Thank you for being a part of the Treffa community. This is our Privacy Policy containing information about who we are, what we do with your data, and what choices you have about it. Please let us know if you need any help in understanding what it means for you or if you have any other questions or concerns regarding this policy.
We are Treffa (Treffa, we, our or us) and we operate the Treffa app and Treffa website.
We want to explain here how we use personal information about you (your data).
Treffa can be accessed via our app (the Service). When you use our Service, we will collect and use data about you. We have written this Privacy Policy to explain what data we collect, how we use it and what choices you have in relation to your data.
If you are a California resident, please also see our California Privacy Disclosures.
1. What data do we collect and how do we use it?
We collect your data when you register to Treffa and whilst you are using our Service. We use your data so that you can use the Service and, from time to time, we may use your data to comply with our legal obligations or for other legitimate reasons. There may also be times when we ask for your consent to use your data.
We collect data from you when you use our Service or when you provide it to us, for example when you:
- Register to use the Service.
- Make a Request or leave a Recommendation
- View, like, save, search for, or comment on a Request, or communicate with other users.
- Sign up to our marketing emails and push notifications.
- Complete a form or survey.
We need a legal reason to collect and use your data. The main reason we use your data is to perform our contract (the Terms of Service with you, so that you can use our Service.
We may also collect and use your data if we:
- Are legally required to.
- Have your consent.
- Have a legitimate reason to do so in a way which might reasonably be expected as part of running our business (known as a legitimate interest), as long as your interests and fundamental rights do not take priority over our legitimate reasons.
We have listed below more information on the types of data we collect and why we use it.
Contact Details and Proof of Identity
When you open your account you may provide us with contact information like your name, email address, gender and birthday. We use this contact information so we can get in touch with you:
- About the Recommendations you have received through the Service.
- About the Bounties you have won through Recommendations on the Service.
- About issues or concerns you or other users have.
- To offer you discounts or special offers.
- To ask you to complete a form or survey.
- For our legitimate interests in verifying your details, understanding the age range of our users, and providing age appropriate service and support to our users.
- To send you marketing communications.
Regardless of whether you enter your date of birth we confirm that you are thirteen years of age or older.
Where we cannot confirm your identity using other information that we hold about you or that you have provided to us, we may need you to send us copies of identification documents, which we will use together with your contact information. We use this data for our legitimate interest of verifying your details and helping prevent fraudulent access to the Service or use of your account.
Comments and Opinions
If you contact us, for example by email, phone, post or complete an online form, we will collect the comments and opinions you communicate to us.
We also collect data you provide to us, which includes comments and opinions, when you:
- Complete a form or survey.
- Comment on Request, leave Recommendation, make a Request or communicate with the public Treffa community in any other way.
We use comments and opinions where we have a legitimate interest to address any issues, concerns or questions, as well as to make our Service better for you and other users.
If you complete forms or surveys, make a Request, give a Recommendation, comment on a Request or Recommendation, like save or otherwise interact with a Request or Recommendation, we use your data, including any comments and opinions, to help determine which Requests or Treffa communities you might be interested in.
Your Content and Images
We collect your content, which may feature images containing your personal data, when you voluntarily submit it to us when using the Service. We may use your content and/or images in our online and offline marketing campaigns, which may be conducted via third parties on our behalf, subject to the license you give us to use such images and content as set out in our Terms of Service. We process your personal data for these purposes either on the basis of our legitimate interests in order to promote Treffa in our publicity and marketing campaigns or with your consent.
In-App Messages, Comments and Item Descriptions
If you send in-app messages or comments, or provide Request or Reccomendation descriptions, we may access, store and review these:
- To help ensure Requests receive proper Recommendations and that Recommendations get properly awarded through our Service.
- To respond to issues, concerns, queries or disputes raised by users and to help resolve disputes.
- If we believe the messages are in breach of our Terms of Service, or show that you have breached our Terms of Service, for example for the purposes of fraud prevention and/or safety of our users.
