Privacy
Privacy notice
Last updated August 25, 2026
What TradeTable collects
TradeTable stores account identifiers and email verification state, public profile information, deal terms and item details, deal status, feedback, and technical security logs. Invitation email addresses, private notes, invite tokens, and uploaded evidence photos are treated as private deal data.
What can become public
Public profiles may show a handle and transaction-backed reputation. Under the current completed-deal policy, both participants accept that successful completion automatically creates a privacy-safe record showing participant handles, the items exchanged, an agreed cash amount when applicable, the completion date and status, and structured feedback.
Public responses do not include account email addresses, invitation tokens, private notes, addresses, payment identifiers, or private evidence photos.
How information is used
Information is used to operate and improve the agreement workflow, protect accounts, enforce access boundaries, create transaction-backed records, and investigate reports. TradeTable does not sell personal information or use it for targeted advertising.
Optional public-page analytics
TradeTable uses Google Analytics only after you choose Allow analytics, and only on public service pages such as the homepage, privacy notice, terms, and contact page. The only event TradeTable authors is a manual page view with a fixed page name and canonical URL without query strings, fragments, or referrers. Google Analytics may derive session and engagement measurements from those permitted visits. TradeTable does not send account identifiers, email addresses, user IDs, deal or invite identifiers, private routes, public-profile or completed-record paths, private notes, evidence, or advertising data.
Your choice is stored in this browser and can be changed through the Analytics choices control. Global Privacy Control and browser Do Not Track signals keep analytics off. Google Analytics is configured without advertising personalization or Google signals. When allowed, its browser identifier expires after 90 days and is not extended by later activity.
Account signup and credentials
Email-and-password signup, sign-in, and recovery are handled directly by Supabase Auth. TradeTable does not store your password. If CAPTCHA protection is enabled for this environment, Cloudflare Turnstile processes the anti-bot check before signup.
Service providers and requests
Cloudflare provides the website edge and security layer. Supabase provides authentication, database, private storage, and server functions. Resend supports account email delivery. For an access, correction, or deletion request, email [email protected]. Completed records may need to retain limited facts to preserve the integrity of both participants’ transaction history.