← Back to TrailMap

Privacy Policy

Draft — not yet in effect

Last updated: [attorney/business to confirm publication date] · Status: DRAFT

1. Scope and roles

This Privacy Policy describes how Sasquatch Creative TX ("TrailMap," "we," "us," or "our") handles personal data in connection with the marketing website at findtrailmap.com, the TrailMap application at trailmap.sasquatchcreativetx.com, and related communications.

TrailMap is a business-to-business (B2B) product. In most of the processing this Policy describes, TrailMap plays two different roles:

  • As a controller ("business" under the CCPA), for account and billing contact information about Customer and its Authorized Users, and for TrailMap's own product/usage analytics. This Policy is the primary document governing that processing.
  • As a processor ("service provider" under the CCPA), for Customer Data — the paid-media performance data a Customer uploads or connects — which TrailMap processes only on Customer's behalf and instructions. The Data Processing Addendum governs that processing in detail and controls if it conflicts with this Policy.

2. Information we collect

2.1 Account and contact information

When Customer or an Authorized User registers, we collect a name, business email address, and a password. Passwords are never stored in plaintext — they are hashed with argon2id before storage. Session identifiers are random tokens; only a SHA-256 hash of the token is ever persisted. We also collect a Workspace/company name and, where Customer connects billing, information Stripe returns to us about the billing contact and subscription status. We do not receive or store full payment card numbers — Stripe handles and tokenizes those directly.

2.2 Customer Data (paid-media performance data)

Customer Data is fundamentally business data about ad campaigns, not consumer personal data: campaign, ad group, ad, and keyword names and IDs; spend, impressions, clicks, conversions, revenue, and related performance metrics; and, for the beta GA4 connector, channel-level conversion figures Google Analytics has already attributed. It is supplied either by direct file upload or by an official-API Connector Customer authorizes.

Customer Data can incidentally include limited personal information — most commonly, naming conventions a Customer or its team chose for campaigns, ad sets, or creatives, or a business contact's name/email in a lead-gen conversion field. TrailMap does not intentionally collect consumer personal data through Connectors — every Connector is a read-only reporting-level integration; it does not pull individual consumer records, browsing history, or ad-targeting audience lists.

2.3 Connector credentials

To use an optional Connector, Customer supplies platform-issued credentials (OAuth refresh tokens, developer tokens, API keys, or long-lived access tokens). These are encrypted at rest with Fernet (AES-128-CBC + HMAC-SHA256), keyed by a secret TrailMap operations manages; production deployments are required to set a real key, and TrailMap supports rotating that key without losing access to already-encrypted credentials. Credentials are never displayed back after they are saved and are never intentionally written to logs.

2.4 Usage and product analytics

We collect data about how the Service is used — page views, feature usage events, signup and activation events, analysis-run counts, and similar product-usage metrics — assembled from a durable, aggregated per-tenant/per-day rollup plus a shorter-lived raw event stream used for near-term troubleshooting. This cross-tenant analytics view is used internally by TrailMap operations and is not exposed to other tenants/customers.

2.5 Log data and IP addresses

Our servers log standard request metadata, including IP addresses, for authentication, rate-limiting, abuse prevention, and debugging.

2.6 Cookies and session data

The TrailMap application sets one functional session cookie — a random token used to keep you signed in — stored on our servers only as a one-way hash. When served over HTTPS in production, the cookie is marked Secure. TrailMap does not use third-party advertising or cross-site tracking cookies on the application.

Attorney/business to confirm: whether the deployed marketing site adds any analytics/cookie script — the version reviewed for this draft loads no third-party script or cookie of any kind beyond the fonts/styles it self-hosts.

2.7 Payment information

Subscription billing is handled by Stripe. Stripe collects and processes payment details under its own privacy policy and terms; we receive from Stripe only the billing contact information, subscription/plan status, and transaction metadata needed to operate the account.

2.8 Support and other communications

If Customer emails [email protected] or [email protected], we collect the content of that communication and the sender's contact information to respond.

