Legal

Privacy Policy

Network accounts, verification, authorized sharing, and individual rights.

Effective date: September 21, 2026

TraidSafe Inc. ("TraidSafe," "we," "us," or "our") provides a persistent identity network and related services, including CardTrade and technology used through participating partner portals. This Policy explains how we collect, use, disclose, retain, and protect personal information in Services that link to it and how you can exercise your rights.

One individual has one TraidSafe network account. Whether you first enroll through CTCA, CardTrade, TraidSafe, or another participating service, we create your TraidSafe account or connect you to the one you already have. Relevant, lawfully maintained history can follow that identity across authorized connections. This does not give every participant access to your records or authorize every type of screening.

This Policy is a privacy notice, not a standalone authorization for a background check, biometric processing, ongoing monitoring, or optional marketing. Where specific consent is needed, we request it separately before that processing.

1. Our role and Partner relationships

A "Partner" is a participating association, marketplace, platform, or other organization. A "Program" is its membership, certification, marketplace, or other connected service. Your TraidSafe account is distinct from, but linked to, your Partner account. CardTrade is owned and operated by TraidSafe and uses the same core privacy framework.

TraidSafe determines the purposes and operation of its network account, identity matching, duplicate prevention, authorized history and reporting, and related consumer-rights functions. For that processing, we are independently responsible under applicable law; we are not acting only on a Partner's instructions. A Partner controls its own Program administration and decisions. We may separately process information solely on a Partner's instructions, such as hosting training or membership records. Our responsibilities follow the actual activity.

When you enroll through CTCA or another Partner, both this Policy and the Partner's applicable notice explain their respective activities. This Policy does not govern an independent Partner's separate business or unrelated websites. You may contact us about TraidSafe processing without first obtaining the Partner's permission. We assist or route requests involving Partner-controlled records as appropriate while addressing our own obligations. The CTCA portal notice is at https://portal.thectca.org. The TraidSafe terms are at https://TraidSafe.com/terms. Those notices do not merge the organizations or let CTCA change the purposes of our independent network processing.

2. Information we collect and where it comes from

We collect information relevant to the features you use, directly from you, from connected Partners and transaction participants, from verification and other service providers, from lawful record sources, and through use of the Services. Not every category is collected from every person. The feature's notice identifies sensitive information requested before collection. "Collect" includes processing by a provider acting for us; it does not necessarily mean TraidSafe stores a separate copy of every source file. Section 11 explains retention by category.

Account and contact information. Name, email, telephone number, postal address, TraidSafe identifier, login credentials or authentication references, preferences, and linked account identifiers. We obtain these from you, the enrolling Partner, and account activity to establish, match, secure, and support your account and communicate with you.

Identity documents and identifiers. Date of birth, legal name and relevant prior names, document images and details, address evidence, and government identifiers such as a Social Security number only when specifically requested for an authorized feature. Sources include you, verification providers, and permitted identity sources. We use them for identity verification, record attribution, and account recovery, not as public profile fields.

Selfies, liveness media, and biometric-related information. Photos or video supplied for verification, facial measurements or templates where generated, liveness and comparison results, and verification outcomes. These are processed by the relevant verification service and, where applicable, TraidSafe for the disclosed purpose. The biometric notice identifies the processing, permitted recipients, and retention schedule before required consent. A selfie and a biometric template are not interchangeable data categories.

Screening and monitoring information. Authorized criminal-record or sex-offender-registry search results, potential matches, record and disposition details, source identifiers, retrieval dates, alerts, review outcomes, disputes, and corrections. We receive these from authorized providers, lawful sources, the relevant Program, and you for the requested screening, review, and monitoring functions.

Membership, certification, and business-role information. Program identifiers, membership and certification status, issue and expiration dates, training completion, quiz results, and relevant business names, roles, and registration information when a business-related feature is requested. Sources include you, the Partner, Program activity, and approved verification sources. We use these to operate the requested feature and provide authorized status verification.

