Privacy Policy
This policy is in effect and binding as described in the Terms of Service, Section 0.
1. Information collected
Tiana & Co. collects:
Information submitted through the intake forms — supplier names and addresses, product descriptions and HS codes, and, for the CPSC Product Registry Filing, certifying-party, records-custodian, manufacturing, and testing-lab details supplied to prepare that filing — including any of those details read, at your request and behind a consent step, from a certificate, test report or invoice you add to pre-fill the form and then confirm. The added document itself is read once by the AI and discarded; it is not retained.
Contact information — an email address, provided at checkout, used to deliver the report or filing and its re-access link.
Guide change alerts — if you ask to be told when the rules on a guide change (“Tell me when the rules on this page change,” offered under a guide’s next step), we store the email address you provide, which guide you asked about, and a per-subscription unsubscribe token. This carries no case data — an email address and the public guide’s identifier, not the supplier or product details you enter into a tool. A copy of that guide is emailed to you once as confirmation; after that, the address is used only to send an occasional note if the regulations the guide covers change, and every such message includes a one-click unsubscribe link.
Package purchases — for the paid deliverable packages (the Detention Decoder response package and the Broker-Ready handoff package), we store only an email address provided at checkout, used for the payment receipt, and the payment reference. No details of the case are stored for these products. The CBP notice, the uploaded documents, and the shipment or listing details are used in your browser (and, where a document is read by the AI, behind an explicit consent step and then discarded) to build the package, and the assembled package is downloaded immediately rather than saved — there is no stored copy, and no re-access after the download session.
Payment information — handled directly by Stripe, the payment processor. Tiana & Co. does not receive or store full card numbers.
Feedback you submit — if you use the feedback feature on a delivered report or filing, we collect what you write, and any optional email address you provide. Feedback may contain commercially sensitive information depending on what you choose to write, and is used only as described in Section 2 — never to change a delivered report, and never shown to other customers.
Assent and acceptance records — when you agree to the Terms of Service and this Privacy Policy, we record the timestamp, IP address, and the version of each document you agreed to, so we can show what you agreed to and when.
Technical/diagnostic data — basic error and performance data collected automatically through Sentry, an error-monitoring service, to help identify and fix bugs. This does not include advertising or third-party marketing trackers, and Tiana & Co. uses no advertising or cross-site tracking cookies.
Usage data — we record which steps of the flow you reach (for example: the page loaded, an intake started, a result shown, checkout opened, a payment completed, a partner laboratory link clicked), using a random identifier that lasts only for your browser tab and is not linked to you. This is first-party and anonymous — no cookies, no third-party trackers, and none of the supplier or product details you enter. It exists only to show where people drop off, so the tool can be improved.
2. How information is used
Information submitted is used to:
- Run the compliance checks and generate the purchased report or filing;
- Send the delivery email and, if needed, a re-access link, through Resend, the transactional-email provider;
- Send guide change alerts you asked for, through Resend, and honour an unsubscribe request at any time;
- Generate the narrative portions of a report using Anthropic’s Claude API — the underlying facts and verdicts are produced by deterministic checks, not the AI model — and, where you add a document to the Detention Decoder, the Broker-Ready or CPC checks, or the CPSC Product Registry Filing’s pre-fill, read that document once into structured fields through the same API, after which it is discarded;
- Review and respond to feedback you submit, and to understand where the Service is falling short;
- Respond to support requests; and
- Maintain and improve the Service, including diagnosing errors and understanding, from the anonymous usage data described in Section 1, where visitors drop off.
Submitted information is not sold, and is not used for advertising or marketing.
3. Where information is stored
Report, filing, feedback, and guide-subscription data are stored in a Supabase (PostgreSQL) database, encrypted at rest by Supabase’s default configuration. Access is restricted at the database level; only the private access-link token for a specific report or filing can retrieve that record’s data.
4. How long information is kept
A purchased report or filing’s underlying record is kept for a period of 12 months, so it remains available to its owner. The access link to that record expires after a stated period (currently 60 days) and must be re-issued through email verification — this is a security measure limiting how long an unused link remains a valid credential, not a deletion of the underlying data.
A package purchase stores only the email and payment reference for that order — no case data. Its access token is short-lived (currently 7 days) and authorises only the download session; because the package is built in your browser and not stored, it cannot be re-issued or re-accessed afterward. The purchase record is kept for 12 months and the transaction record for 7 years, as stated here.
Feedback submitted on a report or filing is kept for a period of 12 months.
A guide change-alert subscription — the email address and guide identifier you provide — is kept until you unsubscribe (one click, in every such email) or ask us to remove it.
Records tied to a completed transaction — the order, amount, and date — are kept for 7 years to meet tax and accounting requirements, and are not deleted on request.
Assent and acceptance records are kept for as long as the agreement they evidence could be at issue, and in any case no less than the limitations period stated in the Terms of Service.
5. Third-party services
Tiana & Co. relies on the following third-party services to operate:
- Stripe — payment processing;
- Resend — transactional email delivery;
- Anthropic (Claude API) — narrative generation for reports;
- Supabase — database and storage;
- Vercel — application hosting;
- Sentry — error monitoring;
- U.S. and other government data sources (e.g. OFAC, DHS/FLETF, CBP, CPSC, GLEIF, national corporate registries) — queried or matched against to produce check results; a supplier or product name submitted may be checked against these sources.
Each of these providers processes information under its own privacy terms as a service provider to Tiana & Co.
6. Your choices and rights
You can request access to, correction of, or deletion of your submitted information, including feedback you’ve submitted, by contacting support@tiana-co.com from the email address on file for the order. Requests are answered within 30 days. Because a request is verified by the email address on file, a request sent from a different address cannot be actioned.
Two exceptions apply. Transaction records are kept for 7 years as described in Section 4 and cannot be deleted on request. Deleting a report or filing record also removes your own access to it, which cannot be undone.
7. Business use only
This Service is offered for business and commercial purposes, consistent with the Terms of Service, Section 2. If you submit information relating to an identifiable individual — such as a contact name at a supplier — you are responsible for having a lawful basis to do so.
8. Children’s privacy
The Service is not directed to, and is not knowingly used by, anyone under 18. We do not knowingly collect information from children.
9. Changes to this policy
This policy may be updated from time to time; the “Last updated” date at the top of this page reflects the most recent version. Material changes are handled the same way as changes to the Terms of Service — see Terms Section 17.
10. Contact
Questions about this policy can be sent to support@tiana-co.com.
End of Privacy Policy.