Privacy Policy
Last Updated: June 21, 2026
Updated to disclose the Fr8bot browser extension, AI-assistant (MCP) integrations, and Gmail / Microsoft mail-send access, with our Limited Use commitment.
FR8Labs ("we", "us", "our") collects and processes personal data through its website (fr8labs.co) and SaaS platform (user.fr8labs.co). By using these services, you accept the practices outlined here.
Key Definitions
- Company: FR8Labs Pte Ltd / PT Freight Solusi Indonesia
- Personal Data: Information relating to identified or identifiable individuals
- Service: The FR8Labs application and platform
- Usage Data: Automatically collected information during service use
Data Collection
Personal Information
- Email address, name, phone number
- Account registration details
Usage Data
- IP addresses, browser type and version
- Device identifiers and diagnostic data
- Pages visited, time spent, timestamps
- Mobile device information when applicable
Data Usage Purposes
We use collected data to:
- Provide and maintain our services
- Manage user accounts
- Perform contracts
- Contact users about updates and services
- Send promotional communications (with opt-out available)
- Conduct business analysis and improvements
Cookies, Local Storage & Tracking Technologies
Google Analytics 4
We use Google Analytics 4 (property G-F1LJVS4JEP) to
measure traffic and understand how visitors use fr8labs.co. We have
configured Google Consent Mode v2 with region-scoped
defaults:
- EU, UK, EEA and Switzerland visitors: all analytics and advertising signals default to denied. Google Analytics still records anonymous, cookieless pings so we can see aggregate page-view counts, but no per-user identifiers or tracking cookies are stored.
- All other regions: signals default to granted. Standard GA4 tracking applies.
You can opt out at any time by installing the Google Analytics Opt-out Browser Add-on.
Country detection (ipinfo.io)
On your first visit, your browser makes a single request to
ipinfo.io to determine your country. This lets us show
the right regional banner (Singapore PSG, Malaysia LHDN e-Invoice,
etc.). Your IP address is transmitted to ipinfo.io; no other
information is sent. See
ipinfo.io's privacy policy.
Browser local storage
We store a 2-letter country code in your browser's local storage
under the key fr8_country. It is used to remember which
regional banner to show you on repeat visits. This is functional
storage only — it contains no personal data and is never sent to our
servers.
Prospect chat widget
Our chat widget is powered by our in-house notification service
hosted at notification-hub.fr8labs.co. When you open
the chat, a session token is stored in your browser's local storage
so you can close and reopen the same conversation. The messages
you type and any email address you share are transmitted to that
service over HTTPS and retained there to enable follow-up from our
team.
Fr8bot Browser Extension
Fr8bot is our optional Chrome browser extension that reads shipment tracking milestones from carrier portals and brings them into your Fr8Labs shipment timeline. It acts on a page only when you explicitly ask it to — by opening a carrier tracking page and starting a pull, or confirming a detected shipment. It is available to signed-in Fr8Labs users.
What the extension accesses
- Your Fr8Labs sign-in: it reads your Fr8Labs session cookie
(
fr8labs-token-production) to confirm you are signed in and to authorize the pull. This is used only to authenticate you to Fr8Labs. - The carrier page you pull: the content of that tracking page (its HTML/DOM and visible text), the tracking reference you enter (container, B/L, or AWB number), and the page's URL.
What we do with it
- Send the page content and tracking reference to Fr8Labs servers to extract the structured milestones and return them to you.
- Use the carrier page's structure (its layout — field positions and labels, not your shipment details) to build and improve the reusable extraction recipe for that carrier, so tracking works better for every Fr8Labs user. Some carriers are extracted with the help of a third-party large-language-model provider and, where a carrier presents an anti-bot challenge, a CAPTCHA-solving service (see Third-Party Processors).
What the extension does not do
- It does not read pages other than the carrier tracking pages you pull, and it does not collect your general web-browsing history.
- Your carrier portal usernames and passwords stay in your own browser session — the extension never transmits your carrier login credentials to us.
- We never sell your data, and we never use it for advertising.
- We do not share your shipment data with other forwarders; only the carrier's anonymized page recipe is reused.
Retention
Extracted milestones live in your Fr8Labs workspace. The raw page content used for extraction and troubleshooting is retained only as long as needed for that purpose and is then deleted. You can request deletion at any time (see Your Rights). Our use of data obtained through the extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
AI Assistant Integrations (Model Context Protocol)
Fr8Labs offers integrations that let an AI assistant retrieve your freight data on your behalf through the Model Context Protocol (MCP) — an open standard (originally created by Anthropic) for connecting AI assistants to external tools. Supported assistants include Anthropic Claude (for example, Claude.ai and Claude Desktop), OpenAI ChatGPT, and other MCP-compatible clients. These integrations are optional and you connect them yourself.
