Privacy Policy
1. Information we collect
TFL is a business-to-business platform. We collect information through direct submissions by users and organizations, through your use of the platform, and through technical processes required to deliver the service.
Account & identity data
- Name, email address, and password (hashed with argon2id — never stored or logged in plain text)
- Phone number, if provided
- Two-factor authentication (TOTP) secret and recovery codes, when enabled — the secret is encrypted at rest, recovery codes are stored only as one-way hashes
- Role and permission assignments within each organization you belong to
Organization & onboarding data
- Legal and trading name, registration number, tax ID, industry, country, and business address
- Primary contact details, website, annual revenue and estimated transaction volume ranges, where provided during onboarding
- Declared directors and beneficial owners, where your organization type requires it, for know-your-business (KYB) verification
- Countries served, currencies supported, and product/service categories your organization declares
Transaction & compliance data
- Trade transaction details, counterparty matches, and status history
- Compliance screening results (sanctions, politically-exposed-person, and adverse-media checks) and risk assessment scores
- Documents you upload in connection with a transaction, encrypted at rest and scanned for malware before storage
- Provider quotes, assignments, and fulfillment records across financing, insurance, logistics, FX, custody, and payment activity
- Settlement, escrow, and disbursement ledger entries
Usage & audit data
- Action logs: approvals, status changes, logins, and configuration changes — timestamped and attributed to the user who performed them
- Login history, including IP address, user agent, and success/failure outcome, retained for account security purposes
- API request logs (endpoint, timestamp, response status) for organizations using API key access
- Browser type, device type, and operating system, for support and reliability purposes
Payment & billing data
TFL does not process consumer credit card payments. Platform and provider-share fees are invoiced monthly to provider organizations as billing statements, settled by bank wire or ACH using payment instructions each party discloses directly — TFL does not collect or store your bank account credentials on your behalf.
2. How we use it
We use the information above only to operate the platform and to meet legal and compliance obligations that come with facilitating cross-border trade transactions:
- Provide matching, compliance screening, risk scoring, provider coordination, and settlement-ledger functionality
- Authenticate users and enforce role-based, organization-scoped access controls
- Perform know-your-business, sanctions, PEP, and adverse-media screening required before an organization or transaction can be approved
- Send transactional communications — account verification, password resets, and status notifications
- Investigate security incidents, enforce our Terms of Use, and meet audit and regulatory recordkeeping obligations
- Maintain the audit trail that compliance officers, auditors, and — where legally required — regulators can rely on
We do not sell your data. We do not use your transaction or business data to train AI or machine learning models beyond the platform's own deterministic, rule-based decision support (see our documentation on AI governance). We do not serve third-party advertising on TFL.
3. Data isolation between organizations
Each organization's data is separated by role-based access control and tenant-scoped authorization checks enforced at the application layer — every request is checked against the organization you're acting on behalf of. Compliance case detail is visible only to TFL platform staff holding the relevant permission, not to the organization's own administrators or its counterparty. Risk assessments are visible to the transaction's own parties, consistent with the transparency the platform is built around.
TFL staff access to organization data is limited to what a given role's permissions allow, and every access to sensitive records is captured in our audit log.
4. Third-party sharing
We do not sell, rent, or trade your information. We share it only in the following circumstances:
- Compliance screening providers — subject names are submitted to a sanctions/PEP/adverse-media screening vendor to perform the checks required before approval. The specific active vendor is configured by TFL and disclosed in our platform documentation.
- Your counterparty, where the platform is designed to show it — for example, both parties to a transaction see the same status, risk assessment, and settlement ledger by design; compliance case detail is the exception and stays internal to TFL.
- Infrastructure and service providers — hosting, database, and email delivery providers that process data on our behalf under contractual confidentiality obligations, and cannot use it for their own purposes.
- Legal requirements — where disclosure is required by law, regulation, court order, or governmental authority, or to protect the rights, property, or safety of TFL, our users, or the public.
- Business transfers — in the event of a merger, acquisition, or asset sale, information may transfer to a successor entity; we will provide notice before your data becomes subject to a materially different privacy policy.
5. Data retention
We retain account and transaction data for as long as your account is active and as necessary to provide the platform. Because TFL facilitates regulated and auditable financial activity, certain records — compliance screening results, settlement ledger entries, and audit logs — are retained beyond account closure to meet recordkeeping obligations typical of financial and trade-compliance recordkeeping, which can extend to several years. Where you request deletion of data that is not subject to such a retention obligation, we will act on that request within a reasonable time.
6. Security measures
Security controls are built into the platform, not layered on afterward:
- Passwords hashed with argon2id — never stored or logged in recoverable form
- Two-factor authentication (TOTP) available to every user and mandatory for TFL platform staff, enforced at the API layer
- Sensitive fields — MFA secrets, webhook signing secrets, provider API credentials, and uploaded documents — encrypted at rest (AES-256-GCM)
- Session tokens are stored server-side and referenced by an HTTP-only, Secure cookie — never exposed to page scripts
- A strict content security policy that does not permit third-party scripts to load on the platform
- Rate limiting on authentication and API endpoints
- Malware scanning on every document upload before it is stored
- Role-based access control enforced at the API layer, with a full audit trail on every material action
- All traffic encrypted in transit via TLS
7. Cookies & local storage
TFL uses two cookies, both strictly necessary for the platform to function: a session cookie (HTTP-only, so it cannot be read by page scripts) and a CSRF-protection cookie. We do not use third-party advertising or tracking cookies, and our content security policy does not permit third-party analytics or advertising scripts to load on the platform at all.
8. Your rights
Depending on where you're located, you may have the right to access, correct, export, or request deletion of your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us using the details below — we aim to respond within 30 days. Note that some data cannot be deleted while your organization has an active or historical relationship with a transaction subject to ongoing legal or audit retention requirements, as described in Section 5.
9. International transfers
TFL facilitates cross-border trade by nature, so information may be processed in the United States and transferred to or accessed from other countries in connection with a transaction's counterparties, providers, or screening requirements. Where applicable law requires a specific mechanism for such transfers, we take steps appropriate to that requirement; contact us if you need details specific to your jurisdiction.
10. Children's privacy
TFL is a business platform intended for use by adults acting on behalf of organizations. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently done so, we will delete it promptly — contact us to request this.
11. Policy updates
We may update this Privacy Policy from time to time. For material changes to what we collect, how we use it, or who we share it with, we will provide at least 14 days' advance notice to your account's primary contact email before the change takes effect. Minor clarifications may be made without separate notice; the "Last updated" date above always reflects the most recent revision.
12. Contact us
Kubera Wealth Management
9227 24th Ct SE Ste 9, Lacey, WA 98513
Thurston County, Washington
Privacy inquiries: privacy@tradefundlogistics.com
General support: support@tradefundlogistics.com