Legal
Privacy Policy
Your data belongs to you. We use it only to make TrustLoopX work, and we treat it with the care we'd want for our own.
Last updated: May 04, 2026 · Effective immediately
1 Who we are
TrustLoopX ("we", "us", or "our") is a software product based in Sikar, Rajasthan, India. We help local businesses collect Google reviews from their customers using QR codes and AI-powered suggestions.
This Privacy Policy explains how we handle information when you use our website and services at trustloopx.in.
2 Data we collect
From business owners (account holders)
- Account info: Name, email, phone number, password (encrypted)
- Business details: Business name, category, city, address, Google Business URL
- Payment info: Razorpay processes all payments — we never see or store your card or UPI details
- GST details: If you opt for GST invoices, we collect your GSTIN and business legal name
From customers (review submitters)
- Reviews: Star rating, review text, optional name (no login required)
- Technical info: IP address, browser type, device — used only for spam prevention
- Language preference: English, Hindi, or Hinglish selection
⚡ What we DON'T collect
We don't collect customer phone numbers, email addresses, or any contact info. Reviews are anonymous unless the customer chooses to add their name.
3 How we use it
We use your data only for these specific purposes:
- To run the service: Create your account, generate QR codes, store reviews, send email alerts
- To process payments: Razorpay handles transactions; we receive only confirmation
- To improve the product: Aggregate, anonymous data tells us which features people use
- To send important updates: Service announcements, payment receipts, security alerts (no marketing spam)
- To prevent abuse: IP addresses help us detect fake reviews and spam
4 Sharing & partners
We share data only with these specific partners, and only what's necessary:
- Supabase — Hosts our database (data center: Mumbai, India)
- Razorpay — Processes payments (PCI-DSS certified, RBI-regulated)
- Resend — Sends email notifications
- Anthropic Claude API — Generates AI reply suggestions (Pro plan only) — no customer-identifiable data is sent
- Netlify — Hosts our website
We never sell your data. We never share your customer reviews with anyone except you. We never use your data to train AI models.
5 Your rights
You have full control over your data:
- Access: Download all your data anytime from Settings → Danger Zone → Export
- Correction: Update your information anytime from Settings
- Deletion: Delete your account permanently — all data removed within 30 days
- Portability: Export your reviews as CSV/JSON to take elsewhere
- Object: Email us if you object to any specific processing of your data
6 Cookies & tracking
We use a minimal set of cookies, only what's needed for the service to work:
- Authentication cookies: Keep you logged in
- Preference cookies: Remember your language choice
- Analytics: We use privacy-first analytics that don't track you across sites
We don't use Facebook Pixel, Google Ads tracking, or any third-party advertising trackers.
7 Data security
We protect your data with industry-standard measures:
- Encryption in transit: All data uses HTTPS/TLS 1.3
- Encryption at rest: Database encrypted on Supabase servers
- Access controls: Only authorized team members can access systems
- Row-level security: Even within our database, your data is isolated from other businesses
- Regular backups: Daily automated backups with 30-day retention
If we ever experience a data breach affecting your information, we'll notify you within 72 hours as required by Indian data protection law.
8 Children's privacy
TrustLoopX is intended for business owners aged 18 and above. We don't knowingly collect data from children under 18. If you believe a child has submitted information to us, please contact us and we'll delete it promptly.
9 Policy changes
We may update this policy occasionally. When we do, we'll:
- Update the "Last updated" date at the top
- Email you about significant changes (at least 30 days before they take effect)
- Show a banner on your dashboard for major changes
Continuing to use TrustLoopX after changes means you accept the updated policy.
10 Contact us
Questions, concerns, or requests about your data? We're here to help.