LEGAL
Privacy policy
Who we are
TradeGear is a hosted service for translating a website and for answering visitors' questions in their language. It has three parts: a plugin you install on WordPress, a dashboard where you manage your account and languages, and a chat page your visitors use. This policy covers all three, and the servers that run them.
The service answers at two addresses. app.tradegear.org serves the dashboard, the translation
service and the chat page your visitors see. assistant.tradegear.org connects websites,
receives the business knowledge you choose to share and answers visitors' questions. The plugin talks to
these two and to no other service of ours; if an administrator points it at their own deployment in its
advanced settings, that deployment's operator is responsible for it instead.
The provider is [registered company name], [postal address]. You can reach us about anything in this policy at hello@tradegear.org.
Who decides what
Your website is yours. You decide which features are switched on, which pages are translated, and which business content the assistant may use. We carry out those instructions on your behalf, so for your visitors' data you are the one who answers to them, and we are the service that acts for you. That is why the plugin offers a suggested paragraph for your WordPress privacy-policy editor: describe the features you actually enabled, and link to this page.
What we collect
Your account
When you create an account we hold your email address, the name of your workspace, the websites you register, the languages you choose and the plan you are on. Signing in is handled by Google's identity service, which tells us that an account is verified and which account it is; your password is never sent to us and we never see it.
Your website content, when you enable translation
The plugin sends the text of the pages being translated, a small set of attributes and metadata (for example image alternative text, page titles, and the descriptions a page publishes for search engines and social previews), each page's address, the source and target languages, and your site's identifier. It does not send your page's HTML, your WordPress users, your customers, your orders or your payment details.
To translate a page well we also read it as a whole, either by fetching the page from its public address or by having a website we cannot reach send us a copy. That copy is read for the meaning around each sentence and then discarded; what we keep is the short context we derived from it, not the page.
Two details are worth your attention:
- A page's address includes its query string. If a page address carries a search term,
a filter or a reference in the part after
?, that value is part of the record we keep for that page. Do not enable translation for a page whose address contains something you would not want stored. - Form text is page text. Labels, headings, button text and options inside a form are extracted and sent like any other visible text. Text typed into a field is not sent, and neither are WordPress administration, login, REST API and checkout paths — those are excluded by default. Account and order pages are not excluded automatically, so add a path exclusion for any page that shows a person their own information.
Your visitors' questions, when you enable the assistant
A message sent through the chat panel forwards the message text, the language it was asked in, and two random identifiers: one for the conversation and one for that single request. Nothing else goes with it — no IP address, no browser information, no page address, no WordPress user, no order. The conversation identifier is a random value held in a cookie on your site; it does not identify a WooCommerce customer and is not shared between websites.
Business knowledge, when you enable knowledge synchronization
Your WordPress site pushes its own published pages and the products visible in its catalogue: titles, descriptions, addresses, prices and availability. It is a one-way push, and it does not include drafts, private or password-protected pages, hidden products, or your cart, checkout and account pages.
When you switch the plugin off
The plugin reports its own state change: your website's identifier and a short reason — deactivated, activated or uninstalled. Nothing else is included, and nothing is erased. We use it to pause that website's translation, knowledge synchronization, assistant and billing while it is off, and to resume them on the same connection when it is switched back on.
Technical records
Our servers, and the cloud platform they run on, record the address of the machine that made a request, the path requested and the result. Those records are how the service is operated and kept safe. We do not join them to a visitor's conversation or to a page's translation record.
Cookies and browser storage
We do not use advertising or analytics cookies, and there is no tracking script on your pages or in the chat panel. These are the cookies our plugin sets on your website:
| Name | Set when | Purpose | Lifetime |
|---|---|---|---|
sd_lang | a visitor opens a translated page | remembers which language they chose | 30 days |
sd_test | an administrator opens a preview link | allows that administrator to preview translations before they are public | 7 days |
sd_assistant_visitor | a visitor opens the chat panel | a signed, random conversation identifier so a visitor's own turns stay together | up to 7 days |
Your WordPress site sets its own cookies for signing in to WordPress, and a shop sets its own for a cart or a customer session; those are yours to describe in your own privacy notice.
