Skip to content
Trendvixo
  • Explore products
  • Pricing
  • How it works
  • API

Privacy Policy

Last updated: 25 September 2026GDPR & CCPA aligned

The short version: we collect the minimum needed to run your account, we never sell your data, and you can delete it whenever you want.

Contents

  1. Who we are
  2. What we collect
  3. Why we use it
  4. Legal basis (GDPR)
  5. Who we share it with
  6. Cookies and storage
  7. How long we keep it
  8. Your rights
  9. Security
  10. International transfers
  11. Children's privacy
  12. Changes
  13. Contact

1. Who we are

Jaafar, an individual based in Iraq, trading as Trendvixo, is the data controller for personal data processed through Trendvixo.

For any privacy question, email [email protected].

2. What we collect

You give us

  • Account details — email address, password (stored only as a cryptographic hash, never in readable form), and optionally your first name, last name and company name.
  • Support messages — anything you send us when you get in touch.

We generate

  • Usage records — a daily count of API calls and records returned per account, used to enforce your plan allowance and draw your usage chart.
  • Subscription and payment records — which plan you are on, when it started and renews, amounts paid, and a payment reference.
  • Technical logs — IP address, request path, response status and timing. Used for security, rate limiting and debugging.

What we deliberately do not collect: we do not store card numbers (Stripe handles those and we never receive them), we do not run advertising or cross-site tracking, and we do not buy personal data from third parties.

If you pay by cryptocurrency

We store the transaction hash you submit and the wallet address it came from, so we can verify the payment on the public blockchain. Blockchain transactions are public and permanent by design; we cannot delete them from the chain.

3. Why we use it

PurposeData used
Create and run your accountEmail, password hash, name
Enforce your plan's usage allowanceUsage records
Take payment and issue receiptsEmail, subscription and payment records
Service emails (receipts, expiry, security)Email
Prevent abuse and secure the serviceIP address, technical logs
Meet tax and accounting obligationsPayment records

We only send marketing email if you opt in, and every marketing email has a one-click unsubscribe. Service emails about your account and payments are not marketing and cannot be opted out of while you hold an account.

4. Legal basis (GDPR)

  • Contract — running your account, providing the service you paid for, and taking payment.
  • Legitimate interests — security, abuse prevention, and improving the service. We have assessed that these do not override your rights.
  • Legal obligation — retaining financial records for tax purposes.
  • Consent — marketing email, where you have opted in. Withdrawable at any time.

5. Who we share it with

We do not sell personal data and never have. We share it only with the processors needed to run the service:

ProcessorPurposeData
CloudflareSecurity, fast delivery of the site, and cookieless visit statisticsIP address, pages visited, browser type
TronGridChecking USDT payments on the public TRON blockchainOur wallet address and your transaction ID, both already public on-chain
Hosting providerRunning the serversAll service data, at rest
Email providerSending service emailEmail address, message content

We may also disclose data where legally required, or to establish or defend legal claims. If we are ever involved in a merger or acquisition, we will notify you before your data becomes subject to a different privacy policy.

6. Cookies and storage

We use only what is strictly necessary to keep you signed in — no analytics, advertising or third-party tracking cookies. That is why you are not shown a cookie consent banner: there is nothing non-essential to consent to. Visit statistics come from Cloudflare Web Analytics, which sets no cookies and does not follow you across other sites.

NamePurposeExpires
access_tokenKeeps you signed in30 days
refresh_tokenRenews your session without re-login30 days
user (local storage)Your email and plan, for displayUntil sign-out

Signing out clears all of these.

7. How long we keep it

  • Account data — while your account is open, then deleted within 30 days of account deletion.
  • Usage records — 13 months, so you can compare year on year.
  • Payment records — 7 years, as required by tax law. This is a legal obligation and survives account deletion.
  • Technical logs — 90 days.

8. Your rights

Under the GDPR, UK GDPR and the CCPA you can ask us to:

  • Access — get a copy of the personal data we hold about you.
  • Correct — fix anything inaccurate (much of it is editable in your profile).
  • Delete — erase your data, subject to records we must keep by law.
  • Port — receive your data in a machine-readable format.
  • Object or restrict — to processing based on legitimate interests.
  • Withdraw consent — for anything you consented to.
  • Opt out of sale — we do not sell personal data, so there is nothing to opt out of.

Email [email protected] and we will respond within 30 days. Exercising these rights is free and we will never treat you differently for doing so.

If you are in the EU or UK and are unhappy with our response, you may complain to your national data protection authority.

9. Security

  • All traffic is encrypted in transit with TLS.
  • Passwords are hashed with bcrypt — we cannot read them, even if we wanted to.
  • API keys are stored only as hashes; the key itself is shown to you once.
  • Card details never reach our servers; Stripe handles them directly.
  • Access to production systems is restricted and logged.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority within 72 hours of becoming aware of it, as the law requires.

10. International transfers

Our processors may store or process data outside your country. Where data leaves the EEA or UK, transfers are covered by adequacy decisions or Standard Contractual Clauses.

11. Children's privacy

The service is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a child has given us personal data, contact [email protected] and we will delete it.

12. Changes

If we make a material change to this policy we will email registered users at least 30 days before it takes effect, and update the date at the top of this page.

13. Contact

Jaafar
Privacy enquiries: [email protected]
General support: [email protected]

See also our Terms of Service and Refund Policy.

Trendvixo

Product research for independent e-commerce sellers: what is gaining interest, the evidence behind it, and where to source it.

Product

  • Explore products
  • Pricing
  • API documentation

Company

  • How it works
  • Contact and support

Legal

  • Terms of service
  • Privacy policy
  • Refunds and cancellation

Some marketplace links may earn us a commission, at no extra cost to you. Commissions never affect which products appear or how they rank — the trend score alone decides that.

© 2026 Trendvixo[email protected]Research signals, not financial advice.