data_handling · 2026-08

Effective date:
2026-08-01
Language:
en
Published:
2026-08-23T22:58:16.598878+00:00
Status:
current
Digest:
758646bee1adcb7e55590ad5e0b1767fa6f2ccce87574ce49fd2e8906eba8f2f
Computed as:
sha256 over pegtrace.legal-doc-text.v1
Data Handling and Subprocessor Disclosure PEGTrace LLC | Last Updated: August 2026 This Data Handling and Subprocessor Disclosure describes the third-party technology providers and material data-routing practices supporting the PEGTrace website, public fraud-report intake, public wallet-exposure check, public verification portal, authenticated Platform, AI-assisted features, evidence-packaging workflows, and related services. This disclosure is intended to communicate PEGTrace’s current operational practices as of the date above. It does not independently create contractual warranties or a separate assent, arbitration, liability, or entire-agreement regime. Contractual obligations applicable to an institutional or professional customer are governed by the Terms of Service, and applicable order form, data processing agreement, or negotiated agreement. PEGTrace may update this disclosure as its providers, services, and technical architecture evolve, subject to any notice or approval rights established in an applicable agreement. 1. Scope and Key Terms 1.1 “AI Coach” means an artificial-intelligence-assisted feature intended to explain application functionality, interface navigation, and workflow mechanics, subject to the Terms of Service, Privacy Policy, and this disclosure. 1.2 “Case Data” means identifiers, transaction hashes, notes, documents, analytical observations, metadata, and other case-related information submitted to or generated through the Platform by or for a user. 1.3 “Evidence Ledger” means the hash-linked chronological record of designated Platform events that is designed to make subsequent alteration detectable. 1.4 “External Providers” means third-party services from which PEGTrace or a user may request blockchain, breach, device-risk, domain, wallet, smart-contract, or other external intelligence, or through which PEGTrace may obtain supporting operational services. Depending on the service and applicable arrangements, an External Provider may operate as a Technology Subprocessor or as an independent third party. 1.5 “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual. Personal Data may include information contained in Case Data, account and contact information, technical and usage information, payment and transaction information, communications, generated reports, and audit or verification records. 1.6 “Platform” means the PEGTrace web application, public verification portal, cryptographic hashing engine, evidence-packaging workflows, and application programming interfaces operated by PEGTrace LLC. 1.7 “Technology Subprocessors” means third-party service providers engaged to support Platform operations, as identified in this Data Handling and Subprocessor Disclosure. 2. Core Technology and Infrastructure Providers 2.1 Lovable—Application Hosting, Deployment, AI Gateway, and Transactional Communications Support. PEGTrace uses Lovable to support application development, deployment, hosting, edge-runtime operations, integrated artificial-intelligence routing, and transactional communications. Because Lovable supports the application layer, it may process or have access to Personal Data, Case Data, application logs, and related technical metadata handled through the Platform, subject to PEGTrace’s configuration and any applicable agreements. 2.2 Supabase—Database, Private Storage, and Authentication Services. PEGTrace uses Supabase for its managed database, private object storage, authentication, and related backend services. Supabase may process account email addresses, authentication records, Case Data, uploaded files, generated records, audit information, and related metadata. Password credentials are handled and hashed through the managed authentication service; PEGTrace does not receive or maintain users’ raw passwords. Case and tenant separation is implemented through row-level security within a shared database architecture rather than through separate databases or physical storage environments. 2.3 Cloudflare and Cloudflare R2—Network, Security, Routing, and Evidence-Export Storage. PEGTrace uses Cloudflare for domain-name-system services, content delivery, traffic routing, distributed-denial-of-service mitigation, and web-application security. Cloudflare may process internet-protocol addresses, device and browser information, request and security logs, and Platform traffic. PEGTrace also uses Cloudflare R2 for a weekly export containing designated append-only evidence records. That export excludes ordinary case records, derived-entity records, and the designated encrypted sensitive-data table and is not a complete backup of the Platform. Deletion from the active Platform does not automatically propagate to previously exported objects. 2.4 GitHub—Public Trust-Anchor Repository. PEGTrace has implemented a mechanism intended to use GitHub to publish periodic cryptographic root or trust-anchor values that may support comparison with designated Platform verification records. PEGTrace does not intend to publish underlying Case Data, source documents, victim identities, report contents, or user-level activity through the public repository. Published values may reveal aggregate activity volume and cadence even though they do not disclose the underlying content. A published value may nevertheless remain linkable to other information depending on the accompanying metadata and the manner in which the repository is maintained. 