Skip to content
Legal

Privacy & Terms

Last updated: August 27, 2026

Written in plain language during Taremint's pilot, and still under review with counsel ahead of general availability. It is not legal advice — but the data-handling commitments described below are binding on Taremint today. Questions? Email hello@taremint.com.

Privacy Policy

1. Who we are

Taremint Inc. (“Taremint,” “we,” “us”) is a company based in El Paso, Texas that helps US–Mexico border scrap yards intake, reconcile, and report manifest data. This policy explains what we collect, why, and the choices you have.

2. Information we collect

Account and contact details you provide — such as your name, work email, company/yard name, and the messages you send us through our forms.

Operational data you connect to the service — including WhatsApp and email manifests, scale tickets, vendor identifiers, weights, freight figures, and the documents attached to them.

Usage and device data — standard log information such as IP address, browser type, and timestamps, used to keep the service secure and reliable.

3. How we use your information

To provide the service: parse manifests, normalize them to the applicable state reporting standards (e.g., Texas DPS/TOM, Arizona AZDPS/LeadsOnline, New Mexico Recycled Metals), reconcile to your accounting system, and stage your reports.

To improve accuracy: corrections you make in the review queue are used to improve parsing for your account.

To communicate with you about your account, support requests, and the pilot, and to meet our legal and compliance obligations.

4. WhatsApp and manifest data

We only process messages from vendor numbers you approve at onboarding. Manifest content is used to produce your compliance and accounting records and is handled as your confidential business data, isolated per customer.

5. Google account data (Gmail intake)

If you choose to connect a Google mailbox, Taremint uses the Gmail API to read messages in that mailbox so we can retrieve the manifests, scale tickets, and supporting documents your vendors send you. We request a single permission — gmail.readonly — which is read-only. That permission cannot send, reply to, modify, label, move, or delete mail, or mark messages as read; this is not a promise we are making, it is the limit of the access we are granted.

What we retrieve and keep: the attachments and inline images that constitute manifest evidence, together with the message metadata needed to identify and de-duplicate them — sender, recipient, subject, date, message identifier, and mail-authentication results. We keep that evidence for as long as it is needed as a compliance record under the state recordkeeping requirements that apply to you. We do not retain the wider contents of your mailbox, we do not read messages outside the scope of this purpose, and you can ask us to delete it.

Who can see it: your documents are visible to users of your own Taremint account. Taremint personnel do not read your Google account data. This is enforced by access controls in our systems, not by policy alone.

Derived improvements: when a reviewer on your team corrects an extracted field, we learn only your vendor's form vocabulary and layout tendencies — never message content, field values, sender identities, or attachments. No content from your documents is shared with other customers.

Sharing: we do not sell Google user data, we do not use it for advertising of any kind, and we do not transfer it to third parties except as necessary to provide the features described above, to comply with applicable law, or as part of a merger or acquisition after giving you notice and obtaining your consent.

Your control: when a mailbox is connected, you can disconnect it at any time from your Taremint settings, which revokes our access. You may also revoke access directly at https://myaccount.google.com/permissions at any time. Disconnecting stops all future access; documents already processed remain in your compliance records unless you ask us to delete them.

Limited Use: Taremint's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Service providers

We share data with vetted subprocessors strictly to operate the service — QuickBooks Online (accounting sync), Amazon Web Services (hosting and storage), Google LLC (Gmail API mailbox intake and Cloud Pub/Sub notifications, if you connect a mailbox), Anthropic (document extraction), Meta (WhatsApp intake), Cloudflare (network protection and website hosting), Resend (transactional email and our pilot mailing list), Sentry (error monitoring), and Stripe (billing). We also use Google Analytics for website traffic measurement, which is separate from mailbox intake and covers this website only. We do not sell your data or share it for advertising.

7. Cookies and analytics

Our website uses Google Analytics to understand how visitors find and use the site — which pages are read, which links bring people here, and how many people request a pilot. This is aggregate website measurement; it is not connected to the manifest or compliance data inside the product.

Google Analytics sets cookies in your browser. We use Google Consent Mode, and these cookies stay switched off until you accept them in the banner shown on your first visit. If you decline, no analytics cookies are stored and we receive only anonymous, aggregate counts.

You can change your choice at any time using the “Cookie settings” link in the site footer, or by clearing cookies for this site in your browser.

