Privacy Policy
The short version: we collect the minimum needed to run your account, we never sell your data, and you can delete it whenever you want.
1. Who we are
Jaafar, an individual based in Iraq, trading as Trendvixo, is the data controller for personal data processed through Trendvixo.
For any privacy question, email [email protected].
2. What we collect
You give us
- Account details — email address, password (stored only as a cryptographic hash, never in readable form), and optionally your first name, last name and company name.
- Support messages — anything you send us when you get in touch.
We generate
- Usage records — a daily count of API calls and records returned per account, used to enforce your plan allowance and draw your usage chart.
- Subscription and payment records — which plan you are on, when it started and renews, amounts paid, and a payment reference.
- Technical logs — IP address, request path, response status and timing. Used for security, rate limiting and debugging.
What we deliberately do not collect: we do not store card numbers (Stripe handles those and we never receive them), we do not run advertising or cross-site tracking, and we do not buy personal data from third parties.
If you pay by cryptocurrency
We store the transaction hash you submit and the wallet address it came from, so we can verify the payment on the public blockchain. Blockchain transactions are public and permanent by design; we cannot delete them from the chain.
3. Why we use it
| Purpose | Data used |
|---|---|
| Create and run your account | Email, password hash, name |
| Enforce your plan's usage allowance | Usage records |
| Take payment and issue receipts | Email, subscription and payment records |
| Service emails (receipts, expiry, security) | |
| Prevent abuse and secure the service | IP address, technical logs |
| Meet tax and accounting obligations | Payment records |
We only send marketing email if you opt in, and every marketing email has a one-click unsubscribe. Service emails about your account and payments are not marketing and cannot be opted out of while you hold an account.
4. Legal basis (GDPR)
- Contract — running your account, providing the service you paid for, and taking payment.
- Legitimate interests — security, abuse prevention, and improving the service. We have assessed that these do not override your rights.
- Legal obligation — retaining financial records for tax purposes.
- Consent — marketing email, where you have opted in. Withdrawable at any time.
7. How long we keep it
- Account data — while your account is open, then deleted within 30 days of account deletion.
- Usage records — 13 months, so you can compare year on year.
- Payment records — 7 years, as required by tax law. This is a legal obligation and survives account deletion.
- Technical logs — 90 days.
8. Your rights
Under the GDPR, UK GDPR and the CCPA you can ask us to:
- Access — get a copy of the personal data we hold about you.
- Correct — fix anything inaccurate (much of it is editable in your profile).
- Delete — erase your data, subject to records we must keep by law.
- Port — receive your data in a machine-readable format.
- Object or restrict — to processing based on legitimate interests.
- Withdraw consent — for anything you consented to.
- Opt out of sale — we do not sell personal data, so there is nothing to opt out of.
Email [email protected] and we will respond within 30 days. Exercising these rights is free and we will never treat you differently for doing so.
If you are in the EU or UK and are unhappy with our response, you may complain to your national data protection authority.
9. Security
- All traffic is encrypted in transit with TLS.
- Passwords are hashed with bcrypt — we cannot read them, even if we wanted to.
- API keys are stored only as hashes; the key itself is shown to you once.
- Card details never reach our servers; Stripe handles them directly.
- Access to production systems is restricted and logged.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority within 72 hours of becoming aware of it, as the law requires.
10. International transfers
Our processors may store or process data outside your country. Where data leaves the EEA or UK, transfers are covered by adequacy decisions or Standard Contractual Clauses.
11. Children's privacy
The service is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a child has given us personal data, contact [email protected] and we will delete it.
12. Changes
If we make a material change to this policy we will email registered users at least 30 days before it takes effect, and update the date at the top of this page.
13. Contact
Jaafar
Privacy enquiries: [email protected]
General support: [email protected]