Privacy Policy
Last updated: August 31, 2026
Fintora Technologies Inc., d/b/a Tandom.ai (“Tandom.ai,” “Tandom,” “we,” “us,” or “our”), operates tandom.ai, its related subdomains, and the services described below (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our sites, use our import tools or catalogs, create an account, use our API or MCP interfaces, submit a sourcing project, or work with us on a supplier-development engagement.
1. Information We Collect
a. Information You Provide
- Account and contact information: Name, work email address, company, role, authentication details, account preferences, and communications with us.
- Sourcing-project information: Product descriptions, specifications, requirements, expected volume, commercial context, timing, links or files you choose to provide, and information about current or prospective suppliers and manufacturers.
- Import-tool inputs: Information you submit to our tariff calculator, AD/CVD lookup, reports, and related tools, such as HTS codes, countries, shipment values, dates, product descriptions, manufacturers, and exporters.
- API, MCP, and bulk-access information: Account and API-key identifiers, requests, parameters, responses, usage records, and support communications associated with programmatic access.
- Billing information: Billing contact details and transaction, subscription, and payment-status information. Payment-card details are collected and processed by our payment provider rather than stored directly by Tandom.ai.
b. Information Collected Automatically
- Device and network data: IP address, browser and device type, operating system, user agent, approximate location derived from IP address, and diagnostic or security information.
- Usage and analytics data: Pages and features viewed, referring pages, traffic source, interactions, tool and account events, performance information, timestamps, and session or account identifiers.
- Cookies and local storage: We use cookies, local storage, and similar technologies for authentication, security, anonymous tool allowances, site functionality, analytics, and service improvement. We do not use this information to serve third-party behavioral advertising.
2. How We Use Information
We use information to:
- Operate, maintain, secure, troubleshoot, and improve the Services.
- Provide import calculations, AD/CVD screening, public catalogs, reports, accounts, API and MCP access, and related support.
- Apply and display anonymous or account-based usage allowances, prevent duplicate charging for the same input where supported, enforce rate limits, and detect abuse.
- Review sourcing-project requests, prepare and perform agreed supplier-development work, and communicate about projects, manufacturers, quotes, samples, and first-order preparation.
- Process transactions, administer subscriptions, and send service, account, security, and regulatory notifications.
- Understand site and product usage, measure conversion and service quality, and distinguish likely automated traffic from human use.
- Comply with law, enforce our agreements, protect rights and safety, and establish, exercise, or defend legal claims.
3. How We Disclose Information
We do not sell personal information. We may disclose information in the following circumstances:
- Service providers: Providers that support hosting and delivery (Vercel), database and authentication services (Supabase), analytics (PostHog, Google Analytics, and Vercel Analytics), email delivery (Resend), rate limiting (Upstash), error monitoring (Sentry), payments (Stripe), and AI-assisted features (Anthropic). A provider receives information only when relevant to the feature or service it performs for us.
- Sourcing and project participants: When authorized by you or reasonably necessary to perform an agreed engagement, we may share relevant project requirements with prospective manufacturers and with inspection, testing, logistics, customs, or other project participants. We seek to limit disclosures to information relevant to the work.
- Professional advisers and legal requirements: Advisers, auditors, insurers, authorities, or other parties when reasonably necessary to comply with law, protect rights or safety, or establish, exercise, or defend legal claims.
- Business transfers: A buyer, successor, or other participant in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.
- At your direction: Other parties when you ask us to disclose information or consent to the disclosure.
4. Analytics, Cookies, and Anonymous Tool Allowances
Our sites use first-party and third-party analytics technologies to measure page views, product events, performance, traffic sources, and service quality. PostHog events are routed through a Tandom.ai path and are configured to mask page text, element attributes, and common personal-data fields. Identified PostHog profiles use an internal user identifier rather than an email address or company name. PostHog may use masked session replay for human traffic to help us diagnose product and usability issues. Google Analytics and Vercel Analytics may also receive standard browser and usage information.
For anonymous tariff-calculator and AD/CVD use, we issue a signed browser identifier and store keyed cryptographic hashes that let us count distinct successful uses and recognize repeated inputs. The anonymous-usage ledger is designed not to store the raw browser identifier, raw tool input, IP address, user agent, or device fingerprint. Deleting the browser cookie or using a private browser profile creates a new anonymous identity.
Use the Privacy choices control at the bottom of any public page to disable optional analytics for that browser. You can also control cookies through your browser settings. Blocking or deleting essential technologies may affect sign-in, allowance counting, saved preferences, or other Service features. Read our Cookie and Analytics Notice for more detail.
5. AI-Assisted Processing
Some features use third-party AI services to analyze or transform information you submit, such as product, document, or scope-related text. When you use an AI-assisted feature, the relevant content and instructions may be sent to the configured AI provider to generate the requested result. Do not submit personal or confidential information that is unnecessary for the feature. AI-generated results may be incomplete or inaccurate and should be independently reviewed.
6. Data Retention and Account Deletion
Calculator query logs and AD/CVD query logs are scheduled for daily removal after 90 days. Sourcing-project requests are scheduled for daily removal after 730 days so we can respond to, evaluate, and maintain records of project inquiries. Anonymous usage identities are designed to expire 365 days after creation, while failed or expired anonymous-attempt records are generally removed sooner.
Other information is retained for as long as reasonably necessary to provide the Services, maintain business and transaction records, resolve disputes, enforce agreements, protect security, and comply with law. Retention therefore varies by data category and context.
When an eligible user completes the self-service account-deletion process, the authentication account and account-linked application records configured for cascading deletion are deleted. If an account cannot be safely deleted automatically, or you want a comprehensive privacy export or erasure review, contact legal@tandom.ai. Certain transaction, security, legal, backup, or provider records may remain when reasonably necessary or legally required. A sole owner may need to transfer or disband a team before deleting the account.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No electronic transmission or storage method is completely secure, and we cannot guarantee absolute security.
8. Your Choices and Privacy Rights
Depending on where you live and subject to applicable exceptions, you may have rights to request access, correction, deletion, or a copy of personal information, or to object to or restrict certain processing. You may also unsubscribe from non-transactional email by using the instructions in the message.
To make a privacy request, email legal@tandom.ai. We may need to verify your identity and authority before completing a request. We will respond within the period required by applicable law.
9. California Privacy Notice
Where applicable, California residents may request information about the categories and specific pieces of personal information we collect, request correction or deletion, and exercise other rights provided by California law. We do not sell personal information or share it for cross-context behavioral advertising. We will not discriminate against you for exercising an applicable privacy right. Submit a request at legal@tandom.ai.
10. International Data Transfers
We and our service providers may process information in the United States and other countries that may have different data-protection laws from your country of residence. Where required, we use appropriate legal mechanisms for international transfers.
11. Children
The Services are intended for business users and are not directed to children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information, contact us so we can review and, where appropriate, delete it.
12. Changes to This Policy
We may update this Privacy Policy as our Services or legal obligations change. We will post the revised policy here and update the “Last updated” date. We will provide additional notice when required by law.
13. Contact Us
Questions and privacy requests may be sent to: