TrustWall — Privacy Policy
Effective date: July 18, 2026
This Privacy Policy explains how The Atlas Project ("we," "us," "our") handles personal information in connection with TrustWall at trustwall.the-atlas-project.net (the "Service"), part of the "An Atlas Project" family. It applies to the Service and our marketing site. It does not cover third-party services you connect or the source platforms whose reviews are assembled, which have their own policies.
§P1 Who we are; roles
For account and billing data, we act as a controller. For testimonials and reviews you submit, collect from your clients, or instruct the Service to assemble and then publish on your Proof Page, you are the party that decides what is collected and published — you are the controller of that content, and we host and display it on your behalf and at your direction. You are responsible for the lawful basis, notices, and consents for the people featured in that content (see the Terms, §20.2).
§P2 Categories of personal information we collect
| Category | Examples | Source |
|---|---|---|
| Account data | name, email, password/OAuth identity (email magic link or Google sign-in), workspace settings | you, at signup (via Supabase auth) |
| Billing data | plan, billing email, partial card metadata, transaction history | you and Stripe (we do not store full card numbers) |
| Usage & device data | log events, feature usage, IP address, timestamps, error logs | automatically, to run and secure the Service |
| Support data | messages you send us, correspondence | you |
| Essential cookies | Supabase auth-session cookie | your browser session |
| Testimonial & review content | reviewer names, titles, companies, photos/logos, ratings, quotes, and review text — submitted by you, submitted by your clients via a collection link, or assembled from public sources | you, your clients, or public/third-party review sources on your instruction |
We do not use analytics or advertising cookies/pixels, and we do not build advertising profiles. If this changes, we will update this Policy and, where required, obtain consent first.
§P3 How and why we use personal information
- Provide the Service — authenticate you, run scans, assemble and host your Proof Page, render embeds and badges, operate collection links, and serve them to the sites where you place them.
- Billing — process subscriptions via Stripe.
- Communicate — send transactional and service messages (e.g., sign-in links, receipts, security notices, collection-request and lifecycle emails, product notices) via Resend. We send marketing email only where permitted and with an unsubscribe option.
- Secure and maintain — detect abuse, debug, protect the Service and users.
- Comply — meet legal obligations and enforce our Terms (including responding to DMCA and takedown requests).
- Improve — understand feature usage in aggregate. We do not use the testimonials, reviews, or other content you submit or assemble to train generalized AI models.
§P4 Legal bases (GDPR / UK GDPR)
Where GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, maintain, and improve the Service, and for limited service communications), balanced against your rights; consent (where required, e.g., any future non-essential cookies or optional marketing); and legal obligation (e.g., tax/records). For the testimonial and review content you publish through the Service, you are responsible for the legal basis, notices, and consents for the individuals featured.
§P5 Subprocessors and third-party recipients
TrustWall uses the following subprocessors and service providers:
| Subprocessor | Function |
|---|---|
| Vercel | Application hosting / edge delivery |
| Supabase | Database and authentication (email magic link and Google sign-in) |
| Stripe | Payment processing and subscription billing |
| Resend | Transactional and service email |
| Public-review / SERP retrieval provider (e.g., ScraperAPI, SerpAPI, or a comparable vendor) | Retrieval of public review data from source platforms and the open web, on your instruction, to build your Proof Page |
We enter data-processing terms with subprocessors where required and require appropriate safeguards. We will update this list and, where required, give notice before adding a subprocessor that materially changes processing of your data. We do not sell personal information and do not share it for cross-context behavioral advertising.
TrustWall does not use analytics providers, advertising networks, or AI/vision-extraction subprocessors, and does not connect to Gmail, Outlook, QuickBooks, Xero, Amazon, Calendly, or mapping/OpenStreetMap services. (Google appears only as an optional sign-in identity provider handled through Supabase, and as a source platform whose public reviews may be assembled — not as a connected data account.)
§P6 Cookies and similar technologies
We use essential cookies only — specifically, the Supabase authentication-session cookie needed to keep you signed in. We do not use analytics, advertising, or tracking cookies or pixels. Because we use only strictly-necessary cookies, we do not show a consent banner for non-essential cookies. If we ever introduce non-essential cookies, we will update this Policy and obtain consent where required.
Note: TrustWall embeds and badges you place on third-party sites are served by us to display your proof; they are not tracking pixels and are not used to profile visitors for advertising.
§P7 Retention
We keep account and billing data for as long as your Account is active and as needed for legitimate business and legal purposes (e.g., tax records) after closure. Testimonial and review content is retained while your Proof Page is live and per your settings, and is deleted or de-identified on request or on termination, subject to residual backups purged on our ordinary cycle and records we must keep by law. Because Proof Pages, embeds, and badges are published artifacts, deletion may take time to propagate, and copies you have placed on third-party sites are your responsibility to remove.
§P8 Security
We use reasonable technical and organizational measures appropriate to the risk, including encryption in transit, row-level access controls, least-privilege, signed and domain-scoped embed/badge tokens, and reliance on reputable infrastructure providers (Vercel, Supabase, Stripe). No system is perfectly secure; we cannot guarantee absolute security. We will notify affected users and regulators of a personal-data breach where required by law.
§P9 Your privacy rights
§P9.1 GDPR / UK GDPR (EEA/UK residents). Subject to conditions, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent where processing is based on consent. You may lodge a complaint with your supervisory authority. Where we host content you publish (testimonials and reviews), we will route or assist with requests as appropriate, directing the individual to you as the publisher where you are the controller.
§P9.2 CCPA / CPRA (California residents). You have rights to know/access, delete, correct, and to opt out of "sale" or "sharing" and limit use of sensitive personal information. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for purposes requiring a right-to-limit. We will not discriminate against you for exercising rights. Authorized agents may submit requests with proof of authorization.
§P9.3 People featured in testimonials or reviews. If you are an individual named or shown in a testimonial or review on a TrustWall Proof Page and want it corrected or removed, contact admin@the-atlas-project.net. Because the business that published the Proof Page controls its content, we may route your request to that business and/or act on it where required by law or under our Terms (including our DMCA and impersonation policies).
§P9.4 How to exercise rights. Email admin@the-atlas-project.net (or admin@the-atlas-project.net) from your Account address, describing your request. We will verify your identity and respond within the time required by law.
§P10 International data transfers
We are based in the United States, and our subprocessors may process data in the US and elsewhere. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum, or another lawful mechanism. By using the Service, you understand your information may be processed in the US.
§P11 Children
The Service is not directed to individuals under 18, and we do not knowingly collect their personal information (see Terms §16).
§P12 Changes to this Policy
We may update this Policy. We will post the new version with a revised "Last updated" date and, for material changes, provide additional notice (email or in-product). Continued use after the effective date constitutes acceptance where permitted by law.
§P13 Contact
Questions or requests: admin@the-atlas-project.net (privacy) or admin@the-atlas-project.net. Postal address: The Atlas Project, [MAILING_ADDRESS — to be added once the entity is formed].
Last updated: July 18, 2026 · The Atlas Project · admin@the-atlas-project.net · admin@the-atlas-project.net
This document was prepared with automated assistance and has not been reviewed by an attorney. It is not legal advice.