ChatWMS Privacy Policy 

How Cellaware Technologies processes and protects information when you use the ChatWMS Platform. Privacy on the cellaware.com website is governed by the Cellaware Privacy Policy

ChatWMS Privacy Policy

Last Updated: September 1, 2026

Cellaware Technologies, LLC ("Cellaware," "we," "us," or "our") respects privacy and is committed to protecting personal data processed through our cloud-based software platform, including ChatWMS and related services (the "Platform").

This Privacy Policy explains how we collect, use, process, retain, disclose, and protect information in connection with the Platform.

1. Scope and Role

Cellaware provides a cloud-based Software-as-a-Service platform designed for commercial warehouse operators and enterprise customers.

In providing the Platform, Cellaware generally acts as a data processor on behalf of its customers (the "Customer"), who determine the purposes and means of processing and generally act as data controllers.

We process Customer data only in accordance with Customer instructions, applicable agreements, and applicable law.

If you are an end user of the Platform, your employer or organization controls your use of the Platform and is generally responsible for determining how your personal data is processed.

2. Information We Process

We intentionally limit the information we process to what is necessary to operate, support, secure, and improve the Platform.

2.1 Account Information

While a user account is active, we may process limited account information provided through the Customer's identity provider, including:

  • User email address
  • Username
  • User ID

Authentication is generally managed through the Customer's Single Sign-On ("SSO") or other approved identity provider.

Cellaware does not require users to create separate ChatWMS passwords where Customer-managed SSO is enabled.

2.2 Customer Data Processed Through the Platform

To provide Platform functionality, we may process warehouse and operational data submitted by, accessed on behalf of, or made available by Customers, including:

  • Warehouse Management System ("WMS") data
  • User prompts and queries
  • Generated responses and outputs
  • Report and alert data
  • Other operational information necessary to provide requested Platform functionality

Temporary Raw Data Processing

Raw WMS data may be temporarily processed or retained when necessary to generate reports, alerts, responses, or other Platform outputs.

Where temporary retention is required, raw WMS data is retained for no more than 3 days, unless otherwise agreed with the Customer or required to address a support, security, or legal matter.

Summarized Data for Quality Assurance

For quality assurance, reliability, support, and service improvement, we may retain:

  • Summarized and/or obfuscated WMS data
  • Summarized user interaction data
  • Operational outputs associated with Platform performance

This information is retained for no more than 90 days, unless a longer period is required by an applicable agreement, legal obligation, or active support or security investigation.

2.3 Usage Data

We collect limited usage and performance information to operate and improve the Platform.

Where used for analytics and product improvement, this information is designed to be aggregated and/or obfuscated and may include:

  • Feature usage
  • Query volumes
  • Platform performance metrics
  • Error and reliability information
  • Operational usage patterns

We do not use device fingerprinting for advertising or behavioral tracking.

2.4 Information We Do Not Collect for Advertising or Tracking

The Platform is not designed as an advertising or consumer tracking service.

We do not:

  • Sell personal data
  • Use Customer data for advertising
  • Use behavioral advertising technologies
  • Use Customer data to build advertising profiles
  • Intentionally collect sensitive personal data unrelated to warehouse operations

3. How We Use Information

We process information only as necessary to provide and support the Platform.

Purposes may include:

  • Account authentication and authorization
  • Providing Platform functionality
  • Processing user prompts and generating responses
  • Producing reports and alerts
  • Customer support and issue resolution
  • Quality assurance
  • Security monitoring
  • System reliability
  • Product improvement
  • Performance optimization
  • Compliance with applicable legal and contractual obligations

We do not use Customer data for advertising or unrelated marketing purposes.

4. Data Sharing and Disclosure

We do not sell, rent, or trade Customer personal data.

We disclose Customer data only where necessary to provide, secure, support, or administer the Platform, or where required by law.

4.1 Subprocessors

We use a limited number of subprocessors to operate and support the Platform, including:

  • Microsoft Azure for cloud infrastructure and hosting
  • OpenAI for AI processing
  • Browserless.io for automation and document-processing services where applicable

Subprocessors are permitted to process data only as necessary to provide their services to Cellaware and are subject to applicable contractual and data protection obligations.

Additional information regarding subprocessors may be made available through Cellaware's Trust Center or applicable customer agreements.

4.2 AI Processing

ChatWMS uses AI services to provide natural language and related functionality.