CardTrade transaction and payment information. Deal participants, item descriptions, photographs and videos, Digital Coin records, transaction messages, agreed terms, shipping addresses and tracking, confirmation events, payment and payout references, subscription history, billing information, claims, and resolutions. Sources include you, counterparties, payment and shipping providers, and transaction activity. Payment information requested and any direct collection by a processor are identified in the payment flow.

Network history and reputation. Relevant positive and negative feedback, reported incidents, supporting evidence, source decisions, restrictions, responses, and correction history from connected services and authorized reporters. We also create association, review, report-version, and delivery records. We use these to associate permitted history with the correct person, provide authorized reports or statuses, investigate errors, and notify affected recipients.

Technical and security information. IP address, device and browser characteristics, operating system, session and authentication events, usage and error logs, and fraud or duplicate-account signals actually used by the feature. These come from your device, our systems, and relevant security providers. Approximate location may be derived from an IP address. Precise location or additional device permissions require a separate feature disclosure and applicable permission.

Communications, consents, and request records. Support messages, complaints, evidence you supply, notices and their versions, acceptance and withdrawal events, case references, investigation steps, and communications with sources and recipients. We use these to respond, document authorizations, resolve errors, comply with law, and maintain proportionate accountability records.

3. Purposes and limits on use

We use information to establish and maintain your TraidSafe identity; prevent duplicate or fraudulent identities; connect requested services; perform authorized verification, screening, and monitoring; administer memberships, training, certification, transactions, payments, and protection features; provide authorized history and status reporting; respond to access requests and disputes; deliver corrections; support and secure the Services; and meet lawful recordkeeping and legal obligations.

We use only information reasonably necessary for the disclosed purpose. When law requires consent, we obtain it before the processing. Where applicable law permits another basis, such as performing a requested service, a specific legal obligation, or proportionate security activity, we use that basis only within its limits. A general reference to fraud prevention does not authorize every use of sensitive information.

We do not use identity documents, government identifiers, biometric information, screening reports, or private incident evidence for targeted advertising or unrelated general-purpose AI model training. We may use appropriately deidentified or aggregated operational information to evaluate reliability, security, and service quality. Information is not treated as deidentified merely because a name is replaced with an account code; we maintain required safeguards and do not attempt reidentification except where law permits verification of those safeguards.

4. Verification within our interface and consent records

Verification may occur within a TraidSafe or Partner interface using technical connections to service providers. A provider may receive information through those connections without you being redirected to its website. The relevant notice and Verification Service Provider Disclosures identify the provider processing applicable to the feature.

For activities requiring affirmative consent, the enrollment or feature flow presents the applicable terms, disclosures, and authorization before processing. We record the accepted version, time, associated person and Program, and other evidence needed to document the permission. We may send the required consent confirmation and identifying details to a provider. A provider API response or a general account-acceptance event is not treated as a substitute for a separate authorization that is required for the activity.

Account acceptance, biometric permission, background-screening authorization, monitoring scope, Partner data sharing, and optional marketing are tracked according to their distinct purposes. A later materially different purpose or connection receives the additional notice and consent required for it. You may ask about the authorizations associated with your records through Section 16.

5. Persistent identity and sharing between connected services

At first enrollment, we check whether you already have a TraidSafe identity. We reuse the existing account when a match is established and create one only when none exists. We use the identity information and verification results appropriate to that process and apply additional verification or review to uncertain matches. A shared name, changed email, or potential match should not by itself attach someone else's history to you.

Your identifier is intended to remain associated with you across connected services. This allows relevant positive history, certifications, transaction experiences, and lawfully reportable negative history to follow the person rather than a replaceable username. We keep source information and context and distinguish allegations, opinions, substantiated facts, and the source's own decision. Calling information a platform incident does not remove applicable access, accuracy, reporting, or privacy requirements.

If CTCA changes its technology provider, that change does not turn TraidSafe's independent network account into CTCA property or authorize continued CTCA access. Migration of CTCA-controlled records is handled separately under lawful instructions and the applicable agreement, without overriding your rights or other individuals' privacy.

