Privacy Policy
Your compliance data is your business. Period.
TRACE NDT exists to keep NDT compliance records organized — not to monetize them. Here's exactly what we collect, what we never do, and who touches your data along the way.
Effective September 2, 2026
What we collect
Account details: your name, email address, phone number if you provide one, and your password (stored only in a scrambled form we can't read).
The compliance data you enter: companies, contacts, technicians, certifications, compliance items, tasks, comments, and the documents you upload — plus whatever the modules you've switched on hold, which can include safety and radiation records, personnel and HR records, equipment and calibration checks, quality-system records, projects, and invoicing. This is your data — TRACE stores and organizes it so you can run your business, and that's the only thing it's used for.
Records of who did what. Some of what TRACE holds is deliberately about accountability rather than about a thing: which named person holds a company's appointments (the Radiation Safety Officer, the Quality Manager, the Responsible Level III), who signed a certification, who administered an exam, who changed a record and when, and who opened or downloaded a document and when. That is the point of a compliance record — it is worth knowing that TRACE keeps it, and that it is about identifiable people.
Billing status: which plan you're on and whether payments succeed. Card numbers stay with Stripe (see below) and never reach our systems. If you entered a referral code when you signed up, we also record which firm's code it was — the referring firm sees only a count of signups their code brought in, never your name or anything about your account.
Emails you send us: if you write to support or use the contact form, we keep the correspondence.
Information other people send to a consultancy through TRACE. If a firm switches on its lead form, whatever a prospect types into it — their name, email, phone, company and message — arrives here as a deal. And if a firm uses a deal's reply address, the emails exchanged with that prospect are filed on the deal: subject, sender, recipient and the message itself. Mail that arrives at a reply address matching no deal is held briefly rather than dropped, so a misdelivery can be traced instead of vanishing.
The people in those messages are not our customers and did not sign up with us. The consultancy that collected the information decides what to do with it and is responsible for it; TRACE holds it on their behalf, exactly as it does for the client and technician records described below. If you have sent something to a firm this way and want it corrected or removed, ask them — and if that goes nowhere, ask us.
What we never do
No selling or renting your data to anyone, for any reason.
No advertising, ad networks, or ad targeting.
No analytics trackers, tracking pixels, or fingerprinting — browsing our site leaves no trail with third parties.
No training AI models on your compliance data.
No reading your data except to operate the service — or when you explicitly ask us to help with your account.
Who touches your data
Eight services. Each sees only what it needs.
TRACE runs on a small set of established providers. None of them are advertising or analytics companies.
Database and file storage
Supabase
Your account data, compliance records, and uploaded documents live here, encrypted in transit and at rest. Access is walled off per account at the database level.
Application hosting
Vercel
Runs the TRACE application itself and delivers pages to your browser over an encrypted connection.
Payment processing
Stripe
Handles subscription billing on Stripe's own checkout pages. Your card number never touches TRACE — we only learn that a payment succeeded or failed.
Email delivery and reply capture
Resend
Sends the emails TRACE generates — expiration digests, password resets, invitations — receiving only the recipient address and the message itself. It also receives mail sent to a deal's reply address, and passes it to TRACE so the conversation can be filed against that deal.
Bot protection
Cloudflare Turnstile
Checks that new signups — and submissions to a firm's public lead form — are human. Designed by Cloudflare specifically to work without tracking cookies or building visitor profiles.
AI Assist and support chat
Anthropic
Powers the AI features — reading a technician's packet, pre-assessing a checklist, answering a question about your portfolio. It receives only what that one request needs, only when a consultant asks for it. The in-app support chat also runs on Anthropic: it sends what you type into the chat plus our own FAQ, and none of your records — it can't read them. Under Anthropic's commercial API terms, none of this is used to train their models.
Optional sign-in
If you sign in with Google rather than a password, Google verifies who you are and tells TRACE your name and email address. It sees nothing else, and accounts that use a password never touch it.
Mobile push notifications
Expo
Delivers push notifications to the TRACE mobile app, by way of Apple's and Google's notification services. A notification carries what it says on your phone — a technician's name, what's due, when — and nothing more, and only for people who installed the app and turned notifications on.
Cookies
Visitors browsing the site get no cookies at all. The single exception is someone taking a test from a share link: starting the attempt sets one short-lived cookie, because a candidate with no account still needs something to hold their place between questions.
Signing in sets the session cookies that keep you logged in as you move between pages, plus display-preference cookies you set yourself (the collapsed sidebar, the technician record you viewed last). They're strictly necessary or a display preference you set yourself, which is why the notice at the bottom of the screen tells you what's happening rather than asking you to accept or reject — there's nothing optional to consent to.
Client and technician accounts
If a consultancy invited you to TRACE — as a client company user or a technician — the records about you were entered and are managed by that consultancy. TRACE stores that data on their behalf. Questions about correcting or removing it should generally start with them; we'll assist either way.
Which consultancy that is can change. A company can move from one consultancy to another, and its records — including records about its technicians — move with it, coming under the new consultancy's management. It cannot happen behind the company's back: the outgoing firm releases, the incoming firm presents a code the client itself passed on, and the company has to accept. If you're a technician whose records sit with a company that moves, ask them who advises them now.
