Skip to content

Draft for legal review

This page is a structured product draft and must be reviewed by qualified legal counsel before public launch.

TrustRail policy draft

Security

This public-facing draft explains TrustRail security principles without exposing internal secrets, fraud rules, token formats, or worker architecture.

Back to TrustRail

Effective date

[Effective date placeholder]

Company legal name

[Company legal name placeholder]

Company registration

[Company registration placeholder]

Registered address

[Registered address placeholder]

Support email

[support email placeholder]

Privacy email

[privacy email placeholder]

Legal email

[legal email placeholder]

Governing law

[governing law placeholder]

Protected payments

TrustRail uses payment-provider records and backend transaction states to show whether funds are pending, secured, refunded, disputed, or eligible for payout.

Users should always verify the browser URL and avoid sending payment outside supported TrustRail flows.

One-time QR verification

QR handover codes are designed for one-time verification and are checked by the backend before transaction state changes.

Do not screenshot or share QR codes outside the intended handover process.

Delivery PIN fallback

Delivery PIN fallback is prepared securely by the backend. The frontend should never show plaintext PINs unless a future approved flow explicitly requires it.

PINs should be shared only after the buyer or authorized receiver has checked the item.

Role-aware access

Seller, rider, buyer, and admin views are separated in the frontend. Backend authorization remains the real security boundary.

Rider links and sessions should not be shared with unauthorized people.

Audit trails and encrypted transport

TrustRail records audit events for important payment, handover, dispute, refund, and notification actions.

Users should access TrustRail over HTTPS. Sensitive notification persistence is designed to avoid ordinary plaintext storage.

Report suspicious activity

Users should report suspicious payment requests, unexpected rider changes, QR/PIN abuse, account access issues, or attempted off-platform transactions to the support email placeholder.

Home
Start
Guide
Help