OpenBoxesLift
FeaturesPricingDemoDocsAboutContact
Sign InStart Free Trial

Privacy Policy

Last updated: August 11, 2026

Table of Contents

  • 1. Introduction and Scope
  • 2. Information We Collect
  • 3. How We Use Information
  • 4. Information Sharing and Sub-Processors
  • 5. Data Security
  • 6. Data Retention
  • 7. Your Rights
  • 8. California Residents (CCPA/CPRA)
  • 9. Canadian Residents (PIPEDA and Provincial Privacy Laws)
  • 10. Cookies
  • 11. Children's Privacy
  • 12. International Visitors
  • 13. Changes to Policy
  • 14. Contact Us

1. Introduction and Scope

OpenBoxes Solutions LLC ("we," "our," or "us") operates OpenBoxes Lift (the "Service"). This Privacy Policy describes how we collect, use, share, and protect personal information when you use the Service or interact with our website.

OpenBoxes Lift is a business-to-business supply chain management platform. We process two distinct categories of data:

  • Customer Account Data — personal information about the individuals who hold subscriptions and administer accounts (typically business contacts at our customer organizations).
  • Customer Tenant Data — the operational data customers upload to OpenBoxes Lift to run their supply chain operations (inventory records, orders, locations, products, etc.). For this data we act as a processor on behalf of our customer (the controller); our processing is governed by our Data Processing Agreement.

This Privacy Policy primarily addresses Customer Account Data. Customer Tenant Data is handled in accordance with the customer's instructions and the DPA.

OpenBoxes Lift currently serves customers in the United States and Canada only.

2. Information We Collect

2.1 Information You Provide Directly

  • Account information: name, email address, organization name, encrypted password, country of business.
  • Billing information: billing address; payment card or bank account details collected and tokenized by Stripe — we do not store full card or bank account numbers on our systems.
  • Profile information: job title, phone number, communication preferences.
  • Communications: support tickets, chat transcripts, emails, and feedback you send us.
  • Tenant data: the supply-chain data you upload to your OpenBoxes instance (inventory, products, locations, transactions, user accounts within your instance). Some of this may be personal information about your employees, customers, or suppliers. You are the controller of that data and are responsible for the lawful basis to provide it to us.

2.2 Information Collected Automatically

  • Usage data: pages visited within the customer portal, features used, API calls made, timestamps; session replay recordings of how you interact with our marketing website, customer portal, and public demo instance (mouse movement, clicks, scrolling, the pages you view, and text typed into forms — payment card and bank account details are entered in Stripe-hosted frames the recording cannot see), captured by FullStory subject to the consent rules in our Cookie Policy (the demo instance has no consent banner — replay there is disclosed when you request demo access; see Section 3).
  • Device and network information: browser type and version, operating system, IP address, approximate geolocation derived from IP.
  • Log data: application server logs, error reports, security-event logs (audit log of administrative actions).
  • Cookies and similar technologies: see our Cookie Policy for the full list and purposes.

2.3 Sensitive Personal Information

We do not knowingly collect or process sensitive personal information about our customers, such as government identification numbers, racial or ethnic origin, religious beliefs, biometric data, or health information, in connection with Customer Account Data. If you choose to upload tenant data that includes sensitive categories about third parties (e.g., your employees), you are responsible for compliance with applicable law.

3. How We Use Information

We use Customer Account Data for the following purposes:

