Privacy Policy
1. Who we are and scope
TradeBridge (the “Platform”) is an e-commerce service that facilitates access to eligible order opportunities and related operational workflows. This Privacy Policy explains how personal data is processed when you register, subscribe, fund Orders, complete identity verification, or contact support.
Registered controller/legal-entity details appear only when configured by the operator. Current trade name: TradeBridge.
Privacy and support contact: support@tradebridge-tb.com. Website: https://tradebridge-tb.com. Or use Contact Us (/contact).
Read this Policy together with the Terms and Conditions (/terms) and the Cookie Policy (/cookies).
2. Data we collect
Account data: email, username, first and last name, phone number, country, language preference (preferred locale), avatar if uploaded, and related profile fields shown in the product.
Authentication data: password (stored using one-way secure hashing — not recoverable as plaintext), session records, and refresh/authentication cookies needed to keep you signed in.
Subscription and Order data: plan and entitlement status, Order interactions (reservation, acceptance, funding, status), settlement-related states, and timestamps.
Wallet and financial metadata: deposit and withdrawal records, amounts, currencies, statuses, fee records, invoice/receipt references, and ledger entries shown in Wallet / Invoice Center.
Payment-provider metadata: payment status, provider references (for example Checkout/PaymentIntent identifiers where card checkout is used), amounts, and confirmation results returned by enabled providers. TradeBridge does not receive or store full card PAN/CVV from hosted card Checkout on its own servers.
Saved payout methods: if you add a withdrawal method, we may store the payout details you submit (for example bank account details, crypto address/network/asset, and/or card payout fields you enter for withdrawals). Treat payout credentials as sensitive.
Crypto deposit data (when enabled): network, deposit address shown to you, transaction hash, amounts, confirmation/attestation status, and related verification metadata. Blockchain records may also be publicly visible on the relevant network.
Deposit proof files: receipt images/files you upload for review. Uploading proof is evidence for review and does not itself credit your wallet.
KYC data (when submitted): identity details (such as name, date of birth, document country/type), government ID images, selfie image, proof-of-address file where requested, consent/review metadata, and status. A selfie/image used for visual review is not described here as biometric processing unless a specialized biometric identification system is enabled (it is not the current default).
Support and contact data: Contact Us messages (name, email, category, message, optional order reference), support-ticket/complaint fields (category, subject, body, optional reference, status), and live-support messages after a human session is opened. Automated support-bot turns are processed to answer questions and are not stored as permanent chat history unless the conversation is escalated to human support.
Notifications: event/type, title/body or structured template data, read/unread state, and timestamps.
Technical and security data: IP addresses associated with signup/login where recorded, device/browser information when captured (for example on certain inquiry forms), session identifiers, and security/diagnostic logs needed to operate and protect the Platform.
Cookies and local storage: described in Section 12 and in the Cookie Policy (/cookies).
3. How we collect data
Directly from you (registration, profile, KYC, deposits, payout methods, Contact Us, support).
Automatically through the Platform (session cookies, security logs, Order/wallet event records).
From payment, crypto-verification, email, or hosting providers when they return status/references needed to run the service.
4. How we use data
We process personal data to: provide and secure accounts; activate subscriptions; display and process eligible Orders; process deposits, order funding, fees, settlement, and withdrawals; verify identity for withdrawal eligibility and fraud prevention; create invoices/receipts; deliver transactional notifications and email; provide support; protect the Platform; and meet legal or payment-provider requirements.
We do not operate a separate marketing email/SMS advertising program in the current product. Service/transactional notices are used to operate your account.
Processing is based on what is necessary to provide the service you request, security and fraud prevention, legal/provider obligations, and — where required — consent for optional activities (for example non-essential cookies if introduced later).
5. Account and authentication
Passwords are stored using one-way secure hashing. Staff cannot read your password.
Sessions use authentication tokens. A refresh token may be stored in an HttpOnly cookie. Access tokens are used to authorize API requests while you are signed in.
Password reset and phone-change verification may use time-limited tokens or one-time codes. Do not share passwords, OTPs, or private wallet keys with anyone claiming to be support.
6. Subscriptions and Orders
We process subscription plan, activation/expiry, and status so the Platform can apply access entitlements.
We process Order activity (including reservation, acceptance, funding, fulfillment confirmations shown in-product, and settlement state) to deliver the service described in the Terms. Subscription and Order funding are service/operations data — not investment account data.
7. Payments and deposits
Where card Checkout is enabled, card entry is handled by the hosted payment provider (currently Stripe Checkout when enabled). TradeBridge stores provider payment references and status needed for accounting and customer records — not full PAN/CVV captured in Checkout.
Deposit records include amount, status, method, and provider/on-chain references. Deposit proof uploads are stored for authorized review workflows and do not alone create wallet credit.
8. Crypto data
If crypto deposits are enabled, we process network, address, transaction hash, amount, and confirmation metadata to verify funding. On-chain data may be public on the blockchain. Crypto rails on TradeBridge are deposit/funding mechanisms — not a crypto investment product.
9. KYC and identity verification
Under current Platform configuration, KYC is generally required before withdrawals (and may be required for other risk-sensitive actions if configuration changes). KYC is not required for ordinary deposits/top-ups under the current default.
We use KYC data for identity verification, fraud prevention, withdrawal eligibility, and legal/provider compliance. KYC approval does not by itself confirm a deposit payment.
