Legal draft

Privacy Policy

Draft for product development · Last updated August 8, 2026

Important: This is a product-development privacy draft, not final legal counsel. Before launch, it should be reviewed against the actual vendors, retention settings, customer contracts, and jurisdictions Proof2Ship serves.

1. Information we may collect

Account information may include your name, work email, organization, authentication identifiers, and workspace membership. Product data may include SKUs, product identifiers, manufacturers, laboratories, points of contact, certificate data, CPSC identifiers, and user-entered notes.

Uploaded documents may contain supplier certificates, CPC/GCC records, test reports, manufacturing information, product specifications, and other materials you choose to provide.

2. How information is used

We use information to provide the Proof2Ship service, authenticate users, process uploaded documents, produce extraction candidates, validate data structure, maintain audit history, support CPSC Product Registry integrations, provide customer support, secure the service, and improve reliability.

3. AI-assisted document processing

When enabled, selected document content may be sent to an AI service provider to extract structured candidate values. Proof2Ship should minimize the data sent, avoid using AI as the final legal decision-maker, and configure retention controls consistent with the final production agreement.

4. CPSC credentials

CPSC API tokens and secrets are sensitive credentials. Production architecture should encrypt them at rest, restrict them to server-side access, scope them to the relevant organization, never place them in browser-visible environment variables, and support rotation/expiration.

5. Storage and retention

Documents should be stored in private object storage with tenant access controls. The production product should define customer-selectable or contract-defined retention periods and deletion workflows. Audit records may need a separate retention schedule.

6. Service providers

Depending on final configuration, providers may include hosting, database/authentication, object storage, AI processing, analytics, transactional email, error monitoring, and payment processors. A final policy must identify the actual provider categories and required disclosures.

7. Security

Planned controls include encryption in transit, tenant isolation, row-level authorization, private storage, signed URLs, credential encryption, least-privilege server keys, audit logs, file validation, rate limiting, and secure secret management. No system can guarantee absolute security.

8. Your choices

Users should be able to access, correct, export, and request deletion of account and organization data subject to legal, security, and contractual retention obligations.

9. Contact

Before production launch, replace this section with the legal entity name, mailing address, privacy contact, and jurisdiction-specific rights process.