TradeClear

Privacy

Last updated 21 August 2026.

TradeClear holds business compliance records, not personal profiles. This page says exactly what it stores and who can see it.

Two kinds of people use TradeClear

General contractors sign in and see their own roster. Trade contractors never sign in at all. They receive a link, supply two things through it, and that is the whole of their interaction.

What is stored about a general contractor

What is stored about a trade contractor

These are business records about a business. TradeClear does not ask for or store personal identifiers such as dates of birth, social insurance numbers or banking details, from anybody.

Where it is stored

In Cloudflare D1 and Cloudflare R2, on Cloudflare's network. Uploaded documents are held in a private bucket with no public address, and are served only to a signed-in session on the deployment that owns them. Cloudflare's global network means data may be processed outside Canada. If your contracts require Canadian residency for these records, tell us before you sign up.

Text messages

A trade contractor's mobile number is used for one purpose: to text them a link asking for the documents the general contractor who engaged them requires, and to remind them when one of those documents is about to expire. The general contractor confirms, at the point of adding them, that the engagement is real and that the number was given to their company for work correspondence.

Replying STOP to any message ends them, and TradeClear records that and tells the general contractor so they can reach the business another way. Replying START turns them back on. Message and data rates may apply.

Mobile numbers are never sold, never rented, and never shared with anyone for marketing, by TradeClear or by anybody it uses. The full messaging programme, including every message the product can send, is on the text messages page.

Who it is shared with

Nobody, other than the four services that make the product work:

Nothing is sold and there is no advertising anywhere. Visits are counted, including on the dashboard, by Cloudflare Web Analytics. It sets no cookie, stores nothing in your browser, and cannot tell one visit from the same person twice or follow anyone to another site. Cloudflare serves every page here, so it already handles every request either way; the beacon only turns those into a count we can read.

Beyond that count, the dashboard sends nothing to any third party while you are reading it. No roster, no trade name and no document ever leaves this service.

Links in our own outreach

There is one exception to the paragraph above, and it is on the public pages rather than in the application. When we put a link to this site in an email we send, a post we write, or a newsletter an association carries for us, that link goes through an address of the form tradeclear.ca/go/… so we can tell whether anyone followed it. Sending mail nobody reads and sending mail people read and ignore are different problems, and we would rather know which one we have.

What is recorded when one of those links is followed is the campaign code we minted, the time, whether the request looked like a person or like a corporate mail scanner, and the name of the site that referred it. That is the whole list. There is no cookie, no identifier, no address, no browser fingerprint, and nothing that survives the visit or connects it to another one. Nothing here identifies a person, and neither does the visit count described above.

A trade contractor's documents

A certificate of insurance uploaded through a link is visible to the general contractor who sent that link, and to nobody else. Where the same trade business works for more than one general contractor, each of them sees the shared WSIB clearance history for that business, which is a public fact the province will confirm to anyone who asks, and each keeps their own separate record of what they have decided about it.

How long it is kept

Clearance records and certificates are kept for as long as the deployment exists, because their purpose is to answer a question an auditor may ask years later. Removing a trade contractor from a roster stops the checks but does not delete the history. To delete a deployment and everything in it, email us and say so explicitly.

Cookies

One, and it is the sign-in session. It carries no identifier that can be traced anywhere else, and it is set with HttpOnly, Secure and SameSite. There are no advertising cookies, the visit counting sets none, and the outreach links described above set nothing at all. The cookie policy goes through this in detail.

Getting in touch

hello@antipodetech.com
Ask for a copy of what is held about you, or for it to be deleted, at the same address.