Privacy Policy
1
Introduction

In our mission to make commerce better for everyone at Tratta, we collect and use information about you, our:

  • merchants using Tratta to power your business
  • customers who shop at a Tratta-powered business
  • partners who develop apps for merchants to use, build stores on behalf of merchants, refer potential entrepreneurs to Tratta, or otherwise help merchants operate or improve their Tratta-powered business
  • users of Tratta apps
  • visitors to Tratta websites, or anyone contacting Tratta support

This Privacy Policy will help you better understand how we collect, use, and share your personal information. If we change our privacy practices, we may update this privacy policy. If any changes are significant, we will let you know (for example, through the Tratta’s admin or by email).

The purpose of this Privacy Policy is to provide you with a clear explanation of when, why, and how we collect and use personal information, as well as an explanation of your rights.

Read this Privacy Policy and make sure you fully understand our practices in relation to your personal information before you access or use any of our Services. If you read and fully understand this Privacy Policy and remain opposed to our practices, you should avoid using our website and services. If you have any questions or concerns regarding this policy, please contact us at legal@tratta.io.

2
Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to periodically review this page for the latest information on our privacy practices.

3
Our values

This Privacy Policy will help you better understand how we collect, use, and share your personal information. If we change our privacy practices, we may update this privacy policy. If any changes are significant, we will let you know (for example, through the Tratta admin or by email).

We carefully analyze what types of information we need to provide our services, and we try to limit the information we collect to only what we really need. Where possible, we delete or anonymize this information when we no longer need it. When building and improving our products, our engineers work closely with our privacy and security teams to build with privacy in mind. In all of this work our guiding principle is that your information belongs to you, and we aim to only use your information to your benefit.

If a third party requests your personal information, we will refuse to share it unless you give us permission or we are legally required. When we are legally required to share your personal information, we will tell you in advance, unless we are legally forbidden.

Many of the merchants and partners using Tratta do not have the benefit of a dedicated privacy team, and it is important to us to help them meet their privacy obligations. To do this, we try to build our products and services so they can easily be used in a privacy-friendly way. We also respond to privacy-related questions we receive in short order and address any privacy concerns you may have.

4
Data we collect

We may collect and process the following types of personal data:

  • Contact Information: Including but not limited to name, email address, phone number, company name, and mailing address.
  • Payment Information: Credit card details and billing information.
  • Technical Data: IP address, browser type, operating system, and browsing behavior on our site.
  • Usage Data: Information about how you use our website and services.
  • Marketing and Communications Data: Preferences in receiving marketing from us and your communication preferences.

Our site uses technologies of third-party partners to help us recognize your device and understand how you use our site(s) so that we can improve our services to reflect your interests and serve you advertisements about the [products and/or services] that are likely to be of more interest to you. Specifically, third-party partners collect information about your activity on our site(s) to enable us to:

  • Measure and analyze traffic and browsing activity on our site(s);
  • Show advertisements for our products and/or services to you on third-party sites;
  • Cross-Device: We may share data, such as hashed email derived from emails or other online identifiers collected on our site(s) with our advertising partners. This allows our partners to recognize and deliver your ads across devices and browsers.
5
Why we process information

We believe you should be able to access and control your personal information no matter where you live. Depending on how you use Tratta, you may have the right to request access to, correct, amend, delete, port to another service provider, restrict, or object to certain uses of your personal information (for example, direct marketing). We will not charge you more or provide you with a different level of service if you exercise any of these rights.

If you use something from a Tratta-powered platform and wish to exercise these rights over information about your transaction, you need to directly contact the merchant you interacted with. We are only a processor on their behalf, and cannot decide how to process their information. As such, we can only forward your request to them to allow them to respond. We will of course help our merchants to fulfill these requests by giving them the tools to do so and by answering their questions.

Please note that if you send us a request relating to your personal information, we have to make sure that it is you before we can respond. In order to do so, we may ask to see documentation verifying your identity, which we will discard after verification.

If you would like to designate an authorized agent to exercise your rights for you, please email us from the email address we have on file for you. If you email us from a different email address, we cannot determine if the request is coming from you and will not be able to accommodate your request. In your email, please include the name and email address of your authorized agent.

If you are not happy with our response to a request, you can contact us to resolve the issue. You also have the right to contact your local data protection or privacy authority at any time.

Finally, because there is no common understanding about what a “Do Not Track” signal is supposed to mean, we don’t respond to those signals in any particular way.

6
Your rights over your information

To operate our business, we may send your personal information outside of your state, province, or country. Due to the restrictive nature of our merchant and customer base, we use only US based partners in protecting and processing your information to the best of our knowledge. For example, all of our servers and databases are in the country where you operate such as the United States. This data may be subject to the laws of the countries where we send it. When we send your information across borders, we take steps to protect your information, and we try to only send your information to countries that have strong data protection laws. If you would like more information about where your information might be sent, please contact us.

