Compliance
Google API Compliance
A technical and legal reference describing exactly how FreightSurf uses Google APIs and Google user data. Written for OAuth reviewers, security teams, and enterprise customers.
Last updated: May 2026 · See also: Privacy Policy · Terms of Service · Security
Overview
FreightSurf is an AI-powered SaaS platform built for freight brokers. Users voluntarily connect their Gmail account to FreightSurf using Google OAuth 2.0 so that FreightSurf can identify carrier communications, extract freight information, verify carriers, and help brokers respond faster.
This page describes, in specific and technical terms, which Google OAuth scopes FreightSurf requests, what Google user data those scopes provide access to, how that data is processed and protected, and how FreightSurf's practices align with the Google API Services User Data Policy, including the Limited Use requirements.
What FreightSurf Is (and Is Not)
FreightSurf helps freight brokers organize carrier responses, extract structured freight information from carrier emails, verify carrier identity, generate summaries, and streamline day-to-day freight operations.
FreightSurf Is
- An operational intelligence layer that sits on top of a broker's existing Gmail account.
- A tool for classifying carrier emails, extracting freight data, and verifying carriers.
- A tool that lets a broker send a reply from within FreightSurf, using Gmail, when the broker chooses to.
FreightSurf Is Not
- An email client, and it does not replace Gmail.
- An email marketing platform or cold-email tool.
- An inbox-warming service.
- A mailbox backup or archiving application.
Gmail Processing Pipeline
FreightSurf uses a multi-stage filtering pipeline to process incoming Gmail messages. Every incoming message in a connected inbox is evaluated by this pipeline, but only a subset of messages are ever processed beyond the initial classification stage.
- Stage 1 — Classification: every incoming message is evaluated to determine whether it relates to freight operations (for example, a carrier responding to a load posting).
- Stage 2 — Filtering: messages determined to be unrelated to freight operations are excluded from all further, downstream processing, including AI processing. They are not summarized, extracted, or analyzed beyond this classification step.
- Stage 3 — Extraction: messages identified as freight-related continue through the pipeline, where structured freight information is extracted from the message content.
Structured Data Extracted From Freight-Related Emails
For messages identified as freight-related, FreightSurf extracts structured fields such as:
- Carrier name
- MC number
- DOT number (where available)
- Equipment type
- Origin and destination
- Lane
- Rate
- Carrier contact information (phone, email)
- Message timestamps
Email Sending (gmail.send)
FreightSurf requests the gmail.send scope solely so that users can send replies to carriers directly from within FreightSurf, without needing to switch to Gmail.
- FreightSurf never sends emails automatically or on a schedule.
- Every outbound email requires an explicit, affirmative action by the user — composing or approving the message and choosing to send it.
- FreightSurf does not modify a message after the user has approved it for sending.
- Users remain responsible for the content of all communications sent from their account, whether drafted manually or with AI assistance.
What Google Data We Access
Under the OAuth scopes described above, FreightSurf may access the following categories of Google user data:
| Data type | Why it is required |
|---|---|
| Sender | To identify which carrier or contact a message came from, and to attribute extracted freight data to the correct carrier. |
| Recipients | To correctly thread and attribute outbound replies, and to avoid misclassifying broadcast or CC'd messages. |
| Subject | Used as a signal during classification (Stage 1) to help determine whether a message relates to freight operations. |
| Message body | Required to extract structured freight information (rate, lane, equipment, etc.) from freight-related messages, and to generate summaries and suggested replies. |
| Timestamps | Used to sequence carrier communications, track response times, and maintain accurate thread history. |
| Message metadata (thread and label information) | Used to group related messages into a single carrier conversation and to avoid re-processing messages already handled. |
| OAuth authentication tokens | Required by Google's OAuth 2.0 protocol to authenticate API requests to Gmail on the user's behalf. See Section 9 for how tokens are secured. |
Data Minimization
FreightSurf follows the principle of least privilege in how it requests and processes Google user data.
- Only the minimum Google OAuth scopes required to provide the Service are requested — gmail.readonly and gmail.send. No broader Gmail or Google Workspace access is requested.
- Only freight-related emails continue past the classification stage of the processing pipeline.
- Emails determined to be unrelated to freight operations are excluded from further processing.
- Unrelated emails are never sent to, or processed by, any AI system.
- Google user data is never collected or retained for any purpose unrelated to providing FreightSurf's requested functionality.
AI Processing
FreightSurf uses AI to provide specific, disclosed features of the Service. AI is not used as a general-purpose analysis tool over a user's inbox.
- Freight classification — determining whether an inbound message is a freight-related communication.
- Information extraction — parsing freight-related message content into structured fields (carrier, MC number, lane, rate, etc.).
