Skip to main content
Legal center

Naara policies

Additional U.S. State Privacy Disclosures

This supplement provides state-law disclosures, a notice at collection, and instructions for exercising applicable U.S. privacy rights.

Last updated: September 17, 2026

1. Scope of these disclosures

These Additional U.S. State Privacy Disclosures supplement the Naara Privacy Notice. They describe Naara's practices using categories and terms found in United States state privacy laws and explain how eligible residents may exercise applicable rights.

These disclosures apply to personal information that Naara Logistics Inc. controls for its own business purposes, such as website, account, subscription, support, and service-security information. When Naara processes personal information contained in Customer Data on behalf of a customer organization, that organization generally controls the information and should normally receive the request first. Naara will assist the organization as required by law and our agreement with it.

State privacy laws have different scopes, thresholds, definitions, and exceptions. A right described here applies where the relevant law applies to Naara and the particular information. As a practical measure, Naara currently accepts the request types described below from all U.S. residents, subject to identity verification and lawful exceptions.

2. Notice at collection: categories collected

Depending on how a person interacts with Naara, we may collect the following categories of personal information. The examples identify the information Naara actually expects to process and are not intended to expand our collection.

  • Identifiers and contact information: name, business email address, telephone number, postal or shipping address, IP address, account identifier, organization, and profile image.
  • Customer-record information: contact details, organization affiliation, account credentials in protected form, and billing-contact information. Naara stores password hashes rather than readable passwords and does not receive complete card numbers entered through Stripe-hosted payment pages.
  • Commercial and operational information: subscription, invoice, transaction, inventory, catalog, purchasing, sales, return, supplier, customer, marketplace, fulfilment, and shipping records associated with use of the Services.
  • Internet and electronic-network activity: browser and device type, operating system, access time, requested pages or functions, session and essential-cookie identifiers, login attempts, diagnostic data, and security or audit events.
  • Professional or employment-related information: organization, job title where provided, assigned business location, role, permissions, and other information connected with business use of Naara.
  • Visual and document information: a profile image and images or documents a customer chooses to upload, such as invoices, receipts, delivery notes, and product images.
  • Approximate location information: a general location that may be inferred from an IP address, together with business, shipping, or delivery addresses entered into the Services. Naara does not currently collect device-based precise geolocation through its production application.
  • Sensitive personal information: an account login together with protected authentication information. Naara does not use account credentials to infer characteristics about an individual.
  • Other information a person provides: support communications, privacy-request information, feedback, and information submitted through forms or customer-selected integrations.

3. Information not intended for collection

Naara does not currently intend to collect biometric identifiers, voiceprints, health or medical information, education records, government identification numbers, precise device geolocation, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, or similar highly sensitive information for its own purposes.

Naara is a configurable business platform, so Customer Data or an uploaded document could contain information that a customer chooses to provide. Customers must not place unnecessary sensitive information in notes, uploads, or general-purpose fields and are responsible for having appropriate authority when they submit personal information.

4. Sources of personal information

We receive personal information directly from individuals; from the customer organization that creates, administers, or invites a user to an account; from authorised users of that organization; from records and files customers enter or import; automatically through interaction with the Services; from customer-selected integrations; and from service providers involved in hosting, payment processing, transactional email, file storage, shipping, fraud prevention, and security.

5. Purposes for collection, use, and disclosure

Naara collects, uses, and discloses the categories above to provide and administer accounts and subscriptions; authenticate users; enforce organization boundaries, roles, and permissions; provide inventory, reporting, marketplace, fulfilment, and shipping functions; process payments; send requested or operational communications; store authorised files; provide support; maintain records; diagnose errors; improve reliability and usability; detect and prevent fraud, abuse, and security incidents; enforce agreements; and comply with legal, accounting, tax, and regulatory obligations.

Naara does not use personal information for a materially different, unrelated purpose without providing appropriate notice and obtaining consent where required.

