1. Corporate Identity & Scope of Policy
This Privacy Policy applies to the web portal toolspot.tradesala.net, including all
micro-applications, WebAssembly modules, frontend assets, and subdomains ("the Website" or "the Tools"), owned
and operated by Tradesala Technologies Pvt Ltd, a private company incorporated under the laws
of the Republic of India (CIN: U74999TN2020PTC137626), with registered corporate headquarters at Old No. 85/3,
New No. 95/3, Naicker Street, Kadalaiyur, Kovilpatti, Thoothukudi, Tamil Nadu – 628902, India ("Tradesala",
"Company", "we", "us", "our").
As a web service accessible internationally, Tradesala is committed to maintaining full compliance with
applicable data protection laws, including the EU General Data Protection Regulation (EU
GDPR), UK GDPR, California Consumer Privacy Act (CCPA/CPRA),
India Digital Personal Data Protection Act (DPDPA 2023), Canada PIPEDA & Quebec
Law 25, Brazil LGPD, Australia Privacy Act 1988,
Singapore PDPA, Japan APPI, South Korea PIPA, South
Africa POPIA, and UAE PDPL.
2. Client-Side Architecture & Data Boundary Commitment
The 64+ applications hosted on Toolspot — spanning PDF manipulation (Merge, Split, Compress, eSign, Redact,
Protect, Unlock, PDF to Word), financial modeling (Income Tax, GST, EMI, SIP, NPS, FIRE, WACC, NPV, IRR),
health trackers (BMI, BMR, TDEE, Diabetes Risk, Blood Pressure), and developer utilities (Password Generator,
JSON Formatter, QR Code Generator) — are engineered with a strict Zero-Trust Client-Side
Architecture.
Client-Side Processing Guarantee: All document contents, uploaded PDFs, converted images,
financial numbers, health parameters, passwords, and user code execute exclusively within your local web
browser's volatile RAM memory using WebAssembly and HTML5 WebCrypto APIs. NO user files, converted documents,
input parameters, or calculation results are ever transmitted to, cached on, processed by, or stored on
Tradesala servers.
3. Automatically Collected Technical & Infrastructure Data
When you access the Website, standard web networking protocols require minimal infrastructure data for routing
and security:
- Anonymized Telemetry & Analytics: We utilize Google Analytics (configured with IP
anonymization) to measure aggregated traffic trends (browser family, device category, screen resolution,
country/region level location, referral URL, and duration). This telemetry data is fully aggregated and
cannot identify individual natural persons.
- Edge Security & CDN Infrastructure: The Website is delivered via Cloudflare, Inc.'s
network. Cloudflare processes technical network data (such as IP address, request headers, TLS ciphers, and
threat scoring) for DDoS defense, SSL handshake termination, and web application firewall (WAF) filtering.
- Server Access Logs: Web server diagnostic logs record standard HTTP request lines for
security diagnostic monitoring, automatically overwritten on a short rolling schedule.
4. Cookie Disclosures & Local Storage Policy
- Strictly Necessary Security Cookies: Cloudflare sets essential security cookies
(`__cf_bm`, `cf_clearance`) required to verify human visitors and prevent automated bot attacks. These are
exempt from consent requirements under EU ePrivacy / GDPR Article 6(1)(f) and US state laws.
- Analytics Cookies: Google Analytics sets non-essential cookies (`_ga`, `_gid`) to measure
aggregate site usage. You may opt out anytime using the Google Analytics Opt-out Add-on or by blocking non-essential
cookies in your browser settings.
- Local Browser Storage (localStorage): User preferences (e.g. Dark/Light mode theme
toggles) are stored locally on your device's browser `localStorage`. This data never leaves your device.
5. Absolute Prohibition on Data Monetization ("Do Not Sell or Share")
Tradesala maintains a strict commitment: WE DO NOT SELL, RENT, LEASE, BARTER, OR SHARE YOUR PERSONAL
INFORMATION OR BROWSING DATA WITH THIRD PARTIES FOR MONETARY OR OTHER VALUABLE CONSIDERATION. We do
not conduct cross-context behavioral advertising, user profiling, or automated credit scoring.
6. Third-Party Service Providers Disclosure
In accordance with data transparency laws, we disclose the sub-processors and infrastructure vendors that
support website delivery:
- Google LLC (Google Analytics & Fonts): Anonymized web analytics and font delivery. Google Privacy
Policy
- Cloudflare, Inc.: CDN hosting, DDoS mitigation, and WAF security. Cloudflare
Privacy Policy
- Cloudflare CDNJS: Delivery of open-source client JavaScript modules (JSZip, PDF.js,
SortableJS). No user files or personal data pass through these scripts.
7. Technical & Organizational Data Security (TOMs)
In compliance with GDPR Article 32, DPDPA 2023, and CCPA security requirements, Tradesala enforces robust
Technical and Organizational Security Measures. For full technical details on our cryptographic controls, edge
security posture, and Vulnerability Disclosure Program (VDP), please review our dedicated Security Policy:
- TLS 1.3 End-to-End Transit Encryption: All browser-to-edge traffic is encrypted using
modern cryptographic ciphers;
- Zero User Database Architecture: Absence of server databases hosting user files,
eliminating server data breach vectors;
- Strict Content Security Policy (CSP): Enforced security headers blocking unauthorized
cross-site scripting (XSS) or data exfiltration.