  • Service delivery: to provision and operate your OpenBoxes Lift instance, authenticate you, and provide support.
  • Billing: to process subscription charges, send billing receipts, and manage trial conversion and cancellation.
  • Communication: to send service-related emails (account verification, security alerts, trial-end notices, billing notifications, downtime notices, policy changes) and — only with your opt-in — marketing communications.
  • Improvement and analytics: to understand how the Service and our marketing website are used and improve them. We use Sentry for error tracking. On the marketing website we run our own first-party usage analytics (pages viewed, time spent per page section, scroll depth, clicks on our own links — that system never stores your IP address or anything you type, and its raw data is deleted after 180 days), Google Analytics, and FullStory session replay. FullStory works differently from the other two: it records how your visit unfolds — mouse movement, clicks, scrolling, the pages you view, and text you type into forms (payment card and bank account details are entered in Stripe-hosted frames FullStory cannot see) — and it receives your IP address as part of providing the service. All three are governed by the consent rules in our Cookie Policy. FullStory also records sessions in the customer portal, where sessions are identified by an internal account identifier — never your email — and can be turned off in the portal's settings. If you request demo access, join the waitlist, send us a message through our contact form, or leave your details with our chat assistant, we may associate your prior browsing on our own site with your inquiry so we can respond knowledgeably; that association is removed when the inquiry is deleted, and the underlying browsing data ages out within 180 days regardless. When you request demo access, we also measure how the demo itself is used — which screens you visit, when your sessions start and end, and whether you follow the "Get your own OpenBoxes" link — and we associate that activity with your demo request so we can understand what interested you and follow up knowledgeably. The demo instance (demo.openboxes.cloud) additionally uses FullStory session replay, which records how a demo visit unfolds — clicks, navigation, and the demo's on-screen contents: the shared sample dataset, including anything you or other visitors enter into the demo before its daily reset. We do not identify demo replay sessions to FullStory, and they are not tied to your identity beyond the usage measurement described above (FullStory does receive your IP address as part of providing the service). The demo usage records we hold are deleted within 90 days, and are deleted immediately if we delete your demo request; replay recordings uploaded to FullStory are retained by FullStory and deleted under its retention policy. We also record actions you take on the signup page itself — including which sign-in method you click — associated with a browser correlation token, and retained for 90 days. We do not sell personal information to third parties.
  • Security and fraud prevention: to detect, prevent, and respond to fraud, abuse, and security incidents — including the per-IP and per-email signup rate limits described in our security documentation.
  • Legal compliance: to comply with tax, accounting, audit, and other legal obligations.

We do not sell, rent, or share personal information for cross-context behavioral advertising. We do not use Customer Tenant Data to train machine-learning models.

4. Information Sharing and Sub-Processors

We share information with the following categories of third parties, all bound by data processing agreements that require security and confidentiality protections at least as protective as our own:

  • Infrastructure providers: Google Cloud Platform hosts the Service in the us-east1 region. See our Sub-Processor List for the full list, kept current and subject to 30 days' advance notice of changes.
  • Payment processing: Stripe, Inc. processes all subscription billing and stores payment card and bank account details directly with their PCI-DSS Level 1 certified infrastructure.
  • Email delivery: our transactional email service for service notifications, account verification, and lifecycle communications.
  • Error tracking and observability: Sentry for application error monitoring. Personal information is scrubbed from error reports before transmission where practical.
  • Session replay and product analytics: FullStory, Inc. records sessions on our marketing website, in the customer portal, and on the public demo instance (subject to the consent rules in our Cookie Policy; on the demo, disclosed when you request access — see Section 3) so we can understand and improve how the Service is used. Recordings are hosted in FullStory's United States (na1) environment.
  • Legal requirements: we may disclose information when required by law, subpoena, court order, or other valid legal process; or to protect the rights, property, or safety of OpenBoxes, our customers, or the public. Where lawful and practical, we will notify the affected customer before disclosure.
  • Business transfers: if we are involved in a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred. Continued use is subject to the privacy policy in effect at the time.
  • With your consent: when you authorize us to share information for a specific purpose.

5. Data Security

We implement reasonable and appropriate technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure, or destruction:

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 for database and backups).
  • Per-tenant data isolation via schema-per-tenant architecture so one customer cannot access another's data.
  • Identity and access management via Keycloak, including multi-factor authentication (TOTP) for administrative roles.
  • Centralized audit logging of administrative actions for security forensics, retained per our retention policy.
  • Automated daily database backups with 30-day rotation.
  • Documented incident response and vulnerability-disclosure intake at security@openboxes.cloud.