Where your data lives
In the United States. The database and every uploaded document sit in Supabase's US East region (AWS us-east-1, Northern Virginia), and the application itself runs in the matching Vercel region in Washington, D.C. Server-side processing of your records happens there too.
Two honest footnotes. Vercel's edge network serves the site's own static files — logos, stylesheets, scripts — from wherever you happen to be, which is how any modern site loads quickly; none of your records are among them. And the nightly encrypted backup goes to a separate provider, which is the point of an offsite backup: we are confirming that bucket's region and will name it here once we have.
Security
Every connection to TRACE is encrypted (HTTPS), and data is encrypted at rest.
Access controls are enforced in the database itself, per account and per role — your compliance records are invisible to every other consultancy, and client or technician logins see only what applies to them. The one deliberate exception is the Community area, described below; it holds no compliance records.
That wall holds against us too. TRACE's own staff can't read your records by default — documents, financials, technicians, certifications, exam results. Support access has to be opened on your account for a fixed window measured in hours, it closes by itself, and every grant is recorded in your consultancy's own audit trail, so you can see when we had access and when it ended. What stays visible to us without a window is the account itself: your consultancy's name, plan, sign-in accounts, and company names.
Two-factor authentication is required on consultancy staff accounts — an authenticator app, or a one-time code emailed per sign-in — and available on every account. A passkey satisfies it on its own, being both something you hold and something only you can unlock. Sign-in attempts are rate-limited to slow down password-guessing.
No system is perfectly secure, and we won't pretend otherwise — but security is engineered into TRACE at the database layer, not bolted on top.
The Community area
Community — the member profiles, the forum, and mentoring — is the one part of TRACE that is deliberately shared across consultancies. Everything else in your account is walled off to your consultancy; this isn't, because a members' space that only your own colleagues could see wouldn't be one.
It is opt-in twice over. Nothing about you appears there until you fill in the profile questionnaire, and until you do, you cannot post at all. What you put in that profile — your display name, headline, bio, region, years of experience, methods, and any certifications summary — is visible to consultants and admins at other consultancies, as is anything you post. You can hide your profile from the directory at any time from within Community.
Two limits hold regardless: client company logins have no access to Community at all, and technician logins see only the specific topics their consultancy has explicitly granted them — none by default, and none of your compliance data — companies, technicians, certifications, documents — is ever visible there. Only what you typed into Community yourself.
Posts are attributed to the name on your profile. If your account is later deleted, your posts remain with that name attached so conversations don't lose their replies.
TRACE sends operational email only: expiration digests (you control the frequency), account notifications, password resets, and invitations. There is no marketing list, and nothing to unsubscribe from beyond the settings on your Account page.
Data retention and deletion
Your data stays in TRACE for as long as your account is active — that's the product.
If you cancel, contact us and we'll permanently delete your account and its data, or export it for you first. Residual copies age out of the encrypted nightly backups within 35 days; monthly archival snapshots persist for up to 12 months.
Changes to this policy
If this policy changes in any meaningful way, we'll update the date at the top and note the change here. We won't quietly weaken it.
September 2, 2026: the in-app support chat runs on Anthropic, so its entry now says so — the chat sends only what you type plus our own FAQ, and cannot read your records. Disclosure for a new lane, not a change to an existing one.
August 28, 2026: noted that a referral code entered at signup records which firm referred you, and that the referrer sees only a count — new disclosure for a new feature, nothing retroactive.
August 25, 2026: the CRM gained two ways for other people to send information into a consultancy's account — a lead form and a per-deal reply address — so this policy now says that TRACE holds data about people who never signed up for it, who is responsible for that data, and that Resend receives mail as well as sending it. New disclosure, not a new practice we had been keeping quiet.
August 23, 2026: added a section saying where your data is hosted — the United States, US East — which this policy had never actually stated. No change to where anything lives; the policy simply had not said it.
August 22, 2026: TRACE now also keeps a record of who opened or downloaded each document, and when, alongside the existing record of who changed what. That is a strengthening of the audit trail, noted here because it is a record about identifiable people.
August 22, 2026: spelled out that the modules hold more than the original list said (safety and radiation, HR, equipment, quality-system, projects, invoicing), and that some of what TRACE keeps is a record of who did what — appointments, signatures, who administered an exam, who changed a record. Both were already true; the policy described a smaller product than the one you're using.
August 21, 2026: named two providers this policy had not been listing — Anthropic, which powers AI Assist, and Google, for accounts that sign in with it — and added the section describing the Community area, the one part of TRACE that is shared across consultancies. Both were already true of the product; the policy had not caught up with them. Disclosure added, nothing about how TRACE handles your data changed.
August 8, 2026: two-factor authentication became required on consultancy staff accounts (emailed one-time codes by default, authenticator app optionally). A strengthening, not a weakening.
August 2, 2026: split the cookie details into a standalone Cookie Policy listing every cookie by name, and added the on-screen notice pointing to it. No change to what TRACE actually sets.
Questions?
Reach out through the contact form — you'll get an answer from a person who actually runs the product, not a form letter.