Legal
Privacy policy
Last updated 6 September 2026
This policy explains what personal data TariffFlow collects, why, and what rights you have over it. You can ask us about any of it at support@tariffflow.app.
Who we are
TariffFlow is operated by Daniel Hamilton (trading as TariffFlow), with a service address in Earl Shilton, Leicestershire, United Kingdom. Our privacy and service contact is support@tariffflow.app. Confirmed company, VAT and ICO registration details will be added here if and when they apply; we do not describe a registration as complete while it is pending.
Our data-protection roles
TariffFlow is the controller for account administration, billing, security, support, service analytics and our own product decisions. When a business customer includes personal data in product documents, classification inputs or shipping-quote requests solely for its own purposes, TariffFlow acts as that customer's processor for that material. The data-processing terms in our Terms of service form part of the contract for that processing.
What we collect and why
We keep data collection to what we actually need to run the service you've signed up for.
Account data
- Email address, name, company name, and role — supplied during sign-up or in Settings. Used to authenticate you, contact you about the service, and personalise Case Packs.
- Authentication is handled by Clerk (see Subprocessors below). Clerk stores password hashes / OAuth tokens. We never see your password.
Classification data
- Product descriptions you type, bounded text extracted from PDFs, and descriptions produced from images you attach. These are processed to produce a commodity-code recommendation. Raw PDF and image files are not stored as upload objects by the current application.
- Structured attributes extracted by AI (material, function, use case, etc.), candidate codes considered, and the final recommendation. Stored on the case so you can export or review it.
Supplier quote suggestions
If you request AI suggestions from pasted supplier quote text, we send that text to the configured text AI provider (currently OpenAI) to suggest purchasing details for your review. TariffFlow does not retain the pasted text or extraction prompt; confirmed fields are saved only when you save an estimate. Short-lived pseudonymous request counts enforce usage limits.
Live shipping quotes
- When you request live rates, we send the origin and destination addresses you provide, including street, city, region, postcode, country and any optional address details, together with parcel count, dimensions and weight, to Shippo and the carriers it uses to return quotes.
- These details are sent when you submit a rate request. We also keep short-lived request counts under a pseudonymous account reference to enforce usage limits and prevent abuse.
UAT feedback data
- If an owner enables UAT mode on your account, we store suggestions, bug reports, questions, conversation replies, and their delivery status so you and TariffFlow can work through them together.
- Feedback text is sent to OpenAI to generate a best-effort automated acknowledgement. When available, the acknowledgement may ask a clarifying question; it is not a promise that a feature or fix will be delivered.
- A TariffFlow owner may copy the feedback transcript, without the account identity fields added by our admin view, into our OpenAI Codex development workspace to investigate and implement product changes. Text you place inside the transcript is included, so please do not submit secrets or unnecessary personal data.
Support data
- When you use the support form or email us for help, we collect the email address, category, subject and message you provide, plus an optional name and the conversation, routing, delivery and reply records needed to handle the request.
- Support-form messages go directly to RelayDesk, our support-desk application. RelayDesk stores the conversation in Cloudflare D1, routes it to our AI support assistant or human support queue, and may use Resend to send a transactional acknowledgement or reply. Support text routed to the assistant is sent to Ollama Cloud so it can draft an answer from TariffFlow's approved support knowledge. Please do not include passwords, payment-card details or other secrets.
- Account information is not made available merely because someone types an email address. If you are already signed in with the same verified address, or complete a one-time Clerk sign-in link from the conversation, TariffFlow may issue RelayDesk a temporary read-only capability. It reveals only the account, plan, usage, case-status, Case Pack-status and saved-product summary needed for that support question. It does not reveal case text, attachments, payment details, provider identifiers or classification reasoning.
Billing data
- If you subscribe, Stripe stores your payment method and billing history. We keep only your Stripe customer ID and subscription status locally. We never see your card number.
Usage data
- Counts of classifications per billing period, per plan, kept to enforce quotas and reconcile Stripe metered usage.
- With your consent, PostHog analytics events capturing which pages you visit and which buttons you click. Route names are allowlisted, and the account is represented by a secret-keyed pseudonym rather than your Clerk ID, email, or name. We never send classification content. You can opt in or out at any time via .
- If you consent to analytics and arrived via a marketing link, we store the utm_source, utm_campaign, utm_medium, utm_content on your user record so we can understand which channels bring which customers.
- With the same consent, an OpenAI Ads click reference may be retained for up to 90 days. OpenAI may receive page-view, registration, checkout and subscription events, along with that reference and hashed account identifiers, to attribute and optimise our ads. We do not send product descriptions, uploads, commodity codes or Case Pack contents in advertising events.