No method of transmission or storage is 100% secure. In the event of a security incident affecting your personal information, we will notify you in accordance with applicable law.

6. Data Retention

We retain your information for as long as your account is active and as needed to provide the Service. After cancellation or account closure:

  • Soft-delete window (30 days): Your data remains recoverable and exportable. You may request account recovery during this period.
  • Hard-delete window (additional 30 days): Tenant data (your OpenBoxes instance) is destroyed at the end of the soft-delete window. Anonymized account metadata is retained for an additional 30 days to support finance and compliance obligations.
  • Backups: Backups roll over on a 30-day rotation, so complete erasure including from backups can take up to 30 additional days.
  • Audit logs: Retained for 7 years for security forensics and compliance. After hard-delete, personal information in audit log records is redacted (email, IP address, user agent) while the action history is preserved.
  • Invoices and tax records: Retained for 7 years to meet tax and accounting requirements. After hard-delete, customer name, email, and address fields are redacted while financial line items remain for accounting.
  • Email suppression list: If you unsubscribe, your address is retained on a suppression list to prevent re-sending. This is maintained indefinitely unless you request deletion.

Full technical detail is available in our internal data retention policy.

7. Your Rights

Subject to your jurisdiction's laws, you have the following rights with respect to your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information. You can correct most account-level information directly in your account settings.
  • Deletion: Request deletion of your personal information, subject to legal retention obligations. Closing your account from the Billing settings page initiates our standard retention process described in Section 6.
  • Portability: Request a machine-readable copy of your data. A self-service export is available from your account settings.
  • Opt-out of marketing: Every marketing email contains an unsubscribe link. Service-related emails (billing notices, security alerts) cannot be opted out of while your account is active.
  • Withdraw consent: Where we rely on consent (e.g., for marketing cookies), you may withdraw consent at any time via the cookie banner or account preferences.
  • Complain to a regulator: California and Canadian residents see Sections 8 and 9 for specific complaint mechanisms.

To exercise these rights, email privacy@openboxes.cloud from the email address associated with your account. We will respond within 30 days. We may need to verify your identity before fulfilling a request.

8. California Residents (CCPA / CPRA)

This section provides additional information for California residents under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA").

8.1 Categories of Personal Information Collected

In the past 12 months we have collected the following categories of personal information about California residents:

  • Identifiers (name, email address, IP address, account ID)
  • Customer records (billing address, payment card or bank account token, business contact details)
  • Commercial information (subscription tier, billing history, purchases)
  • Internet activity (pages visited, features used within the customer portal, session replay recordings of interactions with our marketing website, customer portal, and public demo instance)
  • Geolocation data (approximate, derived from IP address)
  • Professional information (job title, organization)

8.2 Sources, Purposes, and Sharing

We collect personal information directly from you when you sign up and use the Service, and automatically when you interact with the customer portal. Purposes are described in Section 3. Sub-processors are listed in Section 4 and our Sub-Processor List.

8.3 Sale or Sharing of Personal Information

We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioral advertising.

8.4 Sensitive Personal Information

We do not collect or process sensitive personal information as defined under the CPRA in connection with Customer Account Data, and we do not use any such information for purposes other than those permitted under CPRA section 7027(m).

8.5 Your California Rights

California residents have the right to:

  • Know what personal information is collected, used, shared, or sold
  • Delete personal information held about you (subject to legal exceptions)
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of personal information (not applicable — we do not sell or share)
  • Limit the use of sensitive personal information (not applicable — we do not process)
  • Non-discrimination for exercising these rights — we will not deny service, charge different prices, or provide a different level of quality because you exercised a privacy right

To submit a request, email privacy@openboxes.cloud. Authorized agents may submit requests on your behalf with proper documentation. We may need to verify your identity before fulfilling a request.

