Legal

Privacy Policy

This Privacy Policy explains how Maventi Group, LLC and its subsidiaries collect, use, disclose, and protect your information when you use the Aulintri platform, Beyond Logix freight services, or Beyond Clearance customs brokerage services. We handle customs entry data, shipment records, and trade compliance information — data types with specific regulatory obligations. This policy reflects those obligations plainly.

Effective July 31, 2026
Governed by Texas Law
Covers All Maventi Group Services
Section 01

Overview

Maventi Group, LLC ("Maventi Group," "we," "us," or "our") operates Aulintri, a logistics intelligence SaaS platform, alongside two operating businesses: Beyond Logix (a licensed Non-Vessel Operating Common Carrier registered with the Federal Maritime Commission) and Beyond Clearance LLC (a licensed customs brokerage). This Privacy Policy applies to all services offered under the Maventi Group umbrella.

By accessing or using any Aulintri service, you agree to the collection and use of your information as described in this policy. If you do not agree, you must stop using our services and contact us to deactivate your account.

Note on customs brokerage data: Beyond Clearance LLC operates as a licensed customs broker under federal law. Certain data collected in connection with customs entry services — including importer of record information, HTS classifications, and declared values — is subject to CBP record-keeping requirements under 19 CFR Part 163 that supersede standard data retention and deletion requests. Section 8 and Section 9 of this policy address those obligations specifically.
Section 02

Covered Entities

This Privacy Policy covers all services and platforms operated by the following entities:

  • Maventi Group, LLCParent holding company. Registered in Texas. All data governance, privacy decisions, and security responsibilities originate here.
  • Aulintri Inc.AI-native logistics SaaS platform. Provides freight quoting, customs clearance workflow, document intelligence, tariff analysis, and invoicing tools to importers, brokers, forwarders, and 3PLs. Also operates AI SDR by Aulintri, an outbound sales product that sends email from a mailbox the user connects. Google user data received through AI SDR is governed by Section 5.
  • Beyond LogixNon-Vessel Operating Common Carrier (NVOCC) licensed by the Federal Maritime Commission (FMC OTI License). Provides ocean freight forwarding, carrier booking, and shipment management services.
  • Beyond Clearance LLCLicensed customs brokerage. Employs Licensed Customs Brokers (LCBs) who file entries through CBP ACE on behalf of importers. Regulated by 19 CFR and CBP directives.
Section 03

Data We Collect

Account and Contact Information

When you create an Aulintri account or engage Beyond Logix or Beyond Clearance for services, we collect: name, email address, company name, job title, phone number, billing address, and your role type (importer, customs broker, freight forwarder, or 3PL). This information is used to create and manage your account and deliver services.

Shipment and Freight Data

To provide freight forwarding and tracking services, we collect and process shipment-specific data including: origin and destination details, container numbers, vessel and voyage information, cargo descriptions, weight and dimensions, Incoterms, and carrier booking confirmations. This data is tied to specific shipment records and shared with carriers, terminal operators, and drayage providers as necessary to move your freight.

Platform Usage Data

We collect information about how you interact with the Aulintri platform: pages visited, features used, time spent, search queries, error events, and device and browser information including IP address. This data is used to improve platform performance and detect issues.

Payment and Financial Information

We collect payment information necessary to process invoices for freight, customs filing fees, and platform subscription charges. Payment card data is processed by a PCI-DSS compliant payment processor and is not stored on Aulintri servers. We retain invoice records, payment history, and duty payment records.

Connected Email Mailbox Data

If you connect a Gmail or Google Workspace mailbox to AI SDR by Aulintri, we receive an OAuth credential for that mailbox and, from it, the reply and delivery data needed to send your outbound sequences and thread inbound replies. This category carries commitments that differ from the rest of this policy and is covered separately and in full in Section 5 — Google User Data & Gmail Access.

Documents You Upload

The Aulintri platform uses AI to extract data from documents you upload, including commercial invoices, bills of lading, packing lists, certificates of origin, and arrival notices. Uploaded documents are stored in encrypted cloud storage (AWS S3) and used to pre-populate shipment and customs entry records. Document content is processed by our AI document extraction pipeline and is not used to train external AI models.