- With the same consent, Google Ads receives a completed-classification event and, after Stripe verifies a paid subscription, its value, currency and an opaque transaction token. This helps us attribute campaign results and avoid counting the same payment twice. We keep ad personalisation disabled and do not send product descriptions, uploads, commodity codes, Case Pack contents, names, email addresses or account IDs to Google Ads.
Required and optional information
An email address and enough product information to run a requested classification are required to provide the service. Without them, we cannot create an account or produce a recommendation. Profile fields, analytics, advertising measurement and non-transactional marketing are optional. Refusing those optional uses does not reduce the core service available on your plan. Live shipping quotes are optional; the requested addresses and parcel details are needed only if you choose to use that feature.
Lawful basis for processing
- Contract — we need to process your classification data, requested shipping-quote details, account information and service-support requests to deliver the service you signed up for.
- Consent — for product analytics, advertising attribution and any marketing email that goes beyond transactional notices. You can withdraw consent at any time.
- Legitimate interests — responding to support enquiries, service security, abuse prevention, reliability diagnostics, and essential operational logs, balanced against your right to privacy. We minimise the data collected.
- Legal obligation — tax, accounting and billing records are retained for the statutory period that applies to the operator and transaction. Those records may therefore survive application-data deletion.
Service providers and recipients
We use the following providers to operate TariffFlow. Their role can differ by service: most process data for us, while payment providers may also act as independent controllers for parts of their service.
| Provider | Purpose | Data involved |
|---|---|---|
| Clerk | Authentication, user management | Account identity and session data |
| Neon (Postgres) | Application database | Account, case and usage records |
| Vercel | Application hosting, edge delivery | Requests, application responses and logs |
| Cloudflare R2 | Private issued Case Pack storage | Issued PDF files and private object metadata |
| Cloudflare D1 (RelayDesk) | Support conversation and ticket storage | Support contact details, messages, routing, status and reply records |
| Ollama Cloud | Text classification before the 4 September 2026 production release; transient image analysis; AI customer support | Classification inputs and derived prompts before that release; image inputs; support messages and approved account-summary fields when support AI is enabled |
| OpenAI | Text embeddings, UAT acknowledgements, feedback investigation in Codex, AI classification reasoning, and supplier quote field suggestions | Classification inputs and derived prompts, embedding inputs, feedback you submit, and supplier quote text submitted for suggestions |
| Stripe | Subscription billing, card processing | Billing identity, payment and subscription records |
| Shippo and relevant carriers | Live shipping quotes requested by you | Origin and destination addresses, optional address details, parcel count, dimensions and weight |
| Resend | Transactional email | Email address and message content |
| PostHog | Product analytics (consent-gated) | Page and feature events; no classification content |
| OpenAI Ads | Advertising attribution (consent-gated) | Click reference, conversion events and hashed identifiers |
| Google Ads | Advertising conversion measurement (consent-gated) | Completed-classification event; verified subscription value, currency and opaque transaction token |
Some providers may process data outside the United Kingdom. Where that is a restricted transfer, we use an applicable UK adequacy regulation or contractual safeguard and assess the transfer as required. Contact us for information about the safeguard relevant to your data.
How long we keep data
- Cases and saved products: retained on every plan until you delete them individually or delete your application account.
- Live shipping quotes: TariffFlow processes addresses and quote results for the request without saving them to your product library or a quote history. Request-count records expire within 24 hours. Shippo and the carriers may retain quote records under their own retention policies; requesting a quote does not purchase a label or book a collection.
- Account deletion: deleting your account removes the linked application records and private stored files, cancels an active subscription, and requests deletion of the linked identity and analytics records. If a provider is temporarily unavailable, the request is retried. Stripe may retain billing and transaction records where it or we have a legal record-keeping obligation.
- Analytics and attribution: browser attribution cookies expire after 90 days. Provider-side analytics and conversion records follow the retention configured in those services and are periodically deleted or aggregated when no longer needed.
- UAT feedback: threads and replies are retained while your account exists, including after a thread is resolved, so the product decision has a usable history. Account deletion removes them.
- Support requests: RelayDesk conversation, contact and ticket records are retained while a request is open and afterwards only while reasonably needed for follow-up, complaint handling, security or legal claims. We review them and delete or anonymise them when those purposes no longer apply. You can email the support address above from the address used in the request to ask for access, correction or earlier deletion. RelayDesk records are separate from your application account, so deleting that account in Settings does not automatically remove them; we handle a valid rights request in the support desk, subject to applicable legal and security exceptions. Temporary account-support capabilities expire within 30 minutes and are revoked when the linked application account is deleted. We retain a field-minimised security ledger of signed tool requests and replay nonces without message text, email addresses, tool results or account identity fields. The support conversation reference remains so we can investigate misuse and delivery failures.
