Commerce Roots LLC
HomeAbout UsProducts & SolutionsSourcing & LogisticsE-CommerceContact UsRequest a Quote

COMMERCE ROOTS LLC

Master Privacy Policy

Effective Date: August 23, 2026Last Updated: August 23, 2026

1. Introduction and Scope

Commerce Roots LLC (“Commerce Roots,” “we,” “us,” or “our”) respects privacy and seeks to handle personal information responsibly.

This Master Privacy Policy explains how Commerce Roots may collect, use, disclose, retain, and protect personal information when an individual uses a Commerce Roots-operated Digital Service that links to or expressly references this Policy, or otherwise interacts with Commerce Roots in connection with the activities described below.

For purposes of this Policy, “Digital Services” means websites, web applications, mobile applications, customer or supplier portals, forms, digital interfaces, communications tools, and other digital products or services operated by Commerce Roots that link to or expressly reference this Policy. This definition establishes a framework for current and future services; it does not state that every listed type of Digital Service currently exists.

This Policy may apply, where relevant, when an individual:

  • visits a Commerce Roots website;

  • uses a form or submits a Request a Quote;

  • uploads documents, specifications, photographs, product images, or other files;

  • creates or uses an account where account functionality is implemented;

  • communicates with Commerce Roots by email, telephone, WhatsApp, SMS, marketplace messaging, a portal, or a similar business channel;

  • interacts with Commerce Roots regarding sourcing, procurement, purchasing, quotations, logistics, inventory, distribution, e-commerce, marketplace operations, or related domestic or international commerce; or

  • uses another Commerce Roots-operated Digital Service that links to this Policy.

Commerce Roots-operated Digital Services are distinct from independent websites, marketplaces, app stores, payment processors, banks, social networks, carriers, logistics companies, suppliers, manufacturers, and other third-party platforms or organizations. Those third parties may collect and process information under their own terms and privacy policies. This Policy does not control their independent practices.

2. Information We Collect Through Current Digital Services

The information Commerce Roots collects depends on how an individual interacts with us and what is reasonably relevant to the applicable inquiry, request, account, service, or transaction.

2.1 Identifiers and Contact Information

We may collect:

  • name;

  • company or organization name;

  • email address;

  • telephone number;

  • WhatsApp or other business contact information; and

  • country or general location.

2.2 Commercial, Request, and Transaction Information

We may collect information relating to an inquiry, sourcing request, quotation, service request, or commercial transaction, including:

  • products, machinery, equipment, parts, or services requested;

  • quantities, specifications, brands, models, part numbers, technical requirements, and intended use;

  • preferred sourcing countries, regions, or suppliers;

  • destination countries, regions, addresses, or delivery information where relevant;

  • quotation references, transaction information, pricing presented to the customer, and payment terms stated in transaction documents;

  • purchasing, logistics, fulfillment, inventory, distribution, or order information where applicable;

  • customer, supplier, or provider communications; and

  • other information voluntarily provided in connection with a request or commercial relationship.

2.3 Uploaded Content

When an individual voluntarily uploads or sends materials, Commerce Roots may collect documents, specifications, photographs, product images, spreadsheets, technical files, and other submitted content reasonably related to the request, service, or transaction.

2.4 Technical, Security, and Usage Information

Where implemented, Commerce Roots or its service providers may process technical information such as IP address, browser or device type, operating system, timestamps, website or application interaction data, access history, security logs, cookies, and similar technologies. The information actually processed depends on the hosting, authentication, security, diagnostics, analytics, and Digital Service technologies in use at the time.

2.5 Business Contact Information

When an individual interacts with Commerce Roots in a professional or business capacity, we may collect business contact information, job title, employer or organization, business role, business communications, and information relating to that professional relationship.

3. Information Future Digital Services May Collect

Future Digital Services may collect different information depending on the feature and only where implemented. Such information may include:

  • account identifiers, profile information, and business roles;

  • shipping or delivery addresses;

  • device identifiers, application diagnostics, and crash information;

  • push-notification tokens;

  • approximate location or, where specifically justified and enabled, precise location;

  • photographs, camera input, files, or photo-library selections submitted through an application;

  • marketplace account, listing, or sales-channel information;

  • order, inventory, logistics, fulfillment, and support information;

  • payment-related transaction information described in Section 15; and

  • other information described in an app-specific, feature-specific, payment-specific, jurisdiction-specific, or transaction-specific notice.

