Privacy policy

# Privacy Policy

**Last updated: May 2026**
**Trovayo | trovayo.com | hello@trovayo.com**

---

Trovayo ("we", "us", "our") is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

---

## 1. Who We Are

**Data Controller:** Trovayo
**Email:** hello@trovayo.com
**Phone:** +44 7737 139025
**Address:** 128 City Road, London EC1V 2NX, United Kingdom

---

## 2. What Data We Collect

### Data you provide directly:
- **Name and email address** — when placing an order or creating an account
- **Payment information** — processed securely by Shopify Payments (we never store card details)
- **Billing address** — for order processing and tax purposes
- **Communications** — emails or messages you send us

### Data collected automatically:
- **IP address and browser information** — for security and analytics
- **Cookies and usage data** — pages visited, time spent, actions taken
- **Device information** — device type, operating system

---

## 3. How We Use Your Data

We use your data to:

- Process and fulfil your orders
- Deliver digital products and access credentials
- Send order confirmation and customer service communications
- Send marketing emails (only with your consent — opt out anytime)
- Improve our website and products
- Comply with legal obligations
- Prevent fraud and protect our platform

**Legal basis:** Contract performance, legitimate interests, consent (for marketing), and legal obligation.

---

## 4. Data Sharing

We do not sell your personal data. We share it only with:

- **Shopify** — our ecommerce platform (order and payment processing)
- **Resend** — transactional email delivery
- **DigitalOcean** — hosting provider for our guide access platform
- **Stripe / PayPal** — secure payment processing
- **Legal authorities** — if required by applicable law

All third parties are contractually bound to protect your data.

---

## 5. Data Retention

- **Order data** — retained for 7 years (UK tax law requirement)
- **Account data** — retained while your account is active, or 3 years after last login
- **Marketing preferences** — until you unsubscribe
- **Support communications** — 2 years

---

## 6. Your Rights Under UK GDPR

You have the right to:

- **Access** — request a copy of your personal data
- **Rectification** — correct inaccurate data
- **Erasure** — request deletion of your data ("right to be forgotten")
- **Restriction** — limit how we process your data
- **Portability** — receive your data in a portable format
- **Object** — object to processing based on legitimate interests
- **Withdraw consent** — for any consent-based processing (e.g. marketing emails)

To exercise any right, email **hello@trovayo.com**. We will respond within **30 days**.

---

## 7. Cookies

We use the following types of cookies:

| Type | Purpose |
|---|---|
| Essential | Shopping cart, login sessions |
| Analytics | Understanding how visitors use our site (Google Analytics) |
| Marketing | Retargeting ads (Facebook Pixel, Google Ads) |

You can manage cookie preferences via your browser settings or our cookie consent banner.

---

## 8. International Transfers

If we transfer data outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses or adequacy decisions approved by the ICO.

---

## 9. Security

We implement appropriate technical and organisational measures to protect your personal data, including SSL encryption, secure cloud hosting, and strict access controls.

---

## 10. Complaints

If you believe we have mishandled your personal data, you have the right to lodge a complaint with the **Information Commissioner's Office (ICO)**:

- Website: ico.org.uk
- Phone: 0303 123 1113

We would always appreciate the opportunity to resolve any concern directly first — please contact us at hello@trovayo.com before escalating.

---

## Contact Us

**Email:** hello@trovayo.com
**Phone:** +44 7737 139025
**Address:** Trovayo, 128 City Road, London EC1V 2NX, United Kingdom