← Back to Home

Privacy Policy

Last Updated: January 20, 2025

Version 1.0

1. Introduction

DeliverX IT LLC, a California limited liability company located in Riverside, California ("Company," "we," "our," or "us"), operates NexPort ("Service" or "System"). This Privacy Policy explains how we collect, use, disclose, process, and safeguard your personal information when you use our shipping management platform.

Compliance: This Privacy Policy is compliant with the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and other applicable privacy laws. California residents have specific rights described in Section 7 of this policy.

Consent: By creating an account, accessing, or using the Service, you acknowledge that you have read and understood this Privacy Policy and consent to our data collection, use, and sharing practices described herein. If you do not agree with this Privacy Policy, you must not use the Service.

Contact: If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at support@nexli.ai.

2. Categories of Personal Information We Collect

We collect the following categories of personal information. For each category, we describe the data collected, purposes for collection, retention period, and whether it is shared with third parties.

2.1 Account Information

Examples: Email address, password (encrypted), user role, company name, account preferences

Purpose: Authentication, account management, service provision, communication

Retention: Duration of account + 90 days after account deletion

Third-Party Sharing: Yes (Supabase for database hosting and authentication)

2.2 Shipping Data

Examples: Shipping addresses (origin and destination), package dimensions, weights, tracking numbers, shipment history

Purpose: Rate calculation, shipment processing, analytics, compliance with shipping regulations

Retention: 7 years (required for tax and compliance purposes)

Third-Party Sharing: Yes (FedEx, UPS, DHL, USPS for rate calculation and shipment processing)

2.3 Business Rules and Configuration Data

Examples: Custom shipping rules, pricing configurations, carrier preferences, automation settings

Purpose: Service customization, rate calculation, business logic execution

Retention: Duration of account

Third-Party Sharing: No

2.4 AI Interaction Data

Examples: Rule generation prompts, AI-generated outputs, user feedback on AI suggestions, business context provided to AI

Purpose: AI service provision, service improvement, feature development

Retention: 2 years

Third-Party Sharing: Yes (OpenAI, Ollama for AI-powered rule generation)

2.5 Technical and Usage Data

Examples: IP addresses, browser type, device information, operating system, user agent, pages visited, features used, timestamps, API response times, error logs

Purpose: Security monitoring, fraud prevention, analytics, performance optimization, troubleshooting

Retention: 2 years

Third-Party Sharing: Yes (analytics and monitoring services if configured)

2.6 Cookies and Tracking Technologies

Examples: Authentication cookies, session tokens, preference cookies, analytics cookies

Purpose: Authentication, session management, user preferences, analytics

Retention: Varies by cookie type (see Cookie Policy)

Third-Party Sharing: Yes (Supabase for authentication cookies)

Note: We do not knowingly collect information from individuals under 18 years of age. If you are under 18, you must not use the Service or provide any personal information.

3. How We Use Your Personal Information

We use the collected personal information for the following business and operational purposes:

Service Provision:

  • Provide and maintain the shipping management platform
  • Authenticate users and manage account access
  • Calculate shipping rates and optimize logistics
  • Process and fulfill shipping requests
  • Execute custom business rules and automation

Service Improvement:

  • Analyze usage patterns and performance metrics
  • Develop new features and improve existing functionality
  • Conduct research and analytics
  • Train and improve AI models (with your data, if you use AI features)

Security and Fraud Prevention:

  • Detect and prevent fraud, unauthorized access, and security threats
  • Monitor system security and investigate suspicious activity
  • Enforce our Terms of Service and Acceptable Use Policy

Communication:

  • Send service updates, security alerts, and administrative messages
  • Respond to customer support inquiries
  • Notify you of changes to our legal agreements

Legal Compliance:

  • Comply with applicable laws, regulations, and legal processes
  • Respond to lawful requests from government authorities
  • Maintain records for tax and compliance purposes
  • Protect our legal rights and interests

4. Third-Party Services and Data Sharing

We Do Not Sell Your Personal Information. We do not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration.

We share your personal information with the following categories of third-party service providers to operate the Service:

Supabase (Database and Authentication)

Purpose: Database hosting, authentication, and data storage

Data Shared: All user data (account information, shipping data, business rules, technical data)

Location: United States

Privacy Policy: https://supabase.com/privacy

Shipping Carriers (FedEx, UPS, DHL, USPS)

Purpose: Shipping rate calculation, label generation, and shipment tracking

Data Shared: Shipping addresses, package dimensions, weights, tracking information

Location: United States

Privacy Policies: See respective carrier websites for their privacy policies

E-Commerce Platforms (Shopify, NetSuite)

Purpose: Order synchronization and e-commerce platform integration

Data Shared: Order data, customer addresses, product information (only if you configure these integrations)

Location: Canada/United States (Shopify), United States (NetSuite)

Privacy Policies: Shopify, Oracle/NetSuite

AI Services (OpenAI, Ollama)

Purpose: AI-powered shipping rule generation and recommendations

Data Shared: Rule generation prompts, business context, user feedback (only if you use AI features)

Location: United States (OpenAI), User infrastructure (Ollama - self-hosted)

AI Training: OpenAI may use your data for model training unless you opt out. See OpenAI's privacy policy for details.