How your data flows
- When you ask your connected assistant something that uses Fr8Labs (for example, "track this shipment"), your request is sent from that assistant to the Fr8Labs MCP service, which returns the relevant freight data for the assistant to show you.
- Those requests and responses pass through the AI assistant you chose. How that provider handles your conversation is governed by their privacy policy (for example, Anthropic's or OpenAI's), not this one — review your provider's policy before connecting.
- Fr8Labs receives only the request details needed to answer you, plus your account authorization, and returns data from your own workspace. We use this only to fulfill your request — never to train AI models, never for advertising, and we never sell it.
- You stay in control: connect or disconnect the integration at any time from your AI assistant's settings.
Third-Party Processors
We use the following processors to operate fr8labs.co. Each is contractually bound to process data only on our instructions.
| Processor | Purpose | Data transmitted |
|---|---|---|
| Google Analytics 4 | Traffic measurement | Page URL, referrer, approximate location, device type (cookieless in EU / UK / EEA / CH) |
| ipinfo.io | Country detection | IP address |
| Cloudflare | CDN, DDoS protection, TLS termination | Request headers, IP address |
| Notification service (Fr8Labs-operated) | Prospect chat, form submissions | Chat messages, email address, any details you share |
| Visibility service (Fr8Labs-operated) | Fr8bot extraction + AI-assistant (MCP) requests | Carrier page content, tracking reference, page URL, your Fr8Labs account ID |
| Large-language-model provider | Extract milestones from carrier page content for supported carriers | Carrier page content and the tracking reference |
| CAPTCHA-solving service | Solve a carrier's anti-bot challenge during a pull | Challenge parameters (site key, page URL) — no shipment data |
In addition, personal data may be shared with:
- Business partners for product offerings, with your consent
- Affiliates of Fr8Labs bound by this policy
- Authorities when required by law
Data Retention & Deletion
The company retains data as long as necessary for stated purposes and legal compliance. Users can delete information via account settings or by contacting support. Some data may be retained for legal obligations.
Google API Services (Gmail)
You may authorize Gmail access so Fr8Labs can send email notifications on your behalf. We request only the minimal Gmail "send" permission — Fr8Labs does not read, store, or access your existing emails, contacts, or calendars. You can revoke access at any time through your Google Account settings.
Fr8Labs' use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Microsoft 365 / Outlook
You may connect a Microsoft 365 / Outlook account so Fr8Labs can send email notifications on your behalf. We request only the minimal mail-send permission and do not read your mailbox, contacts, or calendar beyond what is needed to send the messages you have set up. You can revoke access at any time from your Microsoft account settings.
Limited Use Commitment
Across the Fr8bot browser extension, our AI-assistant (MCP) integrations, and Google / Microsoft account access, Fr8Labs' use of the data we receive complies with the Google API Services User Data Policy and the Chrome Web Store User Data Policy, including their Limited Use requirements. Specifically:
- We use the data only to provide and improve the user-facing features described in this policy.
- We do not transfer or sell the data, except as needed to provide or improve those features, for security purposes, or to comply with applicable law.
- We do not use the data for advertising, and we do not use it to train generalized AI / ML models.
- We do not allow humans to read the data, except with your consent (for example, to troubleshoot at your request), where required for security or to comply with law, or where the data has been aggregated and anonymized.
Data Transfer and Storage
- Marketing site data (chat transcripts, form submissions) is stored on infrastructure located in Singapore.
- Aggregated analytics data is processed by Google Analytics infrastructure in the United States.
- Edge requests are handled by Cloudflare's global network, with the nearest point of presence serving you.
By using fr8labs.co you consent to your data being transferred to and processed in these locations. We employ commercially reasonable security measures — TLS 1.2+ on all transmissions, encrypted storage at rest, least-privilege access controls — but no internet transmission is 100% secure.
Your Rights
Depending on your jurisdiction (GDPR in the EU / UK, PDPA in Singapore, UU PDP in Indonesia, and similar regimes elsewhere), you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email contact@fr8labs.co with the subject line "Data Subject Request." We respond within 30 days.
Children's Privacy
Services are not directed to individuals under 16. The company does not knowingly collect data from children and will remove such information if discovered.
Policy Changes
FR8Labs may update this policy periodically, with notice provided via email or prominent website notice.
Contact
General inquiries: contact@fr8labs.co
Singapore Office
FR8Labs Pte. Ltd.
60 Paya Lebar Road, #07-54
Singapore 409051
Indonesia Office
PT. Freight Solusi Indonesia
Jalan Denpasar Raya Blok C4/24
Jakarta Selatan 12950
Support
Email: customersuccess@fr8labs.co
Hours: 9 AM – 6 PM SGT Mon–Fri; 9 AM – 1 PM SGT Sat