LEGAL
Privacy Policy
1. Introduction
TradeHox (“we”, “our”, “us”) respects your privacy. This Privacy Policy explains how we collect, use, share, and protect personal information when you visit tradehox.com or engage our services.
2. Information We Collect
Information you provide directly:
- Contact details: name, email address, company name, role
- Communications: messages sent via contact form, email, scheduled calls
- Business context: information shared during discovery calls, audits, and engagements
Information collected automatically:
- Site analytics via Plausible (privacy-first, no cookies)
- Server logs (IP addresses, browser type, pages visited)
- Form submissions and their metadata
We do NOT collect:
- Sensitive personal data (race, religion, political views)
- Health information
- Children’s data (under 18)
- Financial account numbers
3. How We Use Your Information
We use your information to:
- Respond to contact form submissions and inquiries
- Schedule and conduct discovery calls
- Send engagement-related communications (invoices, project updates)
- Improve our website and services
- Comply with legal obligations
We do NOT:
- Sell your data to third parties
- Use your data for advertising
- Share with marketing networks
4. Legal Basis (GDPR / DPDP Act)
We process personal data under these legal bases:
- Consent: When you submit contact forms
- Contract: When we have an active engagement
- Legitimate interests: For service improvement and security
- Legal obligation: For tax and regulatory compliance
5. Data Sharing
We share data only with:
- Service providers (subprocessors) listed in our Trust Center
- Legal authorities when required by law
- Successors in case of business transfer (with notice to you)
6. Data Retention
- Contact form submissions: 24 months
- Active engagement data: duration of engagement + 7 years (tax/audit)
- Marketing communications: until unsubscribed
- Cookies/analytics: 0 days (we don’t use cookies)
7. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (subject to legal retention requirements)
- Object to processing
- Data portability
- Withdraw consent
To exercise these rights, email [email protected]. We respond within 30 days.
8. Data Security
We implement:
- TLS 1.3 encryption in transit
- Encrypted data at rest
- Access controls and audit logs
- Regular security reviews
- Incident response plan
9. International Transfers
If you are in the EU or UK, data may be transferred to the United States (Vercel hosting, Resend email) and India (our operations). We use Standard Contractual Clauses (SCCs) for these transfers.
10. Children’s Privacy
TradeHox services are B2B and not intended for users under 18. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy. Material changes will be communicated via email to active clients and posted with an updated “Last updated” date.
12. Contact
- Privacy questions: [email protected]
- Data Protection Officer: [email protected]
- General inquiries: [email protected]
Questions about this policy? [email protected] · General contact