Version 2026-07-07-v5
Privacy Policy
How Trotter handles personal data — and your rights over it.
TROTTER PRIVACY POLICY — VERSION 2026-07-07-v5 This Policy explains what personal data Trotter processes, why, on what legal basis, who we share it with, and the rights you have. "Trotter", "we", "us" means the operator named in Section 1. "Personal data" has the meaning given in the EU/UK General Data Protection Regulation (GDPR). This Policy is not legal advice. 1. WHO WE ARE. Trotter is software operated by a Norwegian sole proprietorship (enkeltpersonforetak / ENK) established in Norway. Privacy contact: hasan@matchlit.ai. We have not appointed a statutory Data Protection Officer; the address above reaches the person responsible for privacy. 2. OUR TWO ROLES — CONTROLLER AND PROCESSOR. Trotter plays two different data-protection roles, and which one applies determines who is responsible: (a) CONTROLLER. For data about our direct users and how they use Trotter — account details, login and security data, billing, product/usage and support data — Trotter is the "controller" and this Policy governs. (b) PROCESSOR. For the operating data a business owner enters to run their business — their clients, the clients' contact details, pets, visits, photos, check-in location, notes and invoices — the BUSINESS OWNER is the controller and Trotter is a "processor" acting on the owner's documented instructions. The owner decides what to collect and why; we process it to provide the Service and per Section 16 (Data Processing terms). If you are a client or pet-owner of a Trotter business, that business — not Trotter — is the controller of your data; contact them first, and see Section 11. 3. WHAT WE COLLECT. - Account & identity: email, hashed password, full name, business name, role, timezone, country (inferred at signup from your network's approximate region), Terms-acceptance evidence (version, timestamp, and a salted hash of IP and user-agent). - Business operating data (as processor): clients and their names, emails, phones, addresses and access notes; pets; services and rates; visits, schedules, sitter check-in timestamps and approximate GPS coordinates; photos and free-text notes uploaded by sitters; invoices; booking requests. - Team/sitter data: sitter name, email, phone, membership, and estimated pay figures you configure. - Technical & security: IP address (salted-hashed when stored for abuse-prevention), user-agent, device/browser data, and error/diagnostic logs. - Payments metadata: when an owner connects Stripe, Stripe processes card and payout data directly on the owner's account. We never receive or store full card numbers. We store non-sensitive references (e.g. a Stripe account or customer identifier) needed to operate the feature. - Email events: sent / delivered / opened / clicked signals from our email provider. We do not intentionally collect special-category data (health, biometrics, etc.). Please do not enter it into free-text fields. 4. LEGAL BASES (GDPR Article 6). We rely on: - Performance of a contract (Art. 6(1)(b)) — to create your account and provide the Service you signed up for. - Legitimate interests (Art. 6(1)(f)) — to secure the Service and prevent abuse, to send you transactional/service messages, to keep records, and to maintain and improve the product; we balance these against your rights and you may object (Section 9). - Consent (Art. 6(1)(a)) — for any optional analytics cookies or optional marketing; you may withdraw consent at any time. - Legal obligation (Art. 6(1)(c)) — to meet accounting, tax and other legal duties and to respond to lawful requests. Where we act as processor (Section 2b), the legal basis for the underlying processing is the business owner's, not ours. 5. HOW WE USE DATA. To provide, operate, secure and support the Service; to send transactional email (visit assignments, sitter/client invites, visit report cards, calendar invites, invoices, billing and account notices); to prevent fraud and abuse; to comply with law; and, only with consent, for optional analytics. 6. SUB-PROCESSORS AND RECIPIENTS. We use a small set of vendors to run the Service, each bound by a data-processing agreement: - Vercel — application hosting (United States / global edge). - Supabase — database, authentication and file storage for photos (EU and/or US region). - Stripe — payments and Connect onboarding/payouts (US, EU/Ireland). - Resend — transactional email (United States). - Cloudflare — DNS, CDN and DDoS protection (global). Data is also shared between users of the same business as inherent to the Service (an owner sees their sitters' and clients' data; a client's portal shows the visits/photos/notes for their pets; a sitter sees their assigned visits). WE DO NOT SELL YOUR PERSONAL DATA AND DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING. We may disclose data if required by law or to protect rights and safety, and in a merger or sale of the business (successors are bound by this Policy). 