Substrate

Privacy Policy

How Trash Club Insights handles personal information in Substrate — what we collect, why, who else touches it, and what you can ask us to do about it.

Last updated August 11, 2026·Trash Club Insights

1In short

We do not sell or share your personal information, and we never have. We run no advertising network, no analytics service and no third-party trackers. The only cookie Substrate sets is the one that keeps you signed in.

Your packaging data is yours. Specifications, weights, citations and filing records belong to the customer who entered them, are exportable on demand in an open format, and remain yours if you stop using Substrate.

This summary is written for speed and does not replace the sections below, which are the operative ones. This policy applies to substratereport.com, the Substrate producer application, the Substrate Supplier Portal and the Substrate PRO Console (together, the “Service”).

2Who we are

The Service is operated by Trash Club Insights (“we”, “us”). For personal information we handle for our own purposes — running accounts, securing the Service, corresponding with you — we are the business or controller, and this policy governs.

For the packaging, volume and filing data a customer loads into their workspace, we act as a service provider under the California Consumer Privacy Act (and a processor under equivalent laws). We handle that data on the customer’s documented instructions and for no other purpose. Where those instructions and this policy differ, the customer’s agreement with us governs, and personal information contained in customer data should be raised with that customer, who is the responsible party for it.

3Personal information we collect

The categories below use the labels California law uses, so that this section can be read directly against the statute. We collect no sensitive personal information as that term is defined by the CPRA — no government identifiers, no financial account numbers, no precise geolocation, no biometric, health, racial, religious or union data, and no contents of your private communications.

Identifiers

WhatYour email address, the display name you choose, and the organization you belong to.

SourceYou, when you create an account or accept an invitation — or the colleague or brand who invited you, who supplies your email address in order to send the invitation.

Account credentials

WhatA one-way bcrypt hash of your password, a count of consecutive failed sign-in attempts, and any resulting lockout expiry.

NoteWe never store your password. The hash is not reversible, and it cannot be read by the application role that serves the website.

Internet and device activity

WhatFor each active session: a SHA-256 hash of your session token, the browser user-agent string, and the times the session was issued, expires, and was revoked. We also record the time of your most recent sign-in.

NoteThe session token itself exists only in your browser cookie. Reading our session table yields nothing that can be replayed as a login.

Professional information

WhatYour role in your organization’s workspace, and — where you sign or submit a regulatory filing — the name and title you attest under, the portal you submitted to, any confirmation reference you record, and the time you did it.

Why it is unusualThis is a legal attestation, not a preference. See §9 on retention: it cannot be edited or deleted, and that is the point of it.

Records of your activity in the Service

WhatAn audit trail of changes made to data in a workspace — which account changed which field, from what value to what value, and when. On the PRO Console, a record of which analyst ran which query against reported data.

WhyBoth exist so that a figure in a filing can be traced to its origin years later, and so that access to competitively sensitive data is accountable. They are integrity controls, not behavioral profiling, and they are not used to evaluate you.

Commercial information

WhatCorrespondence you send us, and the record of a supplier’s consent to publish a specification to the brands that requested it.

What we do not collect

  • No advertising or cross-site tracking identifiers.
  • No analytics or product-telemetry service. The Service embeds no such script.
  • No precise geolocation.
  • No purchase of personal information from data brokers.
  • No consumer data. Substrate is a business-to-business tool; the packaging data it holds describes materials and weights, not people.

4Why we use it

We use personal information only for the purposes it was collected for:

  • To operate your account — authenticate you, keep you signed in, apply your role’s permissions, and let colleagues and counterparties identify you inside a workspace.
  • To secure the Service — detect and slow credential-guessing, expire and revoke sessions, and investigate suspected misuse.
  • To maintain the integrity of regulatory records — record who confirmed a figure and who attested a filing, so that a submission remains defensible for as long as the relevant state may question it.
  • To communicate with you — service notices, invitations you have been sent, and replies to your enquiries.
  • To meet our legal obligations — including responding to lawful requests and enforcing our Terms.