Section 04

Customs & Trade Data — Special Handling

Customs brokerage services involve data categories that carry heightened sensitivity and specific legal obligations. When Beyond Clearance LLC acts as your customs broker, we collect and process the following:

  • Importer of Record (IOR) InformationLegal business name, EIN/taxpayer ID, CBP importer number, continuous bond information, and power of attorney documentation.
  • Entry Summary DataHTS classification codes, declared values, country of origin, duty calculations, and all data required for CBP Form 7501.
  • Government-Issued IdentifiersIn cases where CBP requires identity verification for the importer of record, we may collect and transmit driver's license, passport, or other government-issued identification numbers. This data is treated as sensitive personal information and is encrypted in transit and at rest.
  • ISF 10+2 DataSeller, buyer, importer of record, consignee, manufacturer, ship-to-party, country of origin, and HTS data submitted to CBP pre-arrival under ISF requirements.
  • PGA Partner DataWhere shipments require Prior Notice to the FDA, USDA APHIS certification, or EPA compliance documentation, we collect and transmit the data required by each partner government agency.
  • Drawback and Refund ClaimsFor duty drawback filings or IEEPA refund claims, we collect and retain transaction records, manufacturing affidavits, and export evidence required by CBP.
Important: Customs entry data filed with CBP is subject to mandatory retention requirements under 19 CFR Part 163 for a minimum of five years from the date of entry. Requests to delete customs-related records may be limited by these federal requirements. We will inform you of any such limitations at the time of a deletion request.
Section 05

Google User Data & Gmail Access

This section governs data we receive from Google APIs. It applies to AI SDR by Aulintri (ai-sdr.aulintri.com), the outbound sales product operated by Aulintri Inc., which lets a user connect their own Gmail or Google Workspace mailbox so that outbound email is sent from that mailbox and replies are threaded back into the product. Connecting a mailbox is optional, is always initiated by the user, and can be revoked by the user at any time.

Where this section and any other provision of this Privacy Policy conflict with respect to data obtained from Google APIs, this section controls.

Limited Use disclosure: Aulintri's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes We Request, and Why

We request the minimum scopes required for the product to function. Google presents these to you on its own consent screen before any access is granted:

  • Sign-inopenid — standard sign-in identifier. Confirms which Google account is being connected. Non-sensitive scope.
  • Email addresshttps://www.googleapis.com/auth/userinfo.email — reads the email address of the connecting account so we can verify it matches the mailbox you entered in AI SDR, and so the mailbox is scoped to the correct organization. Non-sensitive scope.
  • Send mailhttps://www.googleapis.com/auth/gmail.send — sends outbound sales email from your mailbox, using your own sending identity, so replies come back to you and your deliverability reputation stays with you. A send only occurs from a sequence or message you or a colleague in your organization authored, scheduled, or approved in AI SDR. Restricted scope.
  • Read mailhttps://www.googleapis.com/auth/gmail.readonly — detects replies and non-delivery reports so an inbound reply can be attributed to the correct conversation and routed to the right person on your team. Read-only: we cannot and do not modify, label, archive, or delete anything in your mailbox. Restricted scope.

We do not request gmail.modify, gmail.compose, gmail.settings, gmail.labels, or any Google Drive, Calendar, Contacts, or Chat scope. If a future feature requires an additional scope, you will be asked to re-consent before it is used.

What We Read, and What We Keep

The two are deliberately different. After you connect a mailbox, AI SDR subscribes to Gmail change notifications for that mailbox and, when notified, retrieves the newly arrived messages in order to evaluate them:

  • DiscardedFor each newly arrived message we examine the sender, subject, and plain-text body only long enough to determine (a) whether it is a reply to a conversation AI SDR started, and (b) whether it is a bounce or non-delivery report. A message that matches neither is discarded and never written to our database.
  • StoredOnly messages belonging to a conversation AI SDR initiated — matched by Gmail thread ID or by a recipient address already in your campaign — are stored. For those we retain the plain-text body with quoted reply history stripped, the sender address, the subject, the timestamp, and the Gmail and RFC-822 message identifiers needed to keep the thread intact.
  • Never storedWe do not download, store, or scan attachments. We do not store message bodies from unrelated threads, and we do not index, catalogue, or search your mailbox at large.
  • CredentialsWe store the OAuth refresh token issued by Google for the connected mailbox. It is never exposed to the browser and is used only to mint short-lived access tokens at send and read time. We never ask for, receive, or store your Google password.
How Google User Data Is Stored and Secured

Google user data is held in the same environment as the rest of your platform data, under the controls described in the Security section of this policy: transmitted only over TLS 1.2 or higher; stored in Amazon RDS (PostgreSQL) in a United States region with AES-256 encryption at rest managed through AWS KMS; access limited by role-based access control; and isolated per organization so one tenant's connected mailbox data is not reachable by another.

