Privacy Policy
Last updated: August 2026
1. Introduction
Trippple Club SAS ("Trippple Club", "we", "our", or "us") operates an AI-native SaaS platform for campaign creation, optimisation, and lead generation, enabling businesses to design, manage, and scale advertising campaigns.
This Privacy Policy explains how we collect, use, and protect personal data when you:
- visit our website (www.trippple.club),
- use our platform as a client, or
- interact with advertising campaigns created through our platform.
We process two main categories of personal data:
- Client Account Data, and
- Lead Data, relating to individuals interacting with campaigns configured via the Platform.
2. Information We Collect
a) Personal Information
Name, email address, phone number, billing details
b) Account Information
Login credentials, preferences, campaign configurations
c) Campaign Inputs
Website URLs, product pages, persona descriptions, campaign parameters, performance metrics
d) Lead Data
Information voluntarily provided by individuals when interacting with advertising campaigns or landing pages operated through the Platform (e.g. name, email, phone number, location)
e) Usage Data
IP address, browser type, device information, pages visited, session duration, cookies
f) Communication Data
Emails, support requests, chat messages
3. How We Use Your Information
We use personal data to:
- Provide, operate, and improve the Platform
- Enable creation and optimisation of advertising creatives using AI tools
- Facilitate campaign management and performance tracking
- Collect and make Lead data available to the relevant Client
- Process payments and manage billing
- Communicate with Clients
- Analyse usage and performance
- Comply with legal obligations
4. Legal Basis for Processing (GDPR)
Where applicable, we rely on:
- Contractual necessity - to provide Platform services
- Legitimate interests - to improve performance and security
- Consent - where required (e.g. cookies, lead forms where applicable)
- Legal obligation - where required by law
5. Data Sharing
We may share personal data with:
- Service providers (hosting, analytics, CRM, payment processing)
- Advertising platforms (e.g. Meta, Google) as part of campaign execution
- Clients - Lead data collected through campaigns is made available to the Client who configured the campaign
- Legal authorities where required
We do not sell personal data.
6. Google User Data (Google Calendar)
The Platform lets you connect your Google Calendar (via Google OAuth) so that appointments picked by your leads in your ad forms are automatically created in your calendar. The calendar.events scope is used exclusively to create appointment events in the calendar you connected — we do not read, modify or delete your existing events. Your Google account email address is collected only to display which account is connected.
OAuth tokens are encrypted in transit (TLS) and at rest, and are stored server-side in an access-controlled database that no client application can read. They are used solely to create the appointment events you have configured. They are never shared with third parties, never sold, never used for advertising, and never used to develop, train or improve any artificial intelligence or machine learning model. No human accesses this data in the course of operating the service. Tokens are kept only for as long as your calendar remains connected: disconnecting revokes them with Google and deletes them immediately, and deleting your account — or asking us to delete it — does the same as part of that erasure.
You can disconnect your calendar at any time from the Platform's "My account" page (tokens are then revoked and deleted) or at myaccount.google.com/permissions. Trippple Club's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
7. Data Roles and Responsibilities
Trippple Club acts as:
- a data controller for the technical collection of personal data through the Platform
- a service provider enabling Clients to manage campaigns and access Lead data
Once Lead data is accessed by a Client, the Client acts as an independent data controller for any subsequent use of that data.
Trippple Club does not use Lead data for its own commercial purposes beyond providing Platform services.
8. Data Retention
We retain personal data only as necessary:
- Lead data: 12 months
- Client account data: duration of the contract + 3 years
- Aggregated/anonymised data: up to 36 months
To request deletion: privacy-policy@get-trippple.me
9. Data Security
We implement appropriate technical and organisational measures to protect personal data — including sensitive data such as Google user data and OAuth tokens — against unauthorised access, disclosure, alteration, or destruction. These measures include:
Minimal scope by design
We request only the calendar.events scope, and use it exclusively to create the appointment events you have configured. The application never reads, lists, modifies or deletes your existing calendar events, and never adds attendees to the events it creates.
Encryption
Encryption of all data in transit using TLS/HTTPS, and encryption at rest of all stored data, including OAuth tokens, on Google Cloud infrastructure (AES-256).
Isolated storage
Credentials and tokens are held in a dedicated, server-side-only database location that is unreachable from any browser or client application. Database security rules deny all client access, and application secrets are never committed to source control.
Least privilege
Access to stored OAuth tokens is restricted to the service itself, under a strictly limited set of administrative identities. No human accesses stored OAuth tokens in the course of operating the service.
Secure revocation and deletion
When you disconnect your calendar, or when your account is deleted or you request deletion, the corresponding OAuth tokens are revoked with Google and permanently deleted from our systems.
Monitoring and review
We continuously monitor and log our systems through error-tracking and infrastructure logging services in order to detect and respond to potential security incidents, and we review these systems regularly.
Trippple Club's handling of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements, and the security expectations of that policy. In particular, Google user data is never transferred to third parties, never used for advertising, and never used to develop or improve artificial intelligence or machine learning models.