We do not use personal information to train machine-learning models, and we do not use it for automated decision-making that produces legal or similarly significant effects.

5We do not sell or share it

We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the twelve months preceding the date of this policy. We do neither today and have no plans to. Because we do not, there is no “Do Not Sell or Share My Personal Information” mechanism to offer — there is nothing for it to switch off.

Global Privacy Control and similar browser opt-out signals are therefore satisfied by default: the Service performs no sale or sharing that such a signal would need to stop.

6The wall between producers and the PRO

Substrate serves two sides of the same regulatory relationship: the producers who file, and the producer responsibility organization that receives filings. These run as two separate deployments, on two hostnames, holding two different database credentials. The PRO deployment holds no producer credential at all.

This is a privacy commitment as much as a competitive one. A producer’s specifications and draft figures are not reachable from the regulator-side application, and what the PRO side can see of reported data is governed by an aggregation policy that suppresses cells derived from too few contributors.

7Cookies

Substrate sets one cookie, substrate_session. It holds your session token, it is strictly necessary to keep you signed in, and it is not used for analytics or advertising. It is set HttpOnly and Secure, so it is unreadable by scripts and never travels over an unencrypted connection.

Because it is strictly necessary, no consent banner is required for it, and blocking it will prevent you from signing in. We set no other cookies, and no third party sets cookies through the Service.

8Who else touches your data

We use two subprocessors, both in the United States. Each is bound by a data-processing agreement restricting them to processing on our instructions:

Vercel Inc.

PurposeApplication hosting and content delivery. Serves the Service and processes request traffic.

Supabase, Inc.

PurposeManaged PostgreSQL database hosting. Stores the data described in §3, in the AWS US-West-2 region (Oregon).

Beyond these, we disclose personal information only: to a customer’s own administrators within their workspace; where you direct us to (a supplier publishing a specification to a brand that asked for it); to professional advisers under confidentiality; where required by law or valid legal process; and to an acquirer in a merger or sale of assets, subject to this policy continuing to apply.

We will maintain a current list of subprocessors and give customers notice of additions in accordance with their agreement with us.

9How long we keep it

Account records are kept for as long as your account is active. When an account is closed we delete or de-identify the account record within 90 days, except where §9’s filing carve-out applies.

Sessions expire on their own schedule and expired rows are purged routinely.

Correspondence is kept for up to 24 months.

Sealed filings and their attestations are permanent, and cannot be deleted. When a filing is sealed it is cryptographically chained to the one before it and becomes append-only in the database — corrections are recorded as amendments, and nothing is overwritten. The name and title of the person who attested it are part of that record.

This is deliberate and it is the product’s central promise: a regulator may question a submission years later, and California’s SB 54 carries penalties reaching $50,000 per day per violation. A filing history that could be quietly edited would be worthless as evidence. We cannot honor a deletion request that would break that chain, and §11 explains the legal basis for declining one.

Audit trails of changes within a workspace are retained for the life of the workspace, for the same reason, and are deleted with it.

10How we protect it

We maintain administrative, technical and physical safeguards appropriate to the data we hold. Specifically:

  • All traffic is served over TLS, with HTTP Strict Transport Security enforced.
  • Passwords are stored only as bcrypt hashes, and the database role that serves the website cannot read the column they are in.
  • Session tokens are stored only as SHA-256 hashes, so a database read cannot be replayed as a login. Sessions are revocable.
  • Producer and PRO data are separated at the credential level rather than by an application-layer filter, as described in §6.
  • Repeated failed sign-ins lock an account for a period, limiting credential-guessing.
  • Access to production data is limited to personnel who need it to operate the Service.

No system is perfectly secure, and we do not claim otherwise. Where a breach of personal information occurs we will notify affected individuals, our customers and the relevant authorities as required by applicable law, in the most expedient time possible and without unreasonable delay. Suspected vulnerabilities may be reported to legal@trashclubventures.com; we will not pursue good-faith security research that respects our users’ privacy and does not degrade the Service.