A new Partner connection identifies the Partner, purpose, and categories requested before any consent-dependent exchange. We provide only the information authorized for its role and purpose, which may include identity confirmation, account linkage, credential status, relevant reportable history, or specified screening information. A basic verification status does not imply permission to view a full report, document image, biometric template, or all network activity.

Partners do not obtain unrestricted access merely by participating in the network. They must use information within the approved purpose and applicable restrictions. A former Partner may receive a narrowly scoped correction about a report it previously received without regaining access to new reports. Reusing an identity does not necessarily mean reusing an old background check; current information or renewed authorization may be needed.

CTCA may supply relevant membership, certification, feedback, and disciplinary records with source information and context to the TraidSafe network as explained during enrollment. Those records may remain associated with your identity when CTCA ends, but only for justified, lawful retention and use. A later marketplace receives private information only under its own approved purpose and the applicable new connection authorization. It is not automatically entitled to a copy of the CTCA file.

6. Recipients, providers, and public information

Service providers. We disclose necessary information to providers performing hosting, identity verification, authorized screening and monitoring, payment processing, shipping, support, security, communications, and other requested functions. Their access is limited by their role, contract, applicable notices, and law. We may change providers subject to required notices, permissions, and contractual obligations; a change does not authorize an undisclosed new purpose.

The Verification Service Provider Disclosures at https://TraidSafe.com/legal/verification-providers identify providers for sensitive verification functions and their policy links. They are accessible without a paid account and linked from the collection flow. The biometric disclosure panel identifies required legal entities, purposes, data, and retention terms before consent. Necessary provider identities are not withheld merely because the main policies use functional provider descriptions.

Partners and transaction participants. Partners receive the limited information described in Section 5. CardTrade transaction counterparties may receive the contact, shipping, transaction, and status information needed to complete the requested deal or resolve a dispute. They do not thereby receive your raw identity or screening records.

Public features. A public profile, review, or credential lookup shows only the fields identified for publication in that feature. A certification lookup may show name, city and state, membership or certification identifier, status, and issue or expiration dates. The applicable Program notice identifies the actual fields and lookup method. Date of birth, private email or telephone number, full residential address, government identifiers, identity images, biometric information, and raw screening reports are not published through a credential lookup. Public information can be copied by others; contact us about correcting or removing content within our control.

Other permitted recipients. We may disclose information to professional advisers, in response to valid legal process, to meet legal duties, or to protect rights and safety where law permits. We assess the request and disclose only what is appropriate. In a merger, financing, reorganization, or business sale, information may be reviewed or transferred with appropriate confidentiality, security, notice, and continuing privacy obligations. The transaction does not erase existing permissions or consumer rights.

7. Screening, monitoring, and withdrawal

A separate disclosure and authorization apply before screening or enrollment in consent-based ongoing monitoring. The applicable flow identifies the requesting Program, purposes, checks, recipients, and duration or stopping event. Monitoring may use repeated searches or provider alerts for specified source updates. It does not mean continuous camera, microphone, location, or general activity surveillance. The Enrollment Summary states whether the selected membership or certification includes monitoring; not every membership is assumed to have that requirement. Monitoring starts only at the stated trigger and ends at the stated stopping event. A paid renewal is not itself a substitute for a fresh authorization when one is required.

Source reporting and identity matching may produce delays, incomplete information, or wrong-person matches. We use review and accuracy procedures appropriate to the activity and provide a way to challenge results. An alert is not automatically a final finding. Automated document review, facial comparison, identity matching, or fraud indicators may assist verification and review. You may request human review of a challenged identity association or screening result. Where a law provides additional explanation, review, or profiling opt-out rights, those rights apply. A Partner is responsible for its own decisions; we remain responsible for ours and for our processing.

Contact us to withdraw permission for a specified Program or request that all consent-based monitoring stop. We accept the request, assess its scope, stop processing that depends on that permission, coordinate provider cancellation, and confirm the outcome. We explain a material effect on features that lawfully require current monitoring. Withdrawal does not reverse completed lawful processing, but it is not permission to repurpose the data.