Privacy Policy: https://openai.com/privacy/

Important: Third-party services have their own privacy policies and data practices. We are not responsible for how third parties collect, use, or protect your information. We recommend reviewing their privacy policies before using integrations.

5. Additional Data Sharing and Disclosure Circumstances

In addition to the third-party service providers described above, we may share your personal information in the following circumstances:

Legal Requirements and Law Enforcement:

We may disclose your information when required by law, court order, subpoena, or government regulation, or when we believe disclosure is necessary to protect our rights, comply with legal processes, or respond to lawful requests from public authorities.

Business Transfers:

In connection with a merger, acquisition, reorganization, sale of assets, bankruptcy, or other business transaction, your information may be transferred to the acquiring entity. We will notify you of any such transfer.

Protection of Rights:

We may disclose your information to protect the rights, property, or safety of the Company, our users, or the public, including to prevent fraud, enforce our Terms of Service, or investigate security incidents.

With Your Consent:

We may share your information with third parties when you explicitly authorize us to do so.

6. AI Data Processing and Automated Decision-Making

If you use our AI-powered features, your data will be processed by artificial intelligence services:

AI Service Providers:

We use OpenAI and Ollama to provide AI-powered shipping rule generation. When you use these features, your prompts and business context are sent to these third-party AI providers.

AI Training:

OpenAI may use your data to train and improve their AI models unless you opt out through OpenAI's data usage controls. Ollama processes data locally on your infrastructure and does not use your data for training.

Automated Decision-Making:

AI-generated shipping rules are suggestions only. We do not make automated decisions that significantly affect you without human review. You are responsible for reviewing and validating all AI outputs before implementation.

Your Control:

Use of AI features is optional. You can choose not to use AI-powered features if you do not want your data processed by AI services.

7. California Privacy Rights (CCPA/CPRA)

California Residents: If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). This section explains your rights and how to exercise them.

7.1 Right to Know

You have the right to request that we disclose:

  • The categories of personal information we collected about you
  • The categories of sources from which we collected your personal information
  • Our business or commercial purpose for collecting or selling personal information
  • The categories of third parties with whom we share personal information
  • The specific pieces of personal information we collected about you

How to Exercise: Email us at support@nexli.ai with the subject line "CCPA Right to Know Request"

Response Time: We will respond within 45 days (may be extended by an additional 45 days if necessary)

7.2 Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions.

Exceptions: We may retain your information if necessary to:

  • Complete the transaction for which the information was collected
  • Detect and resolve security incidents or fraud
  • Debug and repair errors
  • Comply with legal obligations (e.g., tax records, shipping logs)
  • Enable internal uses reasonably aligned with your expectations

How to Exercise: Email us at support@nexli.ai with the subject line "CCPA Right to Delete Request"

Response Time: We will respond within 45 days

7.3 Right to Correct

You have the right to request correction of inaccurate personal information we maintain about you.

How to Exercise: Email us at support@nexli.ai with the subject line "CCPA Right to Correct Request" and specify the inaccurate information

7.4 Right to Opt-Out of Sale or Sharing

We Do Not Sell Your Personal Information. We do not sell your personal information to third parties for monetary or other valuable consideration. Therefore, there is no opt-out mechanism required for sales.

7.5 Right to Limit Use of Sensitive Personal Information

We do not use or disclose sensitive personal information for purposes other than those permitted by CPRA. If this changes, we will provide you with the ability to limit such use.

7.6 Right to Non-Discrimination

You have the right to exercise your CCPA/CPRA rights without receiving discriminatory treatment. We will not:

  • Deny you goods or services
  • Charge different prices or rates for goods or services
  • Provide a different level or quality of goods or services
  • Suggest that you will receive a different price or quality of goods or services

7.7 Verification Process

To protect your privacy and security, we will verify your identity before processing your CCPA/CPRA request. We may request additional information to verify your identity, such as:

  • Email address associated with your account
  • Account details or recent activity
  • Government-issued identification (for sensitive requests)

7.8 Authorized Agents

You may designate an authorized agent to make CCPA/CPRA requests on your behalf. The authorized agent must provide written authorization signed by you, and we may require you to verify your identity directly with us.

