Truss privacy
Privacy Policy
Effective date: August 4, 2026.
1. Scope
This Privacy Policy explains how Truss (“Truss,” “we,” “us,” or “our”), operated by Rhatid Hub Ltd., handles information when you use the Truss mobile application, invitation pages, support tools, and related websites (together, the “Service”).
2. Information we handle
The information depends on how you use Truss. It may include:
- Account and contact information: name, email address, phone number, account identifiers, role, and merchant business details.
- Agreement and ledger information: customer and merchant details, agreement terms, amounts, due dates, payment records, notes, approvals, signatures, disputes, evidence, and audit activity.
- Security information: passkey and trusted-device metadata, MFA status, recovery events, authentication events, and security logs. Truss is designed not to receive your passkey private key.
- Support information: support category, subject, messages, attachments or evidence you choose to send, queue status, and responses.
- Purchase information: product identifier, transaction and verification metadata, app-account binding, and grant history for Truss Checks. Payment-card details are handled by the applicable app store.
- Device and technical information: device or installation identifiers, push-notification token information, app version, approximate event timing, diagnostics, and security telemetry needed to operate and protect the Service.
- Invitation information: a one-time invitation or claim token when a merchant invites a customer. Do not share an invitation link with anyone who should not access it.
3. How we use information
- Create and authenticate accounts, including passkeys and MFA.
- Provide agreement, ledger, payment, dispute, notification, synchronization, and support features.
- Verify Truss Check purchases and grant purchased checks safely and idempotently.
- Prevent fraud, unauthorized access, abuse, duplicate grants, and security incidents.
- Keep a returning customer linked to eligible verified history so account deletion cannot be used to reset a Trust Score.
- Respond to support requests, investigate disputes, and maintain auditable records.
- Maintain, troubleshoot, measure, and improve the Service.
- Meet legal, regulatory, accounting, safety, and dispute-resolution obligations.
4. How information is shared
We do not sell your personal information. We may share information:
- With the merchant or customer who is part of the relevant agreement or authorized workflow.
- For an authorized cross-merchant trust lookup, where Truss is designed to return only the permitted, masked result and require the relevant customer-link authorization.
- With service providers that host, authenticate, store, secure, synchronize, notify, or support Truss, under instructions and appropriate protections.
- With Apple or another app store when needed to process or verify an in-app purchase.
- When required by law, legal process, safety needs, fraud prevention, or protection of rights.
- As part of a merger, financing, acquisition, restructuring, or transfer of the Service, subject to applicable law.
Truss is not intended to publish customer records as a public directory. Use another person’s information only for the authorized purpose for which it was provided.
5. Security
Truss uses access controls, authenticated API requests, database authorization boundaries, secure credential storage, passkeys, MFA, and other safeguards appropriate to the Service. No system can guarantee absolute security. Protect your device and credentials, and contact Support promptly if something looks unfamiliar.
6. Retention
We apply the following retention schedule unless a longer or shorter period is required by law, a legal hold, an unresolved dispute, fraud prevention, or protection of another person’s rights:
- Deleted customer login: authentication credentials, passkeys, MFA factors, trusted-device registrations, active invitations, push tokens, notification delivery records, and account email are deleted or disabled when deletion completes.
- Agreement and trust history: customer identity links, approved agreements, ledger and payment records, signatures, consent evidence, disputes, related audit records, and score history may be retained for the life of the agreement and up to seven years after the agreement is closed.
- Support records: ordinarily retained for up to two years after the request is resolved, unless linked to a retained dispute, security investigation, or legal obligation.
- Security logs: ordinarily retained for up to twelve months, unless needed for an active investigation.
- Unused invitations and temporary verification data: expire automatically and are ordinarily removed within thirty days.
- Backups: deleted information may remain in protected rolling backups for up to ninety days before being overwritten.
We review this schedule and delete or de-identify information when its retention purpose ends. Retained history is access-controlled and is not retained for advertising.
7. Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or information about our handling of your personal information. You may also be able to object to or withdraw consent for certain uses. We may need to verify your identity and may retain information where the law permits or requires it.
Customers can delete their login from Account & Privacy > Delete Account. The deletion removes account access and the login-related information listed above. It does not silently rewrite valid financial history, resolve a dispute, or reset a Trust Score. A returning customer must be verified through a new merchant invitation linked to the same customer record; eligible retained history is then restored and the score is recalculated under the current model.
If information is inaccurate or unauthorized, use the dispute flow before deletion. If you no longer have the app, visit truss.today/delete-account to request account deletion. We will explain any information that must be retained and the reason.
Push notifications can be controlled through your device settings. You can revoke a trusted passkey device from the account security controls. Removing a notification permission does not delete the underlying account or ledger record.
8. Children
Truss is a business and agreement-recording service and is not directed to children. Do not provide information or approve an agreement if you are not legally able or authorized to do so. If you believe a child provided information improperly, contact Support.
9. Third-party services
Truss may depend on third-party services such as hosting, authentication, app-store billing, and push notifications. Those services may process information under their own privacy policies. Review the policies of the app store and services you use to access Truss.
10. International processing
Truss and its providers may process information in countries other than the one where you live. We assess service providers and use contractual, access-control, encryption, and other safeguards appropriate to the information and applicable law. Where Jamaican law requires an adequate level of protection or another permitted transfer basis, we apply that requirement.
11. Changes
We may update this Policy as the Service, providers, or legal requirements change. We will update the effective date and, where appropriate, provide notice in the app or through another reasonable channel.
12. Contact
Use the secure Truss Support channel in the app or visit truss.today/support for privacy requests and questions. Account-deletion instructions are available at truss.today/delete-account.