- Service-notice evidence: for material processor notices, we retain the campaign version, effective time, a pseudonymous recipient hash, Resend message ID, and delivery state for as long as reasonably needed to demonstrate that the notice was sent. The notice ledger does not duplicate your email address or name.
- Security and error logs: retained only for the period reasonably needed to investigate reliability, fraud and security issues, then deleted under the provider configuration.
Your rights
Under UK GDPR you have the following rights. Most are available self-serve from your Settings page; for the rest, email support@tariffflow.app and we'll respond within one calendar month.
- Access — download a JSON export of your data from Settings → Your data → Export.
- Erasure — delete your application account from Settings → Your data → Delete your account, then contact us if a provider-side record also needs review. Legal and security exceptions can apply.
- Rectification — edit your profile in Settings.
- Portability — the JSON export is in a standard machine-readable format.
- Restriction — tell us to pause processing pending a dispute resolution.
- Objection — object to processing based on legitimate interests, and object absolutely to direct marketing.
- Withdraw consent — change analytics and advertising measurement consent via . Withdrawal does not affect processing that was lawful before it.
- Complaint — you can complain to the UK ICO at ico.org.uk. We ask that you raise concerns with us first.
Cookies
TariffFlow uses essential storage and optional analytics/advertising storage:
- Essential and preference storage — Clerk session cookies keep you signed in; Stripe uses storage on its hosted checkout;
tf-cookie-consentand its matching preference cookie remember your choice. These are not used for advertising. - Analytics and advertising — PostHog storage, first/last-touch UTM cookies, the OpenAI Ads click-reference cookie, and Google Ads
_gcl_*attribution storage are only written after you click Accept all. The UTM and OpenAI click-reference cookies expire after 90 days; Google's storage follows the lifespan set by its tag. Use at any time to change your choice; future optional events stop and accessible Google Ads attribution storage is cleared when you withdraw it.
AI data handling
Short retrieval text is sent to OpenAI for embedding generation. From the 4 September 2026 production release, product descriptions, bounded text parsed from PDFs, image-derived descriptions, relevant retrieved tariff and ruling text, and derived prompts are also sent to OpenAI for classification reasoning. From that time, OpenAI classification requests are sent with API response storage disabled. UAT acknowledgement requests are already sent with response storage disabled. This is not the same as Zero Data Retention, and limited provider security and abuse-monitoring retention may still apply under our project's data controls. Before then, text-classification inputs were sent to Ollama Cloud. PDF parsing happens in your browser, and image bytes continue to be sent to Ollama Cloud for transient vision processing. Attached PDFs are parsed in your browser; PDFs fetched from a public URL are parsed on TariffFlow's server. Raw PDF and image files are not retained as upload objects. Bounded text extracted from attached PDFs or public product/datasheet URLs, sanitized URL provenance, and image-derived observations are retained with the Case until you delete that Case or your account. This lets a paused classification resume from the same evidence and keeps later product comparisons auditable. When you use the UAT feedback tab, the feedback conversation is also sent to OpenAI to produce the automated acknowledgement shown in that thread, while we retain the conversation in your TariffFlow account. An owner may separately use the transcript in our OpenAI Codex development workspace to investigate the report as described above. Do not include unnecessary personal data or special-category data in a classification or feedback report. Your inputs are transmitted over encrypted connections. See AI disclosure for more.
When AI customer support is enabled, RelayDesk sends the support message and relevant TariffFlow knowledge to Ollama Cloud for Milly to prepare a response. After a matching Clerk sign-in, Milly may also receive only the allowlisted account-summary fields described above. Server-enforced tools—not the model—select the account and permitted fields. Requests involving secrets, security, legal issues or protected account actions are routed to a human rather than executed by the assistant.
Security
We use encrypted transport, managed hosting and database controls, role-restricted administration and provider-managed authentication. Passwords are not stored in the TariffFlow application database. We assess and document personal-data breaches. Where a breach is likely to risk people's rights and freedoms, we notify the ICO without undue delay and, where feasible, within 72 hours after becoming aware of it. Where it is likely to result in a high risk, we also notify affected individuals without undue delay.
Updates to this policy
We update this policy when we change subprocessors, add new data collection, or change retention. The "Last updated" date at the top reflects the current version. Substantive changes are brought to your attention before a new material use begins, normally by email or an in-product notice.
Contact
Questions, access requests, or concerns: support@tariffflow.app. We acknowledge privacy queries promptly and normally complete rights requests within one calendar month.