1. Scope and contact
ImportSmart provides landed-cost, customs-duty and tax estimates, logistics-risk calculations, subscription access and an optional AI explanation feature for imports into supported destination markets.
The ImportSmart operator is responsible for the processing described in this policy. Questions, access requests and privacy requests can be sent to support@importsmart.net.
2. Information ImportSmart processes
| When | Information | Why it is needed |
|---|---|---|
| Using the calculator | Product name, full product description, intended use, relevant characteristics, destination, origin, product or tariff code, value, quantity, freight, insurance, currency, carrier, port, container details, dates and selected treatment options. | To check whether the product is supported before calculating and, where supported, return the requested estimate and source status. |
| Verifying Premium | Payment email, six-digit verification code, plan and subscription status. | To verify control of the email and confirm entitlement with Stripe. |
| Optional two-step verification | A pseudonymous account identifier, encrypted Authenticator secret, one-way recovery-code hashes, security version, failed-attempt counters and short-lived challenge records. | To provide the additional protection you choose to enable and prevent code reuse or unauthorised reset. |
| Using Starter | A one-way hash derived from the verified identity, month, calculation count, request identifier and request fingerprint. | To apply the monthly calculation allowance and prevent duplicate charging of the allowance. |
| Using the AI helper | Your latest question and up to two recent sanitised user questions from the same separated mode. For Guide, semantic retrieval uses those Guide questions and the generator receives them with only the retrieved reviewed claims. For Current result, the generator receives those result-chat questions and server-controlled field identifiers, not the exact result values. Assistant answers, mixed-mode chat history, access tokens, result tokens, payment email and payment data are excluded from provider prompts. | To retrieve reviewed ImportSmart material and select a server-validated answer plan. |
| Security and operation | Hashed IP or identity keys, request timing, rate-limit counters, route/status metadata and sanitised error codes. | To prevent abuse, protect access and diagnose failures. |
| Contacting support | Your email address and the content you choose to send. | To answer and resolve your request. |
ImportSmart does not ask you to create a password. Premium access is tied to verification of the payment email. Optional Authenticator two-step verification can be enabled by the customer. The access token contains the verified email, plan, authentication method and security version and, where applicable, a Stripe subscription identifier; it is signed against tampering but is not presented as encrypted storage. Authenticator secrets and recovery codes are never placed in that token.
3. Purposes and legal bases
ImportSmart uses information only as needed to:
- provide calculations, Premium features, subscription access and support;
- authenticate access, apply plan limits, prevent fraud and secure the service;
- process payments, invoices, cancellations and required financial records;
- comply with legal obligations and establish or defend legal claims; and
- operate an optional AI request only when you choose to send one.
Where applicable law requires a legal basis, the basis may be performance of a contract or steps requested before a contract, legitimate interests in operating and protecting the service, compliance with legal obligations, or consent where the law specifically requires it. You may withdraw consent for future processing where consent is the basis, without affecting earlier lawful processing.
4. Payments, subscription verification and cancellation
Payments and recurring subscriptions are processed on Stripe-hosted pages. Stripe receives payment and transaction details, which may include your email, billing information, payment method, amount, subscription status, invoices, refunds or disputes. ImportSmart’s application code does not receive or store your full card number.
After email verification, ImportSmart queries Stripe for the matching customer, eligible payment or active subscription. The secure Stripe Customer Portal can show invoices, allow payment-method updates and schedule cancellation at the end of the current billing period shown by Stripe.
Read Stripe’s Privacy Policy for Stripe’s own processing.
5. Optional AI helper
The Premium AI helper uses the Google Gemini API in two strictly separated modes. ImportSmart guide sends the latest sanitised Guide question and at most two recent sanitised user questions from that same Guide chat to semantic retrieval, then sends those questions and only the retrieved reviewed ImportSmart claims to the generator. Current result sends the latest question, at most two earlier user questions from that separate result chat and server-controlled field identifiers only; exact calculation values remain in ImportSmart’s deterministic renderer and are not supplied to Gemini for recalculation. Assistant answers, mixed-mode chat history, the access token, result token, payment email and payment data are not added to provider prompts.