8.6 Shine the Light

California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

9. Canadian Residents (PIPEDA and Provincial Privacy Laws)

This section applies to residents of Canada. OpenBoxes Lift complies with the federal Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy laws including British Columbia's Personal Information Protection Act ("PIPA"), Alberta's Personal Information Protection Act, and Quebec's Act respecting the protection of personal information in the private sector ("Law 25").

9.1 Lawful Basis for Processing

We rely on the following lawful bases:

  • Performance of a contract: for delivering the Service to you, billing, and managing the subscription relationship.
  • Legitimate interest: for security monitoring, fraud prevention, service improvement, and audit logging — balanced against your privacy interests.
  • Consent: for marketing communications and non-essential cookies.
  • Legal obligation: for tax records, audit records, and regulatory compliance.

9.2 Your Rights Under PIPEDA and Provincial Laws

Canadian residents have the rights described in Section 7, and additionally:

  • The right to challenge our compliance with our privacy practices
  • The right to know the policies and practices for managing personal information
  • For Quebec residents under Law 25: the right to data portability, the right to information about automated decision-making, and the right to be informed about the specific categories of personal information collected and the purposes
  • For Quebec residents: privacy concerns may also be directed to our Privacy Officer (contact details in Section 14)

9.3 Filing a Complaint

If you believe we have not adequately addressed a privacy concern, you may file a complaint with:

  • Office of the Privacy Commissioner of Canada — www.priv.gc.ca
  • Your provincial privacy commissioner (Quebec, British Columbia, and Alberta have provincial commissioners with jurisdiction over private-sector privacy)

9.4 Cross-Border Data Transfer

Personal information is stored and processed on infrastructure located in the United States (Google Cloud Platform, us-east1 region). By using the Service you acknowledge that your information will be transferred to and processed in the United States, where data protection laws differ from those in Canada. We rely on contractual safeguards (data processing agreements with sub-processors) to ensure your information receives a comparable level of protection.

10. Cookies

We use cookies and similar technologies for authentication, security, preferences, and analytics. Analytics on the marketing website runs on an opt-out basis for most visitors, and on an opt-in basis for visitors sending the Global Privacy Control signal or whose device timezone indicates the EU/UK — the banner is a working control in both directions. For the full list, purposes, and your control options, see our Cookie Policy.

11. Children's Privacy

The Service is not intended for, marketed to, or designed for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will delete it promptly. If you believe a child has provided us with personal information, please contact privacy@openboxes.cloud.

12. International Visitors

The Service is currently offered only to customers located in the United States and Canada. Signups from other regions are not accepted at this time. If you access our website from outside the United States or Canada (for example to learn about the Service or to join the waitlist) you do so on your own initiative. Any personal information you provide will be transferred to and processed in the United States.

If we expand to additional regions, we will update this Privacy Policy to address the applicable data protection requirements (including the GDPR for European Union residents).

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to the address associated with your account and by posting the updated policy with a new "Last updated" date at least 30 days before they take effect. Non-material changes (clarifications, typo fixes) may take effect immediately on posting. The "Last updated" date at the top of this document reflects the most recent revision.

14. Contact Us

For questions or requests about this Privacy Policy or our data practices:

Email: privacy@openboxes.cloud
Security inquiries: security@openboxes.cloud
Mailing address: OpenBoxes Solutions LLC, Boston, Massachusetts, United States

Quebec residents may also direct inquiries to our Privacy Officer at the email address above.

OpenBoxesLift

Warehouse and inventory management made simple.

Product

  • Features
  • Pricing
  • Lift vs Self-Hosted
  • Status
  • Security

Resources

  • Documentation
  • Getting Started
  • API Reference
  • Community

Company

  • About Us
  • Contact
  • Careers

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Data Processing Agreement
  • Sub-Processors

© 2026 OpenBoxes Solutions LLC. All rights reserved.