This section does not state that Commerce Roots currently collects precise GPS location, contacts or address-book data, microphone data, biometric information, advertising identifiers, push-notification tokens, or complete payment-card credentials. Any materially new collection should be reviewed before implementation and described through an updated or supplemental notice where appropriate.

4. Mobile Device Permissions

If Commerce Roots introduces a mobile application or device-enabled feature, the Digital Service may request access to device capabilities such as the camera, photo library or files, notifications, approximate location, precise location, or another capability that is necessary for a specific implemented feature.

Permissions should be requested only where reasonably necessary for the feature. Permission choices can generally be managed through device settings. Denying or withdrawing a permission may prevent the associated feature from functioning. A materially new permission or collection practice should trigger privacy review and, where necessary, an updated or supplemental notice.

Commerce Roots does not currently represent that it operates a native mobile application or requests these permissions.

5. Personal Information About Other Individuals

If a user provides personal information relating to another individual through a website form, application, portal, file, communication, or other Digital Service, the user represents that the user is authorized or otherwise has a lawful basis to provide that information for the relevant legitimate business purpose. Commerce Roots may rely on that representation unless circumstances reasonably indicate otherwise.

Users should not upload or provide unnecessary personal information about another individual. Third-party information included in a request, file, transaction, or communication should be limited to what is reasonably necessary for the applicable commercial purpose.

6. Sensitive Personal Information and File-Upload Warning

Users should not submit sensitive personal information unless Commerce Roots specifically requests it and the information is reasonably necessary for a legitimate transaction or business purpose.

Information that ordinarily should not be submitted through general Digital Services or ordinary business communications includes government identification numbers or documents, full financial-account credentials, complete payment-card details, medical or health information, passwords, authentication secrets, and other highly sensitive information.

Files should contain only information reasonably necessary for the request, service, or transaction. If sensitive information is genuinely necessary, Commerce Roots may provide a more appropriate secure process where implemented. Users should follow any file-format, size, content, or security instructions provided for the relevant Digital Service.

7. How We Use Personal Information

Commerce Roots may use personal information, where applicable and reasonably related to the interaction, to:

  • respond to inquiries and communicate with customers, prospective customers, suppliers, providers, and other business contacts;

  • receive, review, classify, and manage Request a Quote submissions;

  • create and administer accounts where account functionality is implemented;

  • identify and evaluate products, suppliers, manufacturers, logistics providers, service providers, equipment, and commercial opportunities;

  • conduct sourcing, procurement, purchasing, supplier evaluation, and commercial research;

  • prepare, revise, deliver, administer, and preserve quotations and related documents;

  • coordinate purchasing, import, export, transportation, delivery, fulfillment, logistics, distribution, or inventory activity;

  • administer e-commerce, marketplace, direct commercial, wholesale, or other sales-channel activity where implemented;

  • administer orders, services, payment status, refunds, disputes, or chargebacks where applicable;

  • provide customer, supplier, account, and technical support;

  • maintain records reasonably related to inquiries, accounts, quotations, transactions, inventory, logistics, payments, compliance, and business administration;

  • protect Digital Services, systems, users, transactions, and the business from fraud, misuse, unauthorized access, harmful files, and security incidents;

  • comply with applicable legal, regulatory, customs, sanctions, export-control, tax, accounting, recordkeeping, and contractual obligations;

  • operate, authenticate, maintain, troubleshoot, secure, diagnose, and improve Digital Services; and

  • understand Digital Service performance and usage where analytics or diagnostics are implemented.

Commerce Roots does not intend to use personal information for a materially incompatible purpose without additional notice or consent where required by applicable law. These purposes do not authorize unrestricted use for all current or future business operations.

