Privacy Policy
Last updated: September 30, 2026
Warden Technologies ("Company," "we," "us," or "our") operates WardenIQ, including the web dashboard, Outlook Add-in, desktop application, and related services (collectively, the "Service"). This Privacy Policy describes how we collect, use, store, share, and protect your information when you use the Service.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, do not use the Service.
1. Information We Collect
1.1 Account Information
When you create an account, we collect your name, email address, company name, and job title (if provided).
1.2 Billing Information
When you subscribe to the Service, payment information (credit card number, billing address) is collected and processed by our payment processor, Stripe, Inc. We do not store your full credit card number on our servers. We receive and store only a truncated card number (last four digits), card brand, expiration date, and billing address for record-keeping purposes.
1.3 Email Data (Outlook Add-in)
When you use the WardenIQ Outlook Add-in, the add-in reads the subject, body, and sender information of the email you are currently viewing. This data is transmitted to our servers over encrypted connections (HTTPS/TLS) solely to parse and extract structured freight information, including origin and destination cities, equipment types, pickup dates, and rate information.
Important: The Outlook Add-in processes emails only when you actively invoke it on a specific email. It does not run in the background, does not scan your mailbox, and cannot access other emails, contacts, calendar, or any other mailbox data. WardenIQ does not keep complete emails. When the panel reads an email it may remember which shipper sent it. If WardenIQ's own reader needed the AI reader (see Section 2.2), it keeps the subject and the first part of the email, up to 2,000 characters, so we can improve the reader. Freight details become a quote request only when you save one.
1.4 Inbox Monitoring & Reply Automation (Microsoft Graph API, Optional)
If you choose to connect your Microsoft 365 account for inbox monitoring and reply automation, WardenIQ requests the following Microsoft Graph API permissions through Microsoft's standard OAuth consent flow:
- Mail.Read — scan your inbox for new freight RFQs (auto-quote and inbox monitoring features).
- Mail.Send — send quote replies and rate confirmation responses on your behalf.
- MailboxSettings.Read — read your timezone and working hours for scheduling.
- offline_access — refresh access tokens automatically without re-prompting.
This integration is opt-in. You can revoke access at any time from your Microsoft 365 admin center (Azure Active Directory → Enterprise Applications). OAuth refresh tokens are encrypted at rest using Fernet symmetric encryption and are tenant-isolated; no other tenant or third party can access them.
1.5 Quote and Business Data
We store freight quotes, rates, carrier pay, lane information, customer and carrier data, outcome data (won/lost), rate sheets, and other business data that you enter or import through the Service.
1.6 Usage Data
We collect basic usage information such as login timestamps, IP addresses, browser type, operating system, features accessed, and actions taken within the Service. We use this data to maintain security, diagnose technical issues, and improve the Service.
2. How We Use Your Information
- To provide, operate, and maintain the Service, including freight quote parsing, pricing intelligence, AI-powered rate recommendations, and dashboard features.
- To authenticate your identity, manage your account, and enforce subscription limits.
- To process payments and send billing-related communications.
- To analyze quoting patterns and improve pricing recommendations and AI features.
- To communicate with you about your account, service updates, security alerts, and support requests.
- To detect, prevent, and address technical issues, fraud, and security threats.
- To comply with legal obligations and enforce our Terms of Service.
- To produce anonymized usage statistics that help us run and improve the Service and cannot identify you or your business (see Section 2.1).
2.1 Your Data Stays With Your Company
Your quotes, rates, truck costs and customer information are used to provide the Service to your company. We do not show them to any other company, and we do not sell them.
- Agency brokerages: if your company is one of several agencies of the same brokerage and the brokerage turns on shared lane numbers, lane prices and truck costs from its agencies are combined and shown to those agencies. Shipper names, and which agency a number came from, are never shown. When a brokerage has only two agencies, each can work out the other's lane numbers. The brokerage decides whether sharing is on, and any agency can take its numbers out.
- Benchmarks between companies: these are opt-in only and start off. Only a company admin can turn them on. They only use data from companies that turn them on, only show combined numbers that cannot identify any company, and are not shown to anyone today. We will update this policy before that changes.
- Usage statistics: we may use anonymized, combined statistics (for example, how many quotes the Service reads) to operate and improve the Service. They cannot reasonably be used to identify you, any individual, or your business.
2.2 AI Features and AI Processing
WardenIQ's pricing and win-chance features learn from your company's data only. We do not use your data to train AI models that other companies use.
Some features send text to an AI service, Anthropic, PBC, under contract, only so it can read it for you:
- Rate confirmations you forward to WardenIQ, to read the load, carrier and rates.
- Quote request emails WardenIQ's own reader can't make out, to read the lanes and dates.
- Questions you type into the dashboard, with the lane details needed to answer them.
These can include shipper, carrier and contact names. Under Anthropic's commercial terms, Anthropic does not use this data to train its models. AI features are rate-limited to prevent abuse and manage costs.
2.3 Lane Scoring & Analytics
WardenIQ analyzes your quote history to generate lane-level scores across four dimensions: supply-demand balance, consistency over time, momentum (trend direction), and timing alignment. These scores are derived entirely from your own account's data and are used to help you assess lane profitability.
Scores are displayed across multiple surfaces in the Service, including the lane map, pending quotes, quote detail view, customer detail, dashboard overview, shipments view, and the Outlook Add-in. Scores are cached server-side for up to 15 minutes per tenant to improve performance, and caches are refreshed when you record new outcomes.
When exact city-level data is insufficient, the scoring engine falls back to broader geographic aggregations (freight market, state, or regional level) using only data from within your own account. No cross-tenant data is used in individual lane scores.
3. Data Storage and Security
Your data is stored on secure servers hosted on DigitalOcean, LLC infrastructure in the United States. We implement the following security measures:
- Encryption in transit: All data transmitted between your browser, Outlook, or desktop application and our servers is encrypted via TLS/HTTPS.
- Encryption at rest: Sensitive credentials (email passwords) are encrypted using Fernet symmetric encryption. Account passwords are hashed using bcrypt.
- Access controls: Server access is restricted to authorized personnel via SSH key authentication. Database access is limited to application processes.
- Network security: Firewalls (UFW), intrusion detection (Fail2Ban), rate limiting, and DDoS mitigation are in place.
- No method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect your data, we cannot guarantee absolute security.
4. Data Sharing and Third Parties
4.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information or business data to third parties. We do not share your personal information for cross-context behavioral advertising.
4.2 Sub-Processors
We use the following third-party service providers to operate the Service:
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| DigitalOcean, LLC | Cloud infrastructure, database hosting | All Service data | United States |
| Stripe, Inc. | Payment processing | Billing information, transaction data | United States |
| Let's Encrypt (ISRG) | TLS/SSL certificate issuance | Domain name only | United States |
| Microsoft Corporation | Outlook Add-in platform (Office.js) | Add-in metadata only | United States |
| Anthropic, PBC | Reading rate confirmations and quote request emails; answering typed questions | Rate confirmation and email text, which can include shipper, carrier and contact names; typed questions | United States |
| Cloudflare, Inc. | Website protection and delivery | All traffic to and from wardeniq.com passes through it | United States (worldwide network) |
| OpenStreetMap Foundation | Finding where a city is | City, state or ZIP only | United Kingdom |
We do not share your business data (freight quotes, rates, customer information, carrier data) with any sub-processor beyond what is strictly necessary for hosting, infrastructure, payment processing, and AI-powered features.
4.3 Integrations You Connect
If you connect your own Truckstop account, WardenIQ uses it to show Truckstop rates beside your quotes. WardenIQ also sends the lanes you win that have a truck cost to Truckstop's rate crowdsourcing program under your Truckstop account: origin and destination city, state and ZIP code, equipment, miles, the date, and the truck cost. Your customer names, contacts and quote prices are not sent. Disconnecting Truckstop stops this.
4.4 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to: (a) comply with applicable law; (b) protect the rights, property, or safety of Company, our users, or the public; or (c) detect, prevent, or address fraud, security, or technical issues.
4.5 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on the Service before your information becomes subject to a different privacy policy.
5. Email Permissions — Detailed Practices
WardenIQ uses two distinct permission scopes. These are independent: you can use the Outlook Add-in without ever connecting Microsoft Graph.
5.1 Outlook Add-in (in-Outlook panel)
The WardenIQ Outlook Add-in requests ReadItem permission only — the lowest level available for Outlook add-ins. Within the add-in panel:
- The add-in can read the subject, body, sender, and recipients of the email you are currently viewing — and only when you actively open the add-in.
