Privacy Policy
This policy explains what information CustomsCopilot collects, why we collect it, who we share it with, how long we keep it, and what choices you have. It covers both our website at customscopilot.ai and the CustomsCopilot platform used by licensed customs brokers and exporters.
1 Who we are
CustomsCopilot is a product of YEM Corporation, a Texas corporation with a place of business at 500 W. Overland Ave., Suite 250G, El Paso, Texas 79901.
In this policy, "CustomsCopilot," "we," "us," and "our" mean that entity. "You" means a visitor to our website, a user of our platform, or a business that has contracted with us.
2 Scope of this policy
CustomsCopilot is a business-to-business service. We sell to licensed U.S. customs brokers and to exporters. We do not offer consumer accounts.
This policy covers:
- Our public website at customscopilot.ai
- The CustomsCopilot application at app.customscopilot.ai and its supporting services
- Email you send to our document intake addresses
An important distinction. When a broker or exporter uses our platform, they upload or forward trade documents belonging to their own customers. We process that content on our customer's behalf and under their instructions. Our customer decides what to send us and what it is used for. If you are an importer or exporter whose documents were submitted by your broker, contact your broker first — their agreement with you governs that data, and we will direct your request to them.
3 Information we collect
3.1 Information you give us directly
- Demo and contact requests. Name, company name, business email, phone number, and anything you type into the message field.
- Account information. For platform users: name, business email, role, the organization you belong to, and a hashed password. We never store passwords in readable form.
- Configuration data. Filer codes, ACE party keys, importer profiles, and similar settings your organization enters so the platform can produce correctly formatted filings.
- Support communications. Messages, screenshots, and attachments you send us when you report a problem.
3.2 Customer content — trade documents
The core of our service is processing documents our customers send us. These typically contain:
- Commercial invoices, packing lists, bills of lading, and related shipment paperwork
- Importer of record numbers, EINs, and other business tax identifiers
- HTS and Schedule B classification codes, quantities, weights, and declared values
- Names and addresses of shippers, consignees, manufacturers, and other parties to a shipment
We treat this as confidential business information, not consumer personal data. It may nevertheless include the names and contact details of individuals acting in a business capacity, and we protect that information under this policy.
3.3 Information collected automatically
- Log and usage data. IP address, browser and device type, pages viewed, actions taken in the application, timestamps, and error diagnostics.
- Security records. Sign-in attempts, session activity, and administrative actions, kept so we can detect and investigate unauthorized access.
- Processing records. A record of each document our system processes and each filing our system generates. Section 5 explains this in more detail.
3.4 What we do not collect
We do not request or intentionally collect Social Security numbers, payment card numbers, health information, biometric identifiers, precise geolocation, or government identity documents. Because documents reach us as email attachments and uploads, we cannot prevent a sender from including such information in a document. Please do not send it. If you tell us it was sent in error, we will remove it where our recordkeeping obligations allow.
4 How we use information
We use information to:
- Provide the service — read documents, extract data, and generate draft filings for review
- Authenticate users and keep accounts secure
- Respond to demo requests, questions, and support tickets
- Monitor reliability, diagnose failures, and improve accuracy
- Maintain the records described in Section 10
- Send service notices about outages, changes, and security matters
- Send marketing email, subject to Section 9
- Comply with law and enforce our agreements
We do not sell your information, and we do not share it for cross-context behavioral advertising. We do not use customer trade documents to train any artificial intelligence model, our own or anyone else's.
5 Artificial intelligence
CustomsCopilot uses artificial intelligence to read trade documents and extract structured data from them. We want to be direct about what that means.
5.1 What the AI does
When a document reaches our platform, its contents — including any text and images in it — are sent to a third-party large language model provider for analysis. The model returns extracted field values, which our software assembles into a draft filing.
5.2 What the AI does not do
AI output is a draft, never a filing. Every entry, export declaration, and in-bond document produced by our platform must be reviewed and approved by a licensed customs broker or an authorized filer before it is transmitted to U.S. Customs and Border Protection or any other agency. The platform does not transmit anything on its own initiative. The licensed broker or filer remains the party responsible for the accuracy of what is filed.
Our full statement on this is on the AI Disclosure page.
