Cookieless Web Analytics (Plausible Analytics)
To measure aggregate website traffic and marketing conversions without compromising visitor privacy, we use Plausible Analytics.
Visitor Hash = SHA-256(daily_salt + domain + ip_address + user_agent)
The pseudo-identifier salt rotates every 24 hours at 00:00 UTC and is irreversibly discarded. Raw IP addresses are discarded in volatile memory immediately after geographic lookup. No personal data is stored on persistent disks.
European Union Residency: All telemetry collected by Plausible is hosted exclusively on bare-metal infrastructure in Nuremberg, Germany (Hetzner Online GmbH) operated by an EU entity. Telemetry is used solely for aggregate audience measurement (pageviews, referral sources, and high-level conversion clicks) and is never shared, sold, or joined across websites.
Commercial Purchasing Data & Purpose of Processing
When an organization uses the Traceline application (app.usetraceline.tech), we process the commercial data necessary to deliver quote normalization and comparison services:
- Source Documents: Supplier quotes and RFQs uploaded by authorized users in PDF, XLSX, CSV, or text format.
- Extracted Purchasing Data: Line item descriptions, manufacturer part numbers, quoted prices, pack quantities, units of measure, payment terms, and freight charges.
- Account Credentials: User work email addresses, names, and Organization memberships managed through WorkOS enterprise authentication. Traceline never stores user passwords.
We process this data solely to execute the contract between your Organization and Traceline: parsing documents, performing deterministic mathematical calculations, displaying Bid Tabs, and generating formula-backed Excel workbooks.
Stateless Model Inference & Zero Training Guarantee
Your commercial quotes are never used for AI training.
Traceline employs frontier large language models exclusively for initial document layout interpretation and schema extraction. All arithmetic calculations, unit conversions, and totals are handled by audited deterministic code.
- Zero Data Retention (ZDR): Every model invocation payload explicitly enforces
data_collection: denyandzdr: trueflags. - Ephemeral Memory: Document text fragments exist in inference model memory solely for the duration of the HTTP extraction request. They are never retained in vendor training caches or debugging disks.
- Zero Customer-to-Customer Leakage: Extraction runs operate in isolated, ephemeral contexts without multi-customer shared memory.
Tenancy Isolation, Operator Grants & Hard Deletion
Commercial purchasing data demands verifiable technical segregation:
- Database Kernel Isolation: Multi-tenant isolation is enforced at the PostgreSQL database engine level using Row-Level Security (RLS) on the active session role (
app.current_org). The application service account lacksBYPASSRLSprivileges. - Time-Boxed Operator Access Grants: Traceline engineering and support personnel have zero default access to customer quote files. Access requires an explicit Operator Access Grant authorized by an organization owner, bounded to an expiring time window, and revocable at will.
- Irrevocable Hard Deletion: When an Organization owner requests the deletion of a Comparison, Project, or Organization, Traceline executes an irrevocable hard deletion across database records and object storage. Historical commercial records and files are permanently purged.
Public Subprocessor Register
We maintain an exhaustive, public register of third-party cloud infrastructure subprocessors used in delivering Traceline:
| Entity | Purpose | Data Handled | Location & Safeguards |
|---|---|---|---|
| Microsoft Azure | Core Cloud Infrastructure, Compute, PostgreSQL Flexible Server, Blob Storage | Encrypted database records, stored supplier PDF/XLSX/CSV quotes | United States / Canada (Azure Tenant) |
| WorkOS | Authentication & Session Management | User email, name, organization membership (Passwords are never stored by Traceline) | United States (SOC 2 Type II certified) |
| Anthropic / OpenRouter | Stateless Document Extraction & Translation | Ephemeral quote text fragments for extraction | United States (Zero Data Retention enforced; data_collection: deny) |
| Plausible Analytics | Cookieless Web Traffic Analytics | Anonymous pageviews, daily rotating salt hash (No cookies, no PII) | European Union (Hetzner, Germany; GDPR compliant) |
| Sentry (Functional Software, Inc.) | Application Error Tracking | Scrubbed error traces (Request bodies and commercial quote PII stripped) | United States (SOC 2 Type II certified) |
Data Subject Rights (GDPR & CCPA/CPRA)
In accordance with the EU General Data Protection Regulation (GDPR), UK GDPR, and California Consumer Privacy Act (CCPA/CPRA), users and customer organizations hold the following rights:
- Right of Access & Portability: You may request a complete export of all personal and commercial data held in your Organization.
- Right of Rectification: You may correct or amend inaccurate user profile information directly in the application.
- Right of Erasure (Right to be Forgotten): Organization owners may initiate complete hard deletion of their account, projects, and stored quotes at any time.
- Right to Object & Restrict Processing: You may withdraw consent or terminate your subscription and processing agreements.
Contact & Governance
For questions regarding this privacy policy, Data Processing Agreements (DPAs), vendor security questionnaires, or to exercise your statutory privacy rights, contact our security and compliance team: