Privacy Policy
This policy describes what [LEGAL ENTITY NAME] (“we”) collects through the Import & Pricing application, where it goes, and how long it is kept. It is written to describe what the system actually does rather than to describe a general intention.
What we collect
- Account data. Your email address, a display name, your organisation, and your role. Authentication is handled by Supabase Auth; we do not store your password.
- Commercial documents you upload. Invoices, bills of lading, customs entries, broker invoices and similar files. These routinely contain business information and may contain personal data — names, signatures and contact details of shippers, consignees, brokers and agents.
- Data you enter or that is extracted. Shipments, line items, values, classifications, charges, parties, and the customs assessments you record for comparison.
- Operational records. An audit log of changes, request logs, and job records used to run and debug the service.
We do not use tracking or advertising cookies. The only cookies set are those required to keep you signed in.
Where your data goes
We use a small number of processors, and your data is exposed to each only for the stated purpose:
- Supabase — database, authentication and file storage. Data is held in the United States (
us-east-1). - Vercel — application hosting and request logs.
- Sentry — error monitoring. When the app hits an error, a report is sent to Sentry so we can fix it. These reports are configured to exclude user identifiers and the contents of your documents and requests — they carry the error itself and technical context, not your commercial data.
- Anthropic — automated reading of uploaded documents. Where you use document intake, the contents of those documents are sent to Anthropic's API for extraction.
- Central Bank of Barbados published rates — retrieved by us; no data about you is sent.
We do not sell your data, and we do not use your documents or entered figures to train machine-learning models.
Separation between organisations
Each organisation's data is isolated at the database level, so users of one organisation cannot read another's shipments, documents or figures.
Retention — stated plainly
Uploaded documents and their intake drafts remain available until an organisation administrator submits a deletion request or the organisation is offboarded. An accepted request is processed asynchronously: the private-storage object is removed before the corresponding intake record is removed, and completion is recorded in the audit log.
Shipment, declaration, calculation and audit records may be retained after account or organisation offboarding where they are needed for statutory, tax, dispute, fraud-prevention or financial-integrity purposes. An authorised legal hold pauses deletion and records the reason. Offboarding revokes user access immediately while the retained records remain restricted to authorised internal staff.
Deletion from the live service does not rewrite existing backup copies. Database backups currently use seven daily snapshots. Uploaded-file backups are separate encrypted archives in private Vercel Blob storage; the retention job keeps the newest 30 successful archives by count. Because count-based retention is not a calendar-age guarantee when a scheduled run is missed, we do not describe those archives as a 30-day maximum. A deletion is reported as complete for the live service separately from backup ageing.
Your choices
You may request a copy of the data held about you, ask us to correct it, or ask us to delete it by writing to [contact@example.com]. Organisation administrators can additionally export their organisation's data themselves, and can do so after offboarding has been filed by asking us, because filing it withdraws their own access. Organisation administrators can submit deletion requests for uploaded documents and intake drafts in the app. Individual users can request deletion of their account; access is revoked immediately and the authentication identity is removed asynchronously. The local profile is pseudonymised rather than cascade-deleted so an opaque actor reference can remain attached to statutory financial and audit evidence without retaining the person's display name or login identity. Organisation offboarding is completed by authorised internal staff so that retention exceptions and legal holds can be applied before private data is removed.
Security
Access requires authentication; data is encrypted in transit; database access is restricted per organisation; and administrative credentials are held only by the operator. No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please report it to [contact@example.com].
Changes
If we change this policy in a way that materially affects how your data is handled, we will say so in the application rather than quietly updating this page.
Governing law: Barbados. Contact: [contact@example.com].