Payment and Transactions
We collect data, including payment information, in relation to requests you place bounties on, or recommendations you receive bounties for, and the payment method(s) you use, so you can pay and receive money.
You should not share your details directly with other users, and if something doesn't feel right or you have any concerns, you can contact us using the contact details in Get in Touch.
If you use our payment partner, Stripe, you authorize Treffa to pass any information and payment instructions you provide (which may include name, email address, unique customer identifier, order ID, bank account details, payment card details, card expiration date, CVC code, date/time/amount of transaction, merchant name/ID and location) to the extent required to complete payments via the Service. Our support and moderation team will also have access to this information in order to process and support transactions and moderate refunds.
Our payment partners may also collect your information, including information collected by cookies or other similar means, to the extent this is necessary to process the transactions or to satisfy security requirements.
We also use your transaction information and your request and suggestion history to help decide which requests, suggestions, products and services you might be interested in hearing about and to send you marketing messages about them. You can read more about marketing messages here.
Your relationship with other users
We collect data about the users you follow (and users who follow you) on our Service. We use this to display items to you in your search results, Recommendations or feed which may be of interest to you. We use technology (an algorithm) to help us do this.
If an account has been blocked or banned, we also store this data. We do this for our legitimate interests of enforcing our Terms of Service and allowing users to manage who can communicate with them on our Service.
Website and app login
When you create an account and log in, we collect your sign-in-provider-specific account ID (usually a unique identifier provided by the authentication provider, such as Apple, Google, Microsoft or Meta), and in some cases email address, name, OpenID, phone number, locale, avatar link, username, password and information about your device. It is in our legitimate interest to use this data to keep your account secure.
If you decide to log in using an authentication provider or social network, such as Apple, Google, Microsoft or Meta sign-in, or any other third party log-in methods, we are not given your password or other account login details for those social networks or other third party services. However, we may receive some information from those third party services depending on the third party account you choose to use to log in. For example, depending upon the third party service you choose to use and your settings on that service, we may receive your email address registered with that third party service.
You should keep your password safe if you choose to log in using a password, and not share them with anyone else. You are responsible for actions that are taken using your password or a device you log in from. If you think someone has access to your password or account, you should tell us immediately and change your password if applicable.
Your Device
We will collect information about the device you are using to use the Service. This includes a computer, smartphone or any other electronic device that you can access the Service from.
This can include the type of device, unique device identifier (such as Android ID, Apple ID or browser fingerprint), what operating system is used on the device, what browsers and applications are used to connect to our Service by your device, your internet service provider or mobile network, your IP address and your device telephone number (if it has one).
If you are logged into a registered account, this information may be associated with you.
We use this device information so that the way the Service is presented and works is suitable for your device. We also use this device information for our legitimate interest of ensuring any users that have been banned are not able to access the Service by creating a new account, as well as detecting and analyzing potentially suspicious user activity in order to protect our Service and other users of our Service.
Your preferences
We use the preference and notification settings you have chosen to:
- Provide you with notifications.
- Send you marketing communications.
- Change how our app and/or website is displayed to you.
- Change what content you see through our Service.
How you connect to and use our Service
We collect data about how you use our Service. This includes:
- Profiles you have viewed.
- Requests and Recommendations you have made, viewed, left a Recommendation on, searched for, saved, shared, liked or commented on.
- The time you access our Service and for how long.
- The website you came to our website from, or went after leaving our website.
- Any choices you make when using our Service.
We use this data (with the help of third party analytics providers) to:
- Understand how our Service is used, which we use for the legitimate interests of improving our Service.
- Show you your feed and search results on our Service and order the results in a way that is relevant to you. We use technology (an algorithm) that uses your preferences and, where you have consented to us using your location data, your location to do this.
- Display your Requests to the most relevant potential Requesters. We use technology (an algorithm) to do this.
- Send you tips and other notifications we think will improve your experience of the Service.
- Assess if our marketing campaigns or promotions have been successful.
- Send you marketing (including via email) about Requests, Recommendations, and services we think may be of interest to you.
- Detect or prevent any breach of our Terms of Service.