Retention of Google User Data
  • OAuth tokensDeleted immediately when you disconnect the mailbox, when you revoke access from your Google account, or when the token is revoked by Google or your Workspace administrator.
  • Reply contentRetained for the life of the campaign record, and deleted within thirty (30) days of a deletion request or of your account being closed.
  • Delivery signalsRetained in aggregate (counts and reputation metrics) for up to twelve (12) months for sending-health purposes. These aggregates contain no message content.
  • Operational logsNinety (90) days. These record that a send or read occurred; they do not contain message bodies.

Google user data is not subject to the customs record-keeping obligations described elsewhere in this policy. Nothing in the five-year CBP retention requirement applies to it, and a deletion request for Gmail-derived data will be honored in full.

Sharing of Google User Data

We do not sell Google user data, and we do not transfer it to any third party for that party's own purposes. It is shared only as follows:

  • AWSHosting, database, and storage for the application itself. United States regions. AWS acts as our processor under its Data Processing Addendum and has no independent right to the data.
  • Anthropic (Claude API)The plain-text body of a reply on a conversation you are working in is sent to the Claude API to classify reply intent and to draft a suggested response. This is done to deliver the feature you asked for, under an agreement that prohibits use of the content for model training.
  • Legal processWhere we are compelled by valid subpoena, court order, or other lawful process. We will notify you before complying to the extent the law permits.

We do not share Google user data with advertising networks, data brokers, information resellers, analytics platforms, or any credit, insurance, employment, or lending decision system. We do not use it for any form of advertising or ad targeting.

AI and Machine Learning — Our Commitments

We do not use Google user data to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models, whether our own or a third party's. Gmail content is processed by a language model only in service of the specific, user-facing feature that requested it — classifying the intent of a reply in a conversation, and drafting a suggested response for that conversation — and it is not retained by that provider for training. We do not build cross-customer models, profiles, or datasets from Google user data.

Human Access to Google User Data

Aulintri personnel do not read the content of your Gmail messages except in these narrow cases: with your explicit permission, to investigate a support issue you have reported; where necessary to detect, prevent, or address a security incident, abuse, or fraud; or where required by law. Any such access is limited to the minimum data needed, is performed by named personnel under role-based controls, and is recorded in our audit log.

Revoking Access and Deleting Your Google Data

You can withdraw access at any time, by any of these routes:

  • In AI SDRSettings → Integrations → Disconnect on the mailbox. This revokes our grant with Google, cancels the Gmail change subscription, and deletes the stored tokens immediately. No further sends or reads are possible.
  • At GoogleRemove "AI SDR by Aulintri" at myaccount.google.com/permissions. Access stops as soon as Google processes the revocation.
  • By requestEmail info@aulintri.com asking us to disconnect the mailbox and delete all Gmail-derived data. We will confirm and complete deletion within thirty (30) days.

Revoking access stops all future access immediately. Message content already stored against a conversation is removed on request as described above, or on account closure under the retention periods in this section.

If you are a Google Workspace administrator: you can review, restrict, or revoke this application organization-wide from the Google Admin console under Security → API controls → App access control. Individual user consents in your domain are visible and reversible there.
Section 06

How We Use Your Data

We use the data we collect for the following purposes:

  • Service DeliveryProcessing freight quotes, booking carriers, filing customs entries through CBP ACE, generating invoices, and managing shipment lifecycle from origin to delivery.
  • AI-Powered FeaturesPowering document extraction (pre-populating entry fields from uploaded invoices and B/Ls), HTS classification suggestions, duty calculation, and exception detection. AI features are powered by the Claude API (Anthropic). Document content sent to the API is governed by Anthropic's data use policies and is not used for model training by default under our enterprise agreement.
  • Compliance ObligationsFiling ISF, entry summaries, PGA notifications, AES export filings, and other regulatory submissions with CBP and partner government agencies as required by law and as authorized by your power of attorney.
  • Platform ImprovementAnalyzing usage patterns to improve Aulintri's features, fix errors, and optimize performance. This analysis uses aggregated, de-identified data.
  • CommunicationsSending transactional emails (shipment milestones, CBP hold alerts, invoice delivery), operational notifications (system downtime, policy updates), and — if you opt in — product updates and platform news.
  • Billing and Financial ReconciliationGenerating customer invoices, reconciling carrier invoices, processing duty payments, and syncing with connected accounting systems (e.g., Zoho Books).

