Privacy policy
Last updated 11 September 2026
This policy explains what information Trendzflow ("we") collects when you use Trendzflow CRM, why we collect it, and the choices you have. It applies to the website and the signed-in application.
Information we collect
- Account details you give us: name, work email, password and company name.
- Business records you add: leads, contacts, companies, deals, quotes, orders, payments, tickets and notes.
- Messages handled through the product: WhatsApp, email, live chat and form submissions.
- Data from services you connect, such as advertising accounts, email providers, calendars or file storage, limited to what the connection needs.
- Usage and security information: sign-in times, actions recorded in the audit log.
How we use it
- To run the product: showing your records, sending messages you ask us to send.
- To keep accounts secure and investigate misuse.
- To support you when you contact us.
- To improve reliability and performance.
We do not sell your data, and we do not use your business records to advertise to you.
Your workspace data stays separate
Each company has its own workspace. Records are stored so that one company cannot read another company's data, and access inside a workspace follows the role you assign to each team member. Meta advertising data connected by one Trendzflow organization is not made available to another Trendzflow organization, and access is controlled by organization-level authentication, authorization and role-based permissions.
Connected services
When you connect a service, we store the access credentials in encrypted form and use them only for the actions you request, such as sending a message or reading advertising performance. You can disconnect a service at any time from the Integrations page, which stops further access.
Google User Data
This section explains how Trendzflow accesses, uses, stores, retains, shares, transfers and discloses Google user data when you connect Google services to Trendzflow CRM.
Google user data access
When a customer connects Google services such as Google Ads through Google's OAuth authorization flow, Trendzflow may access only the Google data that the customer explicitly authorizes. Access is limited to the permissions (scopes) the customer approves on Google's consent screen, and the connection is created only by an authorized user of that customer's Trendzflow organization.
For Google Ads, this can include:
- Google Ads customer and account identifiers
- Campaigns
- Ad groups
- Ads
- Keywords
- Impressions
- Clicks
- Conversions
- Advertising spend
- Performance metrics
- Other data made available through the authorized Google Ads API
Purpose of use
Trendzflow uses Google user data only to provide functionality that the customer has requested, including:
- Advertising reporting
- Campaign performance analytics
- CRM attribution (linking leads, deals and revenue to advertising activity)
- Business performance insights
- ROI analysis
- Customer-facing AI-assisted summaries, recommendations, forecasting and analytics within Trendzflow CRM
Trendzflow does not use Google user data to train generalized or non-personalized AI/ML models.
Trendzflow does not use Google user data for:
- Targeted advertising
- Selling data
- Data brokerage
- Advertising profiling
- Unrelated commercial purposes
- Training generalized or non-personalized AI/ML models
How Google User Data Is Shared
Trendzflow does not sell Google user data.
Google user data may be shared, transferred or processed only with the following, and only as needed to operate the service:
- Trendzflow's authorized service providers. This includes the cloud hosting, database, storage, infrastructure and security providers required to operate Trendzflow CRM. These providers process data only on behalf of Trendzflow and are subject to appropriate contractual and security obligations.
- The customer organization that authorized the Google connection. Google user data is visible within that organization to its authorized users, according to that organization's Trendzflow roles and permissions.
- Government authorities, courts, regulators or other parties when disclosure is legally required, or reasonably necessary to comply with applicable law or to protect rights, safety, security or property.
- Other recipients only when the customer has explicitly requested or authorized the transfer as part of a Trendzflow feature.
We do not disclose Google user data to unrelated third parties for their own advertising, marketing, data brokerage, or independent commercial purposes.
Data security
Google OAuth credentials, access tokens and related sensitive data are protected using appropriate technical and organizational security controls. Access to connected Google data is restricted using authentication, authorization, organization-level tenant isolation and role-based access controls. Third-party access credentials are stored in encrypted form on our servers and are not exposed to the browser.
Data retention and deletion
Trendzflow retains Google-related data only as necessary to provide the service, maintain security, comply with legal obligations, resolve disputes and enforce our agreements.