11Your rights

If you are a California resident, the CCPA as amended by the CPRA gives you the rights below. We extend the same rights to everyone who uses the Service, regardless of where you live, because operating two standards is how the weaker one becomes the real one.

  • To know what personal information we have collected about you, the sources, the purposes, and the categories of third parties it was disclosed to.
  • To access a copy of that information in a portable format.
  • To correct inaccurate personal information.
  • To delete personal information we hold about you, subject to the exceptions below.
  • To limit the use of sensitive personal information — noted for completeness; we collect none, so there is nothing to limit.
  • To opt out of sale or sharing — again noted for completeness; we do neither.
  • Not to be discriminated against for exercising any of these rights. We operate no financial incentive program tied to personal information.

Where we may decline a deletion request

The statute permits a business to retain information necessary to comply with a legal obligation, to maintain the security and integrity of a system, or to complete a transaction. Two of our records fall squarely inside those exceptions:

  • Filing attestations. The name and title attached to a sealed regulatory filing is part of a record made to satisfy a state law, and both we and our customer may be required to produce it. We will not remove it.
  • Audit trails. Removing a row from an integrity log defeats the log. We will restrict its use rather than erase it.

Where we decline in part, we will tell you which part and why, and we will action the remainder.

If you are in the EEA or the United Kingdom

The Service is offered from the United States and is directed at US regulatory programs. If you nevertheless use it from the EEA or the UK, you additionally have the rights of restriction, objection and portability, and the right to lodge a complaint with your supervisory authority. Our lawful bases are the performance of a contract (operating your account) and our legitimate interests in securing the Service and maintaining the integrity of regulatory records.

12How to exercise your rights

Email legal@trashclubventures.com from the address associated with your account, or write to us at the address in §17. Please tell us which right you are exercising.

We will acknowledge within 10 business days and respond substantively within 45 calendar days, extendable once by a further 45 days where the request is complex — we will tell you if that happens. There is no fee unless a request is manifestly unfounded or excessive.

Verification. We verify a request by confirming control of the account email, and for higher-risk requests by asking for information that matches what we already hold. We will not ask you for a government identifier. An authorized agent may act for you with written permission that we can verify with you directly.

If your personal information sits inside a customer’s workspace, we will refer your request to that customer, tell you we have done so, and assist them in responding.

13Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. We have no actual knowledge of having sold or shared the personal information of anyone under 16 — and as §5 records, we perform no sale or sharing at all. If you believe a child has provided us information, write to legal@trashclubventures.com and we will delete it.

14Changes to this policy

We review this policy at least annually, as California law requires, and update it when our practices change. The “last updated” date at the top of this page always reflects the current version.

Where a change materially reduces your rights or materially expands how we use personal information, we will give account holders notice — by email or in the Service — at least 30 days before it takes effect.

15Business contact information

Most personal information in the Service is business contact information: a work email, a name, a job title. California’s partial exemption for such information expired on 1 January 2023, and this policy therefore treats it with the same rights and protections as any other personal information. We mention this because policies written before that date often still carve it out, and it is a difference worth being explicit about.

16Your data belongs to you

Separately from the rights above, and as a matter of how Substrate is sold: the packaging specifications, weights, citations and filing records in a customer workspace belong to that customer. They are exportable on demand in an open, documented format, they are versioned, and they remain the customer’s if they stop using Substrate.

What we own is the Substrate platform itself, which customers license. The distinction matters and we keep it sharp: owning your data is not the same as owning the software, and neither claim is a substitute for the other.

17Contact us

For privacy questions or to exercise a right: legal@trashclubventures.com. For anything else, see our contact page.

Trash Club Insights
PO Box 1067

Indian Hills, CO 80454

© 2026 Trash Club Insights
PrivacyTermsContact