Legal
Privacy Policy
1. Who We Are; What This Policy Covers
EntryCert is a software platform operated by SideDrop LLC, a New York limited liability company located in Brooklyn, New York ("EntryCert," "we," "us," or "our"). This Privacy Policy explains how we handle information in two places:
- This website (entrycert.com) — for visitors and people who request a demo.
- The EntryCert service (the application at app.entrycert.com) — for customers, their team members, and the vendor users they invite.
Use of the service is also governed by our Terms of Service, which is the subscription agreement between EntryCert and each customer. Where this policy and the Terms address the same subject, the Terms control for customers.
2. This Website: What We Collect (and What We Deliberately Don't)
This website runs no analytics, no advertising tags, and no third-party scripts. We do not use Google Analytics, advertising pixels, remarketing, or cross-site tracking of any kind. We set no cookies of our own. Our hosting provider may set strictly-necessary cookies or process limited technical data (such as IP address and pages requested) to serve and protect the site.
If you submit the demo-request form, the details you type — typically your name, work email, company, and message — are sent to us as a single notification email through our email-delivery provider. The form submission is not stored in any database; the email in our inbox is the only copy. To keep the form from being abused, our form handler applies short-lived, in-memory rate limiting by IP address; those addresses are not logged or retained.
We use demo-request details only to reply and schedule your walkthrough — no mailing lists, no drip campaigns.
3. The Service: Account Information
Accounts are identified by work email address and display name. Sign-in uses one-time email links and codes — we never collect or store passwords. We keep standard operational records (sign-ins, invitations, and actions taken in the service) in an audit trail so customers can see who did what, and when.
4. The Service: Customer Content
Customers and their invited vendors put business records into the service: product catalogs, certificate data, shipment information, manufacturer details, and lab-report documents. This content belongs to the customer (see Terms §8). We process it only to provide the service — validating certificates, filing them with the CPSC Product Registry at the customer's direction, and producing broker handoff packets. Each vendor sees only its own products and submissions; vendors are isolated from one another, and this is enforced on our servers on every request.
5. AI Processing
When a lab report is analyzed, the document is sent to our AI provider (Anthropic) over an encrypted connection, and the analysis result comes back as suggestions a person confirms. Under our API arrangement with the provider, your documents are not used to train AI models. The lasting record of an analysis is the result saved in your account — your documents stay in your account's private storage, and we do not create a separate AI copy of them.
6. Service Providers (Sub-processors)
We use a small set of providers to run the service, each only for the purpose listed:
- Render — application hosting (United States).
- Supabase — database and private document storage (United States).
- Cloudflare — website hosting and delivery.
- Anthropic — AI analysis of lab reports (API; not used to train models).
- Alibaba Cloud DirectMail — transactional email delivery (sign-in links, notifications, and the demo-request form).
- Stripe — subscription billing. Payment details are entered on Stripe's systems; full card numbers never touch EntryCert.
- GitHub — encrypted backup storage and service automation.
We do not sell personal information, and we do not share customer content with anyone except as described here, at the customer's direction (for example, a filing to the CPSC or a packet link for a customs broker), or where required by law.
7. Filings Go to the Government — At Your Direction
The point of the service is to file Certificates of Compliance with the U.S. Consumer Product Safety Commission. When a customer approves a filing, the certificate data is transmitted to the CPSC Product Registry under the customer's own certifier account. Government handling of filed data is governed by the government's own rules, not this policy.
8. Retention, Backups, and Deletion
- Customer content is kept for as long as the customer's account is active.
- Nightly backups are encrypted (AES-256) before storage and retained for 30 days, after which they expire automatically.
- Customers can export their data at any time (Terms §8) and can request deletion at or after termination; deleted content leaves backups as those backups expire.
- Audit records and billing records may be retained longer where we have a legitimate business or legal need (for example, tax and dispute records).
9. Support Access
Our operators do not browse customer accounts. Support access to a customer account happens through a dedicated support-session mechanism that requires a fresh email confirmation, is visibly indicated in the interface while active, and is recorded in the audit trail — start and end.
10. Security
Data moves over encrypted connections (TLS) and is stored with access controls; documents live in private storage that only signed-in, authorized users can reach; backups are encrypted; and vendor isolation is enforced server-side. No method of transmission or storage is completely secure, but the service is built and operated to protect this data first. See the Security overview for the fuller picture.
11. Your Rights
Depending on where you live — for example, under the EU/UK GDPR or California's CCPA/CPRA — you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. Contact us at [email protected] and we will respond as the law requires. If you are a vendor user invited by a customer, note that the customer controls the account's content; we may refer your request to them where they are the responsible party.
12. International Visitors
We operate in the United States, and the service is provided from the United States. If you use the site or service from elsewhere — including vendor users signing in from outside the U.S. — your information is processed in the United States, where data-protection laws may differ from those in your country.
13. Children
The site and service are business tools and are not directed to children. We do not knowingly collect personal information from children.
14. Changes to This Policy
When we update this policy we will revise the "last updated" date above, and for material changes affecting customers we will give notice as the Terms provide.
15. Contact
Questions or requests about privacy: [email protected] — SideDrop LLC, Brooklyn, New York.