Privacy Policy

Last updated: April 2026

This Privacy Policy explains how BandarTrade ("we", "us", "the Service") collects, uses, and protects information when you use our software-as-a-service product. We have written it as plainly as we can; please reach out if anything is unclear.

What we collect

Account data. When you sign up we record your email address and a hashed password (we never see or store your plaintext password). If you join an organization via invite, we record your role within it.

Operational data. Anything you create in the product — quotes, bills of lading, invoices, shipments, customers, carriers, rate sheets, and the documents you upload — is stored on your behalf and is visible only to members of your organization.

Third-party credentials. If you connect a Gmail inbox, an IMAP mailbox, a WhatsApp Business account, or bring your own AI provider key, we store those credentials encrypted at rest with AES-256-GCM. Only the organization that owns them can use them.

Usage telemetry. We log basic events (request paths, status codes, timestamps) for security and debugging. We do not run third-party analytics trackers on the dashboard.

How we use it

  • To provide the features you use — extracting BLs, sending quotes, tracking shipments, generating invoices.
  • To send you transactional emails (account confirmations, invites, the documents you choose to email).
  • To diagnose and fix problems in the service.
  • We do not sell your data. We do not use your data to train AI models.

Sub-processors

We rely on the following service providers to operate BandarTrade. Each has access only to the data needed for their specific function:

  • Supabase — database, authentication, file storage
  • Render — application hosting
  • Resend — transactional email delivery
  • Groq — AI text + vision extraction (when using our shared key)
  • Google — Gmail OAuth (only if you connect a Gmail inbox)
  • Meta — WhatsApp Business API (only if you connect WhatsApp)

If you bring your own AI key (BYOK), AI requests go directly to that provider and do not consume our shared quota.

Data retention & deletion

Your data persists as long as your organization is active. You may request a full export of your organization's data at any time. To delete your organization and all associated data, email us — we will action the request within 30 days.

Security

Every database table is protected by row-level security so that one organization cannot read or modify another's data even if there is a bug in the application code. Stored third-party credentials are AES-256-GCM encrypted. Email and WhatsApp webhook endpoints are signature-verified.

Children

BandarTrade is a B2B logistics tool and is not directed at children under 16.

Changes to this policy

If we make material changes, we'll notify the email on file at least 14 days in advance and update the "Last updated" date above.

Contact

Questions or requests (export, deletion, anything else) — email upliftdigitalpartners@gmail.com.

This document is provided as a starting point. For production use, please have it reviewed by counsel familiar with your jurisdiction's data-protection requirements.