Customers can disconnect Google Ads at any time from the Integrations page in Trendzflow CRM. After disconnection, Trendzflow stops using the OAuth authorization and removes or deactivates the stored authorization credentials in line with our deletion and retention procedures. Imported advertising data that was already recorded in the customer's workspace is handled according to that workspace's data-retention settings.
To request deletion of applicable Google-related data, contact us using the details below and we will process the request within a reasonable time.
Customer organization isolation
Google Ads data connected by one Trendzflow organization is not made available to another organization. Connected Google accounts are tied to the organization whose authorized user created the connection, and access is enforced through organization-level tenant isolation and access controls at the data layer.
Google API Limited Use
Trendzflow's use and transfer of information received from Google APIs will adhere to Google's API Services User Data Policy, including the Limited Use requirements.
Meta User Data
Trendzflow allows customers to connect their own Meta advertising accounts through Meta's authorization process. When a customer connects a Meta service, such as Meta Ads, to Trendzflow CRM, Trendzflow may access information made available through Meta's APIs and permissions that the customer authorizes. Access is limited to the permissions required to provide the connected feature.
Depending on the permissions actually granted to the Trendzflow Meta application and the customer's connected advertising account, this may include:
- Meta advertising account identifiers
- Business/account identifiers required to identify the connected advertising account
- Campaigns
- Ad sets
- Ads
- Advertising insights
- Impressions
- Clicks
- Conversions
- Advertising spend
- Reach and other performance metrics
- Other advertising information made available through the authorized Meta APIs
Purpose of Use
Trendzflow uses Meta data only to provide functionality requested by the customer, including:
- Meta advertising reporting
- Campaign performance analytics
- Ad performance analysis
- CRM attribution
- Linking advertising activity with leads, deals and revenue
- ROI analysis
- Business performance insights
- Customer-facing dashboards
- AI-assisted summaries, recommendations, forecasting and analytics
Trendzflow does not sell Meta user data.
Trendzflow does not use Meta data for:
- Data brokerage
- Targeted advertising on behalf of unrelated third parties
- Advertising profiling unrelated to the customer's requested Trendzflow services
- Unrelated commercial purposes
- Training generalized or non-personalized AI/ML models
How Meta Data Is Shared
Meta data may be shared, transferred or processed only in the following situations:
- Trendzflow's authorized service providers. Meta data may be processed by service providers required to operate Trendzflow, such as applicable cloud hosting, database, storage, infrastructure, security and other technical service providers. These providers process data only as necessary to provide services to Trendzflow and are subject to appropriate contractual, confidentiality and security obligations.
- Customer organization. Meta advertising data connected by a customer may be displayed within that customer's Trendzflow organization to authorized users according to the organization's roles and permissions.
- Legal requirements. Meta data may be disclosed when reasonably necessary to comply with applicable law, lawful requests, court orders, regulatory requirements, or to protect the rights, safety, security or property of Trendzflow, its customers or others.
- Customer-authorized transfers. Meta data may be transferred to another service only when the customer explicitly requests or authorizes a Trendzflow feature that requires such transfer and the transfer is permitted by applicable platform policies.
Trendzflow does not disclose Meta user data to unrelated third parties for their own advertising, marketing, data brokerage, or independent commercial purposes.
Meta Data Security
Meta OAuth credentials, access tokens and related sensitive data are protected using appropriate technical and organizational security controls. Access to connected Meta data is restricted using authentication, authorization, organization-level tenant isolation and role-based access controls. Third-party access credentials are stored securely and are not exposed to the browser.
Meta Data Retention and Deletion
Trendzflow retains Meta-related data only for as long as reasonably necessary to provide the requested service, maintain security, comply with legal obligations, resolve disputes and enforce agreements.
Customers can disconnect their Meta Ads account at any time from the Integrations page in Trendzflow CRM. After disconnection, Trendzflow stops using the Meta authorization for future API access, and stored authorization credentials and tokens are deleted, deactivated or otherwise handled according to our deletion and retention procedures. Historical advertising data already stored in the customer's Trendzflow workspace may be retained according to applicable workspace retention requirements.
