Privacy Policy
Version 2026-08-05 · Last updated August 5, 2026
It is maintained in English; if a translation ever differs, the English version governs.
Jump to section
1. Overview
This policy explains what Trim — operated by SyncSanctuary (SYS, Business Registration No. 657-09-03349), Seoul, South Korea — collects, why, who processes it on our behalf, and the choices you have. Privacy questions: support@trimprocure.com.
A design principle worth stating up front: Trim never sees your card details (payments are handled entirely by our Merchant of Record), and our own logs automatically redact emails, card-like numbers, phone numbers, and secrets.
2. Data we collect
- Identity. Sign-in is handled by Firebase Authentication. Every visitor starts as an anonymous guest; you can link a Google or GitHub account or sign in with a one-time email code. Sign-in codes are 6 digits, stored only as a keyed hash (never in plain text), expire after 10 minutes, and are rate-limited. Your user record holds your role, email, locale, preferred currency, and created / last-seen timestamps.
- Audit inputs. The pricing details you enter (product, category, price, currency, billing model, seats, term, features, country) and, optionally, contract text you paste (sanitized and capped at 8,000 characters) and/or a pricing document you upload (PDF, PNG, JPEG, or WebP, up to 10 MB). We transcribe the document’s text and analyze the text; the file itself is stored privately in your own storage folder, auto-deleted within 24 hours, and deleted immediately when you delete the audit. Normalized USD figures are computed from your inputs and an observed exchange rate.
- Idea Validator inputs. The idea, problem statement, or prompt text you submit. We keep it for the life of your account, or until you delete the account — at which point it is removed or stripped of its link to you. We may study anonymized, aggregated patterns across submissions — never content tied back to your identity — to improve Trim.
- Messages. Deal-room messages with their sender and timestamps, stored as written (control characters and prompt-injection markers are stripped).
- Seller profile data. Company and contact details you enter; if you connect GitHub, public account signals (handle, repository / star / follower counts, account age, top languages, rolling-year contribution counts, organization memberships) — the OAuth token is used transiently and never stored. If you add a credential, we fetch the issuer’s public record for that badge (we send the issuer only the badge id, no personal data). Website ownership is verified through a DNS record only — we never request your site. Fields you self-report (LinkedIn, website, company, bio, X handle, years in business) are always labeled “self-reported”.
- Payment metadata. Order and subscription ids, SKU, amount and currency, and our payment provider’s customer id, which we use as an abuse-prevention fingerprint. Card data never reaches Trim.
3. How we use it
- To run the product: audits, Tools, auctions, deal rooms, seller tools, and the Idea Validator (performance of our contract with you).
- To manage billing state (Pro status, credits, commitment fees) mirrored from our payment provider (contractual necessity).
- To prevent abuse: for example, guarantee claims are limited per account per 90 days, and the payment-provider customer id helps us spot the same payer behind multiple accounts — a claim that matches another account’s fingerprint is flagged for human review, not auto-granted (our legitimate interest in keeping the marketplace trustworthy for everyone using it).
- To send transactional email only — sign-in codes and money-back-guarantee notices (contractual necessity). We do not send marketing email.
We do not sell personal data, and we do not share it with third parties for cross-context behavioral advertising.
4. What vendors can see
Trim is a marketplace, so we state precisely what the other side ever sees:
- Your price is never disclosed to vendors. The pricing details you enter, any contract text you paste or document you upload, and your audit results are available to you alone — no vendor-facing screen or API response includes them.
- Auctions are blind.A vendor browsing or bidding in your auction sees only the product category you are buying in, the pricing basis (a monthly / total-contract label — never an amount), and the deadline. Your maximum (reserve) price is compared against bids on our servers and its value is never disclosed to vendors; vendors also cannot see other vendors’ bids or identities, or how many bids exist.
- Your identity is revealed only by your own action. Auctions do not identify you to vendors. A vendor learns who you are only when you choose to open a conversation with them or select them as the winner; the vendor you select is also told which product the deal concerns.
5. AI processing
- Audit scoring uses Google’s Gemini models on Vertex AI. What the model receives: your sanitized audit fields and, if you provided one, your sanitized document text. If you upload a file, a dedicated model call first transcribes the document’s text verbatim; only that transcribed text — sanitized exactly like pasted text — feeds the analysis. The model is schema-constrained to reference verified benchmarks and produce qualitative wording — it structurally cannot author a number you see; all displayed figures are computed by our servers.