Depending on the requested function, information sent for AI processing may include:

  • User prompts
  • Relevant WMS data
  • Summarized or aggregated operational data
  • Context required to generate the requested response

Zero Data Retention is the default configuration for AI processing within ChatWMS.

Under Cellaware's enterprise arrangements with its AI providers:

  • Customer data is not used to train AI or foundation models
  • AI providers do not retain Customer prompts, WMS data, or generated outputs beyond the processing necessary to provide the requested functionality when Zero Data Retention is enabled
  • Data is processed only for the purpose of delivering the requested AI functionality
  • Cellaware does not permit AI providers to use Customer data for advertising, profiling, or independent product development

If a specific Customer configuration requires an AI service that does not support Zero Data Retention, any alternative retention arrangement will be governed by the applicable Customer agreement and disclosed as appropriate.

AI-generated responses may contain inaccuracies, and Customers remain responsible for determining how outputs are used in their operations.

5. International Data Transfers

Cellaware provides the Platform to Customers in multiple regions.

By default, Platform infrastructure may be hosted in Microsoft Azure Central US, unless another hosting region has been agreed with the Customer.

Regional hosting options may be available depending on Customer requirements and technical availability.

Where personal data is transferred from the European Economic Area, United Kingdom, or another jurisdiction requiring transfer safeguards, Cellaware may rely on:

  • Standard Contractual Clauses
  • The UK International Data Transfer Addendum or equivalent mechanisms
  • Other legally recognized transfer safeguards

6. Data Retention

Cellaware retains information only for as long as reasonably necessary to provide the Platform, meet contractual obligations, support security and reliability, or comply with applicable law.

Unless otherwise agreed:

  • Account information: retained while the user account remains active and for a limited period following account deactivation or deletion
  • Temporary raw WMS data: retained for up to 3 days where temporary retention is necessary for reports, alerts, or other Platform functionality
  • Summarized quality assurance data: retained for up to 90 days
  • Aggregated and obfuscated usage data: may be retained for longer periods where it cannot reasonably be used to identify an individual

Customer Termination

Following termination of a Customer's use of the Platform, Customer-related data may be retained for up to 90 days to support transition, recovery, contractual obligations, security, or other legitimate operational requirements.

After the applicable retention period, data is securely deleted or anonymized unless continued retention is required by law or an applicable agreement.

7. Data Security

Cellaware maintains administrative, technical, and organizational safeguards designed to protect information processed through the Platform.

Our security program includes:

  • ISO/IEC 27001 certification and periodic independent audits
  • Encryption of data at rest
  • TLS 1.3 encryption for data in transit where supported
  • Role-based access controls
  • Customer-managed authentication through SSO
  • Least-privilege access controls
  • Network and infrastructure security controls
  • Security monitoring and incident-response processes

Additional information about Cellaware's security program is available through our Trust Center:

https://trustcenter.cellaware.com

8. User Rights and Requests

Because Cellaware generally acts as a data processor, end users should ordinarily direct privacy requests to their employer or organization.

Customers may submit requests to Cellaware concerning personal data processed through the Platform, including requests relating to:

  • Access
  • Correction
  • Deletion
  • Restriction
  • Export or portability, where applicable

Requests may be submitted to:

privacy@cellaware.com

We will assist Customers with applicable data subject requests in accordance with contractual obligations and applicable law.

9. Communications

Cellaware does not use Platform user information to send unrelated marketing communications.

We may send operational or service-related communications, including:

  • Security alerts
  • Service notices
  • Outage notifications
  • Product or maintenance notifications
  • Important account or operational updates

10. Children's Privacy

The Platform is intended for commercial and enterprise use and is not intended for individuals under 18 years of age.

We do not knowingly collect personal data from minors through the Platform.

11. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in the Platform, our data practices, legal requirements, or applicable agreements.

When changes are made, we will update the Last Updated date at the top of this page.

If a change materially affects how Customer personal data is processed, additional notice may be provided where required by applicable law or contract.

12. Contact Us

If you have questions about this Privacy Policy or Cellaware's data practices relating to ChatWMS, contact us at:

Cellaware Technologies, LLC

Email: privacy@cellaware.com

13. Governing Law

Unless otherwise provided in an applicable agreement between Cellaware and the Customer, this Privacy Policy is governed by the laws of the State of Texas, United States, without regard to conflict of law principles.