Data & Account Removal
This page explains how to disconnect Google access, deactivate a CargoFlow user, and request access, correction, restriction, or removal of stored operational or Gmail-derived records.
1. Disconnect the shared Gmail inbox
An authorized CargoFlow Administrator can disconnect Gmail directly from the application.
CargoFlow removes the stored encrypted OAuth refresh token, stops future Gmail sync, and attempts to revoke the token with Google. The Gmail mailbox itself is not deleted or changed.
Access can also be revoked through the connected Google account's third-party connection or security settings.
2. What a Gmail disconnect does not automatically delete
Disconnecting Gmail does not automatically erase carrier-reply records that were already imported and classified into CargoFlow. Those records may have become part of the organization's operational and audit history.
Previously imported records may include sender information, subject, limited message preview, carrier match information, Administrator classification, and Administrator summary. A signed-in user can submit a request concerning those records from Settings → Privacy & Data Requests.
3. Carrier Inbox retention
- Ignored Carrier Inbox candidates are currently deleted after 180 days.
- Short-lived OAuth state records expire after approximately 10 minutes.
- Classified carrier communications may be retained as operational or audit history until an authorized Administrator removes them or the organization applies its retention policy.
4. CargoFlow account deactivation or removal
A CargoFlow Administrator can deactivate a team account so it can no longer sign in. A signed-in user who wants an account reviewed for removal can submit a Deletion request from Settings → Privacy & Data Requests. If account access is unavailable, contact the CargoFlow Administrator or the organization that issued the account.
Deactivating or deleting a user account may not remove audit records that identify actions previously performed by that user. Audit history may need to remain for security, business, contractual, or compliance reasons.
5. Shipment, customer, document, and business records
Shipment records, customer data, purchase orders, documents, tracking events, approvals, communications, and other operational information are business records controlled by the organization deploying CargoFlow. Requests to remove those records must be reviewed by an authorized Administrator and may be subject to organizational, contractual, customs, legal, security, or records-retention obligations.
6. How to make and track a privacy or removal request
Submitting a request does not automatically delete or alter records. An Administrator reviews the request first and determines whether information can be provided, corrected, restricted, removed, preserved, or must remain under an applicable business or retention requirement.
If you cannot sign in, contact the CargoFlow Administrator or the organization that provided your account and identify the information you want reviewed.
7. Google account revocation
If you are the owner of the connected Google account, you can separately revoke CargoFlow's Google access through your Google Account security or third-party connections controls. Revoking access prevents future API access but does not automatically erase business records that were already imported into CargoFlow.
8. Questions
Questions about a specific deletion, retention, account, or Google-access request should be directed to the CargoFlow Administrator or the organization responsible for your CargoFlow account.