Location
If you have given us your consent, for example via your device settings where permissible, we collect and use your location information to provide you with features of the Service that are relevant to you and your location. We may use other information we have together with your location to do this. For example, this helps you get Recommendations from people who may live in your area.
If you change your mind about allowing us to use your location information, you can update your preferences in your device settings at any time.
Other Users
Sometimes other users of our Service may provide data about you, such as comments, Recommendations, likes, saves relating to your Requests or Recommendations, and messages they send to you.
If users want to invite you to use our Service or share information about our Service, we will use data they provide to us about you to help them to do this. We will only do this if they have told us that you have agreed they can communicate with you in this way.
Fraudulent or Criminal Activity
We use data about fraudulent or criminal activity which is related to your use of our Service. We use this for our legitimate interests in detecting and preventing fraud and crime, and to comply with our legal obligations. We may monitor the data you provide to detect potential fraud, abuse or breaches of our [Terms of Service], including Requests, Recommendations, messages, user profile information, location, linked account information and/or device ID, as well as detecting users that may have previously been removed from our Service. We may use this information for the purposes of automatically removing certain users from our Service in order to protect our Service.
Other uses of your data
We will use data we collect to:
- Monitor and improve our Service.
- Help us develop new products and services.
When we use your data for these purposes, this won't result in any data that wasn't previously publicly available being made public on our Service.
We also use your data to resolve disputes between users, provide support to users, to troubleshoot and help solve problems, and to enforce our Terms of Service.
Sensitive Data
We may collect sensitive data, such as information about your religious beliefs, racial or ethnic origin, physical and mental health details, or sexual orientation.
We collect and use such data when we have your express consent, for example when you complete a survey. With your permission, we may feature you or your profile in publicity and marketing campaigns and to feature you or your profile on the Service. Providing your sensitive data for these purposes is entirely voluntary.
We may also collect and use such data to comply with government regulations and guidance.
If you put your own sensitive data on the Service (including where you self-declare certain types of sensitive data on the Service), you acknowledge you are deliberately making this data public at your own choice and that we may use such data for the purposes mentioned above. We may remove such data, or request that you remove such data, from our Service at any time.
2. Your Marketing Preferences
We may send you emails about products and services we think you will like, but you can always tell us if you don't want to receive these anymore.
If you give us your permission, we will send you push notifications and share your email address with third parties you have told us you are happy to hear from about their products and services. When you give us your permission, you can always tell us later if you have changed your mind.
- Email: We may contact you by email about our products and services. If you don't want us to contact you by email with marketing messages, you can unsubscribe from our marketing emails by clicking on the unsubscribe link in the emails we send to you.
- Push notifications: If you give us permission in your device settings to send push notifications, we will send you these notifications from our Service. You can change your push notification settings at any time in your device settings or via the Treffa app.
- Third parties: If you have given us your permission, we may share your email address with certain third parties so they can send you email messages about their products and services. If you give us your permission but you later change your mind and you don't want us to share your email address with third parties, you can tell us by contacting us via help@treffa.com.
3. What data can other users see through the Service?
When you use our Service, some of your data is public and can be seen by others. This includes your profile information, such as your username, name, pronouns, and other information you choose to share in your bio. Requests you make, Recommendations you make, and comments or information on either of these are also public. This information is public to allow users to use our Service, including to allow them to make informed decisions regarding Recommendations and Requests.
Our Service helps users interact with each other. To make this happen, some data generated through the Service is shared with other users of the Service.
- User profile: When you create an account, the Service creates a user profile for you. The data in your user profile is publicly available. This includes your profile information, such as your username.
You can also choose to add and change this information in your profile, such as your username, name, pronouns, profile picture, profile description or bio, and website address. If you add these to your profile, they will also be publicly available.
- Recommendation & Request: If you create a Recommendation or a Request on the Service, any information you add will be publicly available. This includes item photographs, videos, bounty and description.
Any comments or links from other users on your Requests or Recommendations, and any replies, comments or images you post, will also be publicly available.
