Privacy Policy
Draft for product development · Last updated August 8, 2026
1. Information we may collect
Account information may include your name, work email, organization, authentication identifiers, and workspace membership. Product data may include SKUs, product identifiers, manufacturers, laboratories, points of contact, certificate data, CPSC identifiers, and user-entered notes.
Uploaded documents may contain supplier certificates, CPC/GCC records, test reports, manufacturing information, product specifications, and other materials you choose to provide.
2. How information is used
We use information to provide the Proof2Ship service, authenticate users, process uploaded documents, produce extraction candidates, validate data structure, maintain audit history, support CPSC Product Registry integrations, provide customer support, secure the service, and improve reliability.
3. AI-assisted document processing
When enabled, selected document content may be sent to an AI service provider to extract structured candidate values. Proof2Ship should minimize the data sent, avoid using AI as the final legal decision-maker, and configure retention controls consistent with the final production agreement.
4. CPSC credentials
CPSC API tokens and secrets are sensitive credentials. Production architecture should encrypt them at rest, restrict them to server-side access, scope them to the relevant organization, never place them in browser-visible environment variables, and support rotation/expiration.
5. Storage and retention
Documents should be stored in private object storage with tenant access controls. The production product should define customer-selectable or contract-defined retention periods and deletion workflows. Audit records may need a separate retention schedule.
6. Service providers
Depending on final configuration, providers may include hosting, database/authentication, object storage, AI processing, analytics, transactional email, error monitoring, and payment processors. A final policy must identify the actual provider categories and required disclosures.
7. Security
Planned controls include encryption in transit, tenant isolation, row-level authorization, private storage, signed URLs, credential encryption, least-privilege server keys, audit logs, file validation, rate limiting, and secure secret management. No system can guarantee absolute security.
8. Your choices
Users should be able to access, correct, export, and request deletion of account and organization data subject to legal, security, and contractual retention obligations.
9. Contact
Before production launch, replace this section with the legal entity name, mailing address, privacy contact, and jurisdiction-specific rights process.
