1. Introduction
Welcome to TriveniCo ("we," "our," "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website trivenico.com, use our platform, or interact with our services (collectively, the "Services").
We are committed to protecting your privacy and ensuring transparency about our data practices. By using our Services, you agree to the collection and use of information in accordance with this policy.
Data Controller: TriveniCo, Inc., Kathmandu, Nepal. Contact: privacy@trivenico.com
2. Data We Collect
We collect information in the following categories:
2.1 Information You Provide Directly
- Account Information: Name, email, phone, password (hashed), business name, address, tax ID
- Business Information: Store details, products, inventory, pricing, tax settings, shipping profiles
- Payment Information: We do not store credit card numbers. Payment data is processed by our PCI-compliant partners (Stripe, PayPal, etc.)
- Communications: Messages with support, feedback, feature requests, survey responses
- Content: Product descriptions, images, blog posts, reviews, marketing materials you create
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, clicks, search queries
- Device Information: IP address (hashed), browser type, OS, device type, screen resolution
- Location Data: Country, city (from IP, anonymized), timezone, language
- Analytics Events: Page views, product views, add-to-cart, checkout started, purchase completed
2.3 Information from Third Parties
- Payment processors (Stripe, PayPal, etc.) for transaction status
- Shipping carriers (Shippo, ShipStation) for tracking updates
- Marketing platforms (Meta, Google, Klaviyo) for campaign performance
- Accounting software (QuickBooks, Xero) for financial sync
- Social login providers (Google) for authentication
We do NOT collect:
- Credit card numbers or full bank details
- Government-issued ID numbers (SSN, passport, etc.)
- Health or biometric data
- Precise GPS location
3. How We Use Your Data
We process your data for the following purposes, under the following legal bases:
Provide & Improve Services
Operate the platform, process orders, manage inventory, enable POS, run AI features, provide customer support. Legal basis: Contract performance, legitimate interest.
Communications
Send order confirmations, shipping updates, security alerts, marketing emails (with consent), feature announcements. Legal basis: Contract, consent, legitimate interest.
Security & Fraud Prevention
Detect unauthorized access, prevent fraud, enforce terms, comply with legal obligations. Legal basis: Legal obligation, legitimate interest.
Analytics & Personalization
Understand usage patterns, improve UX, provide AI insights, recommend products. Legal basis: Legitimate interest, consent (for AI features).
Marketing & Advertising
Show relevant ads on Meta, Google, Taboola; send promotional emails/SMS (with consent). Legal basis: Consent.
Legal Compliance
Respond to legal requests, regulatory audits, tax reporting, law enforcement. Legal basis: Legal obligation.
4. Data Sharing & Disclosure
We do not sell your personal data. We share data only in the following circumstances:
Service Providers (Processors)
Cloudflare (hosting, D1, R2, Workers AI), payment gateways, shipping carriers, email providers, analytics tools. All under DPAs with strict confidentiality.
Business Partners
Shipping carriers for delivery, accounting software for sync, marketing platforms for campaigns (with your consent).
Legal Requirements
Court orders, subpoenas, regulatory investigations, tax authorities, law enforcement with valid legal process.
Business Transfers
In case of merger, acquisition, or sale of assets, your data may be transferred with appropriate safeguards.
Aggregated/Anonymized Data
We may share aggregated, non-identifiable insights with partners, investors, or publicly (e.g., "TriveniCo stores in 142 countries").
5. Data Security
Encryption
TLS 1.3 in transit; AES-256 at rest (Cloudflare R2, D1). Passwords hashed with PBKDF2 (100,000+ iterations).
Access Controls
Role-based access, principle of least privilege, MFA for admin access, regular access reviews.
Monitoring & Auditing
Continuous security monitoring, vulnerability scanning, annual third-party penetration tests, SOC 2 Type II certified.
Incident Response
24/7 monitoring, automated alerts, incident response plan, breach notification within 72 hours as required by GDPR.
Data Minimization
We collect only what's necessary. No credit card storage, no government IDs, no health data. Ephemeral AI processing (deleted after use).
6. Your Rights
Depending on your location, you may have the following rights under applicable law (GDPR, CCPA, LGPD, etc.):
Access & Portability
Request a copy of your data in machine-readable format (JSON/CSV).
Rectification
Correct inaccurate or incomplete personal data.
Erasure ("Right to be Forgotten")
Request deletion of your data, subject to legal retention requirements.
Restriction & Objection
Restrict processing or object to processing for direct marketing or legitimate interests.
Withdraw Consent
Withdraw consent for marketing, AI features, or cookies at any time.
Automated Decisions
Right to not be subject to solely automated decisions with legal effects.
To exercise your rights:
Email privacy@trivenico.com or use the Data Rights Request form in your dashboard. We respond within 30 days (GDPR) or 45 days (CCPA).
7. International Data Transfers
TriveniCo operates globally. Your data may be transferred to and processed in countries outside your jurisdiction, including the United States, European Union, and Nepal.
We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) with all cross-border processors
- Adequacy Decisions for EU-US Data Privacy Framework certified recipients
- Binding Corporate Rules for intra-group transfers
- Data Localization options for enterprise customers (data stays in chosen region)
Enterprise customers can choose data residency: US, EU, or Asia-Pacific.
8. Data Retention
We retain personal data only as long as necessary for the purposes outlined in this policy:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & Profile Data | Duration of account + 90 days after closure | Contract |
| Order & Transaction Data | 7 years (tax/legal compliance) | Legal Obligation |
| Communications & Support Tickets | 3 years after last interaction | Legitimate Interest |
| Analytics & Event Data | 13 months (anonymized after) | Legitimate Interest |
| Marketing Preferences | Until withdrawal + 2 years | Consent |
| AI Processing Data | Ephemeral (deleted after processing) | Legitimate Interest |
| Authentication Logs | 12 months | Security |
9. Children's Privacy
Our Services are not directed to children under 16 (or the applicable age in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us at privacy@trivenico.com and we will delete it immediately.
10. Changes to This Policy
We may update this policy to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes:
- Via email (for significant changes)
- Through in-app notification
- By updating the "Last Updated" date at the top of this page
Your continued use of the Services after changes constitutes acceptance of the updated policy.
11. Contact Us
Questions, concerns, or requests regarding this Privacy Policy:
Data Protection Officer: dpo@trivenico.com
General Privacy Inquiries: privacy@trivenico.com
Postal Address: TriveniCo, Inc., Thamel, Kathmandu 44600, Nepal
EU Representative: TriveniCo EU B.V., Amsterdam, Netherlands (eu-privacy@trivenico.com)
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority (e.g., ICO in UK, CNIL in France, Garante in Italy).