Version 1.0 · Effective August 1, 2026

Mailroom Privacy Policy

Version 1.0 — Effective August 1, 2026 Entity: Oliver Lucky Industries, a Wyoming corporation ("Mailroom," "we," "us")


1. Who we are and what this covers

Mailroom provides shipping software for organizations, primarily through a Slack application, a web administration panel, mobile apps, and an API. This policy explains what we collect, why, and your choices. It covers the Service; it does not cover the practices of Slack, UPS, FedEx, or other third parties, which have their own policies.

Mailroom is used through organizations (typically your employer). Your organization controls its Mailroom account and much of the data in it; for data we process on an organization's behalf, the organization is the primary decision-maker and this policy supplements our agreement with them. Where data protection laws such as the GDPR apply, the organization is generally the controller of the data it submits to the Service and Mailroom processes that data on its behalf; Mailroom acts as a controller of account, billing, security, and usage data it processes for its own purposes.

2. Information we collect

From Slack, when your workspace installs Mailroom or you use it:

  • Workspace ID and name; your Slack user ID and display name
  • OAuth tokens that let the app operate in your workspace (stored encrypted)
  • The content you enter in Mailroom's Slack commands and dialogs (not your other Slack messages — the app only receives events it is subscribed to)

Shipping information you or your teammates provide:

  • Names, company names, phone numbers, and physical addresses of senders and recipients (address book contacts, ship-from addresses, and recipients' self-submitted addresses)
  • Shipment details: item descriptions, weight, dimensions, package type, declared value, selected carrier and service, quoted and billed amounts
  • Generated shipping labels (PDFs), which contain sender and recipient addresses and tracking numbers

Account and sign-in information (if you sign in to Mailroom directly rather than through Slack):

  • Your email address and password. Passwords are stored only as cryptographic hashes (argon2) — we never store or can see your plaintext password.
  • Your email-verification status.
  • Session records: IP address, device or platform name, client application, last-active timestamps, and hashed refresh tokens. We do not store session tokens in plaintext.
  • Mobile push notification device tokens, if you enable notifications in the mobile app.
  • If a colleague invites you to their organization, we receive your email address from them; it is used solely to deliver and process the invitation.
  • Your organization's subscription and billing status (e.g., trial or active subscription).
  • When you accept legal terms in the Service, the consent record itself stores your IP address and browser user agent along with the accepted version.

From carriers: tracking events for your shipments (status, location city/state, timestamps) delivered by carrier webhooks and polling.

Billing information (organizations on Mailroom's shipping account or a paid subscription): payment method details, processed by our payment processor Stripe — we do not store full card numbers. Billing history including balance top-ups, subscription charges, and carrier adjustments.

Usage and technical data: product analytics events (e.g., that a shipment was created, a report was run) with associated org/user IDs and properties; server logs; error reports via Sentry, which may include technical context about a failed request.

Cookies: the Mailroom web app uses httpOnly session and refresh cookies for authentication only — they are strictly necessary for sign-in and are not used for advertising or cross-site tracking. Our marketing site uses PostHog for product analytics. We do not use advertising cookies. Where applicable law requires consent for non-essential cookies, we will request it.

3. How we use information

We use the information above to: create and purchase shipping labels and pass shipment data to the carrier you select; validate addresses with carriers; track packages and notify senders and recipients; operate approval workflows and notification channels; generate reports for your organization; bill organizations and process carrier adjustments and credits; provide support; secure, debug, and improve the Service; and comply with law.

AI features. When you use "Suggest weight & size," the item description you typed (e.g., "a laptop") is sent to a machine-learning model — currently Amazon Nova Pro, hosted on Amazon Bedrock in AWS — to estimate package details. The description is processed to generate the suggestion. Per AWS's service terms, Amazon Bedrock does not use customer inputs to train models. We do not send names, addresses, or payment data to the model. The specific model may change over time; we will keep this description current.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your data to advertise to you.

4. How we share information

  • Carriers (UPS, FedEx, USPS): sender/recipient names, addresses, phone numbers, and package details — necessary to rate, purchase, track, and deliver shipments. Carriers use this under their own policies.
  • Slack (for Slack-connected organizations): messages and interactive content the app posts into your workspace.
  • Service providers (subprocessors): Stripe (payment processing); Amazon Web Services (hosting and storage in us-east-1, email delivery via Amazon SES, AI inference via Amazon Bedrock); Expo (mobile push notification delivery); PostHog (product analytics); Sentry (error monitoring). Each is bound to use data only to provide services to us.
  • Your organization: admins can see the organization's shipments, contacts, settings, and reports; approval managers see shipments requiring their approval.
  • Legal: when required by law or to protect rights, safety, or the integrity of the Service.
  • Corporate events: in a merger, acquisition, or asset sale, with notice.

A current list of subprocessors is available on request via hello@olicorp.us.

5. Data retention

  • Shipping label PDFs: deleted automatically after 90 days.
  • Server logs: 30 days.
  • Shipments, tracking events, contacts, and account records: retained while the organization's account is active, and for 90 days after account termination for billing (late-arriving carrier adjustments can arrive 90+ days after shipment), tax, and legal purposes, then deleted or de-identified within a reasonable period.
  • Session records: deleted when the session is revoked (e.g., you sign out) or expires.
  • Push notification device tokens: deleted when you log out or remove the device.
  • Recipient self-submitted addresses: stored in the organization's address book until the organization or the user deletes them.

Organizations can request deletion of their account data at hello@olicorp.us; we honor deletion requests except where retention is legally required.

6. Security

Data is encrypted in transit (TLS) and at rest (encrypted database storage; carrier credentials and Slack tokens are additionally encrypted at the application layer with AES-256-GCM). Label files are stored in private cloud storage accessible only via short-lived signed URLs. Access to production systems is restricted and logged. No system is perfectly secure; we will notify affected organizations of a breach as required by law.

7. Your choices and rights

  • Recipients: if someone asks to ship to you and you decline to share your address, no address is collected from you.
  • Access, correction, deletion: Users can view and edit their contacts and addresses in-product. For other requests (access, correction, deletion, or a portable copy of your data), contact your organization's admin or hello@olicorp.us; we honor such requests as required by applicable law and will not discriminate against you for making them. Where your organization controls the data, we may refer the request to your organization.
  • Notifications: shipment notifications are part of the Service; organizations configure the notification channel.

8. Where data is processed

Data is hosted in the United States (AWS us-east-1). If you use the Service from outside the U.S., your information is transferred to and processed in the U.S. Where applicable law requires safeguards for such transfers, we rely on appropriate safeguards, such as standard contractual clauses.

9. Children

The Service is for business use and not directed to anyone under 16; we do not knowingly collect children's data.

10. Changes

We'll post changes here and, for material changes, notify organization admins through the Service or email. The "Version" line above shows the current revision.

11. Contact

Oliver Lucky Industries 30 N Gould Street Sheridan, WY 82801 hello@olicorp.us