- Summarization — producing concise summaries of carrier communications.
- Suggested replies — drafting reply content for the user to review, edit, and choose whether to send.
Google API Services User Data Policy Compliance
In accordance with that policy, Google user data obtained through the Gmail API is never:
- Sold to any party.
- Licensed to any party.
- Transferred to advertisers.
- Transferred to data brokers.
- Used for targeted advertising.
- Used for unrelated profiling.
- Used for general AI model training.
Security
FreightSurf applies the following security controls to Google user data and other account data. This section describes controls that are actually implemented, not aspirational goals.
- OAuth tokens are encrypted at rest and stored separately from other account data.
- All data transmitted between FreightSurf, your browser, and Google's APIs is encrypted in transit (TLS).
- Data stored at rest, including extracted freight data and OAuth tokens, is encrypted.
- Access to Google user data is authenticated and restricted to the systems and personnel that require it to operate the Service (least privilege).
- FreightSurf is hosted on established cloud infrastructure providers with their own security and compliance programs.
- Production access and system activity are monitored for security events.
- Users retain control over their own Google account access at all times (see Section 10).
User Control
Users are in control of their connection to Google at every stage:
- Connect Gmail to FreightSurf voluntarily, via Google's OAuth consent screen.
- Disconnect Gmail from FreightSurf at any time, from within FreightSurf account settings or from Google Account permissions.
- Revoke FreightSurf's OAuth access at any time from Google Account settings.
- Delete their FreightSurf account entirely.
- Request deletion of any Google-derived data stored by FreightSurf.
When a user disconnects Google or revokes access, FreightSurf revokes and deletes the associated OAuth tokens and stops making any further Gmail API calls for that account. Full details on retention timelines are in the Privacy Policy.
Third-Party Services
FreightSurf relies on a small number of categories of third-party providers to operate the Service. Each provider receives only the data necessary to perform its specific function.
| Category | Purpose | Data received |
|---|---|---|
| Cloud infrastructure | Hosting, compute, and database storage for the Service | Encrypted account data, including extracted freight data and OAuth tokens |
| AI processing | Freight classification, extraction, summarization, and suggested replies | Freight-related message content, processed solely to deliver these features |
| Analytics | Aggregate product usage analysis to improve reliability and features | Usage events; no Gmail message content |
| Error monitoring | Detecting and diagnosing application errors | Technical error data; Gmail message content is not intentionally included |
A complete, named list of subprocessors is maintained in the Privacy Policy.
What FreightSurf Does NOT Do
- Does not replace Gmail.
- Does not send cold emails.
- Does not perform email marketing.
- Does not warm inboxes.
- Does not sell user data.
- Does not profile users for advertising.
- Does not use Google Workspace data to train AI models.
- Does not transfer Google user data to advertisers or data brokers.
Frequently Asked Questions
Why does FreightSurf need Gmail access?
Freight brokers manage carrier relationships primarily through email. FreightSurf needs read access to identify carrier responses and send access so users can reply without leaving the platform. Without Gmail access, FreightSurf cannot provide its core carrier-intelligence features.
Why is gmail.readonly required?
gmail.readonly is required to classify inbound messages as freight-related or not, and to extract structured freight information from the messages that are freight-related.
Why is gmail.send required?
gmail.send is required only to let users send replies to carriers directly from FreightSurf. It is never used to send messages the user has not explicitly authorized.
Does FreightSurf read all my emails?
Every incoming message is evaluated by the classification stage of the processing pipeline to determine whether it is freight-related. Messages determined to be unrelated to freight operations are excluded from all further processing and are not analyzed beyond that classification step.
Does FreightSurf store my emails?
FreightSurf stores structured data extracted from freight-related emails (carrier name, MC number, lane, rate, etc.) and associated metadata. Content from messages classified as unrelated to freight operations is not retained.
Does FreightSurf use AI?
Yes. AI is used to classify messages, extract structured freight data, generate summaries, and draft suggested replies. See Section 7.
Is my Gmail data used to train AI?
No. Google Workspace data is never used to train general-purpose AI models, and it is never shared with AI providers for their own model training. See Section 8.
Can I disconnect my Gmail account?
Yes, at any time, from either your FreightSurf account settings or your Google Account permissions. Disconnecting revokes and deletes FreightSurf's OAuth tokens and stops all further Gmail API activity for your account.
How is my data protected?
Through encryption in transit and at rest, encrypted and separately stored OAuth tokens, least-privilege access controls, and monitored cloud infrastructure. See Section 9.
Questions
If you are a Google OAuth reviewer, an enterprise security team, or a user with questions about how FreightSurf handles Google user data, contact us at privacy@freightsurf.com. We aim to respond to compliance and security inquiries within 5 business days.