Legal
Privacy Policy
Last updated: 2 September 2026
1. Who we are
trendJack ("we", "us", "our") is a marketing intelligence SaaS platform operated by trendJack Ltd., a company registered in England and Wales under company number 17429744.
For any questions about this policy or your data, contact us at info@trendjack.io.
2. What data we collect
Account data
- Name, email address, password (hashed)
- Company name and role, if provided
- Billing details (handled by our payment processor, see Section 4)
Usage data
- How you use the platform: features accessed, queries run, content generated
- Device and browser information, IP address, log data
- Cookies and similar tracking technologies (see Section 7)
Content and third-party data
- Content you upload or connect to trendJack (e.g. campaign data, marketing assets)
- If you connect third-party accounts (social media, advertising platforms, analytics tools) to trendJack, we access data from those accounts as permitted by your authorisation and their terms
3. Why we collect it (legal basis)
Under UK GDPR, we process your data on the following bases:
| Purpose | Legal basis |
|---|---|
| Providing and maintaining the service | Contract |
| Processing payments | Contract |
| Improving the platform, analytics | Legitimate interests |
| Marketing communications | Consent (opt-in) |
| Legal and regulatory compliance | Legal obligation |
4. Payment processing
Payments are processed by Stripe and Revolut Business. We do not store full card details on our own servers. Our payment processor's own privacy policy governs how they handle your payment data:
- Stripe: https://stripe.com/privacy
- Revolut: https://www.revolut.com/legal/privacy
5. Who we share data with
We share data with:
- Service providers: hosting, payment processing, analytics, customer support tools, under data processing agreements
- Our development team: engineers working on trendJack, including team members based outside the UK/EEA, may access personal data as needed to build, maintain, and support the Service, under contractual confidentiality and data protection obligations (see Section 6)
- Third-party integrations you connect: only the data you authorise, and only to enable the connected functionality
- Legal authorities: where required by law
We do not sell your personal data. Access to personal data is limited to what's needed for the relevant role, and we require anyone with access, including offshore team members, to follow the same data protection standards as this policy.
6. International transfers
Some of our service providers and development team members are located outside the UK/EEA, in Malaysia. Where we transfer personal data outside the UK, we put appropriate safeguards in place before doing so, which may include:
- The UK's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses
- Assessing whether the destination country has adequacy regulations recognised by the UK government
- Contractual confidentiality, security, and data-handling obligations with any individual or firm accessing personal data, including offshore developers
We carry out a transfer risk assessment before enabling any offshore access to personal data, and limit what data offshore team members can access to what's necessary for their work (e.g. using anonymised or test data during development wherever possible, rather than real user data).
7. Cookies
We use cookies for:
- Essential functionality (login sessions, security)
- Analytics (understanding usage patterns)
- Marketing and advertising
You can control cookies through your browser settings or our cookie consent tool.
8. Data retention
We retain your data for as long as your account is active, plus 6 years after closure for legal, accounting, or dispute-resolution purposes, unless a longer retention period is required by law.
9. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Object to or restrict certain processing
- Data portability
- Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, contact info@trendjack.io. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
10. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and regular security reviews. No system is completely secure, and we cannot guarantee absolute security.
11. Children
trendJack is not directed at individuals under 18. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified via email or in-app notice. Continued use of trendJack after changes constitutes acceptance.
