Trust Center

Trust Center

Evidence-based information about security, privacy, providers and incident processes. Ranjero does not claim certifications that are not verified.

Security Overview

Ranjero separates public pages, protected user areas and admin functionality. Admin areas remain protected server-side through role checks.

Privacy

Personal data is processed only for accounts, analysis, support, billing and security. Details are available in the Privacy Policy.

Data Processing

Analysis data may include images, notes, market values, comparable offers and generated copy. Payment data is processed by Paddle.

Authentication

The app uses Supabase Auth for registration, sign-in, password reset and session management.

Access Controls

Roles such as user, business, admin, super_admin and alpha control visible features and server-side access.

Encryption

Transport encryption depends on the production hosting and Supabase configuration. End-to-end encryption is not claimed.

Backups

Ranjero does not publish fixed backup intervals unless they are organizationally documented and verified.

Data Deletion

Users can contact support for privacy and deletion requests. Account and analysis data is processed under applicable rules.

Availability

No availability percentage is claimed unless reliable monitoring and reporting are in place.

Incident Management

Known incidents are published on the status page where publicly relevant.

Business Continuity

Continuity measures are not presented as certified. Critical dependencies are visible in the provider list.

Subprocessors and Providers

Active providers are listed with purpose, data categories and privacy links.

Responsible Disclosure

Security issues can be reported confidentially to support@ranjero.ch. Please do not publish technical details before the issue has been reviewed and fixed.

Compliance Status

Ranjero does not claim ISO 27001, SOC 2, PCI DSS or GDPR certification. Paddle processes payments as Merchant of Record.

Subprocessors and Providers

ProviderPurposeDataRoleRegionPrivacy
SupabaseAuthentication, database, storage and server-side application data.account data, analysis history, uploaded images, support requests, security logsInfrastructure and data processing providerConfigured in the Supabase project; not disclosed in the public app.Link
PaddleSubscription billing, checkout, taxes, receipts and refund handling.billing identifiers, customer identifiers, subscription status, transaction referencesMerchant of RecordPaddle-controlled payment infrastructure.Link
OpenAIAI-assisted product recognition, valuation reasoning and listing text generation.uploaded item photos, product notes, analysis prompts, generated analysis outputAI processing providerProvider-controlled infrastructure.Link
TavilyComparable offer and web search support where configured.search keywords, product names, marketplace URLs, search result snippetsSearch providerProvider-controlled infrastructure.Link
Hosting providerDelivery of the Next.js application and API routes.HTTP requests, technical logs, IP address, browser metadataHosting infrastructureDeployment-specific and not disclosed in the repository.Link

Responsible Disclosure

Security issues can be reported confidentially to support@ranjero.ch. Please do not publish technical details before the issue has been reviewed and fixed.

Ranjero