- Your activity on the Service: By default, some of your activities on the Service are public. These are when you comment on or like a Request or Recommendation, create a Request or Recommendation, when your Recommendation has been chosen, and when you select a Recommendation. These activities are public to allow users to use our Service, including to allow them to make informed decisions regarding Requests and Recommendations.
4. Who do we share your data with?
We may need to share your data, for example with third parties that provide us with services or for legal reasons.
We may share your data with:
- Our service providers: These are third parties that provide services to us. These third parties are only allowed to use your data in accordance with our instructions to them. We may need to share your data with service providers such as:
- Payment providers, to process sales transactions.
- Identification verification service providers, to verify your access to the Service and prevent fraudulent activity on your account.
- Moderators who monitor our Service, to ensure our Terms of Service are not being breached and that no criminal activity is taking place using our Service.
- Analytics providers, who help us better understand how our Service is used.
- Third party service providers that help us with improving the functionality of our Service.
In some cases, our service providers may collect data directly from you, for example if they are asked to conduct a survey for us. Where this happens, you will be notified of their involvement and any data you provide to them will be completely optional. The service provider's use of your data is governed by its privacy policy.
Law enforcement, regulators and others for legal reasons: If we are under a legal obligation, we may need to disclose your data to third parties such as law enforcement or regulators. We may also need to disclose your data to third parties to protect our (or others) rights, property or safety or to detect or investigate illegal activity and any breaches of agreements we have with you, including our Terms of Service.
Business reorganization: In the event of a sale, merger, liquidation, receivership or transfer of Treffa's assets, we may need to share your data with the relevant third parties, which is in our legitimate interests in order to conduct our business and affect these transactions.
Information that cannot identify you
We don't disclose data that could be used to identify you to anyone else, except as mentioned in this Privacy Policy.
We may provide third parties with aggregated statistical information and analytics information about users of our Service, but if we do we make sure no one can be identified from this information before we disclose it.
5. How long do we keep your data?
We will only keep your data for as long as we need it. If you have an account, this means we keep your data when your account is active. If your account is deactivated, we also keep your data for a reasonable period of time afterwards. We may also keep your data for legal or technical reasons.
We only keep your data for as long as we need it and for the purpose it was collected for. This includes when we need to keep your data to comply with any legal, compliance, accounting or reporting requirements, or for the purposes of fraud prevention.
When we decide how long we need to keep your data for, we take into account the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure of your data, the purposes we use your data for and whether we can achieve those purposes another way, and applicable legal requirements.
If you have an account with us, we will keep your data for as long as your account is active. If you deactivate your account, or we deactivate it because you have been inactive for a long time, your data will be kept for a period of time after your account has been deactivated.
After your account has been deactivated, we may also need to keep your data for legal or technical reasons (including back-up systems), for example to retain proof of transactions, so we can enforce our rights, and enable the other party to a transaction to access records of past Recommendations or Requests. Following this period we will either delete the data or change it to a form that does not identify you, with or without notice to you.
If your account is deactivated, some of your data may persist and appear within the Service, for example where your data has been shared by other users of our Service. If your account has been banned, we will retain certain data about you to prevent you from opening a new account, in order to protect us, our users and the safety of our Service. For details of retention periods for other aspects of your data, please contact us at data@treffa.com.
6. Is my data transferred to another country?
Your data may be transferred to a country outside of the country where you live. Not all countries have the same standards of data protection. However, where we do transfer your data to another country, we will only do this where we have appropriate measures in place to protect your data.
Treffa is a worldwide service. By using our products or services, you authorize us to transfer and store your information outside your home country, including in the United States, for the purposes described in this policy. The privacy protections and the rights of authorities to access your personal information in such countries may not be equivalent to those of your home country. Children under 13 are not allowed to use Treffa. If you are based in the EEA you may only use Treffa if you are over the age at which you can provide consent to data processing under the laws of your country. Because Treffa is a worldwide service, we may transfer the personal data of EEA residents to a country outside the EEA. When we transfer information from the EEA to a country that doesn't provide an adequate level of protection, we'll only do so under appropriate safeguards to protect your information, like standard contractual clauses.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your data, we cannot guarantee the security of your data transmitted through our Service and any transmission is at your own risk. Once we have received your data, we will use strict procedures and security features to try to prevent unauthorized access.
