CT
CarrierTrust
Language
Privacy

Privacy Policy

Version 2.0Effective 25 July 2026
Data controller

SIA JAKOVLEV CAPITAL

VAT ID: LV44103016716

Legal address: Kupriču iela 1E–93, Riga, LV-1021, Latvia

Email: support@carriertrust.eu

This Privacy Policy explains how SIA JAKOVLEV CAPITAL, operating CarrierTrust, collects, uses, stores, shares and protects personal data in connection with the CarrierTrust website, accounts, company profiles, reviews, replies, reports, verification, billing, analytics and support.

CarrierTrust is primarily a business-to-business platform. Company information may still contain personal data where a sole trader, director, employee, manager, representative, contact person, reviewer or other identifiable individual is involved.

1. Who is responsible for your data

SIA JAKOVLEV CAPITAL is the controller of personal data processed through CarrierTrust, unless a separate notice expressly states otherwise.

Privacy requests should be sent to support@carriertrust.eu. CarrierTrust may request information reasonably necessary to verify the identity and authority of the requester before disclosing, changing or deleting data.

2. Personal data we collect

The categories collected depend on how you use CarrierTrust. We seek to collect only data reasonably necessary for the purposes described in this Policy.

  • Account and authentication data: email address, user ID, authentication records, password-reset and email-confirmation events.
  • Company and representative data: company name, VAT number, country, company profile, role, owner or manager status, authority and verification information.
  • Content and interaction data: reviews, ratings, official replies, reports, appeals, support requests, attachments, evidence and correspondence.
  • Billing data: subscription, order, invoice, payment status, billing contact and tax information. Full payment-card details are normally handled by the payment provider rather than CarrierTrust.
  • Technical and security data: IP address, timestamps, browser, operating system, device type, user agent, approximate location derived from IP, logs, rate-limit and abuse-prevention signals.
  • Analytics and usage data: pages viewed, URL, referrer, search activity, company-profile interactions, campaign parameters, visitor and session identifiers and feature events.
  • Communication data: messages sent to support, legal, privacy, billing or media channels and related metadata.
  • Public and third-party data: information from public registers, public websites, licensed data sources, users, companies and service providers.

3. Sources of personal data

We receive data directly from users when they register, claim a company, publish content, purchase a service, submit evidence or contact us.

We may also obtain company-related and professional information from public registers, public websites, business directories, other users, the company concerned, contractors and technical service providers. Public availability does not remove the need to process personal data lawfully.

4. Purposes and legal bases

We process personal data only where a legal basis applies. The applicable basis depends on the purpose and context.

  • Contract and pre-contract steps: creating and administering accounts, providing requested platform functions, processing paid services, support and account communications.
  • Legitimate interests: operating and improving a B2B reputation platform, maintaining company profiles, enabling reviews and replies, protecting users and the platform, preventing fraud and abuse, moderating content, establishing or defending legal claims and measuring service performance where permitted by law.
  • Legal obligations: tax, accounting, court, regulatory, law-enforcement, sanctions and other mandatory requirements.
  • Consent: where we expressly request consent for a specific optional processing activity, including non-essential device storage or access where consent is legally required.
  • Protection of rights: investigating complaints, preserving evidence and enforcing agreements and platform policies.

5. Company profiles, reviews and public content

Company profiles, reviews, ratings and official replies are intended to be publicly visible. Public content may be indexed by search engines, copied by third parties, quoted in disputes or remain available in cached or archived form outside CarrierTrust's control.

Users must not publish unnecessary personal data, confidential information or documents containing personal data unless publication is lawful and necessary. CarrierTrust may redact, restrict or remove such information.

A reviewer’s personal identity is not necessarily displayed publicly, but CarrierTrust may retain account, company, technical and evidentiary data connected with the review for moderation, security and legal purposes.

6. Analytics, browser storage and similar technologies

CarrierTrust may use cookies, local storage, session storage and similar technologies for authentication, language preferences, security, session continuity, analytics and service improvement.

Analytics may include a first-party visitor identifier, session identifier, viewed URL, referrer, campaign parameters, browser, device and interaction events. These data help us understand usage, diagnose problems, measure campaigns, prevent abuse and improve the platform.

Technologies strictly necessary for the requested service may be used without consent where permitted. Where applicable law requires consent for non-essential analytics or access to information on a user’s device, CarrierTrust will rely on consent and provide a method to withdraw it. This Privacy Policy is information and does not by itself constitute consent.