3. How we use information

We use the information above to:

  • provide, operate, and maintain the Service, including the deterministic engine and (where configured) the AI narrative layer;
  • authenticate accounts, enforce role-based permissions, and secure the Service;
  • process billing through Stripe and manage subscriptions;
  • provide customer support and respond to inquiries;
  • monitor, maintain, and improve the Service, including aggregated, cross-tenant product analytics;
  • communicate service-related notices; and
  • comply with legal obligations and enforce our Terms of Service.

We do not sell personal information, and we do not use Customer Data to train TrailMap's own general-purpose foundation models.

4. The AI narrative layer — what is (and is not) sent to the AI provider

  • TrailMap's deterministic engine computes every figure in a report first, from Customer Data, inside TrailMap's own application code.
  • Only after that, if an AI provider is configured, the engine's pre-computed findings and the Business Profile context Customer supplied are sent to a commercial large-language-model provider to generate the written narrative and prioritize recommendations.
  • Raw uploaded files, raw connector API responses, and Connector credentials/API keys are never sent to the AI provider.
  • If no AI provider key is configured ("keyless mode"), no data is sent to any AI provider at all — the dashboard and export still render fully; only the written narrative is skipped.
  • On TrailMap's top subscription tier, Customer may instead point the analyst-AI layer at a self-hosted or customer-managed model endpoint, so narrative-generation content never leaves Customer's own infrastructure.
  • Consistent with TrailMap's vendor-neutral convention, this Policy describes the default AI provider generically as "a commercial LLM provider" rather than naming a specific vendor or model — see the Subprocessors list for DPA purposes.

5. How we share information

We share information only as follows:

  • Subprocessors — the vendors listed in the Subprocessors list (hosting/infrastructure, the commercial LLM provider, Stripe, and, where configured, an email-delivery provider), each engaged under an appropriate data-processing agreement.
  • Legal requirements — if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of TrailMap, our customers, or others.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to the acquiring party's assumption of obligations at least as protective as this Policy, with notice.
  • With Customer's direction — e.g., when a Workspace owner invites an Authorized User, that user's name/email and role become visible to other Workspace members as normal product functionality.

We do not share Customer Data across tenants — every Workspace's data and analysis are isolated to that Workspace.

6. Data retention

  • Account and Customer Data are retained for as long as the Workspace is active, plus any period reasonably needed to give effect to export/deletion (Section 8) and termination.
  • Audit-log entries are retained for a window TrailMap configures per deployment. [Attorney/business to confirm a specific retention period once product/engineering finalizes one.]
  • Raw usage-event data is retention-limited (aged out faster than the durable, aggregated rollup). [Attorney/business to confirm the exact window.]
  • Upon a Workspace's deletion, Customer Data, uploaded files, and normalized datasets tied to that Workspace are removed; a durable operator-facing log line recording that the deletion occurred (never the deleted data itself) is retained for TrailMap's own operational/audit purposes.
  • Backups age out on TrailMap's infrastructure provider's normal backup-retention cycle rather than being individually purged on request.

7. Your rights

Depending on where you and your organization are located, you may have rights under laws like the GDPR (EU/UK) or the CCPA/CPRA (California), including the right to know/access, correct, delete, port, object to or restrict certain processing, and (CCPA) opt out of the "sale" or "sharing" of personal information — we do not sell or share personal information, so there is nothing to opt out of today.

How to exercise these rights: If you are a Workspace owner, use the in-app export and deletion tools described in Section 8. If you are an Authorized User (not the owner) or an individual who believes your personal data appears in a Customer's account, contact [email protected], and we will assist, including, where appropriate, coordinating with the relevant Customer.

Attorney/business to confirm: a specific response-time commitment for rights requests (e.g. within 30/45 days) and any state-specific requirements.