8. Data retention

Compliance records are retained on a write-once basis for as long as the state recordkeeping requirements that apply to your operation require, so that a record you may be asked to produce still exists when you are asked for it. We are documenting that retention period with counsel and will state it here once it is settled. Other data is kept for as long as your account is active or as needed to provide the service, then deleted or anonymized.

9. Security

We use multi-tenant isolation, least-privilege access, encryption in transit, and per-customer storage separation. Taremint is not SOC 2 certified and does not represent itself as certified; a SOC 2 report requires an examination by an independent CPA firm. The platform is built to SOC 2 readiness. No system is perfectly secure, but we work to protect your data and to notify you of material incidents as required by law.

10. Your rights and choices

You may request access to, correction of, or deletion of your personal information, and you can export your data in QuickBooks-clean format on the way out. To make a request, email hello@taremint.com.

11. Changes and contact

We may update this policy as the product matures; we'll revise the “last updated” date above. For any privacy question, contact us at hello@taremint.com.

Terms & Conditions

1. Agreement

These Terms govern your access to and use of Taremint's website and services. By using the service you agree to these Terms. If you are using Taremint on behalf of a company, you represent that you have authority to bind that company.

2. The service

Taremint reads incoming manifests, normalizes them to applicable compliance standards, and helps you reconcile and report them. You are responsible for reviewing outputs before relying on them for filings or accounting.

3. Pilot / beta status

The service is offered on a pilot basis and may change, be interrupted, or contain errors. Features, pricing, and availability may evolve as we develop the product.

4. Acceptable use

Do not use the service unlawfully, attempt to disrupt or reverse-engineer it, upload content you don't have rights to, or use it to violate the rights of others.

5. Your data and ownership

You retain ownership of the data you submit. You grant us a limited license to process it solely to provide and improve the service for you, as described in our Privacy Policy. You can export your data on exit.

6. Fees

Paid plans are billed as agreed in your order or subscription. Pilot terms, if any, are set out separately in writing. Fees are non-refundable except where required by law.

7. Disclaimers

The service is provided “as is” without warranties of any kind. Taremint is a software tool and does not provide legal, tax, accounting, or regulatory advice. You are responsible for your own compliance determinations.

8. Limitation of liability

To the maximum extent permitted by law, Taremint will not be liable for indirect, incidental, or consequential damages, and our total liability is limited to the amounts you paid to us in the twelve (12) months before the claim.

9. Governing law

These Terms are governed by the laws of the State of Texas, without regard to conflict-of-laws rules. Venue for any dispute lies in the state or federal courts located in El Paso County, Texas.

10. Changes and contact

We may update these Terms; continued use after an update means you accept the revised Terms. Questions? Email hello@taremint.com.

Data Processing Addendum

1. Roles of the parties

For data you submit to the service, you act as the data controller and Taremint acts as the data processor, processing that data only on your documented instructions and as described in our Privacy Policy.

2. Scope and instructions

We process your data solely to provide the service — intake, parsing, normalization, reconciliation, reporting, and support. We will not use it for any other purpose, and we will inform you if we believe an instruction violates applicable law.

3. Subprocessors

You authorize Taremint to engage vetted subprocessors to operate the service: Amazon Web Services (hosting and storage), Google LLC (Gmail API mailbox intake and Cloud Pub/Sub notifications), Anthropic (document extraction), Meta (WhatsApp intake), Intuit (QuickBooks Online sync), Stripe (billing), Cloudflare (network protection and website hosting), Resend (transactional email), and Sentry (error monitoring). We impose data-protection obligations on each and remain responsible for their performance. We will give you notice before adding a new subprocessor.

4. Security measures

We maintain technical and organizational measures appropriate to the risk, including multi-tenant isolation, least-privilege access, encryption in transit, and per-customer storage separation. Taremint is not SOC 2 certified and does not represent itself as certified; a SOC 2 report requires an examination by an independent CPA firm. The platform is built to SOC 2 readiness.

5. Data-subject requests

We will assist you, taking into account the nature of the processing, in responding to requests from individuals to exercise their rights of access, correction, deletion, or portability.

6. Breach notification

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, and provide information reasonably available to help you meet your notification obligations.

7. Return and deletion

On termination, you may export your data in QuickBooks-clean format. We will delete or return your data thereafter, except where retention is required for compliance (for example, write-once records held for up to seven years).

8. International transfers

Where data is transferred across borders, we rely on appropriate safeguards and process it consistent with applicable law and this addendum.

9. Audit and contact

On reasonable request and subject to confidentiality, we will make available information necessary to demonstrate compliance with this addendum. For DPA matters, email hello@taremint.com.