Skip to content
TradeWeave legal documents background
Legal

Privacy Policy

Effective date: 14 July 2026

TradeWeave Inc. (“TradeWeave,” “we,” “us” or “our”) respects your privacy. This Privacy Policy explains what Personal Data we collect, the sources of that data, why we use it, how we disclose it, how long we retain it, and your rights and choices. It applies when you access or use our websites, applications, software, consulting services, and related offerings (collectively, the “Services”) or otherwise interact with us. This Policy is a notice of our practices and does not itself create consent where applicable law requires separate consent. Where consent is required, we will request it separately.

1. Why We Have a Privacy Policy

We publish this policy to:

Comply with laws such as the European Union’s General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), California Online Privacy Protection Act (CalOPPA), Children’s Online Privacy Protection Act (COPPA) and other local data‑protection laws;

Provide transparency about our data‑handling practices, including when we use analytics, cookies and payment systems; and

Enable customer-selected integrations, including ServiceTitan, Stripe, cloud and analytics providers, and mobile app stores, in accordance with applicable customer instructions and platform authorizations.

2. Personal Data We Collect

We collect information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to a particular person (“Personal Data”). The categories of Personal Data we collect include:

Contact and account information: name, business name, postal address, email address, telephone number and password.

Payment and billing information: partial credit‑card or debit‑card information (we collect this through Stripe, who stores your full payment details), billing address and tax ID.

Service usage information: records of purchases and subscriptions, customer support inquiries, preferences, communications, account settings and interactions with our software.

Technical and device information: IP address, browser type, operating system, device identifiers, log files, usage data and performance metrics (e.g., when you open the app or pages you visit). We may collect device location if you enable location‑based features.

Cookies and tracking information: we use cookies, pixel tags and similar technologies to collect data about your interactions with the Services (see Section 8 below).

Third-party and connected-platform data: we may receive information from service providers, resellers, social networks, partners, and integrations that you or your organization enable, including ServiceTitan. We combine third-party information with other data only where permitted by the applicable customer agreement, platform authorization, and law.

Optional information: when you participate in surveys or marketing programs or provide feedback, we may collect information you submit.

You may choose not to provide certain Personal Data. However, some Personal Data is necessary for us to provide our Services, such as account registration or processing payments.

2.1 Customer and Connected Service Data

At a business customer’s direction, and only within the tenants, endpoints, scopes, fields, purposes, and other limits approved by ServiceTitan or another connected platform, we may receive and process “Connected Service Data.” Depending on the customer’s configuration and enabled features, Connected Service Data may include:

Identifiers and contact information relating to the business customer, its personnel, technicians, contractors, prospects, and end customers.

Professional or employment-related information, including roles, schedules, assignments, permissions, and operational performance data.

Commercial and service records, including appointments, calls, dispatch records, jobs, estimates, opportunities, invoices, payment status and amounts, memberships, campaigns, pricebook information, equipment, inventory, forms, tags, business units, and related transaction and configuration data.

Communications and content, including notes, messages, attachments and, when specifically enabled and lawfully authorized, call recordings or transcripts.

Integration identifiers, authorization tokens, account configuration, system events, device or network activity, and security, synchronization, and diagnostic logs.

Inferences and derived information, including analytics, anomaly indicators, scores, forecasts, summaries, recommendations, benchmarks, estimated impacts, and artificial-intelligence outputs.

We may obtain this information from the business customer and its authorized users; ServiceTitan and other customer-authorized connected platforms; individuals interacting with the customer; our service providers; and information generated through authorized use of the Services. Not every category is collected for every customer. We limit collection to information reasonably necessary for approved functionality and governing written authorizations. Our analytics features do not need or intend to receive full payment-card credentials.

2.2 Our Role for Customer-Controlled Data

Our role depends on the processing context. For information used to administer our websites, accounts, billing, security, marketing, and business operations, TradeWeave generally determines the purposes and means of processing and acts as a data controller or “business.” When TradeWeave processes Personal Data supplied by a business customer or made available through an authorized connected platform solely to provide Services to that customer, TradeWeave generally acts on the customer’s documented instructions as a data processor, service provider, or contractor. The customer remains responsible for its notices, lawful bases, consents, and responses to individuals.