8. Data export and deletion (this really exists in the product today)

Unlike many draft privacy policies, this section describes a capability that is shipped, not planned:

  • Export. From the app's account settings, a Workspace owner can download a complete JSON snapshot of everything the active Workspace holds — users, uploads, runs, ad accounts, column mappings, connector accounts, API keys (metadata, not raw secrets), audit events, and usage events. This is rate-limited and the export action itself is recorded in the audit log (by event count only, never the exported content).
  • Deletion. From the same settings, a Workspace owner can permanently and irreversibly delete the active Workspace and every row scoped to it — including uploaded files and normalized datasets on disk — by typing the exact Workspace name to confirm. Deletion of an agency's billing-root Workspace is blocked while it still has active child (client) workspaces.
  • Scope and limits, stated honestly: both capabilities operate at the Workspace level and are gated to the owner role — an Authorized User who is not the owner cannot self-export or self-delete only their own contribution through the in-app tool today; that request should go through the Workspace owner or to [email protected].

9. Security

We take the confidentiality, integrity, and availability of Customer Data seriously, and we would rather describe our actual practices precisely than market a stronger claim. In summary (see TrailMap's internal security documentation for the complete, current statement, which controls if this summary and that document ever diverge):

  • Passwords are hashed with argon2id; login uses a constant-time dummy verification for unknown emails so response timing does not reveal whether an account exists.
  • Session tokens are random values; only their SHA-256 hash is persisted.
  • Connector credentials and per-tenant AI-provider keys are encrypted at rest with Fernet (AES-128-CBC + HMAC-SHA256); production deployments are required to configure a real encryption key, and the key can be rotated without losing access to already-encrypted data.
  • Role-based access control (owner/admin/analyst/viewer) and a tenant-scoped, admin-viewable audit log cover who did what. Administrative/operator endpoints are protected by a shared secret compared in constant time.
  • An in-process rate limiter throttles login and registration attempts.
  • Every push and pull request runs automated dependency and static-analysis security scanning (pip-audit, bandit, npm audit) in CI.
  • We do not claim SOC 2, ISO 27001, or any other third-party security certification. SOC 2 readiness is an internal roadmap item, not a completed certification, as of this Policy's last-updated date.
  • Known, honestly-disclosed limitations: secrets are currently managed via environment variables rather than a dedicated secrets manager/KMS (appropriate for a single-operator or trusted-ops deployment; a managed secrets backend is the documented upgrade path); file ingestion is batch, not streaming, bounded by a configurable per-upload size limit; and, by default, the authentication rate limiter and the background connector-sync scheduler are single-node/in-process (Postgres itself is fully supported for the storage layer).
  • We recommend, and TrailMap's own deployment guidance requires for production, terminating TLS/HTTPS in front of the Service and marking session cookies Secure.

If you believe you have found a security vulnerability, please report it to [email protected] rather than filing a public issue.

10. Children's privacy

TrailMap is a business-to-business product and is not directed to, and must not be used by, individuals under 18, or by consumers acting in a personal or household capacity. We do not knowingly collect personal data from children.

11. International data transfers

TrailMap and its subprocessors may process data in countries other than where Customer or its Authorized Users are located.

Attorney/business to confirm: TrailMap's hosting region(s) and each subprocessor's processing location(s) — see the Subprocessors list, which marks these as to-be-confirmed — and add the appropriate transfer mechanism (e.g., the EU Standard Contractual Clauses and the UK International Data Transfer Addendum) once known. The Data Processing Addendum is the intended home for the executed transfer mechanism.

The Service and the marketing site link to third-party destinations (for example, the Stripe Customer Portal, or a connected ad platform's own site). This Policy does not apply to those third parties; review their own privacy policies.

13. Changes to this policy

We may update this Privacy Policy from time to time. For material changes, we will provide notice — for example, by email to the Workspace owner(s) or an in-app notice — before the change takes effect.

14. Contact

Questions about this Policy or a data-subject rights request: [email protected].
Security reports: [email protected].

Consolidated attorney/business checklist

Legal entity name · marketing-site cookie/analytics confirmation · audit-log and raw-usage-event retention windows · rights-request response-time commitment · hosting and subprocessor regions + transfer mechanism · whether a DPO/EU-UK representative is required · full GDPR/CCPA legal-basis analysis. See legal/PRIVACY_POLICY.md for the full list with section references.

This page mirrors legal/PRIVACY_POLICY.md in the TrailMap repository, which is the authoritative source and carries every citation to the engineering documentation this draft is grounded in. It is a draft pending attorney review and is not currently in effect.