1. Who we are
Trottflow (“Trottflow”, “we”, “us”) provides booking-management software used by businesses (“operators”) to take and manage reservations, and a companion mobile
staff scanner app used to check in tickets. This policy explains what personal data we process and why, for both the web platform and the scanner app. For questions, contact us at
hello@trottflow.com.
2. Data we process
- Account data: your name, email address and a securely hashed password when you create or sign in to a workspace.
- Operator business data: the records, bookings, customers and tickets you create in your workspace.
- Scanner app — camera: the app uses your device camera solely to read the QR code on a ticket. Images are processed on-device and are not stored or transmitted; only the decoded ticket reference is sent to validate the check-in.
- Authentication tokens: after sign-in, access tokens are stored in your device’s secure storage (iOS Keychain) to keep you logged in.
- Technical data: standard server logs (IP address, timestamps, error diagnostics) needed to operate and secure the service.
3. Why we process it (legal bases)
We process data to provide and secure the service and to perform our contract with the operator (GDPR Art. 6(1)(b)), to meet our legitimate interest in operating and improving the product and preventing abuse (Art. 6(1)(f)), and, where required, on the basis of consent (Art. 6(1)(a)) — for example the device permission that grants camera access, which you can revoke at any time in your device settings.
4. Sharing and sub-processors
We do not sell personal data. We share data only with service providers that help us run Trottflow, under contract and only as needed: cloud hosting and database (Google Cloud, Supabase), transactional email (Resend), and, where the operator enables it, payment processing (Stripe, SumUp). Each acts as a processor on our instructions.
5. Retention
We keep account and business data for as long as the workspace is active, and for a limited period afterwards as needed to comply with legal obligations, resolve disputes and enforce our agreements. You can request deletion as described below.
6. Security
Data is encrypted in transit (HTTPS). Passwords are stored only as salted hashes; payment provider credentials are encrypted at rest; and authentication tokens on the scanner app are held in the device’s secure storage. Access to production data is restricted.
7. Your rights
Subject to applicable law (including the GDPR), you may request access to, correction or deletion of your personal data, restriction of or objection to processing, and data portability. To exercise these rights, email
hello@trottflow.com. If a business uses Trottflow to process data about you as its own customer, that business is the controller for that data and you should contact them first.
8. International transfers
Where data is processed outside your country, we rely on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) with our sub-processors.
9. Children
Trottflow is a tool for businesses and is not directed to children. We do not knowingly collect data from children.
10. Changes
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above.