Privacy policy

Effective Date: 1 August 2026

This Privacy Policy describes how ClearBond Holdings, Inc. or its applicable operating subsidiary (“ClearBond,” “we,” “us,” or “our”) collects, uses, and discloses information in connection with the ClearBond importer/MGA compliance platform (the “Service”). This Policy is directed at our business customers and their authorized personnel (“Users”) and covers business and trade data processed through the Service. The Service is not offered to individual consumers, and this Policy does not address consumer personal information collected outside the Service (for example, on ClearBond’s marketing website).

1. Scope

This Policy applies to information collected through the Service from business customers. ClearBond currently operates the Service, and expects to store and process Customer Data, within the United States.

2. Information We Collect

2.1 Account and User Information: name, business email address, role, and organization affiliation, collected when an administrator invites a User or a User logs in.

2.2 Organization Information: business identifiers and records submitted about Customer’s organization, including CBP ACE identifiers, D&B DUNS number, articles of incorporation, business description, and related organization metadata.

2.3 Customs and Trade Data: entry summary data, tariff and duty information, bond information, and shipment records (including bill of lading, container, and vessel data) submitted by Customer or its authorized data sources, including automated CBP report feeds.

2.4 Uploaded Documents and Extracted Data: trade documents uploaded through the Service or emailed to Service-monitored mailboxes (for example, commercial invoices, bills of lading, certificates of origin or analysis, health and USDA/FSIS certificates, packing lists, and ISF filings), together with data extracted from those documents through the automated processing described in Section 4.

2.5 Usage and Log Data: IP address, browser and user-agent information, and access logs recorded when Users interact with the Service, including a record of each document download.

2.6 We do not intentionally collect Social Security numbers, government identification numbers, or consumer financial account information through the Service.

3. How We Use Information

We use the information described above to: provide and operate the Service; process and extract data from uploaded trade documents; authenticate Users and enforce organization-level access controls; communicate with Users about their accounts; monitor, secure, and improve the Service; detect and prevent fraud, abuse, and security incidents; process subscription billing; and comply with our legal obligations.

4. Automated Processing and AI Use

4.1 Uploaded documents are processed using Amazon Web Services (“AWS”) Textract for optical character recognition, and AWS Bedrock — which runs Anthropic Claude models — for semantic field extraction and, where applicable, translation of non-English document content.

4.2 Extractions that fall below a confidence threshold are routed to human review by authorized ClearBond personnel before being finalized in Customer’s records.

4.3 We do not use Customer Data to train foundation models made available to other customers or the general public.

5. How We Share Information

We share information with the following categories of service providers (“Subprocessors”) solely to provide the Service, and we do not authorize them to use Customer Data for their own independent purposes:

We do not sell information, and we do not share information with third parties for their own independent marketing purposes.

6. Data Storage and Security

We use encryption at rest (via AWS Key Management Service) for stored documents and database records, and access controls scoped to each organization, together with additional administrative and technical safeguards designed to protect Customer Data.

7. Data Retention and Deletion

7.1 We retain Customer Data for as long as Customer maintains an active account, and for a limited period thereafter to support data export requests and legal or compliance needs.

7.2 Raw CBP report files are retained under a locked retention period (currently up to 90 days) during which they cannot be deleted or altered by anyone, including ClearBond, after which they are automatically expired.

7.3 Deactivating or deleting a User or organization record disables further access to the Service but does not necessarily immediately erase all associated records from our systems; residual data may persist in backups, archives, and audit logs for a limited period consistent with our data-retention practices.

7.4 Customers seeking deletion or export of specific records should contact privacy@clearbond.us. We will respond consistent with our then-current technical capabilities and applicable legal obligations.

8. Your Choices and Rights

Because the Service is offered to business customers and is not designed to process consumer personal information, individual rights available under state consumer privacy laws generally do not apply to data processed through the Service. Business contacts may request access to or correction of their own account information by contacting their organization administrator or privacy@clearbond.us.

9. International Data Transfers

The Service and its infrastructure are operated in the United States, and we do not currently expect to transfer Customer Data outside the United States.

10. Children’s Privacy

The Service is intended for business use by adults and is not directed to, and should not be used by, individuals under 18 years of age.

11. Changes to This Policy

We may update this Policy from time to time. We will notify Customer of material changes by email or in-product notice.

12. Contact Us

Questions about this Policy may be directed to privacy@clearbond.us.