Privacy Policy
This policy describes what [LEGAL ENTITY NAME] (“we”) collects through the Import & Pricing application, where it goes, and how long it is kept. It is written to describe what the system actually does rather than to describe a general intention.
What we collect
- Account data. Your email address, a display name, your organisation, and your role. Authentication is handled by Supabase Auth; we do not store your password.
- Commercial documents you upload. Invoices, bills of lading, customs entries, broker invoices and similar files. These routinely contain business information and may contain personal data — names, signatures and contact details of shippers, consignees, brokers and agents.
- Data you enter or that is extracted. Shipments, line items, values, classifications, charges, parties, and the customs assessments you record for comparison.
- Operational records. An audit log of changes, request logs, and job records used to run and debug the service.
We do not use tracking or advertising cookies. The only cookies set are those required to keep you signed in.
Where your data goes
We use a small number of processors, and your data is exposed to each only for the stated purpose:
- Supabase — database, authentication and file storage. Data is held in the United States (
us-east-1). - Vercel — application hosting and request logs.
- Sentry — error monitoring. When the app hits an error, a report is sent to Sentry so we can fix it. These reports are configured to exclude user identifiers and the contents of your documents and requests — they carry the error itself and technical context, not your commercial data.
- Anthropic — automated reading of uploaded documents. Where you use document intake, the contents of those documents are sent to Anthropic's API for extraction.
- Central Bank of Barbados published rates — retrieved by us; no data about you is sent.
We do not sell your data, and we do not use your documents or entered figures to train machine-learning models.
Separation between organisations
Each organisation's data is isolated at the database level, so users of one organisation cannot read another's shipments, documents or figures.
Retention — stated plainly
Uploaded documents and the records derived from them are currently retained indefinitely while your organisation's account exists. We have not yet implemented automatic expiry of uploaded documents. If you need a document or an organisation's data deleted, contact us and we will delete it.
Backups of the database are retained for a rolling seven days, so deleted data may persist in a backup for up to that period before ageing out.
Your choices
You may request a copy of the data held about you, ask us to correct it, or ask us to delete it, by writing to [contact@example.com]. An administrator of your organisation can also remove documents and records directly in the app. Note that some records — audit entries in particular — exist to keep the change history of commercial figures honest, and may be retained where we have a legitimate need to keep them.
Security
Access requires authentication; data is encrypted in transit; database access is restricted per organisation; and administrative credentials are held only by the operator. No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please report it to [contact@example.com].
Changes
If we change this policy in a way that materially affects how your data is handled, we will say so in the application rather than quietly updating this page.
Governing law: Barbados. Contact: [contact@example.com].