8. CRM and Internal Business Systems

Commerce Roots may store and process information in internal business systems used to manage:

  • customer, prospect, supplier, provider, and business-contact records;

  • requests, quotations, communications, and files;

  • supplier and provider relationships;

  • commercial catalog, classification, and sales-channel records;

  • inventory, cost, purchasing, logistics, fulfillment, and transaction records;

  • activity, access, security, and audit history; and

  • future order, payment-status, portal, marketplace, or application records where implemented.

Access is intended to be limited according to legitimate business need, assigned responsibilities, authenticated access, and system permissions. Commerce Roots may preserve records necessary to maintain commercial, security, compliance, and audit history.

This Policy describes internal processing at a general level and does not disclose private routes, database names, credentials, access tokens, API keys, or confidential security architecture.

9. Account-Based Digital Services

Where Commerce Roots implements customer, supplier, employee, marketplace-management, mobile, or web-application accounts, information may include an account identifier, name, email, organization, business role, permissions, login or access history, security logs, and account activity.

Identity and authentication services may be operated by Commerce Roots or an approved identity provider. This Policy does not state that Commerce Roots stores plaintext passwords. Users should protect authentication credentials and promptly report suspected unauthorized access.

10. Transactional Emails and Business Communications

Commerce Roots may use transactional email and communications service providers to send request confirmations, quotations, quote attachments, account or security notices, operational messages, and other communications relating to an inquiry, Digital Service, or transaction.

Those providers may process recipient contact information, message content, delivery metadata, and attachments as reasonably necessary to transmit, secure, and administer the communication. Commerce Roots seeks to limit communications to information appropriate for the applicable purpose.

11. How We Disclose Personal Information

Depending on the request, Digital Service, or transaction, Commerce Roots may disclose information to:

  • hosting, cloud, database, storage, and security providers;

  • authentication and identity providers;

  • transactional email, communications, and customer-support providers;

  • suppliers, manufacturers, product providers, and service providers;

  • logistics companies, carriers, freight providers, warehouses, fulfillment providers, and customs professionals;

  • distributors, buyers, sellers, and other commercial counterparties;

  • payment processors, payment gateways, financial institutions, digital-wallet providers, and marketplace payment providers where payments are implemented;

  • e-commerce platforms, marketplaces, marketplace-management providers, and app stores where applicable;

  • accounting, insurance, legal, tax, compliance, and other professional advisers;

  • analytics, diagnostics, automation, or AI providers where implemented following appropriate review; and

  • government, customs, regulatory, judicial, or law-enforcement authorities when required or permitted by applicable law.

Information disclosed may include contact information, business role, account information, product or service requirements, specifications, quantities, sourcing or destination information, shipping details, transaction information, payment status or metadata, communications, and documents or files reasonably necessary for the applicable purpose.

Commerce Roots intends to limit disclosures to information reasonably necessary to evaluate or fulfill a request, administer a Digital Service or transaction, operate and secure the business, protect legitimate interests, or comply with applicable obligations.

12. Service Providers and Independent Third Parties

Some providers process personal information on Commerce Roots’ behalf to provide hosting, storage, authentication, communications, security, support, diagnostics, or other services. Where appropriate, Commerce Roots may seek contractual commitments concerning confidentiality, security, permitted use, retention, deletion, breach notification, and subprocessors.

Other recipients act independently and may have their own direct relationship with an individual or their own legal obligations. Independent suppliers, manufacturers, marketplaces, app stores, payment processors, banks, carriers, freight providers, customs professionals, logistics companies, and similar organizations may process information under their own terms and privacy policies.

Disclosure to an independent organization does not, by itself, make that organization an employee, agent, affiliate, partner, or legal representative of Commerce Roots.

13. Third-Party Integrations

Where implemented, Digital Services may integrate with payment providers, marketplaces, logistics platforms, communications providers, identity providers, cloud or storage services, accounting services, app stores, AI providers, or other external platforms.

An integration may permit information to flow between Commerce Roots and the third party according to user choices, account permissions, the feature, transaction requirements, and applicable agreements. Independent service terms and privacy policies may apply. Listing a potential integration does not mean it is currently active.