2.5 Transactional Communications. PEGTrace uses its integrated hosting and email infrastructure to send authentication messages, password-reset communications, security notices, and other transactional messages. Information transmitted may include the recipient and sender addresses, subject line, rendered message content, message-purpose label, and delivery metadata. PEGTrace maintains delivery-status and error records concerning these communications. PEGTrace does not currently provide SMS communications or use a separate marketing-email provider through the Platform. 2.6 ElevenLabs—Authenticated Text-to-Speech Services. PEGTrace uses ElevenLabs to provide text-to-speech functionality on authenticated analyst surfaces. When an authenticated user invokes this functionality, ElevenLabs receives the text selected for spoken guidance and the voice or configuration information required to generate the audio. This integration is not currently available through PEGTrace’s public or consumer-facing services. Provider-side logging, retention, human review, and other processing are governed by the terms applicable to PEGTrace’s implemented account and configuration. 2.7 Cloudflare Turnstile—Bot and Abuse Prevention. PEGTrace uses Cloudflare Turnstile on its public fraud-report intake and wallet-exposure-check functions. Turnstile receives the applicable challenge token and internet-protocol address and may process browser, device, interaction, and related technical information as necessary to evaluate the request and prevent automated abuse. 3. Artificial-Intelligence Provider and AI Coach Data Handling 3.1 Lovable AI Gateway—Authenticated AI Services. PEGTrace routes authenticated AI-assistant requests through the Lovable AI gateway. The underlying model provider is not independently verifiable from the presently reviewed codebase, and PEGTrace therefore does not identify a particular underlying model vendor in this disclosure. The user’s browser does not contact the gateway or underlying model service directly. PEGTrace’s server may transmit applicable system instructions; limited interface and route context; a static navigation-destination catalogue; prior conversation turns; and the text submitted by the authenticated user. Depending on the invoked function, the server may also transmit limited aggregate case context, consisting of the case number, identifier count, and attachment count; an on-screen form schema containing field names and types but not field values; or, when expressly authorized for that message, the literal text of a designated field. By code design, the server-assembled payload does not include identifier values, wallet addresses, attachment contents, victim statements, or evidence bytes. The AI service has no direct access to PEGTrace’s database, object storage, tools, attachments, or Evidence Ledger. PEGTrace does not use artificial intelligence to generate consumer report output. Consumer output is produced through deterministic templates and canonical hashing. The AI assistant is restricted to authenticated administrative surfaces, and consumer-submitted free text is not transmitted to the AI gateway. 3.2 Prohibited and Restricted Inputs. Users must not submit to the AI Coach private keys, seed phrases, passwords, authentication credentials, full payment-card or bank-account information, privileged communications, or Case Data and Personal Data prohibited by the interface instructions or the Acceptable Use Policy. PEGTrace applies pre-transmission controls to certain legal-advice and identity-attribution requests and limits the Case Data automatically assembled by the server. PEGTrace does not, however, scan or block every item of Personal Data that a user may type into the AI Coach. Text entered by the user is transmitted as entered, and users therefore must not submit prohibited or unnecessary sensitive information. 3.3 PEGTrace Logging and Retention. PEGTrace stores case-scoped AI Coach questions and responses by user and case for up to ninety (90) days, after which a scheduled process deletes them. PEGTrace also records an audit entry showing that an AI request occurred, the actor, and the message count, but not the prompt or response content. PEGTrace does not use AI Coach conversations for its own model training, benchmarking, analytics, or product-development purposes, and the Platform does not provide PEGTrace personnel with a dedicated interface for reviewing those conversations. 3.4 Provider Retention and Model Training. Provider-side logging, retention, human review, safety monitoring, and model-training treatment are governed by the terms applicable to PEGTrace’s AI-gateway and model-provider accounts. PEGTrace does not represent that zero-data-retention treatment or another particular provider-side practice applies unless confirmed for the implemented account and configuration. 3.5 AI Outputs and User Review. AI-generated responses may be inaccurate, incomplete, or inappropriate for a particular matter. Users are responsible for independently reviewing AI outputs and must not treat them as legal, investigative, regulatory, financial, or other professional advice or as a substitute for professional judgment or source verification. 3.6 Changes to AI Services. PEGTrace may replace or supplement its artificial-intelligence provider or materially modify the AI Coach’s processing architecture. PEGTrace will reflect a material provider or processing change in a subsequently published version of this disclosure, subject to any notice or approval obligation expressly established in an applicable written agreement. 