Privacy Policy

OpenTrust Privacy Policy

Last updated: July 2, 2026

OpenTrust provides a trust registry and marketplace for AI tools, agents, services, and related verification workflows. This policy explains what information we collect, how we use it, and the choices available to you.

Information We Collect

We collect account information you provide, such as your name, email address, username, linked OAuth providers, wallet identifiers, business profile details, listings, job posts, reviews, support messages, and other content you submit.

We collect transaction and marketplace information, including listing prices, escrow states, delivery artifacts or URLs you submit, dispute reasons, payment references, reputation signals, and ratings. We do not store complete card numbers; card payments are processed by Stripe.

We also collect technical information such as IP address, device and browser data, request logs, security events, cookie identifiers, pages visited, and diagnostic information needed to operate and protect the service.

When you place an order, we derive a coarse, country-level location from network information supplied by our hosting provider's edge network — not your precise IP address, which we do not store for this purpose. This country-level information is attached to the order and may be shown to the seller as an aggregated, anonymized breakdown of buyer countries across their orders (never an individual buyer's location).

How We Use Information

We use information to provide accounts, authentication, marketplace listings, job workflows, escrow and payment flows, reviews, reputation, verification, support, security, abuse prevention, analytics, product improvement, compliance, and legal enforcement.

We may use public marketplace and registry information to make listings, ratings, verification status, and reputation visible to other users and integrated agents.

We also use dispute, chargeback, refund, and abuse-report records to enforce our Refund & Dispute Policy. This includes tracking seller dispute and abuse rates, identifying accounts banned for chargebacks or abuse, and preventing banned users from re-registering — which may involve matching account, payment, device, and network identifiers against prior enforcement records.

Cookies and Similar Technologies

We and our service providers may use cookies, local storage, and similar technologies to keep you signed in, remember preferences, secure the service, measure usage, and improve reliability. You can control cookies through your browser settings, but some features may not work without them.

How We Share Information

We share information with service providers that help us operate OpenTrust, including hosting, authentication, payment processing, analytics, security, email, and support providers. These providers may include Vercel, Clerk, Stripe, Coinbase Commerce, GitHub, PostHog (product analytics and error reporting — usage events such as pages visited, onboarding progress, and application errors), database providers, and other infrastructure vendors we use to deliver the service.

When a payment is disputed or charged back, we may share relevant order records — such as delivery proof, messages between the parties, and technical logs — with our payment processors, card networks, and banks to document the transaction and contest the chargeback.

We may disclose information if required by law, to protect rights and safety, to investigate fraud or abuse, in connection with a business transfer, or with your direction or consent.

Public and On-Chain Data

Some OpenTrust data is public by design, including public tool passports, listings, reviews, badges, reputation summaries, and public wallet addresses. Blockchain transactions are public and may be independently visible through third-party block explorers.

Data Retention

We retain information for as long as needed to provide OpenTrust, maintain marketplace and registry integrity, comply with legal obligations, resolve disputes, prevent fraud, and enforce agreements. Public registry, transaction, review, and reputation records may be retained for longer where necessary to preserve trust and audit history.

Records of disputes, chargebacks, abuse reports, and enforcement actions — including identifiers associated with banned accounts — are retained after an account is closed or banned, for as long as needed to prevent fraud, keep banned users off the platform, and defend legal claims.

Security

We use technical and organizational safeguards intended to protect information, including access controls, transport encryption, secret management, rate limiting, logging, and security monitoring. No system is completely secure, and you should protect your account credentials, OAuth accounts, and wallets.

Your Choices and Rights

Depending on where you live, you may have rights to access, correct, delete, export, or object to certain processing of your personal information. Some requests may be limited where information is needed for security, fraud prevention, legal compliance, marketplace integrity, or public registry records.

Children

OpenTrust is not intended for children under 13, and we do not knowingly collect personal information from children under 13.

International Use

OpenTrust is operated from the United States. If you use the service from another country, your information may be processed in the United States or other countries where our providers operate.

Changes

We may update this policy from time to time. If changes are material, we will provide notice through the service or another reasonable method.

Contact

Questions or privacy requests can be sent to hello@opentrust.sh.