Skip to content
Hemut
ROI & Case StudiesWhy HemutIndustry Research
 Get started for free

Privacy Policy – Hemut CoPrivacy Policy - Hemut Co

Effective Date: April 23, 2026 | Updated: September 22, 2026

Hemut Co (“Hemut”, “we”, “us”, or “our”) respects your privacy and is committed to protecting it through this Privacy Policy. This document explains how we collect, use, and disclose information when you visit our website or interact with our services (collectively, the “Services”).

By accessing or using our Services, you agree to this Privacy Policy.

Hemut’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

1. Information We Collect

We collect information in the following categories:

a. Information You Provide

We collect information you voluntarily provide to us, including:

  • Name
  • Email address
  • Company name
  • Job title
  • Any other information submitted through forms, demo requests, or communications

b. Automatically Collected Information

When you access our Services, we may automatically collect certain information, including:

  • IP address
  • Browser type and device information
  • Pages visited and time spent on the site
  • Referring URLs and navigation paths
  • Interaction data, such as clicks and session activity

This information is collected through cookies and similar tracking technologies.

c. Aggregated and Derived Data

We may create aggregated or anonymized data from the information collected, which does not identify individual users and may be used for analytics, research, and business purposes.

2. How We Use Information

We use the information we collect to:

  • Operate and maintain our Services
  • Improve functionality, performance, and user experience
  • Respond to inquiries and communicate with users
  • Analyze usage patterns and trends
  • Ensure security and prevent misuse
  • Comply with legal obligations

3. Sharing of Information

We do not sell personal information.

We may share information with:

  • Service providers who perform services on our behalf (e.g., hosting, analytics, infrastructure)
  • Legal authorities when required to comply with applicable laws or legal processes
  • Successors or affiliates in the event of a merger, acquisition, or sale of assets, where your information may be transferred as part of that transaction

4. SMS/Text Message Alerts

As part of the Hemut platform’s alert and notification functionality, Hemut may send SMS/text messages to Authorized Users (people given access to the platform by a business customer of Hemut, their “Customer Organization”) on behalf of their Customer Organization. These messages may include operational alerts, load updates, ETA and delay notifications, safety notifications, account messages such as an invitation or sign-in link for the Hemut Driver App, and other time-sensitive information. Drivers may receive these messages at a work mobile number provided by their Customer Organization for operational communication.

  • Opt-In: Authorized Users consent to receive SMS messages by entering a mobile number, selecting alert categories, and checking the consent box on the platform’s Settings → Alerts page, or when their Customer Organization provides a work mobile number for operational communication. Consent is not a condition of purchasing any goods or services or of using the platform.
  • Opt-Out: Reply STOP to any message, or disable SMS alerts in platform settings. Opting out does not affect other platform functionality.
  • Message Frequency: Varies based on alert activity and the Authorized User’s role and notification preferences.
  • Rates: Standard message and data rates may apply depending on your mobile carrier and plan.
  • Carrier: Carriers are not liable for delayed or undelivered messages.
  • Marketing: Phone numbers are never used for marketing purposes — only for platform alerts, notifications, and account messages.

For help with SMS alerts, contact privacy@hemut.com or reply HELP to any message.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors that support our services, such as our messaging provider or customer support tools, is permitted solely to deliver those services. All other categories of use exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

5. Google OAuth and Gmail
Integration (QuoteFlow)

a. What QuoteFlow Does With Gmail Access

QuoteFlow is Hemut’s freight document automation feature. When you connect your Gmail account, QuoteFlow monitors your inbox for incoming load request emails from shippers. When a load request is detected, QuoteFlow extracts the relevant load details, automatically creates a load order in your Hemut account, and sends a quote reply to the shipper on your behalf — eliminating manual data entry and response time.

Here is the exact sequence of what happens when an email arrives in your connected Gmail inbox:

  • 1. Push notification received. Google sends a real-time notification to QuoteFlow’s servers whenever a new email arrives in your inbox. This notification contains only your Gmail account identifier and a history marker — no email content.
  • 2. Email metadata fetched. QuoteFlow uses the gmail.readonly scope to retrieve the new email’s subject line, sender address, and body text.
  • 3. AI classification. The subject line and body text are sent to Google Gemini to answer one question: is this a rate confirmation or load request email? If the answer is no, processing stops immediately — the email is not read further, not stored, and not acted on.
  • 4. PDF extraction (rate confirmations only). If Gemini classifies the email as a rate confirmation, QuoteFlow fetches the full email message using the gmail.readonly scope and extracts the PDF attachment from it. The PDF is held in memory only — it is never written to disk.
  • 5. Order creation. The PDF bytes are forwarded over HTTPS to Hemut’s order processing system, which parses the document and creates a load order. The PDF is not stored by QuoteFlow after forwarding.
  • 6. Label applied. QuoteFlow uses the gmail.modify scope to apply a status label to the email in your Gmail inbox — either QuoteFlow/Approved (order created successfully) or QuoteFlow/Review Pending (could not process automatically, requires your attention). No other change is made to the email — it is not moved, deleted, archived, or marked read/unread.
  • 7. Quote reply sent. QuoteFlow uses the gmail.send scope to automatically reply to the shipper’s email with a quote containing the original load details and your offered rate for the lane. The reply is sent from your connected Gmail address. No other emails are sent on your behalf.

