your data to train our AI models without your explicit consent. Your business data remains confidential and is not shared with other customers or used for general model improvement.
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your data only in the following circumstances:
- Service Providers: Third-party vendors who assist in providing our services (e.g., cloud hosting, AI processing providers) under strict confidentiality agreements
- Within Your Organization: Other authorized users in your organization as permitted by your account settings
- Legal Requirements: When required by law, regulation, or legal process
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: For any other purpose with your explicit consent
6. Data Security
We implement robust security measures to protect your data:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- OAuth 2.0 for secure email authentication (we never store your email password)
- Regular security audits and penetration testing
- Access controls and authentication requirements
- Secure cloud infrastructure with SOC 2 compliant providers
- Employee security training and background checks
7. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Upon account termination:
- You may request deletion of all your data
- We will delete or anonymize your data within 30 days of request
- Some data may be retained as required by law or for legitimate business purposes (e.g., billing records)
8. Your Rights and Choices
You have the following rights regarding your data:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Portability: Receive your data in a structured, machine-readable format
- Withdraw Consent: Disconnect email accounts and revoke access at any time
- Opt-Out: Opt out of non-essential communications
To exercise these rights, contact us at privacy@flagshiprtl.com.
9. Email Provider Permissions
When connecting email accounts, we request only the minimum permissions necessary:
- Gmail: We use Gmail API restricted scopes and comply with Google's API Services User Data Policy
- Outlook: We use Microsoft Graph API with limited scopes as defined in our application registration
You can revoke email access at any time through your account settings or directly through your email provider's security settings.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including Standard Contractual Clauses and compliance with applicable data protection laws.
11. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through our platform. Your continued use of our services after changes become effective constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
FlagshipRTL
Email: privacy@flagshiprtl.com
Data Protection Officer: dpo@flagshiprtl.com