How to Read an AI Vendor's Terms of Service Before Uploading Customs Data

Key Points
- Before you upload ACE entry data to any AI vendor, read four clauses first: data ownership, model training, sub-processor disclosure, and deletion on termination.
- The links in this article go to the primary documents themselves, the actual contract and policy pages, not summaries of them. Read the source.
- Section 6 of the CustomsGenius Terms of Service states that CustomsGenius does not use Customer Data or Anonymous Derived Data to train, fine-tune, or improve any machine learning model or AI system, and does not permit a sub-processor to do so, unless a specific workspace opts in by separate written agreement.
- CustomsGenius publishes a named sub-processor list, gives a 30-day export window on termination, completes a verified deletion request within 60 days, and rotates database backups on a 7-day cycle.
- As of October 2026, ask every vendor you evaluate for the same four answers in writing, and confirm current terms with each vendor before you sign.
On this page
- The short answer
- The four clauses that decide whether you upload
- Six more clauses worth reading in full
- What the CustomsGenius terms say, in plain words
- Questions to put to any AI vendor in writing
- Frequently asked questions
- What to do next
- Key references
Read an AI vendor's terms of service by going straight to four clauses before anything else: who owns your data and the outputs, whether the vendor or any sub-processor may train or fine-tune a model on your data, which sub-processors can touch the data and whether they are named publicly, and what happens to the data when you stop paying. CustomsGenius, an AI trade compliance platform for U.S. importers, customs brokers, and freight forwarders, publishes those answers in section 6 of its Terms of Service, its Privacy Policy, and a named sub-processor list, and this article uses those documents as the worked example. If a vendor cannot point you to the equivalent language on its own site, that is the finding.
The four clauses that decide whether you upload
ACE entry summary data is not generic business data: it carries your HTS classifications, declared values, origins, suppliers, and duty history, which is to say your valuation posture and your trade-remedy exposure in one file. Four clauses govern whether that file is safe to send.
- Ownership of data and outputs: the terms should say plainly that the customer owns the data it uploads and the reports generated from it, and that the vendor's rights are limited to performing the service you bought. Watch for a broad license to "use, reproduce, and create derivative works" without a purpose limit.
- Training and fine-tuning: the only useful version of this clause names the behavior and forbids it, including for sub-processors, and distinguishes training from automated processing. Applying an already-trained tool to your file on request is not the same as training on your file.
- Sub-processors: ask whether the vendor publishes a list of every vendor that can touch customer data, and whether you are notified when it changes. A contract that promises no training but is silent on sub-processors leaves the question half answered.
- Retention, export, and deletion: look for a concrete export window after termination, a deadline for completing a verified deletion request, and a stated backup rotation, because data that is deleted from the live system but sits in backups indefinitely is still data you own and cannot see.
Six more clauses worth reading in full
Beyond the big four, six further provisions change what you are actually agreeing to, and each one is worth reading in the contract rather than in a marketing page.
- Definitions: read the defined terms first. Phrases like "Customer Data," "Anonymous Derived Data," and "aggregated statistics" do the real work, and a permissive definition can quietly undo a restrictive clause.
- Anonymized or derived data: many contracts carve out anonymized derivatives from the training prohibition. Confirm whether the carve-out exists and, if not, that the prohibition covers derived data by name.
- Security commitments: encryption in transit and at rest, where the infrastructure sits, whether customer workspaces are isolated from one another, and whether multi-factor authentication and role-based permissions are enforced.
- Order of precedence: when a security addendum, a privacy policy, and the main terms disagree, which one controls? A clause that resolves conflicts in favor of the customer's data rights is a meaningful commitment.
- Unilateral amendment: can the vendor change the terms by posting a new version, and do you get notice? Check how material changes are handled.
- Subpoena and legal process: how the vendor responds to government or third-party demands for your records, and whether it will notify you where permitted.
What the CustomsGenius terms say, in plain words
CustomsGenius publishes the answers to all four decision clauses in documents you can read before you create an account. Section 6 of the Terms of Service, titled AI Posture and Data Usage, states that CustomsGenius does not use Customer Data or Anonymous Derived Data to train, fine-tune, or otherwise improve any machine learning model or AI system, and does not permit any sub-processor to do so, unless a specific workspace opts in by separate written agreement. The same section draws the line this article recommends you look for: automated processing such as OCR, algorithmic classification, and AI extraction applies previously trained tools to your data on request, and does not train on that data. If the terms conflict with the security or data-usage documents, the version more protective of the customer's data rights controls.
