TrustConnect Network

Effective 24 August 2026

Privacy

This policy describes what TrustConnect Network collects when you apply for membership or use the member area, why we hold it, who else processes it on our behalf, and how long it is kept. It is published in English; that version is the authoritative one.

Who this is from

TrustConnect Network operates this network and decides how the data described below is used. Questions about this policy, or a request about your own data, go to privacy@trustconnectnetwork.com.

What we collect

What you put in an application. The firm’s registered name, entity type, registration and tax identifiers, date of incorporation, registered and operational addresses; for each director or key contact, their name, identity numbers, phone and email; financial details including turnover, bank name and account details; and how you trade — countries, volumes, frequency, Incoterms, services, lanes, website and trade references. Some of those are named rather than left inside a category, because they are the most sensitive records here: for an Indian applicant the identity numbers include each director’s PAN and the last four digits of their Aadhaar number, and the financial details include the bank account number in full; for an overseas applicant, each director’s passport number. They are collected because a member is admitted on the strength of them, and because the documents uploaded against them have to be checked for a match.

What we do not keep. A full Aadhaar number. The form asks for the last four digits and nothing more, so the whole number never reaches us as data — it appears only on the Aadhaar document you upload, where our screening team reads it to check the match, and it is that document’s own retention that governs it. If you applied before 27 August 2026 the full number was collected, and it is deleted from your record the next time that record is saved.

Documents you upload. Registration certificates, tax filings, bank statements and identity documents for the people named in the application.

Your account. Your email address and a hash of your password — never the password itself — and a record of each sign-in session.

A record of what happens. An append-only log of actions that change something: an application submitted, a member admitted or disabled, a password reset, a sign-in that failed. Each entry records the action, who took it and when.

Technical data. Requests to this site are logged with a request identifier and timing. If analytics is enabled, the pages visited and product events described below.

Why we hold it

To screen an applicant before admitting them, which is what the network is for; to run the membership — the directory, the member area, the emails an application generates; to keep the service secure and to investigate misuse; and to meet obligations that apply to us, including keeping a record of decisions we have taken.

Who else processes it

We use a small number of service providers, each for one job and none of them to build a profile of you:

  • A hosting provider, which runs this application and keeps its request logs.
  • A managed database, which is where the records described above are stored.
  • An object storage provider, which holds the documents you upload.
  • An email delivery provider, which sends the messages an application produces, such as a link back to a part-finished one.
  • An analytics provider, for product events and, on three public pages only, session replay. See the next section.

Each of these is a processor acting on our instructions and for no purpose of its own. We will name the company behind any of them, and the region it holds data in, on request — the same undertaking as the one below about where data is held.

We do not sell data and we do not share it for advertising. Other members see only what the directory shows, described below.

Cookies, analytics and session replay

Two cookies are set by this application. A session cookie keeps you signed in and is required for the member area to work at all; signing out revokes it on the server, not only in the browser. A preference cookie remembers the language you chose. There is no third: requests that change something carry a signed token in a request header rather than a cookie, which is what stops another site submitting a form as you. A cookie could not do the same job here, because anything able to write a cookie for this domain could supply both halves of the check.

Where analytics is enabled, our analytics provider sets its own cookies and records product events — an application started, an application submitted, a sign-in, a directory search. Session replay records only three pages: the home page, the page where you choose which side you are applying as, and the sign-in page. It stops the moment you navigate away from them, so the application form, the directory and any member’s details are never recorded. Passwords are never captured.

What other members can see

The directory is why membership exists, and it shows each side only the other: an Indian cargo interest sees overseas providers, and a provider sees Indian cargo interests. Nobody browses their own side. A listing carries the firm’s name, country and the operating details it gave; contact details are behind a further step rather than on the page. Documents you upload are never visible to another member — only to our own screening team.

How long we keep it

  • An application left unfinished is deleted, with the documents attached to it, after seven days without activity. That window is configurable and seven days is the default.
  • A link back to an unfinished application expires seven days after it is issued.
  • A sign-in session expires after seven days without use, and thirty days after it began whether it is used or not, and immediately when you sign out, when an administrator resets your password, or when an account is disabled.
  • Documents belonging to a person removed from an application are deleted with them.
  • A member's record and its listing are kept for as long as the membership lasts.
  • The log of actions is kept permanently. It is what allows a decision about an applicant to be accounted for afterwards, so entries are not deleted when other records are.

How it is protected

A password is never stored. What we keep is a one-way hash of it, produced with a current password-hashing algorithm and individually salted, which is why nobody here — including us — can tell you your password, only reset it. Sessions are records in our own database rather than self-contained tokens, which is what makes revoking one immediate. Documents are never public: each view is a short-lived signed link, bound to the exact file, and the application’s database role holds only the permissions it needs. Every state change is written to the log described above, in the same transaction as the change itself.

Where it is held

This network connects Indian importers with providers outside India, so the data described here is processed across borders by the providers described above. The regions they store it in are the ones configured for this deployment, and we will name both the providers and their regions on request.

Your choices

You can ask what we hold about you, ask us to correct it, ask for an account to be closed and its records deleted where we are not required to keep them, and object to how we use it. Write to privacy@trustconnectnetwork.com and say what you are asking for. If a request would mean deleting a record we are obliged to keep — the log of decisions, for instance — we will say so rather than quietly keeping it.

Changes

When this policy changes, the date at the top changes with it. A change that affects what we do with data already collected will be told to members directly rather than only published here.