6. Disclosures for business purposes

During the preceding 12 months, Naara may have disclosed the categories described in Section 2 for the business purposes described above. A recipient receives only the information reasonably necessary for the relevant function, subject to contractual and legal obligations where applicable.

  • Authorised users and administrators of the relevant customer organization, according to the organization's roles and permissions.
  • Infrastructure and database hosting providers, currently Railway for Naara's production application and primary PostgreSQL database in the United States.
  • Payment and subscription providers, currently Stripe, for checkout, payment processing, invoices, and subscription administration.
  • Communications and file providers, currently Resend for transactional email and UploadThing for authorised file storage.
  • Shipping providers, currently Shippo and participating carriers, when an organization requests a shipping or tracking function.
  • Customer-selected integration providers and marketplace or fulfilment participants where disclosure is necessary to perform the requested function.
  • Professional advisers, authorities, or other parties when reasonably necessary to obtain advice, comply with law, protect rights and safety, investigate misuse, or complete a financing, merger, acquisition, reorganization, or sale of assets subject to appropriate safeguards.

7. No sale, sharing, or targeted advertising

Naara has not sold personal information for money or other valuable consideration during the preceding 12 months. Naara has not shared personal information for cross-context behavioural advertising and does not currently process personal information for targeted advertising as those terms are defined by applicable state privacy laws.

Naara does not currently use advertising pixels or non-essential advertising technologies in production. Because these activities do not occur, there is presently no personal-information sale, sharing, or targeted-advertising activity to opt out of. If this practice changes, Naara will provide required notice and opt-out controls before beginning the new activity.

8. Sensitive personal information

Naara uses account login and protected authentication information only to provide accounts, authenticate users, prevent misuse, maintain security, and comply with law. Naara does not use or disclose sensitive personal information to infer characteristics about individuals or for purposes that require a right to limit under California law.

Naara does not knowingly process other sensitive personal data for its own purposes without consent where consent is legally required. Customer organizations remain responsible for sensitive information they direct Naara to process in Customer Data.

9. Retention by category

Naara does not retain personal information longer than reasonably necessary for the disclosed purposes. The retention period for each category is determined using the following criteria.

  • Account identifiers, contact details, professional information, and authentication records are generally retained while the account or customer relationship is active and afterward for account closure, security, dispute, and legal-compliance needs. Superseded credentials are removed or rendered unusable through the applicable authentication process.
  • Commercial, billing, subscription, and transaction information is retained for the customer relationship and afterward for applicable accounting, tax, fraud-prevention, chargeback, audit, contractual, and legal recordkeeping periods.
  • Customer operational, marketplace, shipping, document, and visual information is retained according to the customer relationship and authorised customer instructions, subject to operational integrity, legal holds, dispute resolution, and standard backup-expiration processes.
  • Internet, diagnostic, security, session, and audit information is retained for periods reasonably necessary to operate and secure the Services, investigate incidents, prevent fraud, demonstrate compliance, and resolve disputes. The period varies with the event's nature and legal significance.
  • Support communications, privacy requests, and related verification records are retained long enough to respond, document compliance, prevent fraud, and address follow-up questions or disputes.
  • When continued retention is no longer necessary, information is deleted or de-identified, subject to standard backup cycles and legal obligations.

10. State privacy rights

Depending on applicable law, a U.S. resident may have the following rights concerning personal information Naara controls. Some rights do not apply to information processed solely in a business-to-business, employment, or processor capacity, and legal exceptions may permit or require Naara to retain information.

  • Confirm whether Naara processes personal information about you and access or obtain a copy of that information.
  • Correct inaccurate personal information, taking account of its nature and purpose.
  • Request deletion of personal information, subject to lawful retention exceptions.
  • Receive eligible information in a portable and, where technically feasible, readily usable format.
  • Obtain information about categories of recipients or, where required, a list of specific third parties that received personal information.
  • Opt out of a sale, sharing for cross-context behavioural advertising, targeted advertising, or qualifying profiling. Naara does not currently conduct these activities.
  • Limit certain uses or disclosures of sensitive personal information where applicable. Naara does not currently use sensitive personal information for purposes that trigger this right under California law.
  • Withdraw consent for processing that relies on consent, with prospective effect.
  • Appeal a decision concerning a privacy request where applicable.
  • Receive service without unlawful discrimination for exercising a privacy right.