Meta Data Deletion Requests
Customers and users can request deletion of applicable Meta-related data by writing to us at contact@trendzbee.com or trendzbeeindia@gmail.com (see Contact below). We may verify the request before processing it, and certain information may be retained where legally required or reasonably necessary for security, fraud prevention, dispute resolution or legal compliance.
Meta Platform Policy
Trendzflow processes Meta platform data in accordance with applicable Meta Platform Terms, Developer Policies, and other applicable Meta requirements.
Shopify store data
When a merchant connects their Shopify store to Trendzflow, we read only the information the merchant authorises: products, inventory levels, orders and customer records. We request read-only permissions and never request permission to change data in the store.
What we receive about a store's shoppers
For each shopper we may receive a name, email address, phone number, city, order history and order totals. We do not receive or store payment card details, bank details or government identifiers, and we do not request any Shopify permission beyond those needed to show the merchant their own store data inside their workspace.
Why we process it (purpose limitation)
Shopper data is processed solely to provide the merchant with their own CRM: customer records, order history, reporting and workspace search. We do not sell shopper data, we do not share it with other merchants, we do not use it for advertising to shoppers, and we do not use it to train generalized AI models. It is processed for no purpose other than operating the service the merchant asked for.
Automated decisions
Trendzflow does not make automated decisions that produce legal or similarly significant effects for shoppers. AI features generate drafts and summaries for the merchant's staff to review; no shopper is approved, refused, priced or profiled automatically.
Roles, consent and opt-outs
The merchant is the controller of their shoppers' data and Trendzflow acts as a processor on the merchant's instructions. Consent, data-sale opt-outs and shopper notices are collected and managed by the merchant in their own store; because Trendzflow never sells shopper data and never contacts shoppers on its own behalf, no separate Trendzflow opt-out applies. Where a merchant uses Trendzflow to send marketing, the merchant is responsible for the lawful basis, and unsubscribe handling is built into those sends.
Shopify privacy requests, uninstall and deletion
Trendzflow implements Shopify's mandatory privacy webhooks. When Shopify sends a shopper data request, we record exactly which stored records relate to that shopper so the merchant can respond. When Shopify sends a shopper redaction request, the shopper's name, email, phone, address and notes are erased from the merchant's workspace immediately. When Shopify sends a store redaction request after an uninstall, all Shopify-sourced products, orders, order lines and customer records for that store are deleted along with the stored access token. If a store stays disconnected or uninstalled, the same deletion runs automatically after 30 days.
Security of Shopify data
Shopify access tokens are exchanged server-side, encrypted before storage and never exposed to the browser or written to logs. All traffic runs over HTTPS and stored data is encrypted at rest by our hosting provider, including backups. Each merchant's data is isolated by workspace and enforced in the database itself, so one merchant can never read another merchant's store data. Access to shopper contact details inside a workspace is restricted to that workspace's signed-in staff and is recorded in the workspace audit log.
Artificial intelligence features
Some features generate drafts, for example campaign copy or landing page text. Content you submit to these features is processed to produce the draft and is not used to train public models. Drafts are always shown to you before anything is published or sent.
Where enabled, Trendzflow may process customer-authorized Google or Meta advertising data to generate customer-facing summaries, recommendations, forecasting and analytics. Such data is not used to train generalized or non-personalized AI/ML models.
Storage and retention
Data is stored with our cloud hosting and database provider. We keep your records while your account is active. When you delete a record it is removed from the product; when you close an account we delete or anonymise the workspace data within a reasonable period, unless the law requires us to keep it longer.
Security
We use encrypted connections, encrypted storage for third-party credentials, role-based access and audit logging. No system is perfectly secure, so please use a strong password and tell us promptly if you suspect a problem.
Your rights
You can ask us to access, correct, export or delete your personal information. Write to us and we will respond within a reasonable time.
Contact
Trendzflow, India. Email: contact@trendzbee.com or trendzbeeindia@gmail.com.
