← Back to signup

Privacy Policy

Last updated: 17 August 2026

This Privacy Policy explains how Trivo Technologies collects, uses, and protects personal information when you use the Trivo platform (the “Service”) as a merchant.

1. Information we collect

Account details (name, email, phone, store URL, country/region), billing information processed by our payment provider, and operational data you enter (products, orders, customers). We also collect technical data such as IP address and usage logs to operate and secure the Service.

2. How we use it

To provide and improve the Service, process your plan billing, send transactional and service messages, prevent abuse, and comply with legal obligations.

3. Your customers’ data

Data about your storefront’s customers is processed on your behalf. You are the data controller for that data; we act as a processor and use it only to provide the Service to you.

4. Sharing

We share data with sub-processors strictly to run the Service (e.g. hosting, payments, email, analytics, AI features) under contractual confidentiality. We do not sell personal information.

5. Retention

We retain account and operational data for as long as your account is active and as needed to comply with legal obligations, resolve disputes, and enforce agreements.

6. Your rights

Depending on your jurisdiction you may have rights to access, correct, export, or delete your personal data. Account-level data export and deletion tools are available in your settings.

7. Security

We use industry-standard measures including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

8. Google user data

Trivo offers an optional integration that connects your own Google account to your Trivo store, so that Search Console and Google Analytics figures appear in your dashboard and you can submit your sitemap without leaving it. This section describes that integration specifically and applies in addition to the rest of this policy. The integration is off until you start it yourself, and nothing here applies if you never connect an account.

What we ask for, and why

When you start the connection we ask Google for the following, and for nothing else. Each is used only for the dashboard feature named beside it:

  • Your name and email address (openid, email) — so the dashboard can show you which Google account is connected and let you confirm you are disconnecting the right one.
  • Google Search Console (webmasters) — to read your search performance (clicks, impressions, click-through rate and average position), to read the index status of individual pages, and to submit or re-submit your sitemap. Submitting a sitemap is a write, which is why this is not the read-only scope; we make no other change to your Search Console property.
  • Google Analytics (analytics.readonly) — read-only traffic figures shown alongside the search data. This one is optional: if you decline it, the Search Console features still work.

How we store it

We store the refresh token Google issues, against your store record, so the dashboard can keep showing your figures without asking you to sign in again. Access tokens are requested from Google as needed and are never written to our database. We do not copy your Search Console or Analytics data into our own storage for any purpose other than displaying and caching the report you asked for.

Limited Use

Trivo’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular we do not sell this data, do not transfer it to advertising platforms, data brokers or resellers, do not use it to serve advertising, and do not use it to train generalised artificial-intelligence or machine-learning models. No Trivo employee reads it except with your explicit permission (for example when you ask us to investigate a support issue), where it is necessary for security purposes, or where we are required to by law.

Disconnecting

You can disconnect at any time from the Google panel in your dashboard under Settings → SEO, which deletes the stored refresh token. You can also revoke Trivo’s access directly from your Google Account permissions page. Revoking access stops all further reads immediately.

9. Contact

Privacy questions, and any request to exercise the rights in section 6, can be sent to privacy@trivotechnologies.com or through the contact form at trivotechnologies.com/contact. Trivo Technologies is the data controller for the account data described in this policy.