If you believe that we haven’t properly addressed your complaint, you can contact the international division of the American Arbitration Association® (ICDR/AAA). ICDR/AAA provides independent dispute resolution services at no charge to you. If you feel that your concerns have not been resolved after reaching out to ICDR/AAA, you can request that your complaint be resolved through binding arbitration.

Finally, while we do what we can to protect your information, we may at times be legally required to disclose your personal information (for example, if we receive a valid court order). For information about how we respond to such orders, please contact us directly.

7
How do we protect your information

Our teams work tirelessly to protect your information, and to ensure the security and integrity of our platform. We also have independent auditors assess the security of our data storage and systems that process financial information. However, we all know that no method of transmission over the Internet, and method of electronic storage, can be 100% secure. This means we cannot guarantee the absolute security of your personal information.

8
How we use “cookies” and other tracking technologies

We use cookies to enhance your experience on our website. Cookies are small text files stored on your device. You can control the use of cookies through your browser settings. Please note that third-party services placing cookies or utilizing other tracking technologies through our services may have their own policies regarding how they collect and store information.

We use cookies and similar tracking technologies on our website and when providing our services in order to improve the performance and experience for all users. For more information about how we use these technologies, including a list of other companies that place cookies on our sites, a list of cookies that we place when we power a merchant’s store, and an explanation of how you can opt out of certain types of cookies, please contact us directly.

9
How we use your information

We use your personal data for the following purposes:

  • To Provide Services: To process your payments, manage your account, and deliver products and services.
  • To Improve Our Website: To analyze how you use our site and improve its functionality.
  • To Communicate: To send you updates, newsletters, and other communications.
  • To Market: To provide you with information about our products, services, and promotions.
  • To Comply with Legal Obligations: To comply with applicable laws and regulations.
10
Opting-out

Our partners may use non-cookie technologies that may not be impacted by browser settings that block cookies. Your browser may not permit you to block such technologies. For this reason, you can use the following third-party tools to decline the collection and use of information for the purpose of serving you interest based advertising:

11
Data retention

We retain non-personal marketing performance data for as long as the applicable user account is active, or as otherwise instructed by such user or any partner that has provided us with such data, or otherwise to the extent authorized under applicable law. We may adopt shorter retention periods to the extent required or authorized by our users, or in accordance with common practices and legal requirements. We may also retain and use personal data as necessary to comply with our legal obligations, to resolve disputes, to enforce our agreements, and to protect our or others’ legal rights and legitimate interests.

12
Third Party Services

Tratta uses Plaid Inc. (“Plaid”) to gather data from financial institutions. By using the Service, you and your users grant Tratta and Plaid the right, power, and authority to act on your behalf to access and transmit personal & business financial information from the relevant financial institution. You agree that this personal, business and financial information is being transferred, stored, and processed by Plaid in accordance with the Plaid end user privacy policy found at https://plaid.com/legal/#end-user-privacy-policy.

13
Third Party Advertising Services

We work with third-party advertising vendors—specifically Google Ads and Meta (Facebook / Instagram)—that place cookies, pixels, and similar identifiers on our site. These technologies collect information such as your IP address, device type, browser details, pages viewed, interactions with our ads, completed purchases or form submissions, and, when you choose to provide it, hashed contact data that allow us to build custom or look-alike audiences. We use this information to personalize ads you see on other websites and social platforms, limit how often those ads appear, measure campaign performance, for conversion tracking and to optimize our marketing spend.

You can opt out of personalized advertising by visiting Google Ad Settings, the Network Advertising Initiative opt-out page, or Meta’s Ad Preferences centre, and by adjusting your choices in our cookie banner.

We also comply with the Children’s Online Privacy Protection Act and do not knowingly collect or use information from anyone under 13 for advertising.

We never merge personally identifiable information—such as your name or email address—with cookie or device IDs unless you have expressly authorized us to do so, and then only for the purposes stated in this policy. Customer lists uploaded to Google Customer Match or Meta Custom Audiences are pseudonymized (hashed) before transfer and are used solely to match our ads to people who have shown an interest in our products or services. We retain advertising-related data for no longer than 26 months and protect it with industry-standard safeguards, including transport-layer encryption, strict access controls, and contracts that require our partners to maintain comparable security.

14
How you can reach us

If you would like to ask about, make a request relating to, or complain about how we process your personal information, you can contact us by email at legal@tratta.io, or via an alternative method on this website. If you would like to submit a legally binding request to demand someone else’s personal information (for example, if you have a subpoena or court order), please contact us at legal@tratta.io directly.