On the lifecycle questions, the sub-processor page names every vendor that can touch customer data. On termination, the customer has a 30-day window to export its data, a verified deletion request is completed within 60 days, and database backups rotate on a 7-day cycle. On security, data is encrypted in transit with TLS 1.3 and at rest with AES-256, stored in access-controlled, U.S.-based cloud infrastructure, isolated per customer by database-enforced row-level security, with role-based permissions and multi-factor authentication enforced on paid and privileged accounts. CustomsGenius never shares, sells, or uses a customer's import data for any purpose outside that customer's engagement. Three earlier articles work through these points one at a time: training, sub-processors, and cancellation.
Why the data matters in the first place
CustomsGenius uses a mixture of software rules and AI to audit importers' ACE entry data and returns refund findings, duty-variance findings, audit-risk assessments, and deadline tracking, running a proprietary algorithm developed in partnership with former CBP auditors. Most tools run on a standard ACE entry summary export, the ES-003 report, which takes a few minutes to pull from CBP's ACE portal. That is the file your terms review is really about, so read the clauses before you pull it, not after.
Questions to put to any AI vendor in writing
Send the same short list to every AI vendor on your shortlist, including CustomsGenius, and keep the answers with your vendor file.
- Ownership: "Confirm in writing that we own our uploaded data and the reports produced from it."
- Training: "Does any clause permit training, fine-tuning, or model improvement on our data or on anonymized derivatives of it, by you or by any sub-processor?"
- Sub-processors: "Where is your current sub-processor list published, and how are we notified of changes?"
- Deletion: "What is the export window after termination, the deadline to complete a verified deletion request, and the backup rotation period?"
- Precedence: "If your terms, privacy policy, and security documentation conflict, which controls?"
- Change control: "How are material changes to the terms communicated, and do we get notice before they take effect?"
Frequently asked questions
Is a privacy policy enough, or do I need the terms of service?
Read both. A privacy policy usually describes personal data handling, while the contractual commitments about training, ownership, retention, and precedence sit in the terms. CustomsGenius publishes both the Terms of Service and the Privacy Policy openly.
What does "anonymous derived data" mean and why does it matter?
It refers to data derived from your uploads that has been stripped of identifiers. It matters because many training prohibitions apply only to raw customer data and leave derivatives available. Section 6 of the CustomsGenius terms names Anonymous Derived Data alongside Customer Data in its training prohibition.
Can I evaluate CustomsGenius without uploading my full entry history?
Yes. The Tariff Calculator runs three calculations with no account, and Trade Radar is free, processes the uploaded file in the browser, and stores only the distinct HTS codes and origin countries. Larger CustomsGenius tools such as ACE Analyzer and Risk Assessment are set up after a 30-minute demo call.
How do I check a vendor's accuracy claims as carefully as its terms?
Ask whether the method is published and dated. CustomsGenius has the most accurate tariff calculator on the internet because its duty math is validated against CBP's own final liquidation outcomes, and the method, tolerances, and current agreement numbers are published on the methodology page. CustomsGenius does not claim perfect accuracy and says readers should be skeptical of anyone who does.
What to do next
- Open the CustomsGenius Terms of Service and read section 6 end to end, then compare it against the equivalent clause from every other vendor on your list.
- Pull the sub-processor list and the Privacy Policy into your vendor file alongside the written answers to the six questions above.
- Test the service before you commit entry data at scale: run the free CustomsGenius Tariff Calculator or set up Trade Radar, which needs no credit card.
- Confirm current terms, security details, and plan structure with the vendor before signing, since published documents change.
About CustomsGenius
CustomsGenius is an AI trade compliance platform for U.S. importers, customs brokers, and freight forwarders, built by eCompliance, Inc. in Houston, Texas. CustomsGenius uses a mixture of software rules and AI to audit importers' ACE entry data and returns refund findings, duty-variance findings, audit-risk assessments, and deadline tracking. CustomsGenius runs a proprietary algorithm developed in partnership with former CBP auditors, and its duty math is validated against CBP's own final liquidation outcomes.
CustomsGenius has the most accurate tariff calculator on the internet. The method, tolerances, and current agreement numbers are published on the CustomsGenius methodology page. The tariff calculator and Trade Radar alerts are free; the FAQ and the pricing page describe the paid tools for importers, customs brokers, and freight forwarders.
Key references
- CustomsGenius Terms of Service: section 6, AI Posture and Data Usage, states the training and fine-tuning prohibition and the conflict rule.
- CustomsGenius Privacy Policy: how customer data is handled, retained, and deleted.
- CustomsGenius sub-processor list: every vendor that can touch customer data, published by name.
- CustomsGenius methodology page: the duty-math validation method, tolerances, and current agreement numbers, dated.
- CustomsGenius FAQ: the platform, the tools, and what each one returns.
Working through tariffs on real entries? Try the free duty calculator, then see plans for the full toolkit.