If CTCA ends while another Program continues, only the other Program's independently valid scope may continue. When no valid authority remains, monitoring stops. Account persistence, stored history, a records request, or a dispute does not renew monitoring. A request concerning one Program does not silently grant or extend another Program's access. A request received through CTCA is coordinated with TraidSafe so the affected provider enrollment is addressed. Canceling automatic billing without withdrawing current authorization ordinarily stops the next renewal, not the already authorized period; you may expressly withdraw current monitoring separately.

8. Biometric information

Where a feature processes biometric identifiers or biometric information, we provide the applicable notice and obtain the required specific consent before collection or disclosure. The notice explains the purpose, relevant collection and processing, recipients, and retention period. The separate Biometric Information Policy provides the public retention and destruction schedule and applicable withdrawal or alternative-method process. Consent to general Terms or this Policy alone is not a biometric release.

Biometric processing is limited to the disclosed identity or authentication purpose. We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. We restrict disclosure to authorized recipients or another legally permitted ground. Information is protected using safeguards appropriate to its sensitivity and permanently destroyed under the applicable schedule and any earlier legal deadline. A retained photograph does not authorize recreating a biometric template after its permitted purpose ends.

A persistent TraidSafe identifier is not a promise to retain biometric templates for the life of the account. Provider-specific storage arrangements and retention periods are described in the applicable notices rather than assumed to be identical for every verification, screening, and monitoring feature.

9. Access to reports, disputes, and corrections

Free access. You may request the disclosable information in your TraidSafe consumer file, available reports we maintain about you, relevant source information, and recipient information without a fee. This includes relevant network history and corrections, not just a pass/fail badge or a provider's report. Access remains available if your application was denied, account is suspended or closed, or membership ended. It does not require a new subscription, screening purchase, biometric scan, or marketing permission.

Where FCRA file-disclosure requirements apply, we provide the required source information and identify recipients that obtained reports within the applicable lookback, generally one year for nonemployment purposes and two years for employment purposes. We provide required contact details and the applicable official Summary of Your Rights Under the Fair Credit Reporting Act. This Policy is not a replacement for that summary. We protect other people's information and limit disclosures only on a lawful basis, not simply because a source is commercially confidential. We do not recreate records lawfully deleted merely to answer an access request.

Submit a dispute. Contact us through Section 16 and identify the item and concern as clearly as you can. You may challenge identity attribution, incorrect facts, incomplete or missing dispositions, duplicate entries, source attribution, misleading missing context, or information that should not be reported. You may submit supporting evidence through a secure method. No special wording is required, and you need not first contact the source or prove the error conclusively. Disagreement with an honest opinion does not necessarily make it false, but factual claims and attribution remain reviewable.

Investigation. We examine relevant evidence, our own records and matching, and source information, then correct or delete inaccurate, incomplete, or unverifiable reported information as appropriate. Ordinary FCRA reinvestigations generally conclude within 30 calendar days, with an additional period only where law permits. Required written results under that procedure are sent within five business days after completion. Different statutory processes and shorter deadlines control where applicable. Source handoffs do not restart the applicable clock.

We identify disputed information appropriately during review and apply reporting restrictions where needed or required. We provide the result, a revised report where applicable, and available next steps. A dispute does not automatically prove falsity, remove accurate and lawfully reportable history, or guarantee Program approval. You do not directly edit an official report.

Corrections and unresolved disputes. We update affected TraidSafe records and derived results and send necessary corrections to identifiable affected recipients. We do not allow a corrected or excluded item to persist as an unexplained negative flag. You may request a description of an applicable FCRA investigation procedure, submit a brief dispute statement for inclusion where required, and request legally available notices to designated prior recipients. We apply required safeguards and notices before reinserting information deleted following a qualifying dispute. Further review and regulatory complaints remain available without waiving legal rights.

