trustlists_
trustlists policies

Privacy Policy

Effective date: July 25, 2026

This policy explains how trustlists handles information across the public directory, app.trustlists.org, and the trustlists Companion browser extension.

It should be read with our Terms of Service and Listing Removal Policy.

On this page
ScopeInformation We CollectAI and Uploaded DocumentsCookies and AnalyticsPayments and BillingHow We Use InformationBrowser ExtensionService ProvidersRetention and SecurityData SharingYour Choices and RightsChanges and Contact

Contents

  1. 1Scope
  2. 2Information We Collect
  3. 3AI and Uploaded Documents
  4. 4Cookies and Analytics
  5. 5Payments and Billing
  6. 6How We Use Information
  7. 7Browser Extension
  8. 8Service Providers
  9. 9Retention and Security
  10. 10Data Sharing
  11. 11Your Choices and Rights
  12. 12Changes and Contact

1. Scope

This policy applies when you use:

  • The public directory, blog, and API at trustlists.org.
  • Account-based tools at app.trustlists.org.
  • The trustlists Companion browser extension.
  • Listing submission, correction, and claim workflows.

Vendor trust centers and other third-party websites linked from the directory operate under their own privacy policies.

2. Information We Collect

Account information

  • Email address and basic profile identifiers provided during sign-in.
  • Session data used to authenticate your account and keep it secure.

Product activity

  • Favorites, usage counters, analysis status, and generated report history.
  • Listing submissions, corrections, claims, and supporting information you provide.
  • Operational logs used for reliability, security, debugging, and abuse prevention.

3. AI Features and Uploaded Documents

When you use AI Lookup or the SOC 2 Analyzer, we process the queries, files, and instructions you submit to produce the requested result.

  • Uploaded reports may contain confidential information. Only upload material you are authorized to process.
  • Source uploads are removed from active processing storage after processing or cleanup. Generated analyses and related metadata may remain in your account history.
  • AI requests may be routed through approved infrastructure and model providers. We limit the information sent to what is needed to provide the feature.

4. Cookies and Analytics

We use essential cookies for sign-in, session continuity, and security. We may also use analytics to understand page usage and improve product reliability.

You can limit non-essential cookies through your browser settings. Blocking essential cookies may prevent account features from working.

5. Payments and Billing

Stripe processes purchases. trustlists does not store full card numbers or card security codes.

We retain transaction identifiers, purchased credit amounts, account identifiers, and reconciliation records needed to grant credits, support customers, prevent fraud, and maintain financial records.

6. How We Use Information

  • Provide directory search, account features, AI Lookup, and analysis workflows.
  • Authenticate users, manage credits, and process purchases.
  • Review listing submissions, corrections, removals, and ownership claims.
  • Monitor reliability, secure the services, prevent abuse, and troubleshoot issues.
  • Improve product quality and communicate about service-related activity.

7. Browser Extension

trustlists Companion uses the browser permissions described in its store listing to provide the side panel, detect relevant websites, synchronize account state, cache limited settings locally, and open trust-center links.

AI Lookup runs only when initiated through the product and sends the submitted lookup information to trustlists services.

8. Service Providers

We use service providers to operate trustlists, including:

  • Supabase for authentication and data infrastructure.
  • Vercel for hosting, workflow execution, and AI request routing.
  • Stripe for payment processing.
  • Approved AI model providers for AI-assisted features.
  • Analytics, monitoring, and email-delivery providers.

Providers receive only the information reasonably needed to perform services for us and are subject to their own contractual and security obligations.

9. Retention and Security

We retain information for as long as needed to provide the services, maintain account history, meet legal and financial obligations, resolve disputes, and prevent abuse. Retention periods vary by data type and product feature.

We use administrative, technical, and organizational safeguards designed to protect information. No system is completely secure, so you should use care when uploading sensitive documents.

10. Data Sharing

We do not sell personal information.

We may share information:

  • With service providers that operate features on our behalf.
  • When you direct us to share or publish information.
  • To comply with law or protect trustlists, our users, or others.
  • As part of a business transaction, subject to appropriate safeguards.

11. Your Choices and Rights

  • Request access, correction, or deletion of account information.
  • Uninstall the browser extension and revoke its local permissions.
  • Request a listing correction or removal under our Listing Removal Policy.
  • Contact us about rights available under applicable privacy law.

We may need to verify your identity before completing a request. Some records may be retained where required for legal, security, fraud-prevention, or financial purposes.

12. Changes and Contact

We may update this policy as the services change. The effective date above identifies the current version.

For privacy questions or requests, email privacy@trustlists.org.

trustlists_
PrivacyTermsListing removal