The model can select only reviewed claim, result-field, action and link identifiers exposed by the server. ImportSmart binds all final numbers, rules and links from its server registry. If retrieval cannot support the question, the helper says it cannot confirm an answer. If Gemini is unavailable or times out, a local server-rendered answer is used instead of exposing the provider error.
The visible chat history is held in the memory of the current page and is cleared when the page is refreshed or reset; ImportSmart does not write that history to its application database. Unknown-question telemetry contains only allowlisted metadata such as mode, language, knowledge version, reason and a coarse score bucket; the raw question, history, result, email, payment data and tokens are not logged by this feature. A keyed question fingerprint is included only when a dedicated telemetry secret is configured. Google may retain API prompts, context and outputs for abuse monitoring under its applicable terms. See the current Gemini API Terms and abuse-monitoring policy.
6. Browser storage and cookies
Session storage
The current tab stores Premium verification status, payment email, plan, entitlement, signed access token, remaining allowance and short-lived operation identifiers. This is normally removed when the browser session ends or when access is cleared.
Local storage
If you save verified carrier or tariff information in the browser, the selected tariff details and source reference remain in local storage until you delete them, clear site data or replace them by importing another saved file.
Cookies and tracking
ImportSmart uses Vercel Web Analytics on the production calculator page to measure visits, referring sources, countries, browsers and device types. This analytics service does not use cookies. ImportSmart removes query parameters and fragments from the page URL before sending page-view events, and does not send calculation form inputs or custom events to Vercel Web Analytics. Referrer information is handled by Vercel Web Analytics.
ImportSmart also keeps daily aggregate counters in its existing application database for completed calculations, unavailable or failed calculations, form-validation failures and clicks on its payment links. These counters contain only a date, event category and allowlisted categories such as plan or outcome. They do not contain product descriptions, shipment values, email addresses, payment details or visitor identifiers, and do not link a visitor’s actions into an individual browsing history. Repeat clicks and validation attempts may be limited to reduce duplicate counts. Reports cover a rolling 90-day period, and older counter records are removed during normal counter processing.
Page-view analytics and optional calculator/payment-link counters are disabled in Preview and when your browser sends Do Not Track. You can disable them in this browser by visiting the calculator with analytics off; this stores only an opt-out preference in local storage, not a unique visitor identifier. Visit the calculator with analytics on to clear that preference. Confirmed payments and subscriptions are still processed for service delivery, billing and aggregate sales accounting when optional analytics is disabled; payment counts come from verified Stripe notifications, not from browser clicks.
ImportSmart uses no advertising pixels. Vercel may use an essential cookie to protect access to non-public deployments, and Stripe uses cookies on its hosted payment and billing pages. Those providers control their own cookies and notices.
7. Service providers, official sources and international transfers
ImportSmart uses the following providers to operate the service:
- Vercel — website hosting, server functions, request delivery, access protection and cookieless page-view analytics. Privacy notice.
- Stripe — checkout, payments, subscription records and the Customer Portal. Privacy policy.
- Neon / Databricks — email-code authentication and database storage for hashed quota/rate-limit records, optional two-step-verification security records and aggregate calculation, payment-link and confirmed-payment counters. Privacy notice.
- Google Gemini API — optional semantic retrieval for the latest sanitised Guide question and at most two recent sanitised user questions from the same Guide chat, plus constrained model selection from retrieved claim IDs or Current-result field IDs. Current result may use the latest and at most two earlier user questions from its separate chat. Assistant answers, exact calculation values, mixed-mode chat history, access and result tokens, payment email and payment data are excluded from model prompts. Service terms.
- Official tariff services — where integrated, server-side tariff queries may send product or tariff code, origin, destination and requested treatment to the relevant customs or legislation source. The payment email is not added to those tariff queries.
These providers may process information in countries outside your own. Where required, ImportSmart and its providers rely on recognised transfer mechanisms and safeguards under applicable data-protection law. Provider-specific locations and safeguards are described in their notices and agreements.
8. Retention
ImportSmart’s application database does not store the shipment inputs or calculation results submitted to the calculator. The following schedule applies to ImportSmart’s own active Neon Postgres tables:
- Starter monthly quota counters: eligible for deletion 90 days after their last update.
- Starter duplicate-prevention request records: eligible for deletion 90 days after creation.
- Both Starter record types have an additional safety rule: records for the current UTC calendar month are never deleted, so cleanup cannot reset the current allowance or count one request twice.
- Expired database rate-limit records are deleted after their applicable 10-minute or one-hour window expires.
- Optional Authenticator setup: an unconfirmed encrypted setup secret expires after 10 minutes. A Premium-login second-factor challenge expires after 5 minutes. Expired or consumed challenge records and abandoned setup records are queued for deletion by the daily cleanup, normally within about 24 hours.
- Enabled optional two-step verification: the Authenticator secret remains encrypted with AES-256-GCM while the feature is enabled. Recovery codes are shown once and stored only as one-way hashes. Disabling the feature deletes the encrypted secret and recovery-code hashes; changing recovery codes invalidates the previous hashes.
- Eligible rows may be removed on a best-effort basis during later database activity and are authoritatively processed in limited batches by a daily automated cleanup. After eligibility, deletion normally occurs by the next successful daily run, within about 24 hours. A failed run or unusually large backlog is reported, and remaining rows stay eligible for later runs.
The quota identity is pseudonymous: it is stored as a one-way hash rather than as the payment email. Quota tables also contain the UTC month, count, request identifier and fingerprint, calculation mode and destination market. Rate-limit tables contain a hashed request identity, window key, count and expiry time.
Short-lived rate-limit entries use a hashed request identity rather than the payment email. They may be held in the active Neon rate-limit table, with automatic expiry and cleanup, or in server memory when a database-backed limiter is not configured. The applicable windows are 10 minutes for AI and billing-portal requests, 15 minutes for email-code attempts, or one hour for calculator requests. Expired in-memory entries are pruned on the next request and may disappear sooner when the serverless instance ends.
- The signed Premium access token issued by the current verification flow expires after 24 hours; a result-help token expires after 30 minutes.
- Session-storage data normally lasts for the browser session. Saved local tariff information lasts until you remove it or clear browser storage.
- AI conversation history kept by the page ends on refresh or reset. Google’s separate retention is governed by the configured Gemini service and its current terms.
- The cleanup above does not delete Neon Auth identity or verification records, Stripe payment and subscription records, Vercel logs, Google Gemini provider records, support correspondence or legally required accounting records. Those records follow the relevant provider settings and applicable security, dispute, tax and accounting obligations. Deleted active database rows may remain temporarily in protected provider backup or restore history for the period included in the configured Neon plan and are not used for ordinary processing.
9. Your rights and choices
Depending on your location, you may have the right to request access, correction, deletion, restriction, portability or objection; to withdraw consent; and to complain to the competent data-protection authority. Some rights are subject to legal exceptions, identity verification and mandatory record-keeping.
You can also clear browser-stored ImportSmart data through your browser settings. To make a privacy request, write from the relevant payment email where possible so the request can be verified.
Privacy contact
Questions or rights requests
10. Security, children and policy changes
ImportSmart uses server-side secrets, signed short-lived tokens, encrypted HTTPS transport, hashing for stored quota/rate-limit identities, AES-256-GCM for an enabled optional Authenticator secret, one-time recovery codes and restricted provider access. No online service can guarantee absolute security.
The service is not designed for children, and the Premium AI feature must not be used by anyone who is not permitted to use it under the applicable Google terms. If you believe a child submitted personal information, contact ImportSmart.
This policy may change when features, providers or legal requirements change. The date at the top will be updated, and material changes will be highlighted where required.