Security Overview
Ranjero separates public pages, protected user areas and admin functionality. Admin areas remain protected server-side through role checks.
Trust Center
Evidence-based information about security, privacy, providers and incident processes. Ranjero does not claim certifications that are not verified.
Ranjero separates public pages, protected user areas and admin functionality. Admin areas remain protected server-side through role checks.
Personal data is processed only for accounts, analysis, support, billing and security. Details are available in the Privacy Policy.
Analysis data may include images, notes, market values, comparable offers and generated copy. Payment data is processed by Paddle.
The app uses Supabase Auth for registration, sign-in, password reset and session management.
Roles such as user, business, admin, super_admin and alpha control visible features and server-side access.
Transport encryption depends on the production hosting and Supabase configuration. End-to-end encryption is not claimed.
Ranjero does not publish fixed backup intervals unless they are organizationally documented and verified.
Users can contact support for privacy and deletion requests. Account and analysis data is processed under applicable rules.
No availability percentage is claimed unless reliable monitoring and reporting are in place.
Known incidents are published on the status page where publicly relevant.
Continuity measures are not presented as certified. Critical dependencies are visible in the provider list.
Active providers are listed with purpose, data categories and privacy links.
Security issues can be reported confidentially to support@ranjero.ch. Please do not publish technical details before the issue has been reviewed and fixed.
Ranjero does not claim ISO 27001, SOC 2, PCI DSS or GDPR certification. Paddle processes payments as Merchant of Record.
| Provider | Purpose | Data | Role | Region | Privacy |
|---|---|---|---|---|---|
| Supabase | Authentication, database, storage and server-side application data. | account data, analysis history, uploaded images, support requests, security logs | Infrastructure and data processing provider | Configured in the Supabase project; not disclosed in the public app. | Link |
| Paddle | Subscription billing, checkout, taxes, receipts and refund handling. | billing identifiers, customer identifiers, subscription status, transaction references | Merchant of Record | Paddle-controlled payment infrastructure. | Link |
| OpenAI | AI-assisted product recognition, valuation reasoning and listing text generation. | uploaded item photos, product notes, analysis prompts, generated analysis output | AI processing provider | Provider-controlled infrastructure. | Link |
| Tavily | Comparable offer and web search support where configured. | search keywords, product names, marketplace URLs, search result snippets | Search provider | Provider-controlled infrastructure. | Link |
| Hosting provider | Delivery of the Next.js application and API routes. | HTTP requests, technical logs, IP address, browser metadata | Hosting infrastructure | Deployment-specific and not disclosed in the repository. | Link |
Security issues can be reported confidentially to support@ranjero.ch. Please do not publish technical details before the issue has been reviewed and fixed.