8. Data Security Measures and Limitations

We implement reasonable and appropriate technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction:

Technical Measures:

  • Encryption of data in transit using TLS/SSL protocols
  • Encryption of data at rest in our database
  • Secure password hashing using industry-standard algorithms
  • Multi-factor authentication (MFA) support for enhanced account security
  • Secure API authentication and authorization

Organizational Measures:

  • Role-based access controls limiting employee access to personal information
  • Regular security audits and vulnerability assessments
  • Security monitoring and incident response procedures
  • Employee training on data protection and security best practices

Security Disclaimer:

NO GUARANTEE OF ABSOLUTE SECURITY: While we implement industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information. You acknowledge and accept the inherent security risks of internet-based services.

Limitation of Liability: To the maximum extent permitted by law, the Company is not liable for unauthorized access, data breaches, or security incidents beyond statutory requirements. See our Terms of Service for complete liability limitations.

Data Breach Notification:

In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law. Notification will be provided via email to your registered email address within the timeframe required by law.

9. Data Retention and Deletion

We retain your personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data category:

Account Information: Duration of account + 90 days after account deletion

Shipping Logs and Transaction Data: 7 years (required for tax, accounting, and compliance purposes)

AI Interaction Data: 2 years from last interaction

Technical Logs and Analytics: 2 years from collection

Business Rules and Configuration: Duration of account

Deletion Process:

When you request deletion of your account or personal information (or when retention periods expire), we will permanently delete your data within 90 days, except for data we are required to retain by law. Deleted data cannot be recovered.

Legal Retention Requirements:

We may retain certain information longer than stated above if required by law, regulation, legal process, or to protect our legal rights. This includes shipping transaction records, tax records, and audit logs.

10. International Data Transfers

Your personal information is primarily stored and processed in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States.

Data Protection Standards: The United States may have different data protection laws than your country of residence. By using the Service, you consent to the transfer of your information to the United States and acknowledge that U.S. law will govern the processing of your information.

Third-Party Transfers: Some third-party service providers (e.g., Shopify) may process data in other countries. See Section 4 for details on third-party data locations.

11. Children's Privacy

Age Restriction: The Service is not intended for individuals under the age of 18. We do not knowingly collect, use, or disclose personal information from children under 18 years of age.

Parental Rights: If you are a parent or guardian and believe that your child under 18 has provided us with personal information, please contact us immediately at support@nexli.ai. We will take steps to delete such information from our systems.

Account Termination: If we discover that a user is under 18 years of age, we will immediately terminate their account and delete their personal information, subject to legal retention requirements.

12. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time at our sole discretion. Material changes will be communicated to you via email to your registered email address or through an in-app notification.

Notice Period: We will provide at least 30 days' notice for material changes that affect your rights or how we process your personal information. The updated Privacy Policy will be posted on this page with a new "Last Updated" date and version number.

Acceptance: Your continued use of the Service after the effective date of the modified Privacy Policy constitutes your acceptance of the changes. If you do not agree to the modified Privacy Policy, you must discontinue use of the Service.

Review Responsibility: We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

13. Your Choices and Controls

Account Information:

You can update your account information, preferences, and settings by logging into your account. You are responsible for keeping your account information accurate and up-to-date.

Email Communications:

You can opt out of promotional emails by following the unsubscribe link in the email. Note that you cannot opt out of service-related emails (e.g., security alerts, legal notices, account notifications).

Cookies:

You can control cookies through your browser settings. See our Cookie Policy for details. Note that disabling essential cookies may affect Service functionality.

AI Features:

Use of AI-powered features is optional. You can choose not to use AI features if you do not want your data processed by AI services.

Account Deletion:

You can request account deletion at any time by contacting us at support@nexli.ai. Account deletion is permanent and cannot be undone.

14. Contact Information and Privacy Requests

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how we handle your personal information, please contact us:

Company Name: DeliverX IT LLC

Service Name: NexPort

Location: Riverside, California, United States

Email: support@nexli.ai

Privacy Request Types:

When contacting us about privacy matters, please specify the type of request:

  • CCPA Right to Know Request
  • CCPA Right to Delete Request
  • CCPA Right to Correct Request
  • General Privacy Inquiry
  • Data Breach Notification
  • Privacy Complaint

Acknowledgment and Consent

BY CREATING AN ACCOUNT, ACCESSING, OR USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THIS PRIVACY POLICY. YOU CONSENT TO OUR COLLECTION, USE, DISCLOSURE, AND PROCESSING OF YOUR PERSONAL INFORMATION AS DESCRIBED HEREIN.

If you do not agree to this Privacy Policy, you must not access or use the Service.