If TradeWeave determines the purposes and means of a separately authorized analytics or data-mining activity, TradeWeave acts as a controller or business for that limited activity and provides any additional notice, choices, and rights required by law. An applicable data processing agreement or customer agreement controls if it conflicts with this Policy.

3. How We Use Personal Data

We use Personal Data for the following purposes:

To provide and maintain our Services. We use your information to register and manage your account, deliver consulting and software services, process transactions, provide customer support and fulfill our contractual obligations.

To process payments and invoices. We share necessary billing information with Stripe to process payments. This includes sharing your contact, payment and transaction details. We use transaction data for internal accounting, fraud prevention and to provide invoices and receipts.

To communicate with you. We send administrative messages, such as account confirmations, invoices, billing notices, technical updates and service announcements. We also send marketing communications with your consent (you can opt out at any time).

To maintain and improve our Services. We use service telemetry and usage information to understand how users interact with the Services, develop features, and improve user experience. We use Connected Service Data for product improvement, cross-customer analytics, or model training or evaluation only within the separately authorized scope described in Section 3.1.

To comply with legal obligations. We process and retain information as required by law, such as tax reporting, anti‑fraud measures and responding to lawful requests from authorities.

To protect rights and safety. We use information to detect and prevent fraud, abuse, security risks and other harmful activity, to enforce our Terms and to protect the rights, property or safety of TradeWeave, our users and others.

For other purposes with your consent. If we collect and process Personal Data for other purposes, we will obtain your explicit consent or rely on other legal bases permitted under applicable laws.

3.1 Connected-Service Analytics, Data Mining and Artificial Intelligence

We use Connected Service Data to provide customer-authorized integrations, audits, monitoring, configuration-drift detection, data-quality analysis, reconciliation, revenue-leakage detection, anomaly detection, forecasting, reporting, alerts, recommendations, support, security, and approved remediation workflows.

Some features may use automated analytics or artificial intelligence to classify information, identify patterns, generate summaries or recommendations, estimate potential impact, or otherwise assist authorized TradeWeave personnel and customer users. Authorized personnel may review inputs and outputs for service delivery, support, security, and quality assurance.

Multi-tenant analytics, data mining, cross-customer benchmarking, sharing, artificial-intelligence processing or model development, and retention beyond an otherwise applicable platform limit occur only to the extent expressly permitted by TradeWeave’s then-current written authorization from ServiceTitan or the applicable connected-platform provider, the affected customer’s agreement or documented instructions, and applicable law. This Policy does not expand those rights.

Cross-customer outputs are aggregated or de-identified unless the governing platform authorization and each affected customer’s agreement expressly permit a tenant-identifiable disclosure. We use reasonable measures designed to prevent de-identified information from being associated with an individual or customer and do not attempt to re-identify it except as permitted by law to test or validate those safeguards.

Unless separately authorized in writing, we do not use Connected Service Data to train or improve a general-purpose or third-party model, allow a model provider to use it for that provider’s own purposes, generate synthetic training data from it, or permit an AI system to expand its own integration scopes or independently select additional API endpoints or fields. Analytics and AI outputs may be incomplete or incorrect and are not used by TradeWeave as the sole basis for a decision producing legal or similarly significant effects about an individual.

4. Legal Basis for Processing (GDPR/UK GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we only process your Personal Data when we have a lawful basis to do so. The legal bases include:

Consent: When you provide consent (e.g., by opting in to marketing emails or cookies);

Contractual necessity: To perform a contract or take steps at your request (e.g., to deliver Services you purchase);

Legitimate interests: To pursue our legitimate interests in operating our business, improving Services and preventing fraud, provided that such interests do not override your fundamental rights and freedoms;

Legal obligations: To comply with legal obligations (e.g., tax and accounting laws);

Vital interests and public interest: Where processing is necessary to protect an individual’s vital interests or for tasks carried out in the public interest.

5. How We Share Personal Data

We may share Personal Data with third parties in the following circumstances:

Service providers and business partners. We share information with vendors who perform services on our behalf, such as Stripe (payment processing), cloud hosting providers, analytics services, email providers, customer support tools and consultants. These providers are contractually required to use Personal Data only as necessary to provide services to us and to protect Personal Data.

