PRIVACY POLICY

Last updated May 6, 2026
This Privacy Notice for TrimHQ (doing business as Trim) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
  • Visit our website at https://www.trim-hq.com or any website of ours that links to this Privacy Notice
  • Use Trim. Trim is a modern web platform designed to simplify how brands and creators connect, collaborate, and grow together. It enables brands to discover and engage with creators who align with their audience, while giving creators tools to manage their profiles, showcase their content, and track their social performance. With real-time analytics, Trim helps both sides make smarter, insight-based decisions that drive meaningful partnerships.
  • Engage with us in other related ways, including any sales, marketing, or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at support@trim-hq.com.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.
Do we process any sensitive personal information? We do not seek to collect special-category data (such as health or biometric data) unless strictly necessary for a feature you choose to use. We do process financial and payments-related information (for example wallet balances, transaction history, and bank or payout details processed via our payment partner) and, when you use or will use our identity verification (KYC) features, government-issued identification and related verification materials as described at collection. For Brand accounts that complete business verification (KYB), we may also process company registration identifiers (for example Corporate Affairs Commission / CAC information where applicable), beneficial-owner or director-related identity data, and documents you submit so we can confirm the business. Laws in your country (including Nigeria and the EU) may classify some of this information as sensitive or requiring heightened protection; we apply appropriate safeguards.
Do we collect any information from third parties? Yes, in limited cases. For example, we receive information from payment processors (such as transaction status through Paystack), social platforms when you connect an account, and analytics or security providers as described in this Notice. See Section 3 for a list of categories of processors.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties.
How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
How do you exercise your rights? The easiest way to exercise your rights is by submitting a data subject access request, or by contacting us.

TABLE OF CONTENTS

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
  • names
  • phone numbers
  • email addresses
  • mailing addresses
  • job titles
  • usernames
  • passwords
  • contact or authentication data
  • billing addresses
  • Payment and billing information, including payment method metadata and billing status as processed by our payments provider
  • Wallet and transaction information, such as wallet balances, transfers, deposits, withdrawals, and transaction history associated with your account
  • Bank account and payout details you provide for payouts (for example account names, bank identifiers, or verification data our partner requires)
Sensitive and high-risk information. We do not intentionally collect special categories of data (such as health data) unless a specific, lawful feature requires it and we tell you at the point of collection. However, we process categories of information that may be treated as sensitive or deserving of extra protection under applicable law—including financial, payments, and banking-related data for wallets and payouts. When you use or will use Know Your Customer (KYC) or similar identity verification, we may collect government-issued identification, facial or liveness images if required by our verification provider, proof-of-address, and related verification results. When Brands use Know Your Business (KYB) or registered-business verification, we may collect company registration details (such as CAC number or equivalent where you operate), business name and address as verified with registries or our partner, director or authorized-representative identity (for example BVN or ID checks for persons associated with the business), and uploads you provide to support verification. We use such data only for fraud prevention, regulatory compliance, and secure operation of the Services, and we apply technical and organizational measures consistent with the NDPR, GDPR (where applicable), and industry practice.
Know Your Customer (KYC). Where we offer or require identity verification, you will be informed of the specific data requested. Verification is performed using our partner Prembly (Identitypass), which acts as a processor on our instructions.
Know Your Business (KYB) for Brands. Where a Brand registers or operates as a registered business, we may require KYB steps to confirm the legal entity, directors or signatories, and related risk controls. As with KYC, applicable checks (including CAC or equivalent company lookups, document review, and director or representative identity verification) may be performed through Prembly (Identitypass) or other processors we name at collection, on our instructions.
Social Media Login Data. We may provide you with the option to register with us using your existing social media account details, like your Facebook, X, or other social media account.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.

Google API

Our use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes only with your prior explicit consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
  • To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order.
  • To respond to user inquiries/offer support to users. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
  • To send administrative information to you. We may process your information to send you details about our products and services, changes to our terms and policies, and other similar information.
  • To enable user-to-user communications. We may process your information if you choose to use any of our offerings that allow for communication with another user.
  • To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual's vital interest, such as to prevent harm.
  • To process payments, wallets, and payouts. We may process your information to operate deposits, withdrawals, wallet balances, and transfers; to prevent fraud and abuse; to reconcile transactions with our payment partners; and to facilitate payouts to bank accounts you designate.
  • To verify identity (KYC). Where offered or required, we may process identification and verification data to meet legal or risk obligations, protect the community, and reduce fraud.
  • To verify businesses (KYB). Where offered or required for Brand accounts (for example registered companies), we may process company registration data, business addresses, director or representative identity information, and related verification results to meet legal or risk obligations and protect the community.

3. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We may share information in specific situations described in this section and/or with specific third parties.
We may need to share your personal information in the following situations:
Third-party processors (service providers). We share data with vendors who process it on our behalf under contractual safeguards, including:
  • Paystack — payment processing, fraud checks, and transaction reporting for deposits, withdrawals, and related wallet operations
  • Cloudflare R2 — storage of files and media you upload (object storage, S3-compatible)
  • Firebase (Google) — client-side realtime data features used in the product (for example messaging-related and notification count experiences, subject to your settings)
  • Pusher — realtime messaging and event delivery over private channels tied to your account
  • PostHog — product analytics, usage measurement, and (where enabled) session-based insights; may set or read identifiers in your browser or device storage
  • Sentry — error and performance monitoring, crash diagnostics, and related technical telemetry to keep the Services reliable and secure
  • Upstash (Redis) — rate limiting and abuse prevention (typically IP or account-level counters, not your full profile contents)
  • Vercel — hosting and edge delivery of the website and API routes (processing occurs on infrastructure in regions Vercel uses for your project)
  • Prembly (Identitypass) — Know Your Customer (KYC) checks (such as BVN and government ID verification) and, for Brands, Know Your Business (KYB) checks such as company/CAC-related verification, business registry checks, and director or representative identity verification when you complete verification for compliance, payouts, or risk controls
Links to privacy information for these providers are published on their respective websites. Where GDPR, the NDPR, or similar law applies, we aim to ensure processing is covered by appropriate agreements and, where required, impact assessments.
  • Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • Other Users. When you share personal information or otherwise interact with public areas of the Services, such personal information may be viewed by all users and may be publicly made available outside the Services in perpetuity.

4. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

In Short: We may use cookies and other tracking technologies to collect and store your information.
We may use cookies and similar tracking technologies (like web beacons and pixels) to gather information when you interact with our Services. Some online tracking technologies help us maintain the security of our Services and your account, prevent crashes, fix bugs, save your preferences, and assist with basic site functions.
Cookie and similar technology summary. The following is a non-exhaustive overview. Exact names may vary by deployment; check your browser's cookie list or contact us for the current list.
Name / typePurposeStrictly necessary?
Session / auth cookiesKeep you signed in, protect your account, route requests securelyYes
PreferencesRemember UI choices and similar settingsOften yes for core function; some may be optional
PostHog (ph_* and related)Product analytics, funnels, and (where enabled) session replayNo — where law requires consent for non-essential analytics, we rely on your choices
TikTok / X (OAuth) tokensMaintain your connected social account after you authorize; link features that depend on those platformsYes, if you connect those accounts (otherwise not set)
Security / anti-abuseRate limiting, bot mitigation, and related telemetry (may combine cookies with server-side signals)Often yes for security; details depend on implementation

5. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

In Short: If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.
Our Services offer you the ability to register and log in using your third-party social media account details (like your Facebook, TikTok, or X logins). Where you choose to do this, we will receive certain profile information about you from your social media provider.
OAuth tokens in cookies. When you connect TikTok, X, or other providers that use OAuth-style flows, we may store short-lived access tokens, refresh tokens, or opaque session identifiers issued by the provider in cookies or similar browser storage so the integration stays connected and can be refreshed securely. These tokens are treated as authentication credentials. You can disconnect the integration in product settings where available, which should clear associated cookies on your device; you can also clear cookies for our domain in your browser.

6. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than six (6) months past the termination of the user's account.

7. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information.

8. DO WE COLLECT INFORMATION FROM MINORS?

In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly collect, solicit data from, or market to children under 18 years of age, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records.

9. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: Depending on your state of residence in the US or in some regions, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time, depending on your country, province, or state of residence.
In some regions (including Nigeria under the NDPR, and jurisdictions such as the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making.
Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:
  • Log in to your account settings and update your user account.
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements.
Cookies and similar technologies: Most Web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Services.
If you have questions or comments about your privacy rights, you may email us at support@trim-hq.com.

10. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.

11. NIGERIA (NDPR) AND INTERNATIONAL USERS

In Short: Many of our users are in Nigeria. Processing may be subject to the Nigeria Data Protection Regulation (NDPR) and related guidance, as well as other laws that apply when you access our Services from abroad.
Trim serves a substantial community in Nigeria. Where the NDPR applies, we aim to process personal data lawfully, fairly, and transparently; collect data only for specified, legitimate purposes; keep data accurate and limited to what is necessary; retain it only as long as needed; and secure it with appropriate technical and organizational measures. Because we process payments, wallet activity, and (where applicable) KYC- and KYB-related data, we apply heightened care to those categories.
Your rights (Nigeria). Subject to applicable law and exceptions, you may have rights to request access to your personal data, correction of inaccurate data, restriction or objection to certain processing, erasure in appropriate cases, and information about processing involving third parties. You may also have the right to lodge a concern with the Nigeria Data Protection Commission. To exercise rights or ask questions, contact us at support@trim-hq.com.
International transfers. Our service providers may process data in Nigeria, the European Economic Area, the United States, or other regions where they operate. Where required, we use appropriate safeguards (such as contractual clauses recognized by regulators) and consider risk for financial and verification-related data.

12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information.
Your Rights
You have rights under certain US state data protection laws. These rights include:
  • Right to know whether or not we are processing your personal data
  • Right to access your personal data
  • Right to correct inaccuracies in your personal data
  • Right to request the deletion of your personal data
  • Right to obtain a copy of the personal data you previously shared with us
  • Right to non-discrimination for exercising your rights
How to Exercise Your Rights
To exercise these rights, you can contact us by submitting a data subject access request, or by referring to the contact details at the bottom of this