14. E-Commerce and Marketplaces

Commerce Roots may sell or distribute selected merchandise through direct commercial channels and, where or when implemented, through Amazon, eBay, Walmart Marketplace, TikTok Shop, Meta or Facebook commerce, Instagram Shop, Shopify or another direct online store, Mercado Libre, wholesale distribution, or other marketplaces and sales channels.

The existence of sales-channel readiness records, catalog classifications, or internal marketplace fields does not establish that Commerce Roots has an active storefront, account, application programming interface, synchronized inventory, listing, or transaction on a named platform.

Independent marketplaces may process account, transaction, payment, shipping, device, fraud, support, and marketplace-interaction information under their own policies. Commerce Roots’ access depends on the channel, permissions, integration, transaction, and applicable law.

15. Payment Processing and Payment-Related Information

Commerce Roots may in the future offer payment functionality using Stripe or another approved payment processor, payment gateway, financial institution, digital-wallet provider, marketplace payment provider, or equivalent lawful provider. This statement is preparatory and does not state that Stripe or another provider is currently active.

Where implemented, sensitive payment credentials should preferably be collected and handled directly by the payment provider or through secure hosted, tokenized, or equivalent technologies designed to reduce Commerce Roots’ direct handling of complete payment credentials.

Commerce Roots may receive limited payment or transaction information such as:

  • payment status, amount, and currency;

  • billing and contact information;

  • processor transaction or customer identifiers;

  • refund, reversal, dispute, or chargeback status;

  • fraud or risk information supplied by a provider; and

  • payment metadata reasonably necessary to administer, reconcile, secure, support, or document the transaction.

Commerce Roots does not currently represent that it stores complete card numbers, card security codes, or complete bank-login credentials. Payment-related information may be used for transaction administration, reconciliation, accounting, order or service fulfillment, refund processing, dispute and chargeback handling, fraud prevention, customer service, tax and legal records, and transaction security.

Independent payment providers may process information according to their own privacy policies, authentication and fraud-prevention practices, legal obligations, retention rules, and international-transfer practices. Commerce Roots should review a provider’s privacy, security, and contractual terms before activation.

This framework is intended to remain provider-neutral when purposes and data categories remain materially similar. A new privacy and legal review should occur when a provider introduces materially different personal-data collection, sensitive credentials, recurring billing, installment financing, credit decisions, profiling or fraud models, international transfers, marketing or data sharing, retention, customer authentication, or advertising use.

16. App Stores and Software Distribution Platforms

If a Commerce Roots application is distributed through the Apple App Store, Google Play, or another software distribution platform, that platform may independently process account or device information, downloads, purchases or subscriptions where applicable, diagnostics, and other platform information under its own terms and privacy policy.

This section does not state that a Commerce Roots native application currently exists or is distributed through an app store.

17. Cookies, Analytics, Diagnostics, Tracking, and SDKs

Essential cookies or similar technologies may be used to operate, secure, authenticate, route, and maintain Digital Services. Preference technologies may be used where implemented. Analytics, crash reporting, diagnostics, attribution, advertising, embedded tracking, or marketing technologies may be introduced only after appropriate review.

Based on the application code reviewed for this draft, no application-level targeted advertising, behavioral advertising, nonessential analytics package, advertising pixel, marketing tag manager, or marketing SDK was identified. Platform-level security, routing, operational telemetry, or authentication technologies may still apply and should be confirmed before publication.

Before introducing Google Analytics or an equivalent service, a mobile analytics SDK, crash reporting, attribution SDK, advertising pixel, marketing SDK, behavioral-advertising technology, embedded tracking, or a tag manager, Commerce Roots should conduct a provider review, update its cookie and SDK inventory, assess notice and consent or opt-out requirements, and review app-store privacy disclosures where applicable.

Where applicable law requires choices concerning nonessential cookies, SDKs, or similar technologies, Commerce Roots will provide appropriate notice and controls. This Policy does not state that a cookie banner currently exists.

18. Sale of Personal Information, Sharing, and Targeted Advertising

Based on the application code reviewed for this draft, Commerce Roots does not currently appear to sell personal information for monetary consideration or use personal information for targeted or cross-context behavioral advertising as those terms may be defined by applicable state privacy laws.

