TrustWall — Privacy Policy

Effective date: July 18, 2026

This Privacy Policy explains how The Atlas Project ("we," "us," "our") handles personal information in connection with TrustWall at trustwall.the-atlas-project.net (the "Service"), part of the "An Atlas Project" family. It applies to the Service and our marketing site. It does not cover third-party services you connect or the source platforms whose reviews are assembled, which have their own policies.


§P1 Who we are; roles

For account and billing data, we act as a controller. For testimonials and reviews you submit, collect from your clients, or instruct the Service to assemble and then publish on your Proof Page, you are the party that decides what is collected and published — you are the controller of that content, and we host and display it on your behalf and at your direction. You are responsible for the lawful basis, notices, and consents for the people featured in that content (see the Terms, §20.2).


§P2 Categories of personal information we collect

CategoryExamplesSource
Account dataname, email, password/OAuth identity (email magic link or Google sign-in), workspace settingsyou, at signup (via Supabase auth)
Billing dataplan, billing email, partial card metadata, transaction historyyou and Stripe (we do not store full card numbers)
Usage & device datalog events, feature usage, IP address, timestamps, error logsautomatically, to run and secure the Service
Support datamessages you send us, correspondenceyou
Essential cookiesSupabase auth-session cookieyour browser session
Testimonial & review contentreviewer names, titles, companies, photos/logos, ratings, quotes, and review text — submitted by you, submitted by your clients via a collection link, or assembled from public sourcesyou, your clients, or public/third-party review sources on your instruction

We do not use analytics or advertising cookies/pixels, and we do not build advertising profiles. If this changes, we will update this Policy and, where required, obtain consent first.


§P3 How and why we use personal information

  • Provide the Service — authenticate you, run scans, assemble and host your Proof Page, render embeds and badges, operate collection links, and serve them to the sites where you place them.
  • Billing — process subscriptions via Stripe.
  • Communicate — send transactional and service messages (e.g., sign-in links, receipts, security notices, collection-request and lifecycle emails, product notices) via Resend. We send marketing email only where permitted and with an unsubscribe option.
  • Secure and maintain — detect abuse, debug, protect the Service and users.
  • Comply — meet legal obligations and enforce our Terms (including responding to DMCA and takedown requests).
  • Improve — understand feature usage in aggregate. We do not use the testimonials, reviews, or other content you submit or assemble to train generalized AI models.

§P4 Legal bases (GDPR / UK GDPR)

Where GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, maintain, and improve the Service, and for limited service communications), balanced against your rights; consent (where required, e.g., any future non-essential cookies or optional marketing); and legal obligation (e.g., tax/records). For the testimonial and review content you publish through the Service, you are responsible for the legal basis, notices, and consents for the individuals featured.


§P5 Subprocessors and third-party recipients

TrustWall uses the following subprocessors and service providers:

SubprocessorFunction
VercelApplication hosting / edge delivery
SupabaseDatabase and authentication (email magic link and Google sign-in)
StripePayment processing and subscription billing
ResendTransactional and service email
Public-review / SERP retrieval provider (e.g., ScraperAPI, SerpAPI, or a comparable vendor)Retrieval of public review data from source platforms and the open web, on your instruction, to build your Proof Page

We enter data-processing terms with subprocessors where required and require appropriate safeguards. We will update this list and, where required, give notice before adding a subprocessor that materially changes processing of your data. We do not sell personal information and do not share it for cross-context behavioral advertising.

TrustWall does not use analytics providers, advertising networks, or AI/vision-extraction subprocessors, and does not connect to Gmail, Outlook, QuickBooks, Xero, Amazon, Calendly, or mapping/OpenStreetMap services. (Google appears only as an optional sign-in identity provider handled through Supabase, and as a source platform whose public reviews may be assembled — not as a connected data account.)


§P6 Cookies and similar technologies

We use essential cookies only — specifically, the Supabase authentication-session cookie needed to keep you signed in. We do not use analytics, advertising, or tracking cookies or pixels. Because we use only strictly-necessary cookies, we do not show a consent banner for non-essential cookies. If we ever introduce non-essential cookies, we will update this Policy and obtain consent where required.

Note: TrustWall embeds and badges you place on third-party sites are served by us to display your proof; they are not tracking pixels and are not used to profile visitors for advertising.


§P7 Retention

We keep account and billing data for as long as your Account is active and as needed for legitimate business and legal purposes (e.g., tax records) after closure. Testimonial and review content is retained while your Proof Page is live and per your settings, and is deleted or de-identified on request or on termination, subject to residual backups purged on our ordinary cycle and records we must keep by law. Because Proof Pages, embeds, and badges are published artifacts, deletion may take time to propagate, and copies you have placed on third-party sites are your responsibility to remove.


§P8 Security

We use reasonable technical and organizational measures appropriate to the risk, including encryption in transit, row-level access controls, least-privilege, signed and domain-scoped embed/badge tokens, and reliance on reputable infrastructure providers (Vercel, Supabase, Stripe). No system is perfectly secure; we cannot guarantee absolute security. We will notify affected users and regulators of a personal-data breach where required by law.


§P9 Your privacy rights

§P9.1 GDPR / UK GDPR (EEA/UK residents). Subject to conditions, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent where processing is based on consent. You may lodge a complaint with your supervisory authority. Where we host content you publish (testimonials and reviews), we will route or assist with requests as appropriate, directing the individual to you as the publisher where you are the controller.

§P9.2 CCPA / CPRA (California residents). You have rights to know/access, delete, correct, and to opt out of "sale" or "sharing" and limit use of sensitive personal information. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for purposes requiring a right-to-limit. We will not discriminate against you for exercising rights. Authorized agents may submit requests with proof of authorization.

§P9.3 People featured in testimonials or reviews. If you are an individual named or shown in a testimonial or review on a TrustWall Proof Page and want it corrected or removed, contact admin@the-atlas-project.net. Because the business that published the Proof Page controls its content, we may route your request to that business and/or act on it where required by law or under our Terms (including our DMCA and impersonation policies).

§P9.4 How to exercise rights. Email admin@the-atlas-project.net (or admin@the-atlas-project.net) from your Account address, describing your request. We will verify your identity and respond within the time required by law.


§P10 International data transfers

We are based in the United States, and our subprocessors may process data in the US and elsewhere. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum, or another lawful mechanism. By using the Service, you understand your information may be processed in the US.


§P11 Children

The Service is not directed to individuals under 18, and we do not knowingly collect their personal information (see Terms §16).


§P12 Changes to this Policy

We may update this Policy. We will post the new version with a revised "Last updated" date and, for material changes, provide additional notice (email or in-product). Continued use after the effective date constitutes acceptance where permitted by law.


§P13 Contact

Questions or requests: admin@the-atlas-project.net (privacy) or admin@the-atlas-project.net. Postal address: The Atlas Project, [MAILING_ADDRESS — to be added once the entity is formed].



Last updated: July 18, 2026 · The Atlas Project · admin@the-atlas-project.net · admin@the-atlas-project.net

This document was prepared with automated assistance and has not been reviewed by an attorney. It is not legal advice.