We do not sell your personal data to third parties. We do not use your data to serve advertising on third-party platforms.

Section 07

Data Sharing

We share your data only in the following circumstances:

Carriers and Terminal Operators

Shipment data — including container numbers, cargo descriptions, and booking references — is shared with ocean carriers (Maersk, CMA CGM, MSC, Hapag-Lloyd), terminal operators, drayage providers, and other logistics partners as necessary to execute your freight instructions.

Government Agencies

Customs and trade data is transmitted to CBP, FDA, USDA, EPA, and other partner government agencies through ABI-certified channels as required by law and as authorized by your power of attorney with Beyond Clearance LLC. See Section 8 for details.

Technology Subprocessors

We use the following key subprocessors to deliver the Aulintri platform:

  • Amazon Web Services (AWS)Cloud infrastructure, data storage (RDS, S3), email (SES), and compute. US-based data centers. AWS DPA applies.
  • Anthropic (Claude API)AI document extraction and classification. Data sent to the API is subject to Anthropic's enterprise data use policy. Not used for model training.
  • ABI Service BureauCertified channel for transmission of customs data to CBP ACE. CATAIR-compliant formatting and transmission.
  • Google LLCWhere you connect your own Gmail or Google Workspace mailbox to AI SDR, outbound mail is sent through, and replies are read from, that mailbox via the Gmail API. Google is your own mail provider in that relationship rather than a subprocessor acting for us. See Section 5.
  • Zoho BooksAccounting and invoicing integration for connected customers. Data synced includes invoice records and payment status.
Business Transfers

If Maventi Group is acquired, merges with, or transfers its assets to another entity, your data may be transferred as part of that transaction. We will notify affected users prior to any such transfer and the acquiring entity will be bound by the terms of this Privacy Policy or provide equivalent protections.

Section 08

CBP & Government Disclosure

As a licensed customs broker, Beyond Clearance LLC is authorized and required by law to transmit certain importer data to U.S. Customs and Border Protection and partner government agencies. This transmission occurs pursuant to the power of attorney you grant to Beyond Clearance LLC at the time of engagement.

The following data categories are transmitted to CBP as part of normal customs clearance operations:

  • ISF Filings10+2 data including IOR information, seller, buyer, manufacturer, and HTS codes — submitted pre-arrival as required under 19 CFR 149.
  • Entry Summaries (CBP Form 7501)Full entry data including IOR number, HTS classification, declared value, duty calculation, and country of origin — filed at time of import.
  • PGA NotificationsPrior notice to FDA, USDA APHIS, EPA, CPSC, and other agencies as required by the commodity being imported.
  • AES Export FilingsElectronic Export Information (EEI) filed through the Automated Export System for qualifying exports.
Legal basis: Data transmitted to government agencies is done pursuant to your written power of attorney, applicable federal regulations (19 CFR, 15 CFR), and the terms of Beyond Clearance LLC's customs broker license. This data transmission is not discretionary — it is a legal requirement for the importation and exportation of goods.

We do not provide government agencies with access to your Aulintri platform account, uploaded documents, or shipment records beyond what is required for customs entry filings, unless compelled by lawful subpoena, court order, or other legal process. In such cases, we will notify you to the extent permitted by law before complying.

Section 09

Data Retention

We retain different categories of data for different periods based on business need and legal obligation:

  • Customs Entry RecordsMinimum five (5) years from date of entry, as required by 19 CFR Part 163. These records cannot be deleted upon request during the retention period.
  • Shipment RecordsThree (3) years from shipment completion, unless required for an open dispute, insurance claim, or regulatory investigation.
  • Account and Contact DataDuration of active account plus two (2) years following account closure, to allow for billing disputes and reactivation requests.
  • Uploaded DocumentsThree (3) years from upload date, or the retention period applicable to the associated entry, whichever is longer.
  • Platform Usage LogsNinety (90) days for detailed logs; aggregated analytics retained indefinitely in de-identified form.
  • Payment RecordsSeven (7) years to satisfy tax and accounting requirements.

