Privacy Policy — Trade Assist Pro
Last updated: 2026-05-11 Status: DRAFT — pending counsel review. Operator: replace placeholders marked <<...>> and remove this banner before going live.
1. Who we are
Trade Assist Pro ("we", "us", or "the Service") is operated by Apex SE Flooring LLC, a Texas LLC ("the Company"). Contact:
- Email: apexsatx@gmail.com
- Postal: 1127 Mindie Lane, San Antonio, TX 78253
2. Data we collect
We collect only what we need to deliver the Service:
- Account data: email address, password hash, full name (if provided), company name, mailing address (required for CAN-SPAM compliance on the outreach feature).
- Payment data: Stripe handles all card data. We store only the Stripe customer/charge identifiers + amount + timestamp; we do not store card numbers, CVV, or expiry.
- Usage data: the AI features (scope generation, document scan, legal Q&A, sign capture, form fill) record per-call telemetry: route name, model name, input/output token counts, latency, status, request id. Token counts and latency are technical metadata; we do not store the prompts or responses themselves except as needed to display them to you in the relevant feature.
- Sign capture photos and extracted data: when you use the Sign Capture feature, we store the photo and the extracted business information so you can review and edit it.
- Outreach send log: when you use the Outreach feature, we log the recipient address, send status, and delivery events from Resend (our email provider) for compliance + customer-support purposes.
- Audit log: security-relevant events (logins, payments, admin actions) are recorded in a tamper-evident hash-chained audit log.
3. How we use it
- To deliver the Service you signed up for.
- To bill you for usage (Stripe processes the actual payment).
- To detect and respond to abuse, fraud, or security incidents.
- To comply with legal obligations including CAN-SPAM Act §5 (when you use the Outreach feature).
We do not sell your personal information. We do not use your data to train third-party AI models without your explicit opt-in.
4. Sub-processors
We use third-party sub-processors to provide the Service (for example: hosting, database and storage, payment processing, AI inference, voice and SMS, messaging, and email delivery). Each processes data only as needed for its stated purpose, under a written data-processing agreement.
The current, itemised list — each sub-processor, its purpose, the categories of data it processes, and its region — is maintained at [/legal/subprocessors](/legal/subprocessors). We keep that list up to date: when we add or replace a sub-processor, we update that page and notify account holders in advance, with an opportunity to object before the change takes effect. Maintaining the list separately lets us keep it accurate as our providers change without republishing this Policy.
5. Retention
- Account data: retained for the life of your account + 90 days after deletion, then permanent deletion.
- Payment records: retained for 7 years per IRS requirements.
- Usage telemetry (`ai_usage_log`): retained for 18 months, then aggregated and purged.
- Sign capture photos + extracts: retained for 24 months or until you delete them, whichever is sooner.
- Outreach send log: retained for 3 years (CAN-SPAM minimum is 5 years for records of consent; we exceed by storing 3 years of send history + permanent suppression-list entries).
- Audit log: retained for 7 years.
6. Your rights
Subject to applicable law (GDPR, CCPA, VCDPA, CPA, etc.):
- Access: request a copy of your personal data.
- Rectification: correct inaccurate data.
- Erasure ("right to be forgotten"): request deletion (subject to retention obligations above for billing/audit records).
- Portability: receive your data in a machine-readable format.
- Objection: opt out of specific processing.
- Automated-decision rights: none of our features make automated decisions with legal effect.
To exercise any right: email apexsatx@gmail.com. We respond within 30 days (or the legally required window for your jurisdiction, whichever is shorter).
7. Outreach feature (CAN-SPAM + GDPR)
The Outreach feature is opt-in per-contractor. Every email we send on a contractor's behalf includes:
- A working unsubscribe link (RFC 8058 one-click + footer link).
- The contractor's physical mailing address.
- Honest sender identity.
If you (the recipient of an outreach email) unsubscribe, your address is added to that contractor's permanent suppression list. We honor opt-outs across all future outreach from that contractor.
EU recipients: we currently restrict outreach to US recipients pending legal review of cross-border cold-outreach posture under GDPR.
8. Security
- Data in transit: TLS 1.2+ to all our services.
- Data at rest: Supabase managed encryption (AES-256); Stripe + sub-processors per their own controls.
- Access control: Row Level Security on multi-tenant tables; service-role keys restricted to documented call sites.
- Incident response: see
docs/security/incident-response.mdand the/statuspage.
9. Children
The Service is not directed to anyone under 16. We do not knowingly collect personal data from children.
10. Changes to this policy
Material changes will be announced via email to account holders and via banner on the Service. Continued use after a change constitutes acceptance of the updated policy.
11. Governing law
This policy is governed by the laws of the State of Texas, without regard to conflict-of-laws principles. Disputes are subject to the exclusive jurisdiction of courts in Bexar, Texas.
12. Contact
apexsatx@gmail.com or postal mail to the address in §1.
END OF POLICY