1.Why this page exists
Sellers upload photographs of products that have not launched yet. Packaging that is under NDA, a colourway nobody has seen, a product that competitors would like an early look at. That is more sensitive than most SaaS data, so it deserves a page rather than one paragraph in a privacy policy.
The two commitments that matter most
Your product photos are never used as AI training data, by us or by any provider we send them to.
Uploads are deleted after 30 days, automatically, whether or not you remember to remove them.
2.Encryption
- In transit — TLS 1.3 for all connections, with HSTS enforced. Plain HTTP requests are redirected, never served.
- At rest — AES-256 encryption for stored images, database contents and backups.
- Secrets — API keys and credentials are held in managed secret storage, never in source control, and rotated on personnel change.
3.Access control
- Access to production systems is limited to the people who need it, under least-privilege roles, with multi-factor authentication required.
- Nobody browses customer images casually. Access to a specific account’s content happens only when you ask us to investigate something, and it is logged.
- Administrative actions are recorded in an append-only audit log.
- Access is revoked the same day someone leaves.
4.Tenant isolation
Every image is scoped to the account that created it and served through signed, expiring URLs. There is no public bucket, no guessable path, and no cross-account read path. Generation jobs run per-request and are not pooled across customers.
5.Sub-processors
We build on established infrastructure rather than running our own data centres. Each provider below is bound by a data processing agreement that prohibits using customer content for training:
| Provider | Role | Region |
|---|---|---|
| Vercel | Website and application hosting | United States |
| Supabase | Account database, authentication and image storage | United States / European Union |
| Payment provider | Merchant of record, payment processing and tax remittance | European Union |
| AI model providers | Image generation compute | United States |
| Resend | Transactional email delivery | United States |
We give 30 days’ notice before adding a sub-processor that handles customer content. Email support@tradarsai.com to be added to that notification list.
6.Retention and deletion
- Source uploads: deleted 30 days after processing
- Generated images: retained 90 days so you can re-download them
- Account deletion: all images and account data erased within 7 days
- Backups: rolling encrypted backups aged out within 35 days, after which deleted content is unrecoverable
Full detail is in the Privacy Policy.
7.Availability and incident response
Infrastructure is deployed across multiple availability zones with automated failover, and backups are restore-tested rather than assumed to work.
If a security incident affects your data, we will notify affected account holders within 72 hours of confirming it, with what happened, what data was involved, and what we are doing about it. We will not wait for a complete forensic picture before telling you something happened.
8.Reporting a vulnerability
Email support@tradarsai.com with steps to reproduce. We acknowledge within 2 business days and aim to remediate confirmed issues within 30 days, faster for anything critical.
We will not pursue legal action against researchers who act in good faith: no accessing other people’s data beyond what is needed to demonstrate the issue, no service degradation, no public disclosure before we have had a reasonable chance to fix it.
9.What we ask of you
- Use a unique, strong password and enable multi-factor authentication
- Do not share one login across a team — use seats
- Remove team members promptly when they leave
- Report anything that looks wrong to support@tradarsai.com
Questions about this document
Email support@tradarsai.com and a person will answer. This document is provided for transparency and is not legal advice.