Trupari

Privacy Policy

Effective: 2026-09-25 · Version 2026-09-25+ee142f5c · Trupari Rate Competitiveness

This Privacy Policy explains how we collect, use, share, and protect personal information when you use Trupari. It is written to satisfy our obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), and the Australian Privacy Principles (APPs).

1. Who we are

Trupari is operated by Can Unlimited (ABN 42813703398), a sole-trader business registered in Victoria, Australia, trading as "Trupari". Our registered business address is held on the Australian Business Register and is available on request to the contact below. We are the data controller for personal data described in this Policy.

Privacy questions or data-rights requests: [email protected]. We have not appointed a separate Data Protection Officer; the privacy mailbox is monitored by the business operator.

2. What we collect

3. Legal basis (GDPR / UK GDPR)

PurposeLegal basis
Providing the service you signed up forContract (Art. 6(1)(b))
Billing and tax recordsContract + Legal obligation (Art. 6(1)(b), 6(1)(c))
Rate-limiting, abuse detection, securityLegitimate interests (Art. 6(1)(f))
Transactional emails (welcome, password reset, payment receipt, trial expired)Contract (Art. 6(1)(b))
Product improvement using aggregated/de-identified dataLegitimate interests (Art. 6(1)(f))
Optional marketing communicationsConsent (Art. 6(1)(a)) - you can opt out at any time

4. How we use it

5. What we never do

6. Who we share it with

We use the following sub-processors. Each of them processes data on our instructions under a written data-processing or equivalent contract, with appropriate safeguards for international transfers. Google Fonts is the one exception and is listed for completeness rather than as a processor: your browser requests those files directly from Google, so no data of ours is passed to them and no such contract applies. The row below sets out exactly what that request discloses.

Sub-processorPurposeLocation
Google Cloud (Cloud Run, Cloud Logging, Secret Manager)Application hosting, operational logs, secret storageAustralia (australia-southeast1)
Firebase Hosting (Google)Static website deliveryGlobal CDN
SupabaseManaged Postgres databaseAWS region as configured at account level
CloudflareCDN, DDoS protection, WAF, DNSGlobal edge
Paddle.com Market LimitedBilling and payments as Merchant of RecordUK / Ireland / global per Paddle
Google (Gemini API)Generating plain-English benchmark summaries from corridor numericsPer Google AI region policy
LoopsTransactional email deliveryUSA
FormspreeDelivery of messages you send us through the in-app contact formUSA
Google FontsWeb fonts on our public pages. Your browser requests these directly from fonts.googleapis.com and fonts.gstatic.com, which discloses your IP address and browser user-agent to Google. No account data is involved, and no cookie is set by these requests.Global CDN

We are working to serve these font files from our own domain, which would remove the request to Google entirely. Until then it is listed above so the disclosure matches what your browser actually does.

If we add a new sub-processor, we will update this list at least 14 days before the change takes effect. You can object to a new sub-processor at [email protected]; if we cannot accommodate the objection, you may cancel your subscription and receive a prorated refund for any unused prepaid term.

7. International data transfers

Trupari is operated from Australia. Sub-processors may store or process data in the EU, the United Kingdom, the United States, or elsewhere. Where personal data of EU / UK residents is transferred outside the EEA / UK, we rely on:

8. Retention

Account, product, and operational data is retained while your account is active and for 30 days after cancellation to allow reactivation. Billing records are retained for 7 years. The ATO requires most business records to be kept for at least five years from the later of when the record was made and when the transaction was completed; we keep billing records longer than that minimum so they still exist through any amendment period or dispute about a payment. Audit-log entries are retained for 2 years. You may request earlier deletion by email; we will action it unless we are legally required to retain the data. When an account is deleted — by you or by the automatic sweep — billing records are stripped of everything that identifies you (your account link and the raw payment-provider payload) and only the transaction skeleton is kept for the remainder of that period.

Consensus Engine uploads: files you upload are streamed to a temporary file on the server's ephemeral, in-memory filesystem, parsed, and deleted as soon as the run finishes — whether it succeeded or failed. Nothing is written to our database or to any persistent storage, and uploads are never sent to any large language model. The temporary file exists only inside the container handling your request; when that container stops, its filesystem goes with it. If you leave or refresh the page, you will need to upload the files again.

Free rate check limits: to apply the daily fair-use limits on the free rate check, we keep a count of checks against a one-way hash of your network address and of the random identifier described in Section 9. The hash is made with a secret key and is different every day. We never store the address, the identifier or anything you entered, and each day's counts are deleted the following day.

9. Cookies and similar technologies

We use a small number of cookies and equivalents:

We do not use advertising or cross-site tracking cookies. Because all cookies in current use are strictly necessary or first-party analytics, no consent banner is presented; however, you may block cookies in your browser at any time. Doing so may break login.

10. Your rights

Depending on where you live, you may have the following rights. We honour all of them for all users regardless of geography to keep things simple.

Email [email protected] from the address on your account. We will respond within 30 days (or sooner where required by applicable law).

11. Marketing communications

Transactional emails (welcome, password reset, payment receipt, trial expired) are not marketing and cannot be turned off while your account is active. Any future marketing emails will be opt-in only, and every marketing email will contain a one-click unsubscribe link.

12. Security

No system is perfectly secure. If you discover a vulnerability, please email [email protected].

13. Children

Trupari is a B2B product and is not directed to children. We do not knowingly collect data from anyone under 18 years old. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

14. Complaints

We would appreciate the chance to address your concern first; please email [email protected] before escalating.

15. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified by email at least 14 days before they take effect. The "Effective" date and the version identifier at the top identify this exact wording: the version contains a hash of the document text, so it necessarily changes whenever the text does. The version recorded against your account at sign-up is the one you accepted.

16. Contact

Privacy and data requests: [email protected].