4. External Blockchain and Intelligence Providers PEGTrace may transmit selected identifiers or other query information to External Providers when a user initiates a supported analytical workflow. The particular information transmitted depends on the provider, query, and Platform configuration. Wallet addresses, transaction hashes, email addresses, internet-protocol addresses, domains, and similar identifiers are not necessarily anonymous merely because a person’s name is omitted. 4.1 Bitquery—Blockchain Data and Transaction Information. PEGTrace uses Bitquery through its public wallet-exposure check, which transmits the submitted wallet address and selected blockchain network. Bitquery functionality is not called through the public fraud-report intake. Additional crypto-tracing endpoints are available through authenticated analyst workflows and may transmit wallet addresses, transaction hashes, blockchain-network identifiers, token or contract addresses, query parameters, or related technical information required for the requested analysis. PEGTrace does not intend to transmit victim names, narrative case notes, uploaded documents, or unrelated Case Data through this integration. 4.2 Have I Been Pwned—Breach and Exposure Information. PEGTrace uses Have I Been Pwned to determine whether an email address or domain appears in identified breach or exposure data. This functionality is available through the authenticated analyst workflow and is not called from PEGTrace’s public or consumer-facing services. For email-account searches, PEGTrace transmits the full plaintext email address to the provider through a server-side request. The email address is not converted to a SHA-256 hash or submitted through a partial-hash or k-anonymity method. Domain searches transmit the complete domain. PEGTrace records the requesting actor and number of addresses checked without placing the queried addresses themselves in the associated audit entry. Provider-returned breach names, dates, and exposed-data categories may be associated with the applicable case and included in generated materials. 4.3 IPQualityScore—Network, Domain, and Device-Risk Information. PEGTrace may use IPQualityScore to obtain risk or reputation information concerning supported network or online identifiers. This functionality is available through the authenticated analyst workflow and is not called from PEGTrace’s public or consumer-facing services. Depending on the enabled service, PEGTrace may transmit internet-protocol addresses, domain names, URLs, email addresses, telephone numbers, device-related information, or other query identifiers selected by the user or generated through the applicable workflow. For device-fingerprinting workflows, the provider’s collector script executes in the browser of the device being evaluated and generates a request identifier that PEGTrace uses to retrieve the resulting evaluation. The resulting information may include fraud scores, emulator or tampering indicators, operating system, browser, connection type, country, network operator, and a device identifier. PEGTrace does not intentionally transmit the querying analyst’s PEGTrace account or case identifier through that integration. PEGTrace will limit the integration to the categories reasonably necessary for the enabled service. 4.4 Public Metadata and Advisory Sources. PEGTrace obtains designated public domain-registration, DNS, internet-protocol geolocation, avatar, Tor exit-node, dark-web-index, phishing-feed, governmental-advisory, consumer-protection, and industry information from public sources, including Ahmia, the Tor Project exit-node list, and OpenPhish. Depending on the source and implemented request method, these services may receive the identifier being investigated, PEGTrace’s originating server information, request metadata, and any credentials required for the applicable request. PEGTrace does not permit users to direct these integrations to arbitrary sources. 4.5 Returned Information and Independent Review. Information obtained from External Providers may be incomplete, delayed, inaccurate, or affected by the provider’s methodology, data sources, coverage, or service availability. External-provider results constitute preliminary intelligence and should be independently reviewed before reliance, publication, submission to a third party, or inclusion in a professional conclusion. PEGTrace does not independently establish the identity of a wallet owner, the intent of a transaction participant, the occurrence of fraud, legal liability, asset recoverability, or the accuracy of a provider’s labels or scores. 4.6 Provider Terms and Processing Practices. External Providers process query information and return results under their own contractual, privacy, retention, and security practices. PEGTrace uses External Providers subject to their applicable terms and PEGTrace’s implemented configuration but does not control every aspect of a provider’s independent systems, data sources, methodologies, or services. 4.7 Additional External Providers. PEGTrace may add, replace, or discontinue External Providers as its supported analytical workflows evolve. PEGTrace will update this disclosure to identify any material provider that receives Personal Data or Case Data and to describe the categories of information transmitted and the provider’s general function, subject to any notice or approval obligation established in an applicable agreement. 