7. Your Rights
You have certain rights relating to the data we hold about you. If you make a request we may not be required to comply with it, but if that happens we will explain why. If you want to exercise any of your rights you can contact us via rights@treffa.us
- Right of access: You can ask to confirm the data we hold about you and to request a copy of that data.
- Right to correct your data: You can ask us to correct any data we hold about you if it is inaccurate or incomplete.
- Right to erasure: In certain circumstances you can ask us to erase your data. However, we may not always be required to comply with your request for specific legal reasons which will be notified to you, if applicable, at the time of your request. We may need to keep some information about you (please see [How long do we keep your data?]{#duration} for more details).
- Right to object: You can object to us processing your data where we are relying on a legitimate interest and you believe it impacts on your fundamental rights and freedoms. We will consider your objection but we may not be required to comply with your request, for example if we can demonstrate that our legitimate grounds override your rights and freedoms.
You can also object to us processing your data for direct marketing purposes (see Your Marketing Preferences for more information about how to do this).
- Right to restriction: You can ask us to suspend the processing of your data in the following scenarios:
- If you want us to establish the data's accuracy.
- Where our use of the data is unlawful but you do not want us to erase it.
- Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
- Where you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
- Right to request the transfer of your data: You have the right to request a transfer of certain of your data to you or a third party of your choice, which we will provide in a structured, commonly used, machine-readable format.
- Right to withdraw consent: If we rely on your consent to process your data, you can withdraw your consent at any time.
- Automated individual decision making: You may have the right not to be subject to a decision that is based solely on automated processing of your personal data, where this produces a legal effect or similarly significantly affects you. However, this does not apply if the decision is necessary for entering into or performing the contract with you, or where you have provided your explicit consent. Where you object to this type of decision making based on solely automated processing of personal data, you have the right to request human intervention, to express your point of view and contest the decision.
- Right to opt-out of behavioral analytics: We use technology (Treffa's internal algorithm) to carry out behavioral analytics such as to display relevant Requests. If you do not want us to use your data to do this, you must close your Treffa account and cease using our Service. This is because it is essential to how Treffa works to suggest the right Requests to you and to display your Requests to the right Recommenders which we can only do by learning about your tastes and preferences and the types of products you list.
To exercise any of your rights, or if you have any questions about your rights, please contact via email at rights@treffa.com. We may need to request specific information from you when you exercise your rights to confirm your identity and to speed up our response. We may not be able to fulfill your request if we are not able to identify you.
You can exercise these rights free of charge. However, in some circumstances we may be entitled to charge a reasonable fee, or refuse to comply with your request where we are permitted under law, for example if your request is unfounded, repetitive or excessive.
We try to respond to all valid requests within one month (once we have been able to verify your identity, if we need to). Sometimes it may take us longer than this if your request is particularly complex or you have made a number of requests. If this is the case, we will let you know if we need more time to respond.
Links to other websites
Our service may contain links to and from third party websites. If you click on one of these links and visit these websites, these websites have their own privacy policies which you should read. We are not responsible for these third party's websites or privacy policies.
Children
Our Service is only available to users aged 13 or older.
The Service is not aimed at children under the age of 13. We do not knowingly collect data from anyone under the age of 13. If you are under the age of 13, you are not allowed to use our Service.
If you think a child under 13 has given us their data, please contact us using the details set out in saferytey@treffa.com so we can remove this data and terminate the relevant account.
8. Get in Touch
If you have any questions or want to make a request regarding your data, you can contact us at data@treffa.usacom.
Changes to this Policy
We may update or make changes to our Privacy Policy from time to time. If we make material changes to this Privacy Policy, we will notify you of any such changes as described below.
How will we notify you?
If we need to tell you about something, which might be for a legal, marketing or other purposes related to our Service, we will contact you using the method we believe is best to get in touch with you.