8. Technical Data Retention Policy
Because Toolspot operates via zero server storage of user files:
- User Uploaded Files & Tool Inputs: Retained for 0 seconds (erased
instantly upon browser tab closure);
- Analytics Data: Aggregated Google Analytics metrics are retained per standard settings
(26 months max);
- Security Infrastructure Logs: Purged within 90 days.
9. Regional Statutory Privacy Addendums
Depending on your country or state of residence, specific statutory data protection rights apply:
🇮🇳 India — DPDPA 2023 & IT Act 2000
Governing Law: Digital Personal Data Protection Act, 2023 & IT Act 2000.
- Data Principal Rights: Right to access summary of data processing, right to
correction and erasure, right to grievance redressal, right to nominate.
- Parental Consent: Minors under 18 require verifiable parental consent.
- Grievance Officer: Dedicated Indian Grievance Officer email at
[email protected].
🇪🇺 🇬🇧 European Union & UK — GDPR / DPA 2018
Governing Law: EU GDPR (2016/679), UK GDPR, ePrivacy Directive.
- Legal Basis: Legitimate Interest (Art. 6(1)(f)) for security/CDN; Consent (Art.
6(1)(a)) for analytics cookies.
- Data Subject Rights: Articles 15-22 Rights (Access, Rectification, Erasure "Right to
be Forgotten", Restriction, Data Portability, Objection).
- Data Transfer: Standard Contractual Clauses (SCCs) for infrastructure routing.
🇺🇸 United States — CCPA/CPRA & State Laws
Governing Law: California CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA.
- Do Not Sell/Share: Tradesala does NOT sell or share personal information.
- Shine the Light / Privacy Rights: Right to Know, Delete, Correct, and Opt-Out of
automated profiling. No financial incentive programs offered.
- Sensitive Data: We do not collect or infer sensitive personal information.
🇨🇦 Canada — PIPEDA & Quebec Law 25
Governing Law: PIPEDA & Quebec An Act respecting the protection of personal
information.
- 10 Fair Information Principles: Accountability, Consent, Limiting Collection,
Accuracy, Safeguards, Transparency, and Access.
- Quebec Rights: Right to de-indexation, portability, and explicit consent for
telemetry.
🇦🇺 🇳🇿 Australia & New Zealand — Privacy Act & APPs
Governing Law: Australian Privacy Act 1988 (APPs) & NZ Privacy Act 2020.
- Australian Privacy Principles: Open and transparent management, cross-border
disclosure protections (APP 8), and correction rights (APP 13).
🇧🇷 Brazil — LGPD (Law No. 13,709/2018)
Governing Law: Lei Geral de Proteção de Dados Pessoais (LGPD).
- Legal Bases: Article 7 Legal Bases (Legitimate Interest, Compliance).
- Data Subject Rights: Confirmation of processing, anonymization, blocking, deletion,
and portability (Art. 18).
🇸🇬 🇯🇵 🇰🇷 Asia-Pacific — Singapore PDPA, Japan APPI, South Korea PIPA
Governing Law: Singapore PDPA 2012, Japan APPI, South Korea PIPA.
- Consent & Notification: Clear notice of technical sub-processors and immediate
access deletion rights across APAC nations.
🇦🇪 🇿🇦 MEA — UAE Federal PDPL & South Africa POPIA
Governing Law: UAE Federal Decree-Law No. 45/2021 & South Africa POPI Act 2013.
- Data Protection Principles: Lawful processing, security safeguards, and right to
object to automated processing.
10. Data Subject Access Requests (DSAR) Procedure
Regardless of your physical country or state of origin, if you wish to submit a Data Subject Access Request
(DSAR) to inquire about, access, rectify, or delete technical telemetry data:
- Send an email to our Privacy Desk at
[email protected] with the subject line "Data
Subject Request (DSAR)";
- Specify your country of residence and the statutory right you wish to exercise (e.g. GDPR Art 17 Deletion,
CCPA Right to Know, DPDPA Access);
- Our Privacy Team will verify your request and issue a formal written response within 30
days (or within statutory timeframes mandated by your jurisdiction) without charge.
11. Children's Privacy Policy
Toolspot is not directed at children under the age of 16 (or 13 under US COPPA / 18 under India DPDPA). We do
not knowingly collect personal data from children. If you become aware that a child has accessed the Website
without parental consent, please contact us at [email protected] for immediate deletion of
associated telemetry metrics.
12. Cross-Border Data Transfers & Standard Clauses
By accessing the Website, technical network requests may route through CDN nodes located in the United States,
European Union, or Asia-Pacific. All cross-border infrastructure transfers comply with Standard Contractual
Clauses (SCCs) and adequacy decisions under international privacy frameworks.
13. Privacy Desk & Grievance Officer Contact
For all privacy inquiries, statutory rights requests, or supervisory authority complaints, contact our
corporate legal desk:
Privacy Notice: This Privacy Policy governs all users of Toolspot by Tradesala. Published by
Tradesala Technologies Pvt Ltd. All rights reserved under applicable data protection laws.