Special requests. Identity theft, qualifying human-trafficking information, and other legally protected information may have separate blocking or exclusion procedures and accelerated deadlines. Tell us the concern so we can route it appropriately; an ordinary wrong-person dispute does not automatically require an identity-theft report. The Consumer Report Access, Dispute and Correction Policy provides additional procedures, including applicable notices and unresolved-dispute rights. We do not charge for this process or penalize good-faith use of it.

10. Cookies, advertising, and privacy choices

We use cookies or similar technologies for login, session security, preferences, functionality, and, where implemented and permitted, service analytics. Nonessential tracking is subject to the disclosures and choices applicable to the activity and jurisdiction. Browser settings can limit cookies, although disabling necessary cookies may affect functionality. A browser's general "Do Not Track" setting is not the same as a legally recognized opt-out preference signal.

Partners may pay for verification, reporting, or other Services. Payment for a service does not itself authorize additional uses of your information. Any disclosure that is legally treated as a sale or sharing is subject to the applicable disclosures and privacy choices. We do not use the sensitive records identified in Section 3 for targeted advertising.

We honor applicable opt-out rights and recognized preference signals, including Global Privacy Control, for the processing to which they apply. Requests do not require account creation or identity verification where law prohibits it. You may also contact us under Section 16. A privacy choice does not itself cancel monitoring or a subscription; use the applicable process for that request.

11. Retention, account closure, and deletion

We retain personal information only as long as reasonably necessary for a disclosed and lawful purpose, subject to applicable rights and shorter legal deadlines. We assess the data's sensitivity, active relationship, statutory requirements, security need, and specific transactions, claims, or disputes. A continuing purpose must be justified; keeping everything indefinitely is not the consequence of having a persistent identity.

Identity and account references. We retain the identifier and necessary matching attributes while supporting your network relationship and, where justified and lawful, afterward for duplicate prevention, security, or resolving existing matters. Closure triggers a review of continued need. A hashed or coded identifier remains personal information when it can be linked to you and is subject to applicable rights.

Identity documents and biometrics. Raw documents, source photographs, and biometric templates have their own purpose-specific schedules. We do not automatically retain them for the life of the network identity. The applicable biometric schedule and earlier purpose-completion or statutory destruction deadlines control biometric data. Legally required destruction is not postponed by an ordinary business preference.

Screening and monitoring records. We retain relevant results during the authorized purpose and for justified legal, accuracy, or dispute needs. Ending monitoring stops new updates; we delete or minimize related records when their lawful retention purpose ends. Restricted evidence preserved for a specific legal duty or claim is not an unlimited active screening archive.

Network history and reportability. Relevant feedback and incidents may remain associated with an identity after the original Program ends only while their continued retention and use are lawful and justified. We assess retention separately from whether an item may be reported to a particular recipient. Applicable record-type, event-date, purpose, and jurisdiction restrictions control; there is no blanket seven-year storage period for every category. An import, rerun, or new Partner link does not restart a reporting-age limit.

Transactions, credentials, consents, and disputes. We retain these records for the active feature and justified periods needed for completion, protection claims, accounting, audits, authorization evidence, investigations, or legal obligations. Technical logs are retained for proportionate operational and security periods. A specific legal hold limits use to the justified purpose rather than creating ongoing permission to report adverse information.

When a deletion requirement applies, we address relevant providers, copies, derived records, and backups under the applicable deadline and restoration controls. Where a lawful exception requires retention, we restrict the remaining use and explain the basis when required. We do not silently republish deleted or corrected information from a backup or recreate a hidden eligibility record from material that must be excluded.

12. Security and international processing

We use reasonable technical, administrative, and organizational safeguards appropriate to the information and risk, including access restrictions and controls intended to protect sensitive information in storage and transmission. No system is perfectly secure. We provide incident notifications and cooperation required by law. A service provider's security certification is not a certification of TraidSafe itself.