Upon account closure, we will delete or de-identify your data within 90 days, subject to the retention periods and legal obligations described above.

Section 10

Security

We implement administrative, technical, and physical security measures appropriate to the sensitivity of the data we handle, including customs entry data, government-issued identifiers, and financial information.

  • Encryption in TransitAll data transmitted between your browser and Aulintri servers is encrypted using TLS 1.2 or higher. All data transmitted to CBP ACE via our ABI service bureau uses certified secure channels.
  • Encryption at RestData stored in Amazon RDS (database) and S3 (document storage) is encrypted at rest using AES-256.
  • Access ControlsRole-based access control (RBAC) limits data access within the platform. Multi-tenant architecture enforces row-level data isolation so one organization cannot access another's records.
  • InfrastructureDeployed on AWS within US-based data centers. Production environments are isolated from development environments.
  • SOC 2 ComplianceWe are currently pursuing SOC 2 Type II certification. Our controls are designed to meet SOC 2 trust service criteria for security, availability, and confidentiality.

No system is completely secure. If you discover a security vulnerability in the Aulintri platform, please report it immediately to info@aulintri.com. We will acknowledge all reports within 48 hours.

Section 11

Cookies & Tracking

We use cookies and similar technologies to operate the Aulintri platform. We do not use advertising cookies or sell cookie data to third parties.

  • Essential CookiesRequired for platform operation — authentication sessions, CSRF protection, and route navigation. Cannot be disabled without breaking platform functionality.
  • Analytics CookiesUsed to understand how the platform is used — page views, feature usage, error rates. Data is aggregated and used to improve the platform. Powered by privacy-respecting analytics. No cross-site tracking.
  • Preference CookiesStore your UI preferences such as table sort order and notification settings. Session-based and cleared on logout.

You can manage cookie preferences through your browser settings. Disabling essential cookies will prevent you from logging into the platform.

Section 12

Your Rights

Depending on your location, you may have the following rights with respect to your personal data:

  • AccessRequest a copy of the personal data we hold about you and how it is being used.
  • CorrectionRequest correction of inaccurate or incomplete data. Note: corrections to customs entry data that has already been filed with CBP may require a Post-Entry Amendment through regulatory channels.
  • DeletionRequest deletion of your personal data, subject to legal retention obligations described in Section 9. We cannot delete customs entry records during the mandatory five-year retention period under 19 CFR Part 163.
  • PortabilityRequest an export of your shipment records, entry data, and account information in a machine-readable format.
  • ObjectionObject to specific uses of your data, including withdrawal of consent for marketing communications at any time.

To exercise any of these rights, submit a request to info@aulintri.com. We will respond within 30 days. We may require identity verification before processing sensitive requests.

Texas residents: Texas law provides residents with rights to access, correct, delete, and obtain a portable copy of personal data. These rights are subject to exceptions including data processed pursuant to legal obligations (such as customs record-keeping requirements). Contact us at the address below to exercise your rights under the Texas Data Privacy and Security Act.
Section 13

Children

The Aulintri platform is a business-to-business service intended for use by companies and professionals engaged in international trade and logistics. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that a minor has provided personal information, we will delete that data promptly. If you believe a minor's data has been submitted to our platform, contact us at info@aulintri.com.

Section 14

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data practices. We will update the "Last Updated" date at the top of this page with each revision.

For material changes — those that significantly affect how we collect or use data — we will notify active account holders by email at least 14 days before the changes take effect. Continued use of the Aulintri platform after the effective date of a revised policy constitutes acceptance of the updated terms.

We encourage you to review this policy periodically. Prior versions are available upon request.

Section 15

Contact Us

For questions about this Privacy Policy, data requests, or security concerns, contact us through any of the following:

Maventi Group, LLC — Privacy
Security Reports: info@aulintri.com
Jurisdiction: Collin County / Dallas County, Texas, United States
Governing Law: Laws of the State of Texas

This Privacy Policy has been drafted for Maventi Group, LLC and its subsidiaries. It should be reviewed by qualified legal counsel before publication. Last internal review: July 2026.