The chat panel keeps the transcript of the open tab in the browser's session storage, so it survives moving between pages. It is scoped to your site, the language and the conversation, and it is discarded when the tab is closed.
What we do not do
- We do not sell your data or your visitors' messages, and we do not build advertising profiles.
- We do not put tracking or analytics scripts on your pages or in the chat panel.
- We do not store a visitor's IP address alongside their conversation.
- We do not ask a visitor for payment details, passwords or identity documents, and we do not let the assistant claim to have checked an order or changed one.
- We do not send your content to a third-party model provider. Translations and answers are produced by language models we operate inside our own cloud environment.
Who else processes it
We use a small number of suppliers, each bound by its own agreement with us:
- Google Cloud — hosting, storage, the translation cache, the model inference we run there, and the secret store that holds service credentials.
- Google's identity service (Firebase Authentication) — account sign-in and email verification.
- Stripe — taking payment and managing a subscription, if you take a paid plan. Card details go to Stripe, not to us.
Your own WordPress site and its host also hold the credentials that connect it to us. If an advanced setting points the plugin at a deployment someone else operates, that operator's policies apply instead of this one.
How long we keep it
| What | How long |
|---|---|
| Translated text and the page addresses it was seen on | while the language is enabled. Turning a language off starts a short grace period of about twelve hours, after which that language's translations and its page addresses are deleted. |
| The context derived from reading a page, and the page summary built for it | kept while your website is connected. It is tied to the page's own text rather than to a language, so it survives turning one language off and is reused if you translate that page again. |
| Glossary terms you have approved, and usage records needed for billing | kept after a language is turned off |
| Cached translations used to serve pages quickly | 7 days |
| Chat conversations | 7 days after the last message, and only the most recent turns are kept |
| Business knowledge from knowledge synchronization | until your content changes, you switch the feature off, or you disconnect the website |
| Account, plan and billing records | while your account exists, and afterwards for as long as tax and accounting rules require |
| Server and platform logs | a limited period, under the retention settings of our cloud project |
Your choices
- Switch any feature off in the plugin. Translation, the chat launcher and knowledge synchronization each stop separately, and switching one off stops new data for it immediately.
- Exclude a path. The plugin takes a list of path exclusions, so a page that shows someone their own information can be left alone.
- Read any page untranslated by adding
?sd_notrans=1to its address. That request is not sent to us at all. - Disconnect a website in the dashboard. Its keys stop working, and the assistant forgets the site.
- Delete a language. Its translations are removed as described above.
- Cancel a paid plan in the billing portal. Your website stays online on the free plan and keeps serving what is already translated.
Access, export and deletion
Ask us and we will tell you what we hold, give you a copy, or delete it. There is no self-service button for this yet — email hello@tradegear.org and say which website you mean. We will confirm what we did.
For a chat conversation, deletion is normally unnecessary: conversations expire on their own after seven days of inactivity. If you need one removed sooner, write to the shop whose chat panel it was, and they can ask us to remove it.
Security
Traffic between your website and us uses HTTPS, and each website has its own credentials rather than a shared password. We do not write message content or credentials into our application logs.
One thing is worth stating plainly, because it is in your hands: the credentials that connect your website to us are stored in your WordPress database. Anyone who can read that database, or who has an administrator account on your site, can read them. Treat them as you treat your other site secrets, and rotate them by reconnecting the website if you think they have been exposed.
Changes to this policy
When this policy changes we change the date at the top, and we describe a material change in the plugin's update notes as well. Continuing to use the service after a change means the new version applies. If you do not agree with it, switch the features off or disconnect your website.
Contact
[registered company name], [postal address] · hello@tradegear.org
See also our service terms.