TRISLON
PrivacyTermsCookiesRefundsBillingAIAcceptable UseData ProcessingData Deletion

Privacy

Privacy Policy

This Privacy Policy explains how TRISLON collects, uses, stores, shares, and protects personal information when you use our website, account dashboard, mini-sites, CRM, AI, analytics, billing, and related services.

Last updated: 20 June 2026Company: TRISLONContact: olexiy.velykyi.dev@gmail.comAddress: 106 Lincoln Road, Peterborough, Cambridgeshire PE1 4YG, United KingdomSite: https://trislon.com

Summary of key points

  • We collect information you provide to us, such as account details, contact details, business profile details, lead and booking information, and support messages.
  • We collect technical and usage information automatically when you use the Services, including device, browser, IP address, log, and analytics information.
  • We do not intentionally collect sensitive personal information and the Services are not designed for medical records, full payment-card data, government identifiers, biometric data, or other highly sensitive information.
  • Payments are processed by Stripe. TRISLON does not store full payment-card numbers.
  • We use personal information to provide, secure, improve, administer, and support the Services, including account access, subscriptions, mini-sites, CRM workflows, AI tools, analytics, and communications.
  • You can exercise privacy rights by contacting us or by using the Data Deletion Instructions page at /data-deletion.
  • You can read more about cookies and optional analytics storage in our Cookie Policy at /cookies.

1. What information do we collect?

We collect personal information that you voluntarily provide when you register for the Services, express interest in our products, create or manage a business workspace, publish a mini-site, submit a form, use a chatbot, contact us, or otherwise interact with us.

The exact information we collect depends on how you use the Services, the choices you make, and the features you use.

Personal information provided by you

  • Names, usernames, email addresses, phone numbers, passwords, account preferences, and authentication details.
  • Business profile information, including business name, category, city, address, opening hours, services, prices, descriptions, contact details, social links, brand settings, website content, chatbot knowledge, reviews, and uploaded images.
  • Lead and booking information, including visitor name, phone, email, preferred date or time, selected service, message, source, campaign attribution, visitor or session identifiers, status, notes, and Telegram reminder details when enabled.
  • Support, billing, feedback, and marketing communication details.

Payment data

If you purchase a paid subscription or paid service, payment data is handled by Stripe. Stripe may collect payment instrument details, billing details, invoices, receipts, refunds, disputes, and subscription status. You can review Stripe's privacy notice at https://stripe.com/gb/privacy.

Social login and platform data

If you choose to register or log in using Google, Facebook, Instagram, Firebase, or another supported provider, we may receive profile information such as provider user ID, name, email address, avatar, and other information made available by that provider according to your settings.

Information automatically collected

  • Log and usage data, including IP address, browser type, device characteristics, operating system, language preferences, referring URLs, pages viewed, timestamps, feature usage, error data, and diagnostic information.
  • Device data, including computer, phone, tablet, browser, hardware model, Internet service provider, mobile carrier, operating system, and system configuration information.
  • Location data that may be inferred from IP address or device settings. You can disable precise location access in your device or browser settings, but some features may not work as expected.
  • Cookie, local storage, session storage, analytics consent, visitor ID, session ID, source, campaign, and interaction data where optional analytics is accepted or otherwise permitted.

Information from other sources

We may receive limited information from public databases, marketing partners, social media platforms, integration providers, payment providers, analytics tools, security tools, or business owners who enter customer, lead, booking, review, or CRM information into their workspace.

Google API data

Where Google APIs are used, our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2. How do we process your information?

  • To create, authenticate, secure, and manage user accounts.
  • To provide and administer the Services, including mini-sites, CRM, calendar and booking workflows, chatbot features, reviews, campaign tools, content generation, analytics, uploads, and automation.
  • To process subscriptions, billing, invoices, refunds, and plan access through Stripe.
  • To respond to support requests, service enquiries, feedback, and administrative communications.
  • To send service notices, policy updates, security alerts, billing notices, and other administrative information.
  • To send marketing and promotional communications where permitted by law and your communication preferences.
  • To understand usage trends, measure feature performance, improve the Services, and develop better product experiences.
  • To prevent fraud, abuse, spam, security incidents, unauthorised access, and other harmful activity.
  • To comply with legal obligations and protect legal rights, vital interests, and the safety of individuals.

3. What legal bases do we rely on?

Where the UK GDPR, GDPR, or similar laws apply, we process personal information only when we have a valid legal basis.

  • Consent: for optional analytics storage, certain marketing communications, Telegram reminders, and other optional features where consent is required. You can withdraw consent at any time.
  • Performance of a contract: to create accounts, provide the Services, manage subscriptions, deliver support, and fulfil our service agreement.
  • Legitimate interests: to secure and improve the Services, prevent fraud and abuse, understand product performance, support marketing activities, and maintain business records where those interests are not overridden by individual rights.
  • Legal obligations: to comply with accounting, tax, fraud prevention, regulatory, law enforcement, dispute, and legal-claims obligations.
  • Vital interests: where processing is necessary to protect someone's vital interests or safety.

4. When and with whom do we share personal information?

We may share personal information with vendors, service providers, contractors, processors, and integration providers that perform services for us or on our behalf. They are only permitted to process the information as needed to provide, secure, support, or lawfully administer the Services.