TraidSafe operates in the United States, and information may be processed there even when you reside elsewhere. Processing in additional countries depends on the relevant providers and disclosed arrangements. Information processed abroad may be accessible to public authorities under that country's laws. We use legally required safeguards; acceptance of this Policy does not waive a required transfer assessment, agreement, restriction, or consent.

13. Additional privacy rights and appeals

Depending on applicable law, you may request confirmation of processing; access, correction, deletion, or a portable copy of personal information; information about recipients; withdrawal of consent; limits on specified sensitive-information uses; opt-outs from sale, sharing for cross-context behavioral advertising, targeted advertising, or covered profiling; and explanation or review of certain decisions. We do not unlawfully discriminate or retaliate against you for exercising these rights. Some information may be exempt from a particular privacy law while remaining subject to another law or our stated commitments.

Contact us through Section 16. We verify identity proportionately before releasing sensitive information, allow authorized agents where law permits, and provide alternative verification if your account is inaccessible. We request only information reasonably needed to protect the records and do not require a new biometric scan simply to exercise a right. Opt-outs are handled without verification where required. You need not establish FCRA coverage before we accept an access or accuracy request.

We respond within applicable deadlines, notify you of a permitted extension, and explain a denial where required. If you disagree, reply with "Privacy Appeal" and the request reference, or contact the same team by another listed method. We provide the applicable appeal process and regulatory escalation information. An internal appeal does not prevent a complaint to an appropriate regulator or suspend statutory rights.

For California residents, Sections 2, 3, 6, 10, and 11 identify the collection categories, purposes, recipient categories, sale/sharing information, and retention criteria. Sensitive information may include government identifiers, account credentials, biometrics used for identification, and other data classified as sensitive under applicable law. Applicable know, correction, deletion, sale/sharing opt-out, sensitive-use limitation, and nondiscrimination rights are available through the methods described here. Other U.S. states may provide additional rights, including recipient details, appeals, and profiling choices.

A report dispute or special blocking request is handled under its own applicable procedure and clock, not delayed under a longer general privacy-request period. We may retain or withhold specific information only on a lawful basis and remain responsible for our own records even when a provider or Partner is involved.

14. Canadian users

Where Canadian privacy law applies, we identify purposes at or before collection and obtain meaningful consent when required. Sensitive identity, screening, and biometric processing receives the applicable express and specific consent. An optional purpose is not made mandatory simply by placing it in this Policy.

You may request access or correction, ask about providers and processing locations, withdraw consent subject to lawful limits and reasonable notice, or challenge our practices. We explain material consequences when a withdrawn permission is necessary for a requested feature. Contact the Privacy Lead identified in Section 16. You may also contact the Office of the Privacy Commissioner of Canada or the relevant provincial regulator. Local requirements apply where they provide additional protections; a U.S. reporting process does not replace them.

15. Age limits and changes to this Policy

The Services are intended for people who are at least 18 and the age of majority where they reside. We do not knowingly enroll children in identity screening or monitoring. Contact us if you believe a child has submitted information so we can investigate and take appropriate action.

We update this Policy to reflect changes in practices or requirements, display the revised effective date, and provide required notice of material changes. We obtain new consent before a new use or disclosure when required. An updated Policy does not retroactively expand an earlier authorization or permit unrestricted reuse of existing records.

16. Contact and related notices

Privacy and consumer-rights contact: TraidSafe Inc., Privacy Lead / Consumer Rights Team, 16039 W Sawyer Rd, Hayward WI 54843.

Email: support@cardtrade.com. This address handles TraidSafe requests from all entry points, including CTCA and other Partners. Secure request form: https://TraidSafe.com/privacy-request. No paid account or active membership is required to contact us or exercise the access and dispute rights described here.

Describe the request in your own words; a special subject line is not required. Do not send unredacted identity documents, full Social Security numbers, or full payment-card details by ordinary email. We provide a secure route for necessary evidence and reasonable assistance for accessibility or lost-account issues.

Related notices are listed below. Each relevant enrollment links to the applicable approved versions. Separate authorizations and required official rights summaries are provided in addition to this Policy; these links do not replace them.