Draft for legal review
This page is a structured product draft and must be reviewed by qualified legal counsel before public launch.
Security
This public-facing draft explains TrustRail security principles without exposing internal secrets, fraud rules, token formats, or worker architecture.
Effective date
[Effective date placeholder]
Company legal name
[Company legal name placeholder]
Company registration
[Company registration placeholder]
Registered address
[Registered address placeholder]
Support email
[support email placeholder]
Privacy email
[privacy email placeholder]
Legal email
[legal email placeholder]
Governing law
[governing law placeholder]
Protected payments
TrustRail uses payment-provider records and backend transaction states to show whether funds are pending, secured, refunded, disputed, or eligible for payout.
Users should always verify the browser URL and avoid sending payment outside supported TrustRail flows.
One-time QR verification
QR handover codes are designed for one-time verification and are checked by the backend before transaction state changes.
Do not screenshot or share QR codes outside the intended handover process.
Delivery PIN fallback
Delivery PIN fallback is prepared securely by the backend. The frontend should never show plaintext PINs unless a future approved flow explicitly requires it.
PINs should be shared only after the buyer or authorized receiver has checked the item.
Role-aware access
Seller, rider, buyer, and admin views are separated in the frontend. Backend authorization remains the real security boundary.
Rider links and sessions should not be shared with unauthorized people.
Audit trails and encrypted transport
TrustRail records audit events for important payment, handover, dispute, refund, and notification actions.
Users should access TrustRail over HTTPS. Sensitive notification persistence is designed to avoid ordinary plaintext storage.
Report suspicious activity
Users should report suspicious payment requests, unexpected rider changes, QR/PIN abuse, account access issues, or attempted off-platform transactions to the support email placeholder.