5.3 Our AI provider
We use a third-party large language model provider located in the United States. We identify that provider to customers under contract. Under our agreement with them, content we submit is not used to train their models.
5.4 Processing records
We keep a record of each AI processing event: which document was processed, when, which model version was used, and what the model returned. We keep these records to support our customers' recordkeeping obligations, to investigate discrepancies, and to demonstrate that a human reviewed each filing before it was transmitted.
8 Service providers
We rely on the following providers. We keep this list current; material additions will be reflected here and, for platform customers, communicated under your agreement.
| Provider | What it does for us | Location |
|---|---|---|
| Large language model provider Identified to customers under contract | AI document extraction | United States |
| Railway | Application hosting, database, job queue | United States |
| Amazon Web Services | Document and attachment storage | United States |
| SendGrid (Twilio) | Inbound document email and outbound notifications | United States |
| GoDaddy | Domain registration and website hosting | United States |
| RB Systems | ACE Suite filing interface | United States |
| Website form provider | Demo request form delivery | United States |
9 Marketing email
If you request a demo or give us your business email, we may send you information about CustomsCopilot. Every marketing message includes an unsubscribe link and our physical mailing address. We honor opt-out requests promptly and in any event within ten business days, as required by the CAN-SPAM Act.
Opting out of marketing does not stop service messages — billing notices, security alerts, and outage notifications — which we send to platform users regardless.
10 How long we keep information
Customs and export recordkeeping rules drive our retention periods. Under 19 C.F.R. Part 163, records relating to customs entries must generally be kept for five years from the date of entry. Export records under 15 C.F.R. § 30.10 carry a comparable five-year requirement. We retain filing-related records accordingly so that our customers can meet those obligations.
| Category | Retention period |
|---|---|
| Documents, extracted data, and generated filings | Five years from the filing date, unless your agreement says otherwise |
| AI processing records | Five years, matching the filings they relate to |
| Account records | For the life of the account, then three years after closure |
| Security and access logs | Twelve months |
| Demo requests and marketing contacts | Until you unsubscribe or ask for deletion |
| Support tickets | Three years |
When a customer's agreement ends, we handle return and deletion of their data as that agreement provides. We may keep records we are legally required to keep, and we may keep backup copies for a limited period until they expire on their normal cycle.
11 Data security
Measures we maintain include:
- Encryption in transit using TLS, and encryption of stored documents and credentials
- Organization-level isolation, so one customer cannot reach another customer's data
- Role-based access controls and enforced session management
- Encrypted storage of filing credentials
- Access logging and monitoring of administrative actions
- Regular security review of the application and its dependencies
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please write to info@yemco.net. We will acknowledge and investigate.
12 Your rights and choices
Whatever your location, you may:
- Ask what information we hold about you
- Ask us to correct information that is wrong
- Ask us to delete information, subject to our legal retention duties
- Unsubscribe from marketing email
To make a request, write to info@yemco.net. We will verify your identity before acting, and we will respond within the time the applicable law allows.
12.1 Texas residents
The Texas Data Privacy and Security Act gives Texas consumers rights over personal data processed for personal or household purposes. Our service is business-to-business, so most of what we handle falls outside it. We honor the requests above regardless.
12.2 If your documents were submitted by your broker
Contact your broker. They control that data and their agreement with you governs it. We will pass your request along to them.
13 Breach notification
If a security breach compromises sensitive personal information, we will notify affected individuals without unreasonable delay, and we will notify regulators where the law requires it — including the Texas Attorney General when 250 or more Texas residents are affected. We will also notify affected business customers under the terms of their agreements.
14 Location of processing
We are a United States company. Our service is offered to United States customs brokers and exporters, and information is stored and processed in the United States. We do not offer the service in the European Union or the United Kingdom, and we do not target users there.
15 Children's privacy
CustomsCopilot is a professional business service. It is not directed to children, and we do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it.
16 Changes to this policy
We may update this policy as the service or the law changes. When we do, we revise the "Last updated" date at the top. If a change materially affects how we handle your information, we will give platform customers advance notice by email or through the application before it takes effect. Previous versions are available on request.
17 How to contact us
YEM Corporation (CustomsCopilot)
500 W. Overland Ave., Suite 250G
El Paso, Texas 79901
Phone: (915) 613-5520
Email: info@yemco.net