11. How to submit a request

Submit a request by emailing support@naara.com with the subject "U.S. Privacy Request" or by writing to Naara Logistics Inc., 8 The Green, Dover, DE 19901, United States. State the request type, your name, the email address associated with your Naara interaction, your state of residence, and the relevant customer organization if applicable. Do not email a password, complete payment-card number, or government identification document unless Naara specifically requests an appropriate verification item through a secure method.

Naara will acknowledge and respond within the period required by applicable law, generally within 45 days where a state comprehensive privacy law applies. Where permitted, Naara may extend the response period and will explain the extension. Requests are ordinarily free, although applicable law may permit a reasonable fee or refusal for excessive, repetitive, or manifestly unfounded requests.

Naara may verify identity and authority using information already associated with the account or interaction. If Naara cannot reasonably verify a request, it may ask for additional information or deny the request and explain the reason. If Customer Data is controlled by a customer organization, Naara may direct the request to that organization and assist it with the response.

12. Authorised agents and appeals

Where applicable law permits an authorised agent to act for a resident, the agent may use the request method above. Naara may require evidence of the agent's authority and may ask the resident to verify identity or confirm the authorisation directly, unless a valid power of attorney or applicable law provides otherwise.

To appeal a decision, email support@naara.com with the subject "Privacy Request Appeal" and identify the original request and the reason for the appeal. Naara will respond within the time required by applicable law. If an appeal is denied, the response will explain the decision and, where required, provide a method to contact the appropriate state regulator.

13. Universal opt-out signals

Some state laws recognise browser-based universal opt-out mechanisms, including Global Privacy Control, for sales, targeted advertising, or certain sharing. Naara does not currently sell personal information, share it for cross-context behavioural advertising, or process it for targeted advertising, so a signal does not change Naara's present processing.

If Naara begins processing covered by a legally recognised universal opt-out signal, Naara will honour the signal as required and update these disclosures and its controls before beginning that processing.

14. California-specific information

For California residents, Sections 2 through 9 provide Naara's categories of personal information and sensitive personal information collected, sources, business or commercial purposes, categories disclosed for business purposes, recipients, sale and sharing practices, and retention criteria for the preceding 12 months. Naara does not offer a financial incentive or price or service difference in exchange for personal information.

Naara does not disclose personal information to third parties for their own direct-marketing purposes as contemplated by California's Shine the Light law. California residents may use the request process above for questions about this practice.

15. Profiling and automated decisions

Naara does not currently use personal information to profile individuals in furtherance of solely automated decisions that produce legal or similarly significant effects concerning employment, housing, education, lending, insurance, healthcare, access to essential goods or services, or another comparable decision.

Naara may generate operational reports, inventory metrics, or other business-support outputs from Customer Data. These outputs assist customer personnel and are not used by Naara to make legally significant decisions about individual consumers.

16. De-identified and aggregated information

Naara may use aggregated or de-identified information to understand service usage, capacity, reliability, security, and business performance. Naara maintains such information in de-identified form and does not attempt to reidentify it except where permitted by law to test whether de-identification measures remain effective.

17. Children and teens

Naara is a business service and is not directed to children or teens. A person must be at least 18 years old to create or use a Naara account. Naara does not knowingly sell or share the personal information of anyone under 18 or use it for targeted advertising.

18. Changes to these disclosures

Naara may update these disclosures as its Services, data practices, and legal obligations develop. The updated version will identify its last-updated date. Naara will provide advance or additional notice of a material change where required by applicable law and will obtain consent before materially different processing where consent is required.

Questions

Contact us if you have questions about this document or how it applies to your Naara account.

support@naara.com