Service providers and integrations

  • AI service providers: OpenAI.
  • Cloud hosting, infrastructure, and optimisation: Vercel and Supabase.
  • Database, backup, and security: Supabase.
  • Billing and invoices: Stripe.
  • User account registration and authentication: Firebase Authentication, Google Sign-In, Facebook Login, and Instagram Authentication.
  • Third-party account connections: Google account, Instagram account, and Facebook account integrations.
  • Uploads and public-form protection where configured: Cloudflare R2 and Cloudflare Turnstile.
  • Email, messaging, analytics, error monitoring, and security providers where configured for the Services.

Business transfers

We may share or transfer information in connection with, or during negotiations of, a merger, sale of company assets, financing, acquisition, reorganisation, or similar business transaction.

Business owner workspaces

For leads, bookings, reviews, chatbot messages, and similar customer data processed for a business owner, TRISLON generally acts as a processor. The business owner is responsible for telling its own customers how it uses their data and for establishing the relevant lawful basis.

5. Do we use cookies and other tracking technologies?

We use cookies and similar technologies to keep accounts signed in, maintain security, save preferences, prevent crashes, fix bugs, support basic site functions, and, where permitted, understand how the Services are used.

Public mini-sites may record a basic anonymous visit and may ask for analytics consent before using persistent visitor or session identifiers and optional interaction analytics. Details are set out in our Cookie Policy at /cookies.

6. Do we offer artificial intelligence-based products?

Yes. TRISLON offers products, features, and tools powered by artificial intelligence, machine learning, or similar technologies.

  • AI automation and workflow suggestions.
  • AI predictive analytics and recommendations.
  • AI-generated draft content, replies, campaigns, chatbot answers, mini-site copy, and image creative support.
  • Image generation and image-related creative tools where enabled.

How we process data using AI

When you use an AI feature, relevant business profile data, services, prices, goals, uploaded media context, lead context, review context, campaign data, chatbot knowledge, analytics summaries, and user instructions may be sent to AI service providers so the requested output can be generated. AI outputs are drafts and should be reviewed before use.

7. How do we handle social logins?

If you register or log in using a supported social login, we receive profile information from that provider. The information may include your name, email address, provider user ID, avatar, and other information you choose to make available. We use this information only for account access, authentication, profile display, security, and related service purposes described in this policy.

8. Is your information transferred internationally?

Our Services may use providers and infrastructure located in the United Kingdom, United States, European Economic Area, and other countries. Where UK, EEA, or Swiss data protection law requires safeguards for international transfers, we use applicable adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, and provider data-processing terms where appropriate.

9. How long do we keep your information?

  • Account, workspace, mini-site, CRM, lead, booking, content, review, chatbot, campaign, and analytics records are normally kept while the account or workspace is active.
  • Data may be deleted when the account holder deletes the relevant workspace, closes the account, or makes a verified deletion request, unless we need to keep it for legal, security, billing, tax, fraud prevention, dispute, backup, or legitimate business reasons.
  • If we no longer have an ongoing legitimate need to process personal information, we will delete or anonymise it where reasonably possible.
  • Deleted information may remain temporarily in restricted backups until those backups are securely rotated or deleted.

10. How do we keep your information safe?

We use appropriate technical and organisational measures designed to protect personal information, including access controls, secure session cookies, server-side validation, rate limiting, billing-webhook verification, database constraints, provider security controls, and operational safeguards. No electronic transmission or storage technology can be guaranteed to be 100% secure, so you should use the Services only in a secure environment.

11. Do we collect information from minors?

We do not knowingly collect data from or market to children under 18 years of age. TRISLON accounts are intended for business users aged 18 or over. If we learn that personal information from a child under 18 has been collected without appropriate authorisation, we will take reasonable steps to delete it. If you believe this has happened, contact us at olexiy.velykyi.dev@gmail.com.

12. What are your privacy rights?

Depending on where you are located and the applicable law, you may have rights to access, correct, delete, restrict, or receive a copy of your personal information, object to certain processing, withdraw consent, and avoid solely automated decisions with legal or similarly significant effects.

If you are located in the EEA or UK and believe we are processing your personal information unlawfully, you may complain to your local data protection authority or to the UK Information Commissioner's Office. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

  • To withdraw consent, contact us using the details in this policy or use available cookie settings where the choice relates to optional analytics.
  • To opt out of marketing emails, use the unsubscribe link in the email or contact us.
  • To review or update account information, log in to your account settings where available.
  • To request access, correction, deletion, or other privacy action, contact us or use the Data Deletion Instructions page at /data-deletion.

13. Controls for Do-Not-Track features

Some browsers and mobile systems include Do-Not-Track signals. At this stage, no uniform standard for recognising and implementing DNT signals has been finalised, so we do not currently respond to DNT browser signals. If a standard is adopted that we must follow, we will update this policy.

14. Do we make updates to this notice?

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated date at the top of this page. If we make material changes, we may notify you by posting a notice, updating the page, or sending a direct notification where appropriate.

15. How can you contact us about this notice?

Email: olexiy.velykyi.dev@gmail.com

Postal address: Trislon, 106 Lincoln Road, Peterborough, Cambridgeshire PE1 4YG, United Kingdom.

16. How can you review, update, or delete the data we collect from you?

To request review, update, correction, access, deletion, or withdrawal of consent, contact us at olexiy.velykyi.dev@gmail.com or use the Data Deletion Instructions page at /data-deletion. We may verify your identity before completing a request and will consider and act on requests in accordance with applicable data protection laws.