CFCARGOFLOWTRUST & DATA PROCESSINGLegal Center
TRANSPARENCY

Subprocessors & Connected Services

This page identifies material infrastructure providers and optional connected services that may process information for CargoFlow. Not every provider is active for every customer or feature.

Effective and last updated: September 21, 2026

1. How to read this page

A subprocessor is a service provider CargoFlow may use to process Customer Personal Data on CargoFlow's behalf. A connected service is generally a provider, account, carrier, or system that a customer or authorized user chooses to connect or query as part of a user-facing workflow. The legal role can vary by configuration and the customer's relationship with the provider.

CargoFlow uses providers only for the functions needed to operate, secure, communicate about, or deliver the service. Customer-specific contracts may impose additional requirements.

2. Core infrastructure

VercelApplication hosting, serverless execution, deployment, content delivery, and related platform infrastructure for CargoFlow.
NeonManaged PostgreSQL database infrastructure used for CargoFlow application records, subject to the customer's tenant and role controls.

3. Conditional service providers

ResendTransactional email delivery for Customer Portal invitations or service messages when that feature is configured and enabled. Typical data can include recipient email address, message content needed for the invitation or service notice, and delivery status metadata.
CloudmersiveMalware scanning for uploaded documents when document malware scanning is enabled. The document bytes and basic file metadata needed to perform the scan may be transmitted to the scanner.
Microsoft AzureMay be used for customer-specific carrier push or messaging integrations, such as a configured carrier event subscription. This is not enabled for every customer.

4. User-authorized connected services

Google Workspace / Gmail. When an authorized Administrator connects the Carrier Inbox, CargoFlow uses Google's Gmail API with read-only access for the user-facing workflow described in the Privacy Policy. Google Workspace data is subject to Google's Limited Use requirements.

Carrier and tracking providers. When tracking is configured and invoked, CargoFlow may send a shipment, container, booking, or transport-document reference to the applicable carrier or tracking provider and receive operational tracking events. Current supported or developing integrations may include Maersk, Hapag-Lloyd, CMA CGM, MSC, ONE, ZIM, Yang Ming, Evergreen, COSCO, OOCL, or customer-specific carrier sources. A carrier is not necessarily a CargoFlow subprocessor; it may instead be an independent data source or a provider with which Customer has a separate relationship.

Microsoft Outlook Web. CargoFlow's current Outlook workflow prepares a draft and opens Outlook Web through the user's browser after review. CargoFlow does not currently connect server-side to Microsoft 365 or obtain Microsoft mailbox permissions for this feature. Once the user opens Outlook Web, Microsoft's own terms and privacy practices apply to that interaction.

5. Changes to providers

CargoFlow may add, replace, or remove providers as the service evolves. Material changes involving a provider that will process Customer Personal Data will be reflected on this page or communicated through another reasonable customer notice mechanism. Customers with a signed DPA may exercise any subprocessor objection rights stated there.

6. Questions

Questions about a provider, data category, transfer, or customer-specific security review may be sent to contact@cargoflowdg.com.