5. Information Security and Access Controls PEGTrace uses administrative, technical, and organizational measures designed to protect Personal Data and Case Data against unauthorized access, acquisition, use, alteration, disclosure, loss, or destruction. The measures applicable to particular information depend on the relevant system, provider, workflow, and implemented configuration. No transmission method, software platform, or storage environment can be guaranteed to be completely secure. 5.1 Encryption in Transit and at Rest. Communications with PEGTrace’s hosting, database, storage, and External Providers use encrypted transport as supported by the applicable provider. Database and object-storage encryption at rest is provided through the relevant hosting providers. PEGTrace additionally applies field-level AES-256-GCM encryption to a designated sensitive-data table using an operator-controlled key. These measures do not prevent authorized PEGTrace services or privileged credentials from accessing information when necessary to operate the Platform. 5.2 Authentication and Logical Access Controls. PEGTrace currently uses email-and-password authentication. Case and tenant access is restricted through role and tenant information and row-level security applied within a shared database architecture. These controls provide logical rather than physical separation. PEGTrace also maintains access-audit records concerning designated case activity. PEGTrace does not currently offer multi-factor authentication through the Platform. 5.3 Data Segregation and Narrative Fields. PEGTrace is designed to store underlying Case Data separately from designated hash-linked Evidence Ledger entries. The effectiveness of that separation depends on the implemented data model and user conduct. Information entered into narrative or free-text fields may appear in generated reports, evidence packages, logs, or other outputs. Analyst notes and other free-text information may be stored in readable format while maintained in the active case. Administrator-authorized deletion of an analyst note removes the note text but may leave its hash and associated immutable event information in the Evidence Ledger. Deletion of an attachment removes the stored file but may leave its filename, type, size, hash, and associated immutable event information. Earlier Evidence Ledger payloads are not rewritten, and Personal Data or other information already recorded in an immutable payload may therefore remain. Users are responsible for reviewing narrative fields and exported materials because automated controls may not prevent every submission or disclosure of Personal Data. 5.4 Logging and Monitoring. PEGTrace may maintain authentication, access, application, security, error, network, and audit logs as reasonably necessary to operate, secure, troubleshoot, and evaluate the Platform. Logs may include timestamps, user or session identifiers, internet-protocol addresses, device or browser information, route or feature activity, error information, and other technical metadata. PEGTrace maintains designated access-audit records and transactional-email delivery records. Several Platform audit, delivery-log, Case Data, derived-entity, third-party-signal, and related record categories currently have no automated expiration period. Evidence Ledger rows, hashes, timestamps, package registrations, and designated access-audit records are maintained as append-only records and cannot be modified or deleted through ordinary Platform operations. 5.5 Provider Backups and Evidence Exports. PEGTrace relies on backup functionality supplied by its hosting and database providers according to the applicable provider configuration and service terms. PEGTrace does not maintain a separate application-level backup or restoration process for ordinary Case Data. The Platform currently permits administrator-authorized deletion of individual notes and attachments, but a case containing activity, derived entities, Evidence Ledger entries, or related immutable records may not be technically deletable in full. The weekly evidence export described in Section 2.3 of this disclosure does not contain all Case Data and is not a complete Platform backup. Deletion through the Platform does not reach provider-managed backups or previously exported evidence objects, and PEGTrace has not implemented a separate recovery-testing process for those exports. 5.6 Security Incidents. PEGTrace will address suspected security incidents and provide notifications when required by applicable law or an applicable written agreement. Reports may be submitted through the security contact identified below. 5.7 Security Limitations. PEGTrace’s safeguards are designed to reduce security risk but cannot eliminate every risk of unauthorized access, system failure, data loss, malicious activity, or human error. Descriptions of particular controls apply only to the systems and configurations for which those controls have been implemented and should not be interpreted as a guarantee of absolute security. 6. Provider Changes and Disclosure Updates 6.1 Engagement, Replacement, and Discontinuation of Providers. PEGTrace may engage, replace, or discontinue Technology Subprocessors and External Providers as reasonably necessary to operate, secure, maintain, or modify the Platform and its supported services. Any provider change remains subject to the notice, approval, or objection rights established in an applicable data processing agreement, order form, or negotiated agreement. 