- The Idea Validator works the same way operationally: the idea you submit goes to Google’s Gemini models on Vertex AI, regionalized as described below, which researches publicly available sources — for example, public code repositories, community discussion, and public product or pricing listings — to generate a gap analysis. Your idea text is not itself posted to those third-party sites; only AI-generated search terms derived from it are used to query them. Those queries reach the retrieval providers we name in section 6 — a code-hosting search API, a web-search provider (through which community discussion, such as Reddit, is reached), a developer-news search index, and, where that integration is enabled, a product-listing API.
- AI processing is regionalized by your country: US region by default, an EU region for EU/UK buyers, a Japan region for Korea/Japan, and a Singapore region for Singapore.
- Contract-risk flags survive only if they quote your own document text verbatim. For Pro deliverables, the model never sees your raw price at all — numbers are inserted server-side from your already-computed audit.
- Chat is not AI-processed. Messages between buyers and sellers are not read, moderated, or answered by AI. Automated notices in a conversation are fixed, server-generated status lines about the deal — not a conversational AI.
- Seller and listing moderation is performed by our team — humans, not automated decision-making. Trust signals (GitHub, credentials, website) are shown as fetched, not AI-summarized.
- Training restriction. Google’s standard Vertex AI terms include a contractual “Training Restriction” (Service Specific Terms, Training Restriction section): Google does not use data submitted through Vertex AI — including audit inputs and Idea Validator submissions — to train or fine-tune its models, including Gemini, without our separate permission. This applies automatically to all Vertex AI usage; it isn’t something we had to individually negotiate.
- Automated decision-making. None of Trim’s AI processing makes a legal or similarly significant decision about you without a human involved: audit scores and Idea Validator output are advisory and qualitative, seller and listing moderation is done by our team, and — as above — the model cannot author a number you see. Because of this, Trim’s AI processing does not trigger GDPR Article 22’s rules on solely automated decisions, and doesn’t meet California’s definition of a “significant decision” under its automated-decision-making regulations (limited to decisions about financial or lending services, housing, education, employment, or healthcare). If you’d like an explanation of how a specific audit score or Idea Validator result was produced, contact us and we’ll walk you through it — including under South Korea’s PIPA, which as of a 2026 amendment gives you a right to request this.
- AI-generated content. Idea Validator results and the qualitative parts of an audit are presented within the product as AI-generated research and analysis — we describe them as such rather than as human-authored fact. South Korea’s AI Basic Act (in effect since January 2026) requires labeling AI-generated content — most squarely content that’s hard to distinguish from reality; advisory text like ours is a softer case, but we present it as AI-generated regardless.
6. Who processes it for us
We share data with the following providers, only for the purposes stated:
- Google Cloud / Firebase — authentication, database (hosted in the Seoul region, asia-northeast3), and file storage for listing media and uploaded pricing documents.
- Google Vertex AI — AI audit and Idea Validator processing, regionalized as described in section 5.
- Serper (google.serper.dev) — the web-search provider the Idea Validator queries for competing products and public discussion (including Reddit results, reached through a site-scoped search). It receives only AI-generated search terms, never your raw idea text.
- Hacker News search (hn.algolia.com, operated by Algolia) — a keyless public search index the Idea Validator queries for developer discussion.
- Product Hunt (api.producthunt.com) — queried by the Idea Validator for competing product listings, only when that integration is enabled for our account.
- Our third-party payment provider — Merchant of Record for web payments: hosted checkout, card processing, tax, and refunds to the original payment method. Trim does not receive or store card numbers.
- Resend — transactional email (sign-in codes, guarantee notices), sent from login@auth.trimprocure.com.
- Vercel — hosting for the web application.
- GitHub (api.github.com) — fetching public profile and contribution data when a seller connects their account for verification, and searching public repositories for the Idea Validator.
- Credly / Accredible — fetching the public record of a credential a seller submits (badge id only; no personal data is sent).
- Google Public DNS (dns.google) — resolving the DNS record used for a seller’s website-ownership verification.