10. Proof files and private documents
KYC files, deposit proofs, and similar uploads are intended to be private. Access is limited to the owning customer workflows and authorized staff/system processes for review, support, and compliance. We do not publish storage paths or bucket internals to customers.
We do not claim end-to-end encryption of every uploaded file unless a specific product feature states that.
11. Withdrawals, settlement, shipping workflow, and invoices
Withdrawal requests process destination details you provide, amounts, status, and related review metadata.
Where the Order workflow includes a shipping/fulfillment step, the Platform may process shipping-fee status, confirmation timestamps, and fulfillment-related display data (for example tracking presentation shown in-product). TradeBridge is not itself a parcel courier. Customer file upload of “shipping proof” images is not a separate general-purpose public upload feature in the current product beyond the Order workflow fields that actually exist.
Settlement and Invoice Center records may cover categories such as deposits, order payments, shipping-related charges, settlements, withdrawals, and deposit proofs, as enabled in the product.
12. Cookies, sessions, and local storage
Essential cookies/technologies currently used include: authentication refresh cookie (`refreshToken`); locale cookie (`mb-locale`); device/security cookie (`mb_did`); support live-session cookie (`mb_cs_session`) when chat is used; short-lived document access cookie (`tb_doc_access`) for secured PDF viewing; and local preference flags such as cookie-consent acknowledgment (`mb_cookie_consent`) and non-secret auth session hints.
These are required for login, language, security, support, or document access where applicable. Blocking essential cookies may break sign-in or secured document viewing.
The Platform does not currently use third-party advertising or analytics pixels (such as Google Analytics/GTM/Mixpanel). Additional cookie categories, if introduced later, will be described in the Cookie Policy (/cookies).
13. Device and security logs
We may process IP addresses and related security/diagnostic logs to protect accounts, prevent abuse, and diagnose service issues. No online service can guarantee absolute security.
TradeBridge may process a technical device identifier to help protect accounts and the Platform, reduce abuse and unauthorized automated activity, and support security controls. The current implementation does not use this identifier for advertising or marketing tracking.
14. Support, complaints, and contact
Contact Us submissions may be emailed to the support inbox and recorded in operational logs for handling.
Support tickets/complaints store category, subject, message, optional reference, status, and timestamps associated with your account.
Support bot messages are processed to answer questions and may use limited account-aware read-only context. The bot should not ask for passwords, OTPs, or private keys. Bot-only chats are not kept as permanent server transcripts unless escalated to human support, after which messages may be stored in the support session.
15. Sharing with service providers
We share data with processors only as needed to run the Platform, including: payment providers enabled in the product; email/SMTP delivery; hosting, database, cache, and file storage; crypto/on-chain verification infrastructure where crypto deposits are enabled; and professional advisers when required.
We name specific vendors in customer notices only when they are actually enabled for your transaction path. Provider privacy notices also apply to data they process.
16. Marketplaces and third parties
Order opportunities may relate to third-party marketplaces or brands. Display of an opportunity does not mean TradeBridge is an official partner of those brands. We share customer data with marketplaces only if an operational workflow actually requires it — not as a general data sale.
17. Staff access
Authorized TradeBridge personnel may access customer data when required for support, KYC review, complaints, fraud/security, invoicing, or operational fulfillment, according to role permissions. Access is not unrestricted for all staff.
18. Legal disclosure
We may disclose data when required by law, court order, regulator, payment-provider rules, or to investigate fraud/security incidents, subject to applicable law.
19. International processing
Depending on hosting and vendor configuration, data may be processed in countries other than your country of residence (for example where cloud storage or payment providers operate). We do not invent specific transfer mechanisms (such as SCCs) in this Policy unless separately documented by the operator.
20. Retention
We retain personal data as long as necessary to provide the service and for legitimate legal, accounting, dispute, security, and fraud-prevention purposes.
KYC document retention is subject to Platform configuration (default target approximately 180 days after a final decision) unless law or disputes require longer. Exact deletion timing can depend on operator configuration and legal holds. A full multi-category retention schedule is not published as a separate automated public timetable.
There is currently no fully self-service account-deletion button for customers. You may request account closure or data deletion via support@tradebridge-tb.com or Contact Us; some records may be retained where law or fraud/accounting duties require.
21. Security
We use reasonable technical and organizational measures appropriate to the Platform, including HTTPS transport, access controls for sensitive records, and one-way password hashing. No method of transmission or storage is 100% secure, and we do not claim PCI DSS certification or “unhackable” systems in this Policy.
22. Your rights and choices
According to applicable law, you may request access, correction, deletion, restriction, or objection to certain processing, and you may lodge a complaint with a competent authority where available. Contact us using the privacy/support contact in Section 1. We may need to verify your identity.
You can update many profile fields in-product. KYC or payout details may require review before changes take effect.
Cookie controls: see Section 12 and /cookies. Essential cookies cannot be disabled if you want full authenticated use.
23. Children and eligibility
The Platform is not directed to anyone under 18. We do not knowingly collect personal data from children under that age. Eligibility also follows the Terms and Conditions.
24. Updates
We may update this Privacy Policy. The version and last-updated date appear on this page. Material changes may be communicated through in-product notices or email where appropriate.
25. Contact us
Privacy and support contact: support@tradebridge-tb.com. Website: https://tradebridge-tb.com. Or use Contact Us (/contact).