This Privacy Policy explains how we collect, use, share, and protect personal information when you use Trupari. It is written to satisfy our obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), and the Australian Privacy Principles (APPs).
Trupari is operated by Can Unlimited (ABN 42813703398), a sole-trader business registered in Victoria, Australia, trading as "Trupari". Our registered business address is held on the Australian Business Register and is available on request to the contact below. We are the data controller for personal data described in this Policy.
Privacy questions or data-rights requests: [email protected]. We have not appointed a separate Data Protection Officer; the privacy mailbox is monitored by the business operator.
| Purpose | Legal basis |
|---|---|
| Providing the service you signed up for | Contract (Art. 6(1)(b)) |
| Billing and tax records | Contract + Legal obligation (Art. 6(1)(b), 6(1)(c)) |
| Rate-limiting, abuse detection, security | Legitimate interests (Art. 6(1)(f)) |
| Transactional emails (welcome, password reset, payment receipt, trial expired) | Contract (Art. 6(1)(b)) |
| Product improvement using aggregated/de-identified data | Legitimate interests (Art. 6(1)(f)) |
| Optional marketing communications | Consent (Art. 6(1)(a)) - you can opt out at any time |
We use the following sub-processors. Each of them processes data on our instructions under a written data-processing or equivalent contract, with appropriate safeguards for international transfers. Google Fonts is the one exception and is listed for completeness rather than as a processor: your browser requests those files directly from Google, so no data of ours is passed to them and no such contract applies. The row below sets out exactly what that request discloses.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud (Cloud Run, Cloud Logging, Secret Manager) | Application hosting, operational logs, secret storage | Australia (australia-southeast1) |
| Firebase Hosting (Google) | Static website delivery | Global CDN |
| Supabase | Managed Postgres database | AWS region as configured at account level |
| Cloudflare | CDN, DDoS protection, WAF, DNS | Global edge |
| Paddle.com Market Limited | Billing and payments as Merchant of Record | UK / Ireland / global per Paddle |
| Google (Gemini API) | Generating plain-English benchmark summaries from corridor numerics | Per Google AI region policy |
| Loops | Transactional email delivery | USA |
| Formspree | Delivery of messages you send us through the in-app contact form | USA |
| Google Fonts | Web fonts on our public pages. Your browser requests these directly from fonts.googleapis.com and fonts.gstatic.com, which discloses your IP address and browser user-agent to Google. No account data is involved, and no cookie is set by these requests. | Global CDN |
We are working to serve these font files from our own domain, which would remove the request to Google entirely. Until then it is listed above so the disclosure matches what your browser actually does.
If we add a new sub-processor, we will update this list at least 14 days before the change takes effect. You can object to a new sub-processor at [email protected]; if we cannot accommodate the objection, you may cancel your subscription and receive a prorated refund for any unused prepaid term.
Trupari is operated from Australia. Sub-processors may store or process data in the EU, the United Kingdom, the United States, or elsewhere. Where personal data of EU / UK residents is transferred outside the EEA / UK, we rely on:
Account, product, and operational data is retained while your account is active and for 30 days after cancellation to allow reactivation. Billing records are retained for 7 years. The ATO requires most business records to be kept for at least five years from the later of when the record was made and when the transaction was completed; we keep billing records longer than that minimum so they still exist through any amendment period or dispute about a payment. Audit-log entries are retained for 2 years. You may request earlier deletion by email; we will action it unless we are legally required to retain the data. When an account is deleted — by you or by the automatic sweep — billing records are stripped of everything that identifies you (your account link and the raw payment-provider payload) and only the transaction skeleton is kept for the remainder of that period.
Consensus Engine uploads: files you upload are streamed to a temporary file on the server's ephemeral, in-memory filesystem, parsed, and deleted as soon as the run finishes — whether it succeeded or failed. Nothing is written to our database or to any persistent storage, and uploads are never sent to any large language model. The temporary file exists only inside the container handling your request; when that container stops, its filesystem goes with it. If you leave or refresh the page, you will need to upload the files again.
Free rate check limits: to apply the daily fair-use limits on the free rate check, we keep a count of checks against a one-way hash of your network address and of the random identifier described in Section 9. The hash is made with a secret key and is different every day. We never store the address, the identifier or anything you entered, and each day's counts are deleted the following day.
We use a small number of cookies and equivalents:
trupari_api_key and trupari_saved_email
in localStorage (not cookies, but equivalent local data). They
store your session and remember your last-used email. Without
them you cannot log in.trupari_insight_cache_v1 caches the plain-English
summaries described in Section 5, together with the benchmark
figures that produced them — your rate, the mid-market rate,
any competitor you named and their rate, and the resulting verdict.
It exists so that reloading the dashboard does not re-run the
summary. Entries expire after 24 hours and are deleted when they
expire. We clear this cache when you sign out, and clear
every item listed here when you delete your account.
trupari.freeRateDemo.used.v1 is a single true/false flag
that earlier versions of the landing page set after a free rate check;
it contains no rates and no personal data, is no longer used, and is
deleted the next time you open the home page.
trupari.freeCheck.visitor.v1 is a random identifier the
free rate check sends with each check, so that its daily fair-use
limit applies to you rather than to everyone sharing your connection.
It is replaced with a new one every day and holds nothing about you.
trupari.planIntent.v1 is kept in session storage, for the
current tab only: it remembers the plan you chose on one of our product
pages while you sign in, and is removed when you close the plan window
or the tab.__cf_bm and cf_clearance are set by
Cloudflare for bot-management and threat-mitigation. We cannot
disable these while keeping our DDoS / WAF protection active.We do not use advertising or cross-site tracking cookies. Because all cookies in current use are strictly necessary or first-party analytics, no consent banner is presented; however, you may block cookies in your browser at any time. Doing so may break login.
Depending on where you live, you may have the following rights. We honour all of them for all users regardless of geography to keep things simple.
Email [email protected] from the address on your account. We will respond within 30 days (or sooner where required by applicable law).
Transactional emails (welcome, password reset, payment receipt, trial expired) are not marketing and cannot be turned off while your account is active. Any future marketing emails will be opt-in only, and every marketing email will contain a one-click unsubscribe link.
No system is perfectly secure. If you discover a vulnerability, please email [email protected].
Trupari is a B2B product and is not directed to children. We do not knowingly collect data from anyone under 18 years old. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
We would appreciate the chance to address your concern first; please email [email protected] before escalating.
We may update this Policy from time to time. Material changes will be notified by email at least 14 days before they take effect. The "Effective" date and the version identifier at the top identify this exact wording: the version contains a hash of the document text, so it necessarily changes whenever the text does. The version recorded against your account at sign-up is the one you accepted.
Privacy and data requests: [email protected].