If we add a new sub-processor, or materially change what an existing one can access, we’ll update this section and notify registered users before the change takes effect.
8. Logging
Server logs are structured and automatically redacted: email addresses, card-like number sequences, phone numbers, and secret-like values (tokens, keys, authorization headers) are masked before a log line is written, and log strings are length-capped.
9. Data security
Beyond what’s described elsewhere in this policy — hashed and rate-limited sign-in codes, automatic log redaction, per-user private file storage with automatic deletion, and OAuth tokens that are never stored — connections to Trim are encrypted in transit (TLS), data at rest is encrypted using our infrastructure providers’ standard disk-level encryption, and access to production data is limited to the people who need it to build or support the product. Separately, South Korea is phasing in a mandatory security certification (ISMS-P) for qualifying private-sector entities, effective July 2027; we’ll assess whether that applies to us well ahead of that date.
10. Deletion and retention
You can delete from your account settings:
- A single audit — deletes the audit, its deliverables, its auctions and bids, any uploaded file, and the conversations tied to it.
- Your entire account — cascades the above for every audit you own, removes your bids on other audits, deletes your seller profile, trust signals, and listings, deletes the conversations you are party to, and finally deletes your sign-in identity itself. Reviews you wrote on sellers’ listings keep their star rating but have the text blanked and the author link removed.
Outside of deletion, here’s how long we hold things by default: your account data for as long as your account is open; audit inputs, messages, and seller-profile data for the life of the account or until you delete the relevant item; uploaded pricing documents for at most 24 hours regardless (see section 2). Idea Validator submissions are kept for the life of your account, and are removed or unlinked from you when you delete it. When any of this is no longer needed for the purpose it was collected for, we delete it or pseudonymize it as described below.
Where data is deleted, electronic records are removed using methods designed to prevent recovery; any physical records we hold (we don’t expect to hold any in the ordinary course) would be destroyed by shredding.
Two honest qualifications, disclosed rather than hidden:
- Deletion can be temporarily blocked. If you have live money attached — an unresolved auction commitment fee, an agreed-but-unpaid deal, or unpaid seller charges — deletion returns an error until those are resolved through the normal flows. It is therefore not always instantaneous.
- Financial records are retained, pseudonymized. Billing ledgers (store credit, billable lead events, orders, subscriptions, guarantee claims, deal records) are kept with your account link stripped: amounts and the payment-provider fingerprint remain. Because that fingerprint could in principle be re-linked to you through our payment provider, we describe these records as pseudonymized rather than fully anonymized — under GDPR they may still count as personal data, and we treat them accordingly. We retain them to meet tax and legal obligations (e.g. GDPR Art. 17(3)(b), and Korean commercial and tax law, which generally requires accounting and supporting records to be kept for at least five years — some corporate books for longer) and to keep the 90-day guarantee-abuse control effective.
11. Data breach notification
If a personal data breach occurs that’s likely to put your rights or freedoms at risk, we will notify you and, where the law requires it, the relevant authority — without undue delay, and within whatever timeline applicable law sets. For the EEA/UK, that means notifying the relevant supervisory authority within 72 hours under GDPR. For South Korea, a 2026 PIPA amendment (effective September 11, 2026) moves the standard from “notify once a breach is confirmed” to “notify as soon as there is a reasonable likelihood of a breach” — we intend to meet that standard going forward, ahead of its effective date.
12. Your rights
Some rights are already self-serve, wherever you are:
- Access and correction — your profile fields are editable in the app; for anything else, write to us.
- Deletion — self-serve, as described in section 10.
- Export / portability — there is no automated export feature today; we handle export requests manually. Email support@trimprocure.com.
- Objection and complaints — contact us first at support@trimprocure.com; you may also complain to your local data-protection authority.
Depending on where you live, you may also have these additional rights:
European Economic Area, UK, and Switzerland. You can also ask us to restrict processing, receive your data in a portable format, object to processing based on our legitimate interests (including the abuse-prevention use described in section 3), and withdraw consent at any time for anything we process on that basis. You can complain to your local supervisory authority (the ICO, if you’re in the UK) directly — you don’t need to contact us first, though we’d welcome the chance to help.
