Privacy Policy

Last updated: November 13, 2024

1. Introduction

Turnify ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, store, and safeguard your information when you use our marketing automation platform and services (collectively, the "Services").

This Privacy Policy applies to all users of our Services, including businesses that use our platform ("Clients") and end-users who interact with campaigns created by our Clients ("End Users").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.

2. Information We Collect

2.1 Information You Provide Directly

Account Registration Information

  • Full name and business name
  • Email address and phone number
  • Business address and contact information
  • Account credentials (username and encrypted password)
  • Business type and industry information

Payment Information

When you subscribe to our paid services, we collect:

  • Billing name and address
  • Payment card information (processed securely by Stripe; we do not store full card details)
  • Transaction history and invoices
  • Tax identification numbers (if applicable)

Customer Data You Upload

As a data processor, we collect and process customer information you upload or collect through our platform:

  • Customer names, email addresses, and phone numbers
  • Customer preferences and communication history
  • Campaign interaction data (QR code scans, email opens, link clicks)
  • Purchase history and transaction data
  • Custom fields and tags you create

Communications

  • Support requests and customer service communications
  • Feedback, survey responses, and testimonials
  • Marketing preferences and communication settings

2.2 Information Collected Automatically

Usage and Analytics Data

  • IP address, browser type, and device information
  • Operating system and device identifiers
  • Pages visited, features used, and time spent on platform
  • Referring URLs and search terms
  • Campaign performance metrics and analytics
  • QR code scan data (location, time, device type)

Cookies and Tracking Technologies

We use cookies, web beacons, and similar technologies to:

  • Maintain your session and remember your preferences
  • Analyze platform usage and improve our Services
  • Provide personalized content and recommendations
  • Track campaign effectiveness and user engagement

2.3 Information from Third Parties

We may receive information about you from:

  • Authentication providers (Clerk) for identity verification
  • Payment processors (Stripe) for transaction information
  • Social media platforms when you connect your accounts
  • Public databases and data enrichment services (with your consent)

3. How We Use Your Information

3.1 Service Provision and Performance

  • Create and manage your account
  • Provide, operate, and maintain our Services
  • Process transactions and send transactional communications
  • Enable campaign creation, management, and analytics
  • Generate QR codes and track campaign performance
  • Facilitate email and SMS communications on your behalf

3.2 Service Improvement and Development

  • Analyze usage patterns and improve platform functionality
  • Develop new features and services
  • Conduct research and data analysis
  • Test and optimize platform performance

3.3 Customer Support and Communication

  • Respond to inquiries and provide customer support
  • Send technical notices, updates, and security alerts
  • Provide training and onboarding assistance
  • Send administrative messages and service announcements

3.4 Marketing and Promotional Activities

With your consent, we may use your information to:

  • Send promotional emails about new features and offers
  • Provide personalized recommendations
  • Conduct surveys and request feedback
  • Display targeted advertisements (you can opt out at any time)

3.5 Security, Fraud Prevention, and Legal Compliance

  • Detect, prevent, and investigate fraud and security incidents
  • Monitor and address technical issues
  • Enforce our Terms of Service and policies
  • Comply with legal obligations and regulatory requirements
  • Respond to legal requests and prevent harm

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide Services you have requested
  • Consent: You have given explicit consent for specific processing activities
  • Legitimate Interests: Processing necessary for our legitimate business interests (e.g., fraud prevention, service improvement)
  • Legal Obligation: Processing required to comply with applicable laws and regulations

5. How We Share Your Information

We do not sell, rent, or trade your personal information. We may share your information in the following circumstances:

5.1 Service Providers and Business Partners

We share information with trusted third-party service providers who assist us in operating our platform:

  • Clerk: Authentication and user identity management
  • Convex: Database hosting and backend infrastructure
  • Resend: Email delivery and management
  • Twilio: SMS messaging services
  • Stripe: Payment processing and billing
  • Vercel: Hosting and content delivery
  • Analytics Providers: Platform usage analysis and optimization

All service providers are contractually obligated to protect your data and use it only for the purposes we specify.

5.2 Legal Requirements and Protection

We may disclose your information when required by law or to:

  • Comply with legal process, court orders, or government requests
  • Enforce our Terms of Service and other agreements
  • Protect our rights, property, or safety, or that of our users
  • Detect, prevent, or address fraud, security, or technical issues
  • Prevent harm or illegal activities

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to the successor entity. We will notify you of any such change and provide choices regarding your information.

5.4 With Your Consent

We may share your information with third parties when you explicitly consent or direct us to do so.

5.5 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you for research, marketing, analytics, or other business purposes.

6. International Data Transfers

Your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States and other jurisdictions where our service providers operate.