We will usually do this by email, or placing a notice on the Service itself. The fact we may send you notices does not stop you from being able to tell us that you do not want to receive certain types of marketing messages as described in Your Marketing Preferences.
9. California Privacy Disclosures
In this section, we disclose information about our data processing practices as required by the California Consumer Privacy Act of 2018 (CCPA) and supplement the disclosures in our Privacy Policy and other notices.
Scope
If you reside in California and access our Service or otherwise provide us with your personal information, this section applies to you. This section does not reflect our processing of California residents' personal information where an exception under California law applies.
Right to Know about Personal Data Collected, Disclosed or Sold
You have the right to request that we disclose what personal information we collect, use, disclose and sell about you specifically (right to know). To submit a request to exercise the right to know, please submit an email request to data@treffa.com and include "California Request to Know" in the subject line. Please specify in your request the details you would like to know, including any specific pieces of personal data you would like to access.
We will ask that you provide certain information to verify your identity. The information that we ask you to provide to verify your identity will depend on your prior interactions with us and the sensitivity of the personal data at issue. We will respond to your request in accordance with the CCPA. If we deny your request, we will explain why.
CCPA Disclosures
The following reflects our practices over the preceding 12 months. What data do we collect and how do we use it? identifies the categories of personal information we have collected about California residents and the purposes for which we use it.
These categories of personal information correspond with the following categories of personal information enumerated under the CCPA definition of "personal information":
- Identifiers including name, postal address, unique personal identifier, IP address, email address and account name.
- Information that identifies or is capable of being associated with you, including payment information.
- Information about your religious beliefs, racial or ethnic origin, physical and mental health details or sexual orientation.
- Information about products or services purchased, obtained, or considered, and other purchasing or consuming histories or tendencies.
- Internet or other electronic network activity information.
- Geolocation information.
- Audio, electronic, visual or similar information.
- If you submit a resume when applying to work for us with information about your education, such education information.
- Inferences drawn from any of the information identified above reflecting your preferences and characteristics.
We collect personal information directly from you. Who do we share your data with? identifies the categories of third parties to whom we have disclosed California residents' personal information for a business purpose. The categories of personal information that we may disclose are those set out in What data do we collect and how do we use it?. These categories of personal information correspond with the categories of personal information enumerated under the CCPA definition of "personal information" listed above in this section.
Right to Request Deletion of Personal Information
You have the right to request the deletion of personal information that we collect or maintain about you. To submit a request to delete personal information, please submit an email request to data@treffa.com and include "California Request to Delete" in the subject line. Please specify in your request the details you would like to have deleted.
We will ask that you provide certain information to verify your identity. The information that we ask you to provide to verify your identity will depend on your prior interactions with us and the sensitivity of the personal data at issue. We will respond to your request in accordance with the CCPA. If we deny your request, we will explain why.
Right to Non-Discrimination for the Exercise of a Consumer's Privacy Rights
You may not be discriminated against because you exercise any of your rights under the CCPA.
Authorized Agent
You can designate an authorized agent to make a request under the CCPA on your behalf in certain circumstances. If you use an authorized agent for this purpose, we may ask you to verify your identity or that you provided the authorized agent signed permission to submit a request under the CCPA on your behalf. If you provide an authorized agent with power of attorney pursuant to Probate Code sections 4000 to 4465, it may not be necessary to perform these steps and we will respond to any request from such authorized agent in accordance with the CCPA.
Removal of Minors' Content
The California Business and Professions Code requires us to provide information about how registered users under the age of 18 who reside in California may have certain content or information that they posted on our services removed.
If you are a California resident under the age of 18 and a registered user of our Service, California Business and Professions Code Section 22581 permits you to request and obtain removal of content or information you posted to our Service and made available to one or more other users.
To make such a request, please send an email with a detailed description of the specific content or information you wish to remove to data@treffa.com. Please be aware that such a request does not ensure complete or comprehensive removal of the content or information you have posted and that there may be circumstances in which the law does not require or allow removal even if requested.