Third‑party integrations. When you choose to integrate or use third‑party services (e.g., connecting your TradeWeave account to a calendar app), you authorize us to share relevant information with those services. Their handling of Personal Data is governed by their own policies.

Compliance with law and protection of rights. We may disclose Personal Data to law‑enforcement authorities, regulators or other third parties when we believe disclosure is necessary to comply with applicable laws or to protect the rights, safety or property of TradeWeave, our users or others.

Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy or sale of all or part of our business, we may transfer Personal Data. We will take reasonable steps to ensure the transferee uses Personal Data in accordance with this policy.

Aggregated or de-identified data. We may create, use, or disclose aggregated or de-identified information only where permitted by the applicable customer agreement, the written authorization of ServiceTitan or another connected-platform provider where applicable, and law. Such information does not include raw Connected Service Data and may not reasonably identify an individual or customer. We maintain safeguards against re-identification.

We do not sell Connected Service Data or disclose it for cross-context behavioral advertising or third-party marketing. We do not sell other Personal Data. Our website cookie practices are described in Section 6, and we provide any notice and choices required where applicable law treats a website advertising practice as a sale or sharing.

5.1 Connected-Service Recipients and Cross-Tenant Controls

Analytics and AI service providers. When an approved feature requires cloud hosting, data warehousing, analytics, security, or artificial-intelligence providers, we disclose only the information reasonably necessary for that provider’s role. Providers processing Connected Service Data must be bound by written confidentiality, security, use, retention, and deletion restrictions applicable to their services, including restrictions against independent use or model training except where separately authorized. TradeWeave remains responsible for its providers as required by applicable agreements and law.

Customers and approved recipients. Customer-specific Connected Service Data is disclosed only to the customer, its authorized users, connected platforms, and service providers needed to provide the Services, except where the governing ServiceTitan or platform authorization and the affected customer’s agreement expressly permit another recipient or cross-tenant use. We do not make one customer’s raw or identifiable Connected Service Data available to another customer.

6. Cookies and Tracking Technologies

TradeWeave uses cookies, web beacons, pixels and similar technologies (“Cookies”) to collect information about your interactions with our Services. Cookies help us provide core functionality, remember your preferences, understand usage patterns, personalize content and deliver advertisements.

6.1 Types of Cookies We Use

Strictly necessary Cookies: Required to operate the Services (e.g., authentication, security, payment processing). These Cookies cannot be switched off.

Performance and analytics Cookies: Help us measure and improve performance and understand how users interact with our Services.

Functional Cookies: Enable enhanced functionality, such as remembering preferences or settings.

Advertising Cookies: Used to deliver relevant ads and track the effectiveness of marketing campaigns.

6.2 Your Cookie Choices

Under the GDPR, we must obtain your explicit consent before activating non‑essential Cookies. We explain in our Cookie banner what data each Cookie collects, the purpose and how long it will be stored, and we record and store your consent. You may withdraw your consent at any time through our Cookie‑settings tool. If you refuse non‑essential Cookies, you will still have access to core functionality.

Most browsers allow you to set preferences for how Cookies are used. You can usually choose to block or delete Cookies. Note that removing or blocking Cookies may negatively impact your user experience and certain features may not function properly.

7. Marketing and Communications

We may use Personal Data to send you promotional messages, newsletters or marketing communications about our Services or partners. We will obtain your consent where required by law. You can unsubscribe at any time by following the instructions in the communication or contacting us. Users must be able to opt out easily, and we must honor the opt‑out requests.

8. Data Security

TradeWeave implements physical, electronic and procedural safeguards designed to protect Personal Data from unauthorized access, disclosure, alteration and destruction. Depending on the data and risk, these measures may include encryption in transit and at rest, de-identification, access controls, logging, tenant separation, selective deletion, backup and recovery controls, and incident response procedures. Despite our efforts, no security measures are perfect or impenetrable. We cannot guarantee absolute security of your information. In the event of a data breach, we will notify affected individuals, customers, connected-platform providers, and regulators as required by law or contract.