This qualified statement must be reconfirmed immediately before publication against the production configuration, hosting telemetry, vendor contracts, SDKs, pixels, analytics, marketplace integrations, and other providers. If practices materially change, Commerce Roots should update this Policy and provide legally required notices, choices, or opt-out mechanisms.

Operational disclosures to providers and commercial counterparties may still occur for the purposes described in this Policy. Whether a disclosure constitutes a regulated “sale,” “sharing,” or targeted-advertising activity depends on applicable-law definitions and the actual arrangement.

19. International Data Transfers

Because Commerce Roots engages in domestic and international commerce, personal information may be processed in a state or country different from the individual’s location. This may occur through service providers, suppliers, manufacturers, logistics providers, marketplaces, payment providers, app stores, or commercial counterparties in other jurisdictions.

Privacy and data-protection laws differ between jurisdictions. Where applicable law requires safeguards for an international transfer, Commerce Roots will seek to use legally appropriate measures based on the circumstances. This Policy does not promise a particular transfer mechanism unless it is implemented for the relevant processing.

20. Data Retention

Commerce Roots may retain personal information for as long as reasonably necessary for the disclosed purposes and applicable legal or legitimate business obligations. Factors may include:

  • inquiry, request, account, quotation, order, shipment, or transaction status;

  • the duration of a customer, supplier, provider, or commercial relationship;

  • transaction, customs, payment, inventory, logistics, warranty, tax, and accounting documentation;

  • fraud prevention, information security, dispute resolution, chargebacks, and enforcement;

  • legal, regulatory, contractual, audit, and recordkeeping requirements; and

  • business continuity and preservation of accurate transaction or security history.

Information should not be retained longer than reasonably necessary for the disclosed purposes and applicable obligations. Commerce Roots has not yet fully operationalized a formal retention and deletion schedule across all current and future record categories. Fixed deletion periods should not be published until an approved schedule exists.

An operational schedule should address leads, customers, requests, files, quotations, suppliers, accounts, payment metadata, orders, logistics, inventory, communications, audit and security logs, application diagnostics, marketplace records, and AI-related records where implemented.

21. Data Security

Commerce Roots uses or intends to use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information and systems involved. Measures may include authenticated access, role-based permissions, private file access, activity records, secure provider configurations, and access restrictions where implemented.

Commerce Roots does not publicly disclose detailed security configurations that could increase risk. No internet transmission, Digital Service, email system, payment system, communications platform, cloud service, application, or electronic storage system can be guaranteed to be completely secure. Individuals should use care when deciding what information to submit electronically.

22. Privacy Rights

Depending on where you reside and applicable law, you may have rights to:

  • request access to personal information;

  • request correction of inaccurate personal information;

  • request deletion of certain personal information;

  • request a portable copy of certain information;

  • obtain information about categories of personal information or third parties involved in certain disclosures;

  • opt out of certain sales, sharing, targeted advertising, or profiling where applicable;

  • withdraw consent where consent is the legal basis;

  • limit certain uses of sensitive personal information where applicable; and

  • appeal a privacy-request decision where required by law.

Rights are not universal and may be subject to eligibility requirements, exemptions, verification, retention obligations, transaction records, security needs, and other legal limitations.

23. How to Exercise Privacy Rights

Privacy requests may be submitted to admin@commerceroots.com with a subject line such as “Privacy Request.”

Commerce Roots may request sufficient information to locate relevant records across website submissions, CRM records, files, accounts, quotations, email records, application records, orders, payment metadata, marketplace records, and AI-related records where applicable, and to reasonably verify the requester’s identity or authority.

Commerce Roots will seek only verification information reasonably necessary for the request and should not require highly sensitive identity information by ordinary email where a safer method is appropriate. Authorized agents may be used where required by law. Commerce Roots may deny or limit a request where permitted by law, including when an exemption applies, identity cannot reasonably be verified, records must be retained, or another person’s rights would be adversely affected.

Where required, Commerce Roots will provide appeal instructions. Commerce Roots will not unlawfully discriminate against an individual for exercising an applicable privacy right.

24. Marketing and Operational Communications

Request confirmations, quotation emails, account and security notices, payment or order messages, transaction notices, and communications needed to respond to an inquiry or administer a Digital Service or commercial relationship are operational or transactional communications.

