Privacy Policy
Last updated: August 1, 2026
1. Introduction
Trellis HQ (“Trellis,” “we,” “us,” or “our”) provides the trellishq.ai website, the Trellis restaurant marketing platform, and related tools (collectively, the “Service”). This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you.
2. Information We Collect
Account, organization, and billing information
We collect information such as your name, email address, restaurant or organization details, team role, and account preferences. Clerk provides authentication, so Trellis does not receive or store your password. If you purchase a subscription, Stripe processes payment details and provides us with transaction, customer, and subscription status information. Trellis does not store full payment-card numbers.
Restaurant content and service activity
We process the photos, videos, captions, brand information, content plans, review replies, team submissions, and other materials you add to the Service. We also store the actions and outputs needed to run the Service, such as scheduled posts, publishing results, usage counters, and support or operational records.
Connected-platform data
When you connect Meta, Google Business Profile, or TikTok, we receive OAuth credentials and the account, Page, location, content, publishing, review, and performance data authorized by your grant. We use this information only to provide the connected features you choose. The exact data available depends on the platform and the permissions you approve.
Device, analytics, and diagnostic data
We may collect browser and device information, IP-derived request information, pages viewed, features used, referring URLs, event timestamps, and error or performance diagnostics. Product analytics may be associated with your Trellis user and organization identifiers. Trellis disables analytics session recording.
Review Pulse
When you use the public Review Pulse tool, we process the restaurant you select and public Google review information to build and retain a scorecard. If you submit an email address, we store it with the selected restaurant and server-calculated score to provide the requested follow-up. We use a one-way keyed identifier, rather than your raw network address or a duplicate raw email, for abuse-prevention counters.
The requested Review Pulse email sequence includes today's baseline and a confirmation link. Only after you confirm do we send three more updates 2, 5, and 7 days later. Every message includes an unsubscribe link. We retain a minimal suppression record after an unsubscribe, bounce, block, spam report, invalid address, or privacy request so we can honor the opt-out and avoid sending future Review Pulse messages.
3. How We Collect Information
We collect information:
- directly from you and other authorized members of your restaurant;
- automatically when you use the Service;
- from services you connect or use with Trellis, including Meta, Google, TikTok, Clerk, and Stripe; and
- from public sources you ask us to analyze, such as public reviews.
4. How We Use Information
- Provide, secure, maintain, and troubleshoot the Service, including content planning, media refinement, publishing, analytics, and review management.
- Perform actions you approve or schedule on connected platforms and report the results back to you.
- Generate requested AI-assisted captions, plans, suggestions, tags, and media refinements.
- Process subscriptions, enforce usage limits, and prevent fraud or abuse.
- Send transactional, service, security, and requested follow-up communications.
- Analyze and improve the Service and comply with legal obligations.
We do not sell or rent personal information or connected-platform data, and we do not use it for third-party targeted advertising. We may send Your Content to AI providers to perform requested features, but we do not use Your Content to train AI models.
5. Facebook and Instagram Data
If you connect Facebook or Instagram, Meta may provide Trellis with a Meta user identifier and basic login information, the Pages and Instagram professional accounts you are authorized to manage, account identifiers and names, access credentials, content and post identifiers, publishing results, and engagement or insights data covered by the permissions you approve. Trellis uses this data to:
- show the Pages and professional accounts available to connect;
- publish restaurant content that an authorized Trellis user creates, approves, or schedules;
- import authorized restaurant media; and
- display connected-account and post performance.
Trellis does not request access to private messages or friend lists. We do not sell Meta data. Trellis processes Meta data in accordance with the Meta Platform Terms and applicable Developer Policies.
You can disconnect Meta in Trellis under Settings → Connected accounts or remove Trellis through your Facebook settings. Disconnecting deletes the stored Trellis connection credentials and stops future platform access, but it does not by itself delete content already imported into your Trellis workspace. To delete Meta-derived data, follow our data deletion instructions. Valid signed deletion requests sent by Meta to our callback are processed through a confirmation-code workflow.
6. How We Share Information
We share information only as needed to provide and protect the Service, carry out your instructions, or meet legal obligations. Service providers and integration partners include:
- Clerk for authentication and identity management;
- Convex, Vercel, and Cloudflare for application hosting, data processing, and private media storage;
- Stripe for subscription and payment processing;
- Meta, Google, and TikTok when you connect those services and ask Trellis to read or publish authorized data;
- Anthropic, OpenAI, and Google Gemini for requested AI-assisted generation, analysis, tagging, or media refinement;
- Creatomate for requested video rendering;
- Brevo for service emails; and
- PostHog and Sentry for configured product analytics, error reporting, and performance diagnostics.
We may also disclose information to comply with law, protect rights or safety, investigate abuse, or as part of a merger, financing, acquisition, or sale of assets, subject to appropriate protections.
7. Retention and Deletion
We retain information for as long as your Trellis organization is active and as reasonably necessary to provide the Service, keep required business and security records, resolve disputes, and comply with law. Subscription cancellation and account deletion are separate actions:
- Subscription cancellation: ending a paid subscription changes feature access according to your billing status but does not automatically delete the Trellis organization or its content.
- Connected-account disconnection: disconnecting a platform deletes its stored connection credentials and stops new access by Trellis. Content previously imported or created in Trellis remains until separately deleted.
- Organization deletion: when deletion of a Trellis organization is verified, access and automated outbound activity are blocked. Customer data enters a 90-day retention period before the permanent deletion workflow runs. Deletion may take longer where needed to complete secure storage cleanup, resolve an operational exception, or meet legal obligations.
- Meta deletion: a valid Meta deletion callback starts deletion of the stored Meta connection, provider-tagged media and stored objects, and matching Instagram import history attributable to the requesting Meta user. The returned status URL and confirmation code show whether processing is in progress, complete, or requires manual review.
Limited records may be retained when required for security, fraud prevention, legal compliance, or to document completion of a deletion request. See our data deletion instructions or email privacy@trellishq.ai.
8. Security
We use administrative, technical, and organizational measures designed to protect information. OAuth credentials are encrypted before storage and decrypted only in server-side operations that need them. Customer media is stored privately and delivered through authenticated, time-limited access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Your Choices and Rights
Depending on where you live, you may have the right to:
- access, correct, or request deletion of personal information;
- request a portable copy of information you provided;
- object to or restrict certain processing;
- withdraw consent where processing relies on consent; and
- appeal a decision or complain to a data protection authority.
You can disconnect integrations in Trellis, manage billing through the Stripe customer portal, and use browser controls for cookies or local storage. To submit a privacy request, email privacy@trellishq.ai. We may need to verify your identity and authority over the relevant restaurant before completing a request.
10. Google API Data
Trellis’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
11. Children
The Service is intended for business users who are at least 18 years old. Trellis is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
12. Changes to This Policy
We may update this Privacy Policy. We will post the revised policy and update the date above. If a change materially affects how we use information, we will provide additional notice when appropriate.
13. Contact Us
Questions or privacy requests can be sent to:
Trellis HQ
Email: privacy@trellishq.ai