Privacy
What we store, who processes it, and how to get it all back.
Last updated 9 September 2026
TerpIQ is software a licensed hemp retailer runs for its own shop. Two different groups of people touch it, and they are treated differently on purpose: the shop staff who sign in, and the members of the public who use a shop’s product finder. Shoppers never get an account, and nothing we keep about a finder session identifies one.
Shop staff who sign in
Signing in creates a Clerk account holding your name, email address, and which shops you belong to with which role (owner, manager, or staff). Clerk is our authentication processor and the only place account passwords exist — TerpIQ never sees one. Clerk’s sign-up flow may load a Cloudflare bot check in a frame.
Inside the product we mirror the parts we need to enforce who can read what: your user id, your role, and your shop. Dashboard actions that change a shop’s public exposure or its records are written to an audit trail with the user id that made them.
Shoppers using a shop’s finder
A finder session stores the answers given and the products matched. It stores no IP address, no user agent, and no cookie id, so two visits cannot be joined to one person. Counter codes are randomly generated and link to nothing but the session row.
We do not ask shoppers for a name, an email address, or a phone number anywhere in the finder, the kiosk, or the embedded widget.
When a shopper arrives from The Strain Finder directory carrying answers already given, those answers are held here for ten minutes, used once, and referenced by an opaque id. The answers are deliberately kept out of the URL: a URL is written to browser history, to referrer headers, and to every access log in between, and a shopper’s stated sensitivities are health-adjacent.
Rate limiting and forms
Unauthenticated routes are rate limited. We do not store the caller’s address: it is reduced to a /24 network and hashed with a server-side secret before anything is written, so the stored value cannot be reversed into an address. The marketing contact form uses a signed token minted when the page rendered, a honeypot field, and the same limiter. There is no CAPTCHA.
Lab reports and the extraction model
COA PDFs a shop uploads are stored in Supabase Storage. Each one is sent once to Anthropic’s API to read its fields into structured chemistry, which a person then reviews before it counts. Request and response bodies from that call are never written to a log or an error report, and every shop can turn extraction off and enter batches by hand. Anthropic does not train models on this traffic.
Connected inventory systems
A shop may connect its own POS or store platform — Blaze, WooCommerce, a REST endpoint, a hosted file, or a spreadsheet. The credentials for those live encrypted with AES-256-GCM in a database column that no tenant role can read at all, and they are never returned by any API, never logged, and never leave the database.
Billing
Subscriptions run through Stripe. Card numbers are entered on Stripe’s own checkout and billing pages and never reach TerpIQ — we hold a customer id, a subscription id, and the current status. Stripe tells us when that status changes.
Operational messages to shop owners — welcome, sync failures, trial notices, contact-form replies — are sent through Resend. These are short plain-text messages; we do not run marketing sequences, and there is no tracking pixel or click wrapper in them.
Hosting and error reporting
The application runs on Netlify, which receives the requests it serves, and the database and file storage are Supabase. No third-party error-reporting or analytics service is enabled: there is no such SDK installed and nothing is sent to one. If that ever changes, the scrubbing rules that keep lab data, credentials, PINs, and shopper answers out of any report are already written and enforced in code, and this paragraph gets rewritten before it ships.
The complete list of processors is therefore: Clerk, Supabase, Stripe, Anthropic, Resend, Netlify, and Cloudflare’s bot check inside Clerk’s sign-up flow. Nothing else receives data from TerpIQ.
Cookies
Signed-in staff get session cookies from Clerk. Shopper surfaces run without a Clerk session at all for visitors who have none, and the marketing pages set no advertising or analytics cookies.
Keeping, exporting, and deleting
A shop’s records are kept for as long as its account exists. Handoffs from the directory expire after ten minutes and are single-use; nothing else is deleted on a schedule, and we would rather say so than describe a cleanup job we do not run.
You can export everything your shop has — products, batches, lab reports, sessions, and settings — as a file, at any time, including after cancelling. Cancelling does not lock you out of your own records.
To have a shop’s data deleted outright, ask us on the contact page and we will remove it and confirm in writing.
Where this applies
TerpIQ is operated from the United States and its processors are US-based. This page describes the system as it is built; if you need something in it changed for your own obligations, tell us before you buy rather than after.