6.2 Updates to This Disclosure. PEGTrace will update this disclosure to reflect material changes to the identity or function of a Technology Subprocessor or External Provider, the categories of information transmitted, or the material processing practices described herein. The updated disclosure will state its effective or last-updated date and will be made available through PEGTrace’s website, Platform, or other designated location. 6.3 Institutional Notice and Objection Rights. If an applicable data processing agreement, order form, or negotiated agreement requires advance notice of a new Technology Subprocessor that will process institutional Case Data, PEGTrace will provide notice in the manner and within the period stated in that agreement. Any customer objection, consultation, suspension, or termination right will be governed exclusively by the applicable agreement and will not arise independently from this disclosure. 6.4 Urgent or Security-Related Changes. PEGTrace may make a provider change without advance notice when reasonably necessary to respond to a security incident, provider failure, legal requirement, service discontinuation, or other urgent operational circumstance. In that event, PEGTrace will provide any notice required by the applicable agreement as soon as reasonably practicable. 6.5 Changes Affecting Personal Data. If a provider or architecture change materially alters PEGTrace’s collection, use, disclosure, or retention of Personal Data, PEGTrace will also update its Privacy Policy and provide any additional notice, consent mechanism, or choice required by applicable law. 7. Third-Party Service Dependencies and Applicable Agreements 7.1 Third-Party Service Dependencies. PEGTrace relies on Technology Subprocessors and External Providers to support portions of the Platform and its services. Those providers may experience outages, service degradation, delays, security events, application-programming-interface changes, data-source limitations, or discontinuation of particular functions. Such events may affect Platform availability, processing time, stored information, external-query results, or particular features. 7.2 Provider Independence. Technology Subprocessors and External Providers operate systems and services that are not controlled in every respect by PEGTrace. PEGTrace may take reasonable steps to evaluate providers, configure available controls, respond to service events, and replace or modify integrations, but cannot guarantee the uninterrupted operation, continuing availability, accuracy, or security of every third-party service. 7.3 Contractual Allocation of Risk. Any warranties, remedies, service commitments, indemnification obligations, exclusions of damages, or limitations of liability applicable to a customer or transaction are governed by the Terms of Service, the Pilot Design Partner Agreement, or by an applicable order form, data processing agreement, or other negotiated agreement. This disclosure does not independently expand, reduce, or replace those contractual rights and obligations. 7.4 Nonwaivable Rights. Nothing in this disclosure limits any right or remedy that cannot lawfully be waived under an applicable agreement or law. 8. Relationship to Other Documents and Contact Information 8.1 Operational Disclosure. This Data Handling and Subprocessor Disclosure describes PEGTrace’s current providers and material data-handling practices as of the date supplied above. It supplements the Privacy Policy and the agreements applicable to a particular customer or transaction. It does not independently create contractual warranties or a separate assent, governing-law, arbitration, liability, or entire-agreement regime. 8.2 Applicable Agreements. Contractual rights and obligations applicable to an institutional or professional customer are governed by the Terms of Service, Pilot Design Partner Agreement, and any applicable order form, master services agreement, data processing agreement, or other negotiated agreement. If an applicable written agreement imposes different or additional data-processing, security, subprocessor, retention, deletion, incident-response, or notification obligations, that agreement governs according to its order-of-precedence provisions. 8.3 Public-Facing Services. A visitor’s use of PEGTrace’s public informational, intake, exposure-check, or verification functions is governed by the terms and notices presented for those functions. Publication of this disclosure does not, by itself, subject a public visitor to the institutional Terms of Service or its arbitration provision. Any future consumer purchase will be governed by separately presented consumer terms, conditions, and notices applicable to that specific transaction. 8.4 Disputes. Any governing-law, forum-selection, arbitration, class-waiver, or dispute-resolution provision applicable to a particular customer or transaction is contained in the principal agreement governing that relationship. No separate dispute-resolution procedure arises solely from this disclosure. 8.5 Questions and Provider Information. Questions concerning PEGTrace’s Technology Subprocessors, External Providers, security practices, or the information described in this disclosure may be directed to PEGTrace’s mailing and correspondence address at: PEGTrace LLC 111 Town Square Pl Ste 1238 PMB #753961 Jersey City, NJ 07310-1810 or to its email address at support@pegtrace.com. Reports of suspected security incidents should be sent to one of the designated addresses above and should not include private keys, seed phrases, passwords, authentication credentials, or other unnecessary sensitive information.

PEGTrace LLC·Jersey City, NJ

Company·Legal·support@pegtrace.com