If Commerce Roots introduces marketing email, push notifications, SMS marketing, or another promotional program, applicable communications should include legally required disclosures and opt-out controls. Operational communications should not be treated as blanket consent for marketing.

25. WhatsApp, SMS, Social Networks, and Third-Party Channels

If an individual contacts Commerce Roots through WhatsApp, SMS, a social network, marketplace messaging, app-store communication, or another third-party channel, that platform may process information under its own terms and privacy policy.

Individuals should avoid sending highly sensitive personal information through such channels unless it is necessary, appropriate, and specifically requested for a legitimate purpose.

26. Automation and AI-Assisted Tools

Commerce Roots may in the future use automation or AI-assisted tools for limited business-support purposes, including CRM classification, customer service, quotation preparation, sourcing, procurement, supplier research, logistics, workflow management, customer or supplier portals, website interactions, mobile applications, WhatsApp or business communications, and marketplace operations.

This section does not state that a fully autonomous agent currently processes public customer submissions, makes binding decisions, or enters transactions. Commerce Roots does not intend to use automated tools to make legally or similarly significant decisions about individuals without notice, human involvement, and safeguards required by applicable law.

Before customer, supplier, employee, or other personal information is provided to an AI provider, Commerce Roots should review purpose, necessity, minimization, training or reuse terms, retention, confidentiality, security, subprocessors, international transfers, human review, customer notice or consent, and legally significant decision risk.

27. Supplemental and Feature-Specific Notices

This Master Privacy Policy may be supplemented by an app-specific privacy notice, feature-specific notice, payment or checkout notice, jurisdiction-specific notice, or transaction-specific notice.

A supplemental notice should be considered when a Digital Service introduces materially different data categories, precise location, camera or photo access, biometrics, health or other sensitive information, payments, advertising or tracking, AI processing, retention, purposes, users, or third-party disclosures. A supplemental notice should be read together with this Policy and should explain any applicable difference.

28. Children’s Privacy

Commerce Roots Digital Services and commercial services are intended for businesses and adults and are not directed to children under 13. Commerce Roots does not knowingly seek to collect personal information from children under 13 through its commercial forms or account features.

If Commerce Roots learns that it collected such information in circumstances requiring deletion, it will take reasonable steps to address it as required by applicable law.

29. Business Transfers

Personal information may be disclosed or transferred in connection with an actual or proposed merger, acquisition, financing, restructuring, sale of assets, insolvency proceeding, or other legitimate business transfer. Handling would remain subject to applicable law and appropriate confidentiality or other protections based on the circumstances.

30. Third-Party Links and Platforms

Digital Services may contain links to independent websites, marketplaces, app stores, social networks, payment services, logistics providers, or other external services. Commerce Roots does not control and is not responsible for independent third-party privacy practices. Individuals should review the applicable third party’s policy before providing information directly to it.

31. Changes to This Master Privacy Policy

Commerce Roots may update this Policy as its Digital Services, technologies, vendors, commercial activities, and legal obligations evolve. The current version and effective date should be published wherever this Policy applies.

Where required by applicable law, Commerce Roots will provide additional notice of material changes. An update should not be interpreted as retroactive authorization for materially incompatible processing where additional notice or consent is legally required.

32. Contact Us

Commerce Roots LLC

Business Location: Newark, Delaware, United States

Email: admin@commerceroots.com

Phone: +1 (501) 201-2617

Phone: +1 (201) 464-1481

Commerce Roots LLC

Global Trade, procurement, logistics, distribution, sourcing, and e-commerce solutions for domestic and international markets.

Emailadmin@commerceroots.comPhone+1 (501) 201-2617Phone+1 (201) 464-1481WhatsApp+1 (929) 689-7798
LocationNewark, Delaware, United States
GLOBAL TRADE  |  PROCUREMENT  |  LOGISTICS

Company

HomeAbout UsProducts & Solutions

Solutions

Sourcing & LogisticsE-CommerceContact UsRequest a Quote

Social Media

© 2026 Commerce Roots LLC. All rights reserved.Privacy PolicyTerms & Conditions