9. Data Retention

We retain Personal Data only for the period reasonably necessary for the disclosed purpose, subject to contractual and legal requirements. Account and billing information is retained for the customer relationship and applicable tax, accounting, dispute, and legal-compliance periods; integration credentials are retained only while a connection is active or as briefly needed to complete revocation and security logging; Connected Service Data, including raw records, derived records, and AI inputs and outputs, is retained only for the period permitted by the governing written platform authorization and customer agreement; security and diagnostic logs follow our documented security schedule; and cookie and marketing information is retained until its stated expiration, withdrawal of consent, or the end of the applicable purpose.

We maintain tenant-level segregation and the ability to identify and selectively delete Connected Service Data. When a customer disconnects or terminates an integration, authorization is revoked or expires, or deletion is required by ServiceTitan, the customer, or law, we stop the affected collection and delete, return, or de-identify the data within the governing timeframe. If multiple requirements apply, the shorter period controls unless law requires longer retention.

Data may remain temporarily in secured backups until overwritten under the regular backup schedule. It is not used for ordinary business purposes while retained only in backup, and any required deletion is reapplied if a backup is restored. Aggregated or de-identified information may be retained only when the governing authorization, customer agreement, and law permit it and the information cannot reasonably identify a customer or individual.

10. International Data Transfers

TradeWeave is based in the United States. If you are located outside the United States, your Personal Data may be transferred to, stored or processed in the United States or other countries with different data‑protection laws. We rely on appropriate safeguards, such as standard contractual clauses, to protect Personal Data transferred from the EEA or UK.

11. Your Rights and Choices

Depending on your location and applicable law, you may have certain rights regarding your Personal Data, including:

Access: The right to know what Personal Data we hold about you.

Correction: The right to request correction of inaccurate or incomplete Personal Data.

Deletion: The right to request deletion of your Personal Data in certain circumstances.

Objection/Restriction: The right to object to or restrict processing of your Personal Data.

Data portability: The right to request a copy of your Personal Data in a structured, commonly used, machine‑readable format.

Opt‑out of marketing: The right to opt out of marketing communications at any time.

Opt-out of sale, sharing, or targeted advertising: The right to opt out where applicable law defines and regulates those activities. As noted above, TradeWeave does not sell Personal Data or use Connected Service Data for cross-context behavioral advertising.

Non‑discrimination: We will not discriminate against you for exercising your rights.

To exercise your rights, please contact us using the information in Section 14. We may verify your identity before responding and may deny requests that are unfounded or excessive. We will respond to verifiable requests within the timeframe required by law.

If TradeWeave holds your information only as a processor, service provider, or contractor for a business customer, please direct your request to that business customer. TradeWeave will assist the customer with verified requests as required by the applicable agreement and law. If TradeWeave acts as the controller or business for the relevant processing, you may submit the request directly to us using Section 14.

Where applicable law provides these rights, you may also use an authorized agent, request that we limit qualifying uses or disclosures of Sensitive Personal Information, use a recognized opt-out preference signal, and access or opt out of qualifying automated decision-making technology. We will explain any applicable appeal process and will not discriminate against you for exercising a privacy right.

12. Children’s Privacy

TradeWeave does not knowingly collect Personal Data from children under 13 years of age (or the minimum age required in your jurisdiction). If we learn that a child has provided us with Personal Data without parental consent, we will delete it. If you believe a child has provided us with Personal Data, please contact us.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated policy on our website and update the “Effective date.” For material changes, we may provide additional notice, such as by email or a prominent notice. Material changes will apply prospectively unless applicable law and a valid agreement permit otherwise. If a change introduces a materially different or incompatible use of previously collected Personal Data, we will provide clear notice and obtain consent where required. Continued use alone will not be treated as affirmative consent where law requires a separate affirmative choice.

14. Contact Us

If you have questions about this Privacy Policy, our data practices or your rights, please contact us at privacy@tradeweave.co or by mail at:

TradeWeave Inc. 8051 N Tamiami Trail, STE E6, Sarasota, FL 34243, USA

We will respond to your inquiry within a reasonable timeframe.