7. INTERNATIONAL TRANSFERS. Some vendors process data in the United States. Where personal data is transferred out of the EU/EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), and/or on a vendor's certification under the EU-US Data Privacy Framework, together with supplementary measures where appropriate. You can ask us for details. 8. HOW LONG WE KEEP DATA. We keep data while your account is active and as needed to provide the Service. Some records are retained longer to meet legal duties (e.g. Norwegian bookkeeping law generally requires retaining accounting records for around five years). A business that is closed/archived may be retained so its team keeps an employment record; you may request hard deletion of your personal data by emailing hasan@matchlit.ai, and we will delete it unless we must keep it by law. Backups are purged on a rolling cycle. 9. YOUR RIGHTS (EU/EEA, UK, Switzerland). You have the right to: access your data; correct inaccurate data; erase data; restrict or object to processing (including profiling and direct-marketing); data portability; and to withdraw consent at any time without affecting prior processing. To exercise any right, email hasan@matchlit.ai — we respond within 30 days (extendable where permitted). We will not discriminate against you for exercising a right. You also have the right to lodge a complaint with your data-protection supervisory authority — in Norway this is Datatilsynet (datatilsynet.no) — or the authority in your country of residence. 10. CALIFORNIA AND OTHER U.S. STATE RIGHTS. If you are a California resident (or in another U.S. state with a comprehensive privacy law), you may request to know, access, correct, or delete the personal information we hold, and to opt out of any "sale" or "sharing" — although we do NOT sell or share personal information and do not process sensitive personal information for inferring characteristics. We do not discriminate for exercising these rights. Submit requests to hasan@matchlit.ai; we may need to verify your identity. 11. CLIENTS AND PETS OF A TROTTER BUSINESS. If your pet-care provider uses Trotter and you are their client, that BUSINESS is the controller of your and your pets' data; Trotter only processes it for them. Please direct access/deletion requests to the business first. If you contact us, we will forward your request to the business and assist as their processor. 12. CHILDREN. The Service is intended for operating a business and is not directed to children. We do not knowingly collect personal data from a child under 16 (or the applicable digital-consent age) as a controller. Where a person under 18 uses Trotter to run a small pet-care business, they must do so only with a parent/guardian as described in the Terms of Service, and the parent/guardian is responsible for the account and its data. If you believe a child has provided us data, email hasan@matchlit.ai and we will delete it. 13. AUTOMATED DECISIONS. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Figures the Service computes (pay, fees, invoice totals, fx conversion) are informational tools, not automated decisions about you. 14. SECURITY & BREACH NOTIFICATION. We use reasonable technical and organisational measures (encryption in transit, access controls, hashed passwords, salted-hashed identifiers). No system is perfectly secure. If a personal-data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, affected individuals, in line with GDPR (generally within 72 hours of becoming aware). Report vulnerabilities to hasan@matchlit.ai. 15. COOKIES & SIMILAR TECHNOLOGIES. We use strictly necessary cookies to keep you signed in and to secure the Service; these do not require consent. We do not use third-party advertising cookies. Any optional analytics is off by default and only set with your consent. 16. DATA PROCESSING TERMS (FOR BUSINESS CUSTOMERS). Where Trotter processes personal data on a business owner's behalf (Section 2b), the owner is the controller and Trotter is the processor. This Section, together with the Terms of Service, forms the data-processing agreement between us: we process such data only on the owner's documented instructions (including to provide the Service); we require confidentiality of personnel; we apply the security measures in Section 14; we use only the sub-processors in Section 6 and will give notice of changes; we assist the owner with data-subject requests, security, breach notification and, where applicable, impact assessments; and on termination we delete or return the data except where retention is legally required. The owner is responsible for having a lawful basis to collect and enter their clients' and pets' data and for informing their clients. 17. CHANGES. We may update this Policy. Material changes will be flagged in the Service or by email, and the version above will change. Continued use after an update is subject to the updated Policy. 18. CONTACT. Privacy questions and requests: hasan@matchlit.ai.
See also our Terms of Service.