7. Risk indicators and automated processing

CarrierTrust may calculate ratings, trust scores, risk levels, flags and similar indicators using reviews, ratings, platform rules, reported information and technical signals.

These indicators are informational and are not intended to produce a solely automated decision that creates legal effects or similarly significantly affects an individual. CarrierTrust may review, correct or override indicators and may provide a human review where required by law or platform procedure.

8. Recipients and service providers

We disclose personal data only where reasonably necessary for the purposes described in this Policy.

  • Hosting, database, authentication, storage and infrastructure providers, including services such as Supabase and Vercel.
  • Email, support, security, monitoring, analytics and communication providers.
  • Payment, billing, tax and accounting providers where paid services are used.
  • Professional advisers, insurers, auditors and contractors subject to appropriate duties.
  • Courts, regulators, law-enforcement bodies and other authorities where legally required.
  • A purchaser, investor or successor in connection with a genuine merger, financing, restructuring, asset transfer or sale, subject to appropriate confidentiality and legal safeguards.
  • Affected users or third parties where reasonably necessary to investigate a complaint, protect rights or resolve a dispute.

9. International transfers

We aim to use service providers and processing locations within the European Economic Area where reasonably possible. Some providers or their support, security or sub-processors may process data outside the EEA.

Where required, transfers are based on an adequacy decision, the European Commission’s Standard Contractual Clauses or another lawful safeguard. Information about applicable safeguards may be requested through the privacy contact.

10. Retention

We keep personal data only for as long as reasonably necessary for the relevant purpose, taking account of account status, content visibility, contractual obligations, security, backups, disputes, limitation periods and legal retention duties.

  • Account and profile data may be retained while an account or company relationship remains active and for a reasonable period afterwards.
  • Published content and associated moderation records may be retained while the content is available and afterwards where needed for disputes, repeat-abuse prevention or legal claims.
  • Billing, tax and accounting records are retained for the period required by applicable law.
  • Security and technical logs are retained according to operational and security needs and may be kept longer where an incident, investigation or claim requires it.
  • Backups may retain deleted data for a limited rolling period before secure overwrite.

11. Security

We use organisational and technical measures designed to protect data against unauthorised access, alteration, disclosure, loss and destruction. Measures may include access controls, authentication, encryption in transit, logging, backups, role-based permissions and service-provider safeguards.

No online service can guarantee absolute security. Users must protect their credentials, use a strong unique password and notify CarrierTrust promptly of suspected account compromise.

12. Your data-protection rights

Subject to the GDPR and any applicable limitations, an individual may have the right to access, rectify, erase, restrict or object to processing and, in certain cases, receive data in a portable format.

Where processing is based on consent, consent may be withdrawn at any time without affecting processing already carried out lawfully. Where processing is based on legitimate interests, an objection will be assessed against compelling legitimate grounds and the need to establish, exercise or defend legal claims.

Rights are not absolute. We may retain or withhold data where required by law, necessary to protect the rights of others, covered by legal privilege, or required for security, fraud prevention or legal claims.

13. How to make a privacy request

Send a clear request to support@carriertrust.eu and identify the relevant account, company or content. Do not send sensitive identification documents unless requested.

We may ask for reasonable verification and clarification. We normally respond within the period required by law. Manifestly unfounded or excessive requests may be refused or subject to a reasonable administrative fee where the law permits.

14. Complaints

We encourage you to contact CarrierTrust first so that we can investigate and respond.

You also have the right to lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija) or, where applicable, another competent EEA supervisory authority.

15. Children and sensitive data

CarrierTrust is a business platform and is not intended for children. Users must not submit children’s data or special-category personal data unless there is a clear lawful basis and the information is strictly necessary.

CarrierTrust may remove or restrict sensitive information and may request additional justification before processing it.

16. Third-party links

CarrierTrust may link to third-party websites and services. Their privacy practices are controlled by those third parties, and this Policy does not apply to their independent processing.

17. Changes to this Policy

We may update this Policy to reflect legal, technical, security or operational changes. The version and effective date appear at the top of the page. Material changes may be communicated through the platform, by email or by requesting renewed acceptance where appropriate.

Translations are provided for convenience. The English version governs in the event of inconsistency, to the extent permitted by mandatory law.

Privacy questions and requests may be sent to support@carriertrust.eu. Content-removal notices should follow the procedure on the Legal page.