Business identity
RETALLY
715 Yorktowne Road
Pottsville, PA 17901
United States
General and qualification questions: email RETALLY.
Public examples use fictional data and are labeled accordingly. They demonstrate our method and reporting format; they are not customer results.
The public website is not the customer-data environment
The public site accepts no freight-file uploads. Qualification fields run in the browser and can prepare a non-sensitive email for the visitor to review and send. Do not send invoices, contracts, credentials, bank/payment details, or unrestricted mailbox access through ordinary email.
Confidential records move only after fit, scope, allowed record categories, and an approved transfer route are confirmed.
Human review remains part of material decisions
Automation can assist ingestion, matching, calculation, prioritization, and evidence assembly. Material ambiguity, unsupported authority, conflicting records, and external recovery actions are not converted into claims merely because software produced a confident output.
The audit methodology keeps candidate differences, validated findings, authorized claims, settlements, reversals, and actual recovered funds distinct.
AI and automation policy
AI-assisted workflows may be used where appropriate for analysis or evidence assembly. Customer records should not be used to train a general-purpose model unless separately disclosed and authorized.
An AI-generated brand representative, if used in future marketing, must be identified as such. RETALLY will not present a synthetic persona as a real employee, freight veteran, customer, or credentialed professional.
Retention and deletion are engagement-specific
Retention and deletion requirements are agreed for each engagement. Before confidential records are accepted, the applicable retention/deletion treatment should be documented for the customer-data environment, including active claims, settlement evidence, contractual recordkeeping, and backup behavior.
Security claims are evidence-bound too
RETALLY does not currently claim SOC 2, ISO 27001, PCI certification, HIPAA compliance, SSO, or other enterprise certification unless and until the applicable evidence exists and accurately describes the customer-data environment.
The marketing site is hosted through GitHub Pages. That hosting relationship should not be confused with the separate environment approved for confidential customer records.
Providers and subprocessors
Material providers that process confidential customer records should be identified as the production environment becomes standardized. Public-site hosting alone does not make a provider a processor of customer freight records.
Engagement-specific diligence can address the approved transfer/storage environment, authorized users, access controls, and additional contractual requirements before records move.
Incident handling
Suspected unauthorized access, disclosure, loss, corruption, or misuse of customer records should be contained, documented, investigated, and escalated according to the applicable environment and engagement requirements.
Security or privacy concerns can be sent through the public business contact. Do not include confidential freight records in the initial email.
Recovery integrity
Potential recovery is not the same as a validated finding. A validated finding is not the same as an approved claim. An approved claim is not the same as recovered money.
Pre-existing, incumbent-known, automatic, duplicate, unsupported, or reversed value is not silently promoted into RETALLY-originated recovery. The Second-Look Audit applies this boundary explicitly to existing audit systems and incumbent providers.
Current limitations
Recovery is not guaranteed. Public methodology is not legal or accounting advice. The current public site is not a secure document portal, customer dashboard, TMS, freight-payment platform, or certification claim.
Confirm any required controls with us before providing confidential records.
