Privacy Policy

Effective: July 19, 2026

This policy covers Waybill — the procurement platform at waybill.to, operated by Waybill, Inc., a company registered in Delaware (“Waybill,” “we”). It explains what data we handle, why, and the choices you have.

The short version. Waybill runs procurement for hardware companies: request, source, approve and pay, track, receive, stock, with customs built in. To do that we process your company’s procurement data — parts, quotes, orders, invoices, shipping and customs documents. Email access is opt-in and scoped: mail unrelated to procurement is discarded at classification and never stored. We do not sell personal data and we do not use your data to train AI models. Customs filings are submitted to government authorities — that is the service working as intended.

1. Our role: processor for your company, controller for the rest

Most data on Waybill belongs to the company you work for. When we process procurement records, documents, and connected email on behalf of a customer, we act as a processor (service provider) under our agreement with that customer, which controls how the data is used. Rights requests about this data go to your employer; we assist them.

For account registration, website visits, and sales or marketing contact, we act as the controller.

2. What we collect

Account data. Name, work email, role (engineer, manager, admin), phone if provided, employer, login and authentication records.

Procurement data. Part requests and MPNs, quotes, purchase orders, invoices, packing lists, air waybills, bills of entry, HS classifications, duty and tax computations, delivery addresses, vendor and carrier communications, goods-receipt and inventory records, approval and payment references.

Connected email. Only if your organization connects a mailbox — see Section 4.

Vendor contact data. Names, emails, and phone numbers of supplier and logistics representatives, processed to execute sourcing, orders, and shipments.

Payment data. Payments run through regulated payment processors (e.g., Razorpay) and banking partners. We store transaction references and invoices, not card numbers or banking credentials.

Usage data. IP address, device and browser information, pages viewed, actions taken, and application logs, used for security, debugging, and product analytics. Our first-party analytics provider, PostHog, also captures anonymized session replays of app usage; sensitive financial data (prices, invoices, and payment details) is masked and never recorded.

3. How we use data

To operate the product: source parts and request quotes, place and manage orders, run approval workflows, execute payments, track shipments, prepare and file customs documents, reconcile invoices, and maintain stock records. To communicate with suppliers, carriers, and customs brokers on your company’s behalf. For security, fraud prevention, and troubleshooting. For legal and trade compliance, including customs, tax, sanctions, and export-control screening. To improve the product, using aggregated or de-identified data. To contact prospective customers about Waybill (a controller activity; unsubscribe anytime).

Where GDPR applies, we rely on performance of contract, legitimate interests, legal obligation, and consent (for marketing and mailbox connection).

We do not sell personal data or share it for cross-context behavioral advertising.

4. Connected email

Email connection is opt-in, per mailbox, authorized by your organization via OAuth.

Purpose. Detect and act on procurement signals: quotes, order confirmations, shipping and customs notices, invoices, and vendor replies.

How it works. Incoming mail is classified automatically. Messages relevant to procurement are ingested into your workspace. Messages that are not procurement-related are discarded after classification and are not stored, indexed, or reviewed. Waybill personnel do not read connected mail except for support or debugging at your request, under access controls and logging.

You can disconnect a mailbox at any time in Waybill settings, or revoke access from your email provider’s security settings.

Waybill’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. AI processing

Waybill’s agents use large language models from third-party providers under enterprise agreements that prohibit those providers from training on your data and that limit their retention of it. We do not use Customer Data to train or fine-tune foundation models. Agent actions with financial or legal effect — payments, purchase orders, customs filings — run under approval controls configured by your organization.

6. Who we share data with

Suppliers and logistics providers. RFQs, purchase orders, and shipment instructions sent on your company’s behalf necessarily include company name, delivery address, and requester contact details where required.

Government authorities. Customs and tax filings (for example, with Indian Customs via ICEGATE and GST authorities) are legally mandated disclosures made as part of the service.

Payment processors and banks. To execute payments you initiate or approve.

Subprocessors. Cloud hosting, AI model providers, and communications infrastructure, bound by confidentiality and data-protection terms. Current list available at privacy@waybill.to.

Corporate. A successor in a merger, acquisition, or asset sale, with notice.

Legal. Where required by law, regulation, or valid legal process, or to protect rights, safety, and the integrity of the service.

7. International transfers

We operate in India and the United States; subprocessors may process data in other regions. Transfers are protected by contract, including standard contractual clauses where GDPR or UK GDPR applies, and in accordance with India’s Digital Personal Data Protection Act, 2023.

8. Retention

Customer Data is retained for the life of your company’s agreement and deleted within 60 days of termination, with export available on request — except records we are legally required to keep. Customs and tax filings and their supporting documents are retained for the statutory period (typically five to six years in India under customs and GST law). Account and marketing data is kept until you ask us to delete it or after 24 months of inactivity. Security and application logs are kept for 12 months.

9. Security

Data is encrypted in transit and at rest. Access is role-based, least-privilege, and logged. Production infrastructure runs on SOC 2–certified cloud providers. We maintain an incident-response process and will notify affected customers of a breach as required by law.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, and to withdraw consent. You may also have the right to lodge a complaint with a data protection authority in your jurisdiction. Write to privacy@waybill.to; we respond within 30 days. If the data is your employer’s Customer Data, we route the request to them and assist.

India (DPDP Act, 2023). Contact our Grievance Officer: Rishi Laddha, Waybill, Inc., 251 Little Falls Dr, Wilmington, Delaware 19808, privacy@waybill.to. If unresolved, you may escalate to the Data Protection Board of India.

11. Cookies

waybill.to uses essential cookies for login and security, and first-party product analytics (PostHog, including masked session replay) to understand product usage. We do not use third-party advertising cookies. You can control cookies in your browser settings.

12. Children

Waybill is a business product for users 18 and over. We do not knowingly collect data from minors.

13. Changes

We post updates to this page and, for material changes, notify customers by email or in-app before they take effect.

14. Contact

Privacy inquiries: privacy@waybill.to

Compliance contact: Rishi Laddha, compliance@waybill.to

Waybill, Inc. (registered in Delaware)
251 Little Falls Dr, Wilmington, Delaware 19808