← Back to TrustLink Home

Privacy & Data Governance Policy

Last updated: August 2026 • Algeris Operations

1. Data We Collect

We collect account profile details (email, full name, business identity), transaction metadata (titles, agreed amounts, milestones, criteria), delivery evidence files, and cryptographic webhook signatures.

2. Financial Data Protection

TrustLink does not store full credit card numbers or banking secrets. Payment credentials are tokenized and processed exclusively within PCI-DSS Level 1 compliant environments maintained by our regulated payment partners.

3. Row Level Security & Encryption

All user data is isolated via Supabase PostgreSQL Row Level Security (RLS) policies. Sensitive developer API tokens and webhook secrets are stored using one-way cryptographic hashing (scrypt / SHA-256).