When we transfer personal data from the EEA, UK, or Switzerland to other countries, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by relevant data protection authorities
  • Binding Corporate Rules and other approved mechanisms
  • Your explicit consent for specific transfers

7. Data Security

We implement comprehensive technical, administrative, and physical security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

Technical Safeguards

  • End-to-end encryption for data in transit (TLS 1.3)
  • Encryption at rest for all stored data (AES-256)
  • Secure authentication and authorization mechanisms
  • Regular security audits and penetration testing
  • Intrusion detection and prevention systems
  • Automated backup and disaster recovery procedures

Administrative Safeguards

  • Access controls and role-based permissions
  • Employee training on data protection and security
  • Confidentiality agreements with all personnel
  • Incident response and breach notification procedures

While we strive to protect your personal information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but continuously work to enhance our security measures.

8. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data:

8.1 Rights for All Users

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal data (subject to legal obligations)
  • Opt-Out: Unsubscribe from marketing communications
  • Account Closure: Close your account at any time

8.2 Additional Rights for GDPR (EEA, UK, Switzerland)

  • Data Portability: Receive your data in a structured, machine-readable format
  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time (where processing is based on consent)
  • Lodge Complaint: File a complaint with your local data protection authority
  • Automated Decision-Making: Opt out of automated decision-making, including profiling

8.3 Additional Rights for CCPA (California)

  • Know: Know what personal information we collect, use, and share
  • Delete: Request deletion of personal information
  • Opt-Out of Sale: We do not sell personal information
  • Non-Discrimination: Equal service regardless of privacy rights exercise

8.4 Additional Rights for PIPEDA (Canada)

  • Access: Access your personal information we hold
  • Challenge Accuracy: Challenge the accuracy and completeness of your information
  • Withdraw Consent: Withdraw consent for collection, use, or disclosure
  • File Complaint: File a complaint with the Privacy Commissioner of Canada

How to Exercise Your Rights

To exercise any of these rights, please:

  • Email us at privacy@turnify.io
  • Use the data export and deletion tools in your account settings
  • Contact our Data Protection Officer (DPO) for GDPR-related requests

We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

9. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Retention Periods

  • Account Data: Retained while your account is active and for 90 days after account closure
  • Customer Data: Retained as long as you maintain your account or as required for legal compliance
  • Transaction Records: Retained for 7 years for accounting and tax purposes
  • Marketing Data: Retained until you opt out or for 2 years of inactivity
  • Analytics Data: Aggregated data may be retained indefinitely
  • Backup Data: Retained for 90 days in secure backups

When personal data is no longer needed, we securely delete or anonymize it. Some information may be retained in anonymized or aggregated form for analytical purposes.

10. Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar technologies to enhance your experience, analyze usage, and provide personalized content.

Types of Cookies We Use

  • Essential Cookies: Required for platform functionality (authentication, security, session management)
  • Performance Cookies: Help us understand how you use our Services (analytics, error tracking)
  • Functional Cookies: Remember your preferences and settings
  • Marketing Cookies: Deliver relevant advertisements and track campaign effectiveness

Managing Cookies

You can control cookies through:

  • Browser settings (most browsers allow you to refuse or delete cookies)
  • Our cookie consent banner (for non-essential cookies)
  • Opt-out tools provided by advertising networks

Note: Disabling essential cookies may affect platform functionality.

Do Not Track

We currently do not respond to Do Not Track (DNT) signals. We will update this policy if we implement DNT support in the future.

11. Children's Privacy

Our Services are not intended for children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children.

If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information immediately. If you believe we have collected information from a child, please contact us at privacy@turnify.io.

12. Third-Party Links and Services

Our Services may contain links to third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to third-party services.

We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you access through our platform.

13. Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  • Notify affected users without undue delay (within 72 hours where required by law)
  • Notify relevant data protection authorities as required
  • Describe the nature of the breach and potential consequences
  • Provide information about steps taken to mitigate harm
  • Offer guidance on protective measures you can take

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make material changes, we will:

  • Update the "Last updated" date at the top of this policy
  • Notify you via email or prominent notice on our platform
  • Obtain your consent if required by applicable law

Your continued use of our Services after changes become effective constitutes acceptance of the updated Privacy Policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@turnify.io

Data Protection Officer: dpo@turnify.io

Mail: Turnify Privacy Team
Address: [Your Complete Business Address]

Response Time: We respond to privacy inquiries within 30 days

EU Representative (GDPR Article 27)

If you are located in the European Economic Area and have questions about our data practices, you may also contact our EU representative:

[EU Representative Name and Address - if applicable]

Supervisory Authorities

You have the right to lodge a complaint with your local data protection authority:

  • EU/EEA: Your national data protection authority
  • UK: Information Commissioner's Office (ICO)
  • Canada: Office of the Privacy Commissioner of Canada
  • California: California Attorney General's Office

16. Additional Regional Information

For California Residents (CCPA/CPRA)

California residents have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). For detailed information about your California privacy rights, please see Section 8.3 above.

We do not sell personal information and have not sold personal information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising.

For Nevada Residents

Nevada residents have the right to opt out of the sale of their personal information. We do not sell personal information as defined under Nevada law.

For Middle East Residents

We comply with applicable data protection laws in Middle Eastern jurisdictions, including the UAE Data Protection Law, Saudi Arabia Personal Data Protection Law, and Qatar Data Privacy Law. You have rights to access, correct, and delete your personal data as provided under applicable local laws.