Privacy policy
Last updated 5 August 2026.
Draft, pending legal review. This document describes how Tariffwright actually works and every factual statement in it has been checked against the running system. It has not yet been reviewed by a lawyer, and it is published in this state so that it is accurate rather than absent. If you are evaluating Tariffwright commercially, ask for the reviewed version.
Who this covers
Tariffwright is operated by the operator of Tariffwright, in Canada. This policy covers three groups of people, who arrive here very differently:
- Customers — importers and brands who create a workspace.
- Their colleagues and reviewers — invited users, including customs brokers.
- Suppliers — people who receive a request link and answer questions about a product. Suppliers never sign up, never agree to anything, and most will never visit this page. Their information is handled with that in mind.
Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies to this service.
What is collected
| Category | What | Where it comes from |
|---|---|---|
| Account | Name, email address, workspace role | You, or whoever invited you |
| Sign-in | A hash of the one-time code, its expiry, the IP that requested it | Generated when you sign in |
| Product data | Styles, SKUs, fibre composition, construction, origin, prices, quantities | Your catalog uploads and manual entry |
| Documents | Tech packs, declarations, invoices, photos | Uploaded by you or by a supplier |
| Supplier contact | Name and email of the person you ask | Entered by you |
| Supplier answers | Their responses and any files attached | The supplier |
| Activity | Who imported, accepted, approved, exported, and when | Recorded as you use the service |
| Technical | Request logs, error logs, IP addresses | Generated automatically |
Uploaded product prices and supplier relationships are commercially sensitive. They are treated as the most confidential thing here.
Why
- To provide the service: finding missing customs facts, collecting them, suggesting classifications, calculating landed cost, producing dossiers.
- To keep an audit trail, because the point of the product is that a decision stays explicable years later. This is why activity history cannot be edited.
- To authenticate you and keep workspaces separated from one another.
- To diagnose faults.
Your product data is not used to improve the service for anyone else, is not aggregated into benchmarks, and is not sold or shared for advertising. There is no advertising here and no third-party analytics or tracking of any kind — the only cookie set is the one that keeps you signed in.
Artificial intelligence, specifically
No customer content is sent to any AI provider. The extraction and
classification in Tariffwright run as deterministic rules on our own servers. The
running system reports its mode as deterministic-only.
If that ever changes, this page will change first, the change will be announced to customers before it takes effect, and customer content will not be used to train anyone's models.
Where it is stored, and who else touches it
- The database — PostgreSQL on hardware we operate ourselves, in Canada. Not a public cloud.
- Uploaded documents — Cloudflare R2 object storage.
- Backups — daily encrypted copies to Cloudflare R2.
Sub-processors
| Who | What they handle |
|---|---|
| Cloudflare | Object storage for uploaded documents and backups; the network layer every request passes through; delivery of sign-in emails |
That is the entire list. There is no analytics provider, no error-tracking provider, no CRM, no email marketing platform, and no AI provider. Cloudflare stores data across its global network; no single-country restriction is currently configured for object storage.
Security, stated plainly
What is true:
- All traffic is encrypted in transit with TLS.
- Sign-in codes, session tokens and supplier links are stored only as hashes. A database read yields nothing you can sign in with.
- Supplier links are scoped to specific products and questions, expire, and can be revoked immediately.
- Every query is filtered by workspace at the data layer, and there are tests that fail if any table holding customer data cannot be filtered that way.
- Uploads are checked against their actual file contents, not the claimed type, and are always served as downloads so they cannot execute in your browser.
- Activity history is append-only, enforced by the database rather than by convention.
- Backups are taken daily and restore-verified daily — restored into a scratch database to prove they can be, rather than assumed.
What is not true, and would be easy to imply:
- The server disk holding the database is not encrypted at rest. Documents in object storage and backup archives are encrypted; the live database volume is not. Someone with physical access to the machine could read it.
- There is no independent security certification — no SOC 2, no ISO 27001.
- There is no formal breach-notification SLA. If customer data were exposed, you would be told promptly and directly, but no contractual timeframe is committed.
These are stated because you should be able to weigh them. They are being worked on, and this section will change when they change.
How long it is kept
- Workspace data — until you delete it, or delete the workspace. There is no automatic expiry: a classification decision has to remain explicable years later, which is the whole point.
- Corrections — a corrected fact keeps its previous version, so that a decision made on the old value can still be understood.
- Sign-in codes — minutes. They expire and are single-use.
- Supplier links — expire on their own and stop working the moment they are revoked.
- Backups — deletion takes effect immediately in the live system. Copies in existing backups age out with the backup rotation rather than being reached into.
- Erasure receipts — when a workspace is deleted, a record that it was deleted is kept: its name, who asked, when, and how many rows went. It holds no product, supplier or document content. It exists so a deletion can be attested to afterwards, which is impossible if the only record of it was inside the thing deleted.
Your rights
Under PIPEDA you may ask what personal information is held about you, ask for it to be corrected, and withdraw consent. In this product most of that is self-serve rather than a request you have to make:
- See and export everything — any workspace owner can download the entire workspace as JSON or CSV, with no cancellation flow and no support request.
- Delete everything — permanently, including uploaded files in object storage.
- Suppliers — you can ask what a brand's workspace holds about you, and ask for it to be corrected. Write to us and we will put you in contact with the brand that invited you, since the product record is theirs.
If you are not satisfied with how a privacy question was handled, you can complain to the Office of the Privacy Commissioner of Canada.
A contact address has not been published yet. Until it is, reach us by replying to any message you have received from us.