TRUST CENTER

Trust & Security

This page is maintained by the ClocheVerse team to answer common security and privacy questions about the ClocheVerse marketplace. It describes the controls and practices we operate today. It is not an independent certification, audit report, or legal guarantee.

Last updated: June 22, 2026 · Maintained by the ClocheVerse team.

Account access & authentication

  • Accounts are protected by email + password sign-in and optional Google sign-in.
  • Sessions are managed by our authentication provider and stored as short-lived tokens in your browser. You can sign out from any device in Settings.
  • Password resets are sent to the verified email address on file.
  • Role-based access is enforced server-side. Admin actions require a server-verified admin role.

How your data is protected in the app

  • Each request runs against row-level security policies so users can only read or modify rows they are entitled to.
  • Sensitive profile fields (phone number, VAT / registration numbers, verification documents, saved addresses, account-status flags) are hidden from other signed-in users. Only you can read your own copy through secured server functions.
  • Booking and unavailability notes you add to your calendar are visible only to you.
  • Public marketplace pages expose only the fields needed to discover suppliers and staff (display name, avatar, country, ratings, public listings).

Platform & hosting context

ClocheVerse runs on managed cloud infrastructure operated by Lovable and its underlying providers. The platform provides encryption in transit (HTTPS/TLS) for traffic between your browser and our servers, and encryption at rest for the managed database and object storage layers. We rely on the platform's standard backup and patching schedule maintained by the provider.

Data we collect & how we use it

  • Account data: the information you enter in sign-up, business profile and verification (name, company, country, contact details, documents you upload).
  • Marketplace activity: listings, availability, bookings, orders, reviews, recommendations and follows that you create.
  • Operational data: sign-in events, login device label and approximate location used to show your active sessions and detect unfamiliar logins.

We use this data to operate the marketplace, match buyers with suppliers and staff, process bookings, send transactional notifications and prevent abuse.

Subprocessors & integrations

We use a small set of trusted providers to deliver the service — for example our cloud database / authentication provider and our email delivery provider. Where you connect an optional third-party integration (for example a social sign-in), data sharing with that provider is scoped to what is needed to make the integration work.

If you need a current list of subprocessors for a procurement or DPA review, please contact us using the details below.

Cookies & analytics

We use the cookies and local storage entries required to keep you signed in and to remember your preferences. We do not sell personal data. Any product analytics we enable are scoped to improving the ClocheVerse product and are documented in our privacy notice.

Retention & deletion

  • You can deactivate or request deletion of your account from Settings → Account.
  • Deletion requests start a 30-day recovery window. After that window, your profile and personal data are removed; aggregate, anonymised records (for example completed-order counts) may be retained for legal, accounting and fraud-prevention purposes.
  • You can export or correct your profile information at any time from the same Settings page.

Reporting a security issue

If you believe you have found a vulnerability or a privacy issue in ClocheVerse, please tell us before disclosing it publicly. Email us at security@clocheverse.example with a description of the issue and steps to reproduce. We will acknowledge receipt and keep you informed while we investigate.

Privacy requests & contact

For privacy-related requests (access, correction, deletion, portability) or general security questions, contact us at privacy@clocheverse.example or open a ticket from Support.

The information on this page describes practices we operate today and may evolve as the product changes. It is not legal advice and does not create a contractual commitment. For specific compliance, DPA, certification or audit questions, please contact us so we can share the relevant documentation.