Privacy Policy
Last updated June 8, 2026
This Privacy Policy explains what information Adaptive Edge Private Limited (“Adaptive Edge”, “we”, “us”) collects through the TradeVan application, how we use it, where it is stored, who we share it with, and the choices you have. It applies to the TradeVan application (tradevan.app) and related services (collectively, the “Service”).
1. Who we are
TradeVan is operated by Adaptive Edge Private Limited, a company incorporated in India. Customers sign in at us.tradevan.app and have their account and business data stored on US-region infrastructure (see Section 5). Adaptive Edge personnel based in India may access this data to operate, maintain, and support the Service.
The marketing pages and the public Contact form at tradevan.app are served by the same US deployment, so public contact-form submissions are processed and stored in the United States regardless of where the visitor is located. Where personal information about visitors in the European Economic Area, the United Kingdom, or Switzerland reaches us this way, transfers are made under Standard Contractual Clauses (or an equivalent mechanism) with our subprocessors.
2. Information we collect
Account information: name, email address, business name, role within your organization, and login credentials (we store only a salted hash of your password; we never see the plaintext).
Business data you enter: customers, service requests, work orders, quotes, invoices, photos, signatures, notes, and related records. This includes personal information about your end customers that you choose to enter.
Technical information: device and browser information, IP address (transient, for anti-abuse and rate limiting), and error reports we use to operate and improve the Service. We do not use third-party advertising or analytics trackers.
Communications you initiate: contact form submissions, support tickets, and feedback you send through the Service. The content of those messages is stored for as long as we need to respond and for reasonable record-keeping.
3. Cookies and local storage
TradeVan uses only strictly necessary cookies and local storage. Specifically:
- A first-party session cookie to keep you signed in.
- Cloudflare Turnstile cookies on public forms to verify you are not an automated bot.
- Browser local storage and IndexedDB used by the offline-first client (your synced records, cached identity, the offline upload queue, and a one-time cookie-notice acknowledgement).
- A Service Worker cache used to make the app available without network.
We do not set advertising cookies and we do not load third-party analytics. Because the cookies and storage above are strictly necessary to deliver the Service you requested, EU/UK GDPR Article 5(3) and equivalent laws permit them without consent. We still display a one-time cookie notice for transparency.
4. How we use information
We use information to provide and maintain the Service, synchronize your data across devices, deliver transactional and customer-facing emails on your behalf (quotes, invoices, status updates), authenticate users, prevent abuse, respond to support requests, and comply with legal obligations. We do not use your business data to train machine-learning models.
5. Subprocessors
We rely on the following service providers to operate the Service. Each processes data on our behalf under their own security and compliance commitments. Data is processed by US-region infrastructure.
- Vercel— application hosting and content delivery (US regions).
- Neon— managed PostgreSQL database (US region).
- PowerSync— offline-first sync layer (US region).
- Cloudflare R2— object storage for photos, signatures, and generated PDFs (US-jurisdiction bucket).
- Resend— transactional email delivery (US infrastructure).
- Cloudflare— DNS, edge security, and Turnstile anti-bot. Cloudflare operates a global edge; requests are routed by geographic proximity but customer business data is never persisted at the edge.
- PostHog— product analytics, error reporting, and session replay for authenticated dealer staff (US region). Session replay masks form input contents by default; customer-portal visitors and magic-link viewers are not recorded.
6. Sharing and disclosure
We do not sell or rent personal information. We share data only with: (a) the subprocessors above, strictly to operate the Service; (b) recipients you direct (for example, the email address of a customer you choose to send a quote to); and (c) authorities when we are legally compelled. We do not share data with advertising networks.
7. International transfers
Customer business data is processed and stored in the United States. Adaptive Edge operates from India, and Adaptive Edge personnel may access US-stored data from India for the purpose of providing, maintaining, and supporting the Service.
Limited cross-border transfers can also occur for shared infrastructure described in Section 5 (for example, DNS resolution and edge security through Cloudflare's global network) and for public marketing-page interactions. Where personal data leaves the European Economic Area, the United Kingdom, or Switzerland, those transfers are made under Standard Contractual Clauses (or an equivalent transfer mechanism) with our subprocessors.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict processing of your personal data, and to object to certain processing. Specifically:
- EU / UK (GDPR / UK GDPR): access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your supervisory authority.
- California (CCPA / CPRA):right to know, delete, correct, and limit use of sensitive personal information, plus the right to opt out of any sale or sharing — we do not sell or share personal information for cross-context behavioral advertising.
- Other US states with comprehensive privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, Texas): equivalent access, correction, deletion, and opt-out rights.
To exercise any of these rights, use the “Report an issue” option in your account or reply to any email you receive from us. We will respond within the timeframes required by applicable law.
9. Data retention
We retain account and business data for as long as your account is active. Support and feedback content is retained for up to 24 months after the issue is closed for record-keeping. On termination, you may request export or deletion of your data subject to legal, accounting, and operational retention requirements.
10. Security
We use industry-standard technical and organizational measures to protect your information, including TLS in transit, encryption at rest where supported by our subprocessors, hashed credentials, per-tenant data isolation, and least-privilege access controls. No system is completely secure; keep your login credentials confidential and notify us promptly if you suspect compromise.
11. Children
TradeVan is a business tool not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us so we can delete it.
12. Roles under data-protection law
For data you submit about your end customers (records you create as part of running your shop), you are the controller and we act as the processor on your behalf. For account information about TradeVan users (you and your staff), we act as a controller.
13. Changes to this policy
We may update this Policy from time to time. If we make material changes, we will provide notice through the Service or by email and update the “Last updated” date at the top.
14. Contact
Questions about privacy? Email us at support@tradevan.app, use the “Report an issue” option in your account, or the public Contact form at tradevan.app/contact. You may also write to us at: Adaptive Edge Private Limited, India.