- The add-in cannot read other emails in your mailbox.
- The add-in cannot send, modify, move, or delete emails.
- The add-in cannot access your contacts, calendar, or any other mailbox data.
- When you click "Reply with Quote," the add-in pre-fills a reply window that you review and send yourself in Outlook.
5.2 Inbox Monitoring & Reply Automation (Microsoft Graph API, optional)
If you opt in to inbox monitoring and reply automation, WardenIQ uses the Microsoft Graph API with the scopes listed in Section 1.4. These permissions are broader than the add-in's ReadItem scope and include the ability to read emails in your inbox (to detect new RFQs) and to send emails on your behalf (to deliver quote replies and rate-con responses). This integration is opt-in via Microsoft's standard OAuth consent flow and revocable at any time.
Email content processed for freight data extraction is transmitted to our servers over encrypted connections. We do not store complete email messages. Structured freight data is retained only when a quote request is created (either by you in the add-in or automatically via inbox monitoring, depending on your configuration).
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Duration of active account + 90 days after cancellation |
| Quote and business data | Duration of active account + 90 days after cancellation |
| Email-extracted freight data | Duration of active account + 90 days after cancellation |
| Email credentials (IMAP/SMTP) | Deleted immediately upon disconnection or account cancellation |
| Billing records | 7 years (as required for tax and accounting compliance) |
| Usage logs and IP addresses | 90 days |
After the 90-day post-cancellation retention period, Customer Data is permanently deleted upon request. If no deletion request is received, data may be deleted at Company's discretion after the retention period.
7. Your Rights
7.1 All Users
- Access: You may request a copy of the personal information we hold about you.
- Correction: You may update or correct your account information through the dashboard or by contacting us.
- Deletion: You may request deletion of your account and all associated data by contacting us at [email protected].
- Data Export: You may request an export of your data in a standard, machine-readable format (CSV or JSON).
We will respond to all rights requests within thirty (30) days. We may verify your identity before fulfilling a request.
7.2 California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purpose for collection, and the categories of third parties with whom we share it.
- Right to Delete: You may request that we delete your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising. There is no need to opt out, but you may contact us to confirm.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes beyond providing the Service.
To exercise any of these rights, contact us at [email protected]. We will respond within forty-five (45) days as required by CCPA.
7.3 Categories of Personal Information Collected (California Disclosure)
| Category (per CCPA) | Examples | Collected |
|---|---|---|
| Identifiers | Name, email, IP address | Yes |
| Commercial information | Subscription plan, billing history | Yes |
| Internet/electronic activity | Login timestamps, features used | Yes |
| Professional information | Company name, job title | Yes |
| Geolocation | IP-derived approximate location | Yes |
| Financial information | Last four digits of payment card (via Stripe) | Yes |
| Biometric information | N/A | No |
| Sensory data | N/A | No |
| Protected classifications | N/A | No |
We do not sell any of the above categories of personal information. We do not share personal information for cross-context behavioral advertising.
8. Cookies and Local Storage
The Service uses browser localStorage to store your authentication token. We do not use tracking cookies, third-party analytics cookies, or advertising cookies. No cookie consent banner is required because we do not use cookies for tracking or advertising purposes.
9. Children's Privacy
The Service is designed for business use and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly.
10. International Data Transfers
The Service is operated from and data is processed in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence.
11. Data Breach Notification
In the event of a data breach that affects your personal information or business data, we will:
- Notify affected accounts by email within seventy-two (72) hours of confirming the breach.
- Include in the notification: the nature of the breach, the categories of data affected, the approximate number of affected accounts, the likely consequences, and the measures taken or proposed to address the breach.
- Notify applicable regulatory authorities as required by law.
12. Compliance
We process data under applicable United States federal and state privacy laws, including the California Consumer Privacy Act (CCPA/CPRA). While we are not currently subject to the EU General Data Protection Regulation (GDPR), we apply data protection principles consistent with GDPR standards, including data minimization, purpose limitation, storage limitation, and the right to deletion. If you have specific compliance requirements (including GDPR, SOC 2, or industry-specific requirements), please contact us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by: (a) sending an email to the address associated with your account; and (b) posting the updated policy on this page with a revised "Last updated" date. Continued use of the Service after the effective date of changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:
Warden Technologies
Email: [email protected]
Web: wardeniq.com/support