California. Under the CCPA/CPRA, you have the right to know what we collect, delete it, correct it, and not be discriminated against for exercising any of these rights. We do not sell or share personal information as those terms are defined by California law, so there is nothing to opt out of. If your browser sends a Global Privacy Control signal, there’s accordingly nothing for it to apply — and we won’t override it. We don’t ask for special categories of data like race, health, or precise geolocation. Two things we do handle could fall within California’s definition of “sensitive personal information” — the contents of deal-room messages (where we’re the platform rather than the intended recipient) and your account log-in credentials — but we use them only to run the service you’ve asked for, never for the purposes that would trigger a right to limit their use, so there is nothing to limit. As noted in section 5, none of our AI features make a “significant decision” as defined by California’s automated-decision-making regulations, so that regime’s specific pre-use notice and opt-out rights don’t currently apply here.
Other U.S. states. If you live in a state with a comprehensive privacy law (for example, Virginia, Colorado, or Connecticut), you generally have similar rights to know, correct, delete, and opt out of sale, sharing, or targeted advertising — none of which we do. Contact us to exercise any of these.
South Korea. Under PIPA, you have the right to access, correct, delete, and suspend the processing of your personal data, and — as of a 2026 amendment — to demand an explanation or review of any decision made through a fully automated process. You can complain to the Personal Information Protection Commission (PIPC) or the Personal Information Dispute Mediation Committee at any time.
Japan. Under the APPI, you have the right to be told our purpose for using your data, to request disclosure, correction, or deletion, and to request that we stop using it. Contact us to exercise any of these.
Exercising any of these rights: write to support@trimprocure.com. We may ask for information to verify it’s really you before acting on a request, and we aim to respond within whatever timeline your local law sets (for example, one month under GDPR, 45 days under the CCPA) — we’ll tell you if we need longer.
13. Where data lives
Our primary database runs in Google Cloud’s Seoul region (asia-northeast3). AI processing is regionalized by buyer country (section 5). Other providers listed in section 6 may process data in their own regions.
Transfers from the EEA and UK to our Korean infrastructure don’t need any extra safeguard on top of that: the European Commission’s adequacy decision for the Republic of Korea (in force since December 2021) and the UK’s own, separate adequacy regulations for South Korea (in force since December 2022, and broader than the EU’s, since it also covers credit information) both already treat Korea as offering an adequate level of data protection.
Several other providers in section 6 are U.S.-based (Vercel, Resend, GitHub, Credly/Accredible), and Google itself processes some data in the U.S. by default outside the regionalized AI flow. There’s no general EU adequacy finding for the U.S. — for these, we rely on Standard Contractual Clauses in our agreements with each provider, and on the EU-U.S. Data Privacy Framework where a provider is certified under it. We’re deliberately not relying on the Data Privacy Framework alone: it’s currently valid, but it’s the subject of an ongoing legal challenge at the EU’s Court of Justice, and a separate, more recent challenge tied to a U.S. Supreme Court ruling on FTC independence — the same pattern that sank the two transfer mechanisms before it. Standard Contractual Clauses are the fallback if that happens again.
14. Children's privacy
Trim is a business tool for people sourcing or selling SaaS products. It is not directed to, and we do not knowingly collect personal data from, anyone under 18. If we learn that an account belongs to someone under 18, we will close it and delete the associated data.
15. Changes
We will update this policy as the product changes — for example, if analytics or new processors are ever added — and revise the date at the top.
16. Contact
Privacy contact: support@trimprocure.com. Trim is operated by SyncSanctuary (SYS), Business Registration No. 657-09-03349, based in Seoul, South Korea. Our registered postal address is available on request.
Chief Privacy Officer. Where South Korea’s PIPA requires a designated Chief Privacy Officer, ours can be reached at support@trimprocure.com. Based on the scale of our processing, we don’t currently meet the separate, narrower GDPR criteria that would require a Data Protection Officer, but EEA, UK, and Swiss inquiries are equally welcome at the same address.
EU and UK representatives. Because Trim is based in South Korea with no establishment in the EU or UK, yet offers its service to buyers there, GDPR Article 27 (and its UK GDPR equivalent) will in most cases require us to designate a representative located in the EU, and a separate one in the UK, as a local point of contact for data-protection matters. Once appointed, their names and addresses will be listed here.