What we collect
- Exposure Checker submissions: the HTS codes and estimated annual customs value you enter, plus a hashed (SHA-256, one-way, not reversible) copy of your IP address for rate-limiting and abuse prevention. We do not store your raw IP address.
- Email address — if you request the full exposure report or a draft comment letter.
- Comment-letter requests: business name, optional business context (what you import, sourcing countries, why the BIS proposal concerns you — capped at 500 characters), and an authorization attestation (that you are an owner, officer, or authorized representative of the named business).
- Standard web analytics (page views, no cross-site tracking) via Vercel/Sentry for uptime and error monitoring.
Where it's sent / who processes it
- Supabase (US-region hosted database) — stores scans, email captures, and comment-letter requests.
- Resend — sends transactional emails (exposure report, comment-letter verification link, delivered letter PDF). Resend processes your email address and the email content only to deliver it.
- A Claude/Sonnet reasoning process (Anthropic) — drafts the text of your comment letter FROM the exposure data and business context you submit, after you've verified your email. Your business context is never used to train models and is passed with an explicit instruction that it is data, not instructions, to the drafting process (see our approach to prompt-injection defense — available on request).
- We do not sell your data. We do not share it with any other business, broker, or law firm without your explicit request (e.g. a referral you opt into).
Retention
- Exposure Checker scan data (HTS codes, value, hashed IP): retained 30 days, then deleted.
- Email opt-ins (email address, for the exposure report / comment-letter flow): retained indefinitely, or until you unsubscribe / request deletion, whichever is sooner.
- Comment-letter requests (business name, context, generated letter text): retained for our legal accountability record (in case a business needs to verify who requested a letter under its name) unless you request deletion, in which case we anonymize the business name/context and retain only the minimum needed to prevent abuse.
Your rights
You can unsubscribe from emails at any time via the link in every email we send. You can request an export or deletion of your data (GDPR data-subject access/erasure, CCPA right to know/delete) at /tariffwatch/account/delete or by emailing hello@citationsafe.com. California residents: TariffWatch does not sell personal information, so there is nothing to opt out of under CCPA's "Do Not Sell" provision — we're confirming that explicitly rather than making you ask.
Data breach notification
If we discover a security incident that affects your personal data, we will notify you without unreasonable delay. For users in the EU/UK, we will notify affected users within 72 hours of becoming aware of the breach in accordance with GDPR Art. 33 and, where applicable, the corresponding supervisory authority. For California residents, we will notify you in the most expedient time possible and without unreasonable delay in accordance with Cal. Civ. Code §1798.82. State-law notice requirements for other U.S. residents will be honored as applicable.
How we notify: primary channel is email to the address on file (email captures or comment-letter request). We may also post a public update on the TariffWatch landing page. What we will include: a description of the incident, categories and approximate number of records/users affected, likely consequences, and the mitigation and remediation steps we are taking. Breach concerns: hello@citationsafe.com.
v0 — attorney-review-pending. This breach-notification commitment is authored in-house and has not yet been reviewed by outside counsel; it is offered as a good-faith statement of practice and does not waive any statutory rights you may have.
Contact
Questions about this policy or a data request: hello@citationsafe.com.