The entire process — from notification to quote reply — is fully automated and typically completes within a few seconds of the email arriving.

b. Gmail Scopes We Request and Why

  • gmail.readonly (active): To read incoming email subjects, body text, and PDF attachments for rate confirmation detection and extraction.
  • gmail.modify (active): To apply QuoteFlow status labels (Approved, Review Pending) to processed emails so you can track document status in Gmail.
  • gmail.send (active): To automatically send a quote reply to the shipper on your behalf. The reply contains the load details from the shipper’s original request and the rate your account has configured for that lane.

c. What Gmail Data Is and Is Not Stored

  • Email subject line and sender address: used for rate confirmation classification. Not stored — discarded after classification.
  • Email body text: used for rate confirmation classification via Gemini AI. Not stored — discarded after classification.
  • PDF attachment bytes: forwarded to the order processing system. Not stored — forwarded in memory, never written to disk.
  • Gmail message ID: used for tracking processing state and applying labels. Stored in Hemut’s database.
  • Gmail thread ID: used for tracking conversation context for quote replies. Stored in Hemut’s database.
  • OAuth access and refresh tokens: used for authenticating Gmail API calls on your behalf. Stored — encrypted at rest, deleted on disconnect.

We do not read, store, or process personal correspondence, promotional emails, newsletters, or any email not classified as a rate confirmation or load request. We do not perform any scan of historical emails. Only emails that arrive after you connect your account are ever accessed.

We do not sell, rent, transfer, or share Gmail data with any third party for advertising, profiling, or any purpose outside of operating the QuoteFlow service.

d. How to Disconnect Gmail

You can revoke QuoteFlow’s Gmail access at any time:

  • In QuoteFlow: Go to Settings → Integrations and click Disconnect Gmail. Your OAuth tokens are deleted from our systems immediately.
  • Directly in Google: Visit myaccount.google.com/permissions and remove Hemut / QuoteFlow from your connected apps.

After disconnection, QuoteFlow immediately stops monitoring your inbox, no further emails are read or replied to, and all OAuth tokens are permanently deleted from our systems within 24 hours. Gmail labels already applied to your emails remain visible in Gmail — you can remove them manually at any time.

e. Security of Gmail Credentials

OAuth tokens are protected as follows:

  • Encrypted at rest using AES-256 via Google Cloud Secret Manager
  • Transmitted only over HTTPS — never over unencrypted connections
  • Never written to application logs or error tracking systems
  • Never shared with any third party
  • Scoped to the minimum permissions required — we request only the three scopes listed above and nothing else

6. AI Processing of Email Content

QuoteFlow uses Google Gemini, a large language model operated by Google LLC, to classify whether an incoming email is a freight rate confirmation or load request. This is the only AI or machine-learning process applied to your email data.

When a new email arrives in your connected inbox, its subject line and body text are sent to the Gemini API with a single question: is this a rate confirmation or load request email? The text is not used to train any model, is not stored by Hemut after the API call completes, and is handled by Google subject to their Gemini API Terms of Service.

If Gemini answers yes, QuoteFlow proceeds to extract the PDF attachment, create a load order, and send a quote reply to the shipper. If Gemini answers no, the email is ignored entirely — no further data is read, sent, or retained.

We do not use email content for advertising targeting, user profiling, or any purpose other than the binary classification described above.

7. Cookies and Tracking
Technologies

We use cookies and similar technologies to operate our Services and analyze usage.

You can control or disable cookies through your browser settings. Disabling cookies may affect certain features of the Services.

With your permission, we use PostHog to understand page visits, referral and campaign sources, approximate location, and interactions with our website. Where enabled, masked session replays and heatmaps help us improve the experience. Form entries are excluded from replays and ordinary interaction events. We respect Global Privacy Control and Do Not Track browser signals.

If you separately choose the optional activity-linking permission on a trial or ROI request, after your request is accepted we link your submitted name, email, company, and job title to your consented website activity in PostHog. We use this information and the pages and products you explored to personalize our response to your business inquiry. Your phone number, free-text message, and financial form details are delivered privately with your inquiry, not sent to PostHog. Your request works without activity-linking permission and does not subscribe you to marketing messages.

You can decline or withdraw analytics permission using Privacy settings on any page. Withdrawal stops future collection and resets the analytics identity in your browser; it does not delete previously submitted inquiries or historical analytics records. Contact us using the details in this policy for access or deletion requests.

8. Data Retention

We retain information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law

9. Data Security

We implement reasonable administrative, technical, and organizational safeguards to protect your information.

10. Your Rights

Depending on your location, you may have rights regarding your personal information, including:

  • Accessing the information we hold about you
  • Requesting correction or deletion
  • Objecting to or restricting certain processing

To exercise these rights, contact us at: info@hemut.com

11. California Privacy Rights

If you are a California resident, you may have the right to:

  • Request access to personal information we collect about you
  • Request deletion of your personal information
  • Request correction of inaccurate information

To exercise these rights, contact us at: info@hemut.com

We do not sell personal information in the traditional sense.

12. Children’s Privacy

Our Services are not directed to individuals under the age of 13, and we do not knowingly collect personal information from children.

13. International Data Transfers

Your information may be processed in the United States or other jurisdictions where data protection laws may differ from those in your location.

14. Changes to This Privacy
Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date.

15. Contact Information

Hemut Co:

info@hemut.com

https://hemut.com/

Download PDF→

Transform your freight operations and leap ahead of the competition.

Our SolutionsCommandCoreForgeReachCustomHemut Diesel
Self serveFree trialPricing
ROI & Case StudiesWhy HemutIndustry Research
MoreOur TeamOur StoryCareersAnnouncementsTrxckwrldPartnership InquiriesSupport
Hemut

© Hemut Co All Rights Reserved 2026

Privacy PolicyLicensingTerms and Conditions