Skip to main content

Trust starts with saying what is public—and what is not.

This hub points to Gerai’s published privacy, security, AI and accessibility information. It also identifies topics that are discussed and agreed for a particular customer during procurement, rather than presented as universal public commitments.

Published information

These pages describe Gerai’s current public position. Each document should be read within its stated scope; publication does not turn a general description into a customer-specific warranty or service level.

The boundaries in plain English

Privacy
What personal data Gerai handles, why it is used, and how rights requests can be made.
Security
System boundaries, merchant payment settlement and the channel for reporting concerns.
AI
Where AI assists catalogue and messaging work, where people review, and what the system does not claim to be.
Accessibility
The public approach to accessible websites and a route for reporting a barrier.

These documents add detail about browser storage, Singapore data-protection information and the rules for using the service responsibly.

Agreed during enterprise procurement

The entries below are not represented as generally published policies or standard terms. They mark subjects that may require customer scope, provider details, technical review, confidentiality, negotiated wording or an executed agreement before they apply. A registry entry is not evidence that a certification, audit report, location option or service level exists for every customer.

No certification by implication

Gerai does not use this hub to claim SOC 2, ISO 27001, PCI DSS or another certification or attestation. References to privacy laws, payment gateways or procurement documents do not imply certification against those frameworks. If a buyer needs a specific control, audit, data-location term, supplier disclosure or contract schedule, it should be raised explicitly and verified against the documents available for that procurement.

Ask a precise question

Email hello@gerai.shop with your organization, role, intended Gerai use, jurisdictions, data categories and the exact document or control you need to assess. Do not send confidential questionnaires or sensitive architecture material until an appropriate handling method has been agreed.

Compliance and Trust | Gerai