Last updated: April 2026
Your privacy matters to us. This Privacy Policy explains what data ImportPilot collects, how we use it, who we share it with, and the rights you have over it. We've written this in plain language. If anything is unclear, email us at support@importpilot.io.
1. What We Collect
We collect only the data we need to run the Service and improve it:
- Account data: email address, password hash (never plain text), full name (optional), and company name (optional).
- Product data: product names, descriptions, HTS codes, countries of origin, suppliers, and any notes you save.
- Search history: HTS lookups and AI classification queries you run, so we can show your history and enforce plan limits.
- Shipment data: any shipment details you enter (values, freight mode, ports, dates) to calculate landed cost.
- Billing metadata: Stripe customer ID, subscription ID, and current plan. We never see or store your card number — Stripe handles payment data directly.
- Technical data: IP address, browser user agent, and basic request logs for security and debugging. Retained up to 30 days.
- Analytics: page views and navigation events via Vercel Analytics. Vercel Analytics is cookieless and does not track individuals across sites.
2. How We Use Your Data
- To provide the Service — authenticate you, run lookups, calculate landed cost, save products.
- To send rate change alerts you've subscribed to, via Resend (our email provider).
- To enforce plan limits (lookups per month, classifications per month, saved product count).
- To improve AI classification accuracy in aggregate — we may analyze patterns of what codes verify correctly, never individual queries tied to you.
- To detect abuse, prevent fraud, and keep the Service secure.
- To communicate service updates, billing notices, and policy changes.
3. What We Don't Do
- We do not sell your data to third parties. Not now, not ever.
- We do not share your individual product catalog, classifications, or shipment data with advertisers, data brokers, or any third party except as listed in Section 4.
- We do not use your data to train foundation models. When we call Claude for AI classification, Anthropic's API terms apply (no training on API inputs by default).
4. Service Providers We Use
We rely on a small number of vetted providers to run ImportPilot. Each receives only what they need:
- Supabase — authentication and database. Stores your account, products, and search history.
- Stripe — subscription billing. Receives your email and billing details when you subscribe. See Stripe's privacy policy.
- Anthropic — powers AI classification. Receives the product description and origin country you submit. Does not train on API inputs per Anthropic's terms.
- Resend — sends rate change alert emails. Receives your email address and message content.
- Vercel — hosting and cookieless analytics.
5. Cookies and Tracking
We use strictly necessary cookies to keep you signed in and to protect your session. We do not use advertising cookies or third-party trackers. Our analytics (Vercel Analytics) is cookieless and does not identify individual visitors.
6. Data Retention
- Account data, products, and search history are kept until you delete them or close your account.
- When you close your account, we delete your personal data within 30 days, except where we're required to retain records (e.g., billing invoices for tax compliance — typically 7 years).
- Server logs are retained up to 30 days.
- Deleted products and shipments are purged within 30 days; backups containing deleted records expire within 90 days.
7. Your Rights
You can, at any time:
- Access the data we hold about you — most of it is visible in-app; request the rest by email.
- Export your products, classifications, and shipments as a JSON or CSV file. Email us to request an export.
- Correct inaccurate information — editable in-app, or email us.
- Delete your account and associated data. Email us at support@importpilot.io and we'll process deletion within 30 days.
- Object to certain processing, or withdraw consent for marketing communications (you'll still receive service-critical emails).
These rights apply to all users regardless of where you live. If you're in the EU, UK, or California, you may have additional rights under GDPR, UK GDPR, or CCPA — we honor them worldwide.
8. Security
We use industry-standard safeguards: TLS in transit, encrypted storage at rest, hashed passwords, scoped access tokens, and row-level security in our database so each user can only read their own records. No system is perfectly secure, but we work hard to keep your data safe and will notify affected users without undue delay if a breach occurs.
9. Children's Privacy
ImportPilot is not intended for children under 18. We do not knowingly collect data from children. If you believe a child has given us data, email us and we'll delete it.
10. International Data Transfers
ImportPilot is hosted in the United States. If you use the Service from outside the U.S., your data will be transferred to and processed in the U.S. By using the Service, you consent to this transfer.
11. Changes to This Policy
If we make material changes to this policy, we'll notify you by email or in-app notice at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the current version.
12. Contact
Questions, requests, or concerns? Email support@importpilot.io. We respond within 5 business days.