AWBGuru processes air waybills and related shipping documents on behalf of freight forwarders. We treat the documents you send us as your confidential content. This page describes how we protect that data and the third parties (subprocessors) that help us run the service.
Data protection commitments
- Third-party AI does not train on your documents. Content sent to our AI extraction subprocessor is not used to train its models under its commercial API terms.
- We improve our own extraction from de-identified data. We may use anonymized data derived from your documents and from your review corrections to improve our own extraction accuracy — prompts/skills, validation rules, and evaluation sets. Anonymized by default; raw documents only with your consent; on by default with an opt-out; retained for up to 24 months, then automatically deleted; and never shared with, or traceable to, any other customer.
- You own your data. Extracted data and source documents are your content; you can export or delete them.
- You control retention. Extracted structured data and the original document files are retained as your system of record for the life of the record — until you delete it or close your account.
Encryption
- In transit: TLS 1.2 or higher for all connections to the web app and API.
- At rest: document files and database contents are encrypted at rest by our cloud provider.
Hosting and data location
AWBGuru runs on Microsoft Azure in the United States (Central US region). Application, database (Azure SQL), and document storage (Azure Blob Storage) are hosted there. Data residency for non-US customers is not currently offered.
Access control
- Access to production systems and customer content is restricted to authorized personnel on a need-to-know basis.
- Customer accounts support role-based access (see the product's RBAC configuration).
Security program
AWBGuru maintains an information-security program with administrative, technical, and physical safeguards appropriate to the size and complexity of our business and the sensitivity of the data we handle. These include encryption in transit and at rest, role-based access on a need-to-know basis, reputable cloud infrastructure (Microsoft Azure), subprocessor due diligence, and secure data disposal. We designate personnel responsible for security and review our safeguards periodically.
Subprocessors
We use the following subprocessors to deliver the service. We will maintain this list and provide notice of material changes.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Microsoft Azure | Cloud hosting, database, document/file storage | Account data, Customer Content (documents + extracted data), logs | United States (Central US) |
| Microsoft Azure Communication Services | Outbound email (sign-in/verification codes, invitations, billing notices, document-result replies, notifications) | Recipient email addresses, message content, and result-file attachments (which may contain extracted personal data) | United States |
| Google Workspace / Gmail | Mailbox that receives documents sent to email-intake addresses | Inbound messages, sender addresses, and attached documents | United States |
| AI extraction subprocessor (identified in our DPA / on request) | AI-based document data extraction | Contents of submitted documents (sent for extraction; not used for model training under commercial terms) | United States |
| Stripe | Payment processing / billing | Billing and payment card data (card data stored by Stripe, not AWBGuru); customer billing metadata | United States |
| Google (Google Analytics / GA4) | Website analytics on public pages | Pseudonymous usage data (pages viewed, device/browser, approximate location from IP) — collected only with cookie consent; no documents or account data | United States |
Note on billing data flow: Stripe processes payment cards and billing data only. Stripe does not receive Customer Content (your documents). Conversely, our AI subprocessor receives document content but no payment data.
Email intake
Documents can be sent to an AWBGuru intake email address. Inbound messages are received into a Google Workspace (Gmail) mailbox we operate and are processed into the pipeline. Once processed, a message is deleted from the intake mailbox within 24 hours; messages held for review are automatically deleted after 30 days. Outbound email (including replies with extracted results) is sent through Azure Communication Services.
Data deletion
On written request or account closure, we delete Customer Content from production systems within 30 days, subject to legal retention obligations. Backups expire on our normal backup cycle.
Breach notification
If we become aware of a security breach affecting your personal information, we will notify affected customers and, where required by law, affected individuals and regulators without unreasonable delay and within the timeframes that apply — including New York's 30-day requirement under the SHIELD Act.
Certifications
AWBGuru does not currently hold third-party security certifications (e.g., SOC 2). We do not claim certifications we do not have.
Reporting a security issue
Report suspected vulnerabilities or incidents to hello@awbguru.com.
Requesting a DPA
Enterprise customers who require a Data Processing Addendum (with subprocessor list) can request one at hello@awbguru.com.