Privacy and data handling

TariffCalc privacy policy.

Effective July 27, 2026 · Policy version 2026-07-27-commercial-legal

What this policy covers

This policy describes information handled by tariffcalc.com during the United States calculator beta. TariffCalc does not sell personal information and does not use calculator results to alter tariff rates.

Information we handle

  • Calculator inputs such as HTS code, origin, value, date, transport, entry type and fee assumptions.
  • Account information such as email address, name, password hash, verification state and workspace records when accounts are enabled.
  • User-requested saved calculations, products and correction reports.
  • Pilot application details such as work email, role, approximate import volume, markets of interest and the workflow you describe.
  • Support request details such as name, contact email, optional company, category, subject, message, internal priority, escalation reason, owner reference and closure evidence.
  • Commercial-interest details such as name, work email, optional company, organization type, plan interest, monthly volume band, requested capability categories, workflow need and internal next-action state. TariffCalc does not request or store payment information in the Release 1.0 acceptance candidate.
  • Calculation feedback such as usefulness, category, a short comment and a random calculation-flow reference.
  • Approved first-party product events such as calculator starts, completed or review-required outcomes, saves and account onboarding.
  • Security and operational information such as request identifiers, privacy-preserving network hashes, user-agent records, authentication attempts and application errors.

Passwords are stored as one-way password hashes. Verification, password-reset and customer-session tokens are stored as one-way hashes. Raw secrets are not written to application logs.

How information is used

  • Produce and, when requested, preserve tariff estimates.
  • Operate account authentication and private workspaces.
  • Prevent abuse, investigate errors and protect service integrity.
  • Answer correction, support, privacy, security and account requests and preserve operator ownership/closure evidence.
  • Evaluate whether a recurring workflow and proposed plan boundary has enough customer demand to justify a future paid launch and record a controlled next action.
  • Select and operate a small invitation-only pilot and understand whether participants return to the exact-code workflow.
  • Maintain an auditable record of data versions and material administrative actions.

Cookies and local storage

The beta uses only essential session cookies needed for security, administrator access and customer accounts. No advertising cookie, cross-site tracking pixel or behavioral advertising system is included in this release.

Pilot analytics are server-side and first-party. The approved event records do not contain an IP address, user agent, browser fingerprint, analytics cookie or raw email address. A random flow identifier may connect the steps of one calculator journey, while authenticated account events may use the internal user ID to measure return use.

Retention and deletion

Unsaved calculator inputs are processed to return a result and are not inserted into the calculation database. User-requested snapshots and active account/workspace records are retained while needed to provide the service, preserve integrity, resolve disputes or meet applicable obligations. Expired security tokens may be removed during maintenance.

Default operational windows are 90 days for raw pilot product events, 365 days for unconverted or finalized pilot applications, 365 days for resolved pilot feedback, 365 days for resolved support requests, 365 days for finalized commercial-interest requests, 180 days for delivery evidence and 730 days for completed account-data request records. Keyed support/commercial rate-limit attempt evidence is removed after two days when the protected cleanup is applied. A specific record may be retained longer for an open request, security investigation, dispute, legal hold or other applicable obligation. Finalized support/commercial records are eligible for cleanup only after their resolution/update boundary, not merely because the original request is old.

An authenticated account holder can immediately export saved calculation history and can submit an audited full-export, correction or deletion request through Account Data Controls. Deletion requests require password reauthentication, the exact confirmation phrase and a default seven-day cooling-off period. They do not cause immediate automatic deletion. An operator verifies scope, workspace ownership and retention duties before any destructive execution. Some deidentified, integrity, security, financial or legal records may remain after closure. Privacy questions may also be sent to support@tariffcalc.com.

Service providers and official sources

Hosting, email and security providers may process the minimum information needed to operate their service. When transactional email is enabled, the configured provider receives the recipient address and message needed to deliver verification, reset or invitation email. Email open and link tracking are disabled in the supplied Postmark integration. Official tariff sources linked from TariffCalc are operated by third parties and have their own privacy practices.

Contact and policy changes

Privacy or security-handling questions may be sent to support@tariffcalc.com. Do not send passwords, private keys, payment data or unrelated customer records. A material policy change will receive a new version and effective date.