trikrypt · legal
Privacy Policy
The short version
We collect what you send us: your name and email when you ask for a plan or a free audit, whatever you tell Triky, and the account details of clients who use the portal. We use it to reply to you and to do the work.
This site runs no analytics, no advertising pixels and no third party trackers. We do not sell or rent your information. Ask us to delete it and we will.
Who we are
Trikrypt is a web, SEO and AI studio operating from Texas and working with clients across the United States. This policy covers trikrypt.com, the client portal at client.trikrypt.com, and the information we receive through both.
Reach us at daniel@trikrypt.us for anything in this policy, including a request to see or delete your data.
What we collect
When you contact us
The project form and the free audit form ask for your name and email, and optionally your website, the service you need, and a message. Name and a valid email are required, because we cannot reply without them. The audit form also needs your website address, since that is the thing being audited.
When you talk to Triky
Triky is our chat and voice assistant. If you ask it to book a call it asks for your name, email and a preferred time, and it saves your name and email in your own browser so it does not have to ask twice. Those two values stay on your device and are not sent to us unless you send the meeting request.
Voice mode uses your browser's own built in speech recognition. We never record, receive or store audio. Note that in some browsers, notably Chrome, that built in feature sends what you say to the browser vendor's servers to be transcribed. That is between you and your browser, but you should know it happens before you use voice.
When you use the client portal
Clients have an account holding a company name, contact email, and the projects, files, invoices, contracts and messages that belong to their work with us. Anything you upload is stored for you and is visible only to your account and to us.
Automatically
Our server keeps standard access logs: IP address, browser and device as reported by your browser, the page requested, and the time. We store the IP address and browser string with a form submission so we can identify and block spam. There is no analytics service, no advertising network and no session recording on this site.
Cookies and local storage
The public website sets no cookies. No Google Analytics, no Meta pixel, no advertising tags, no embedded third party maps, videos or fonts. Fonts and images come from our own server.
Two things do store data, and both are functional rather than tracking:
- The chat widget saves your first name and email in your browser's local storage, under the keys
tk_nameandtk_email, so Triky remembers you. Clearing your browser data removes them. - The client portal sets one session cookie once you sign in. It is Secure, HttpOnly and SameSite, it holds nothing but a session reference, and it expires when you close your browser. Without it you cannot stay signed in.
Neither follows you across other websites, because neither can. If we ever add analytics or advertising tools we will update this page and say so before we do.
How we use it
To reply to you, prepare proposals and audits, carry out work you have engaged us for, run the portal, invoice you, and answer questions afterwards. We keep business records because tax and contract law expects us to.
We do not run marketing campaigns off form submissions. If you fill in a form you get a reply about your enquiry, not a newsletter.
Who we share it with
We do not sell, rent or trade your personal information, and we do not share it for anyone else's marketing.
A few providers handle data because the business cannot run otherwise: our hosting provider, which operates the server holding this site, the portal and its database; our email provider, which delivers notifications and carries correspondence; and, if and when card payments are switched on, a payment processor. Card details would be handled entirely by that processor and never touch our server.
Each may use the data only to provide their service to us. Otherwise we disclose information only where the law requires it, in response to a valid legal request, or where necessary to establish or defend a legal claim.
Data belonging to our clients
When we build or maintain a website we often get access to systems holding a client's customers' data, such as a contact form database or a hosting account. In that situation the client is responsible for that data and we act on their instructions. We use such access only for the work agreed, we do not copy customer lists out of it, and access ends when the engagement ends.
How long we keep it
Enquiries are kept while we are in contact and afterwards as a record of who approached us and why. Client records, project files, contracts and invoices are kept for the life of the relationship and then for at least four years, which is the window Texas law allows for most contract claims. Server access logs rotate automatically and are short lived.
Ask us to delete something and we will, apart from records we are legally required to keep.
Your rights
Email daniel@trikrypt.us to ask us to show you what we hold, correct it, delete it, or stop contacting you. We will verify the request comes from you and respond within a reasonable time, normally inside 45 days, at no charge.
Texas residents may have further rights under the Texas Data Privacy and Security Act, including a right to appeal a refusal. To appeal, reply to our response and we will review it and explain the outcome in writing. We handle these requests the same way regardless of where you live.
How we protect it
Everything is served over encrypted HTTPS. Portal sign in uses single use links that expire quickly rather than passwords you could reuse elsewhere, sessions are regenerated on sign in, database queries are parameterised, and uploaded files are stored outside the public web root so they cannot be fetched by guessing a URL.
No system is perfectly secure and we will not claim otherwise. Please do not send card numbers, bank details or similar sensitive information through a web form or chat.
Children's privacy
This is a business to business site. It is not directed at children and we do not knowingly collect information from anyone under 13. Tell us if you think we have and we will delete it.
Links to other sites
We link to our own social profiles and sometimes to client websites we have built. Once you follow one of those links you are on someone else's site under their policy, not ours.
Changes
If we change how we handle information we will update this page and the effective date above. Material changes, such as adding analytics or advertising tools, will be described here rather than made quietly.
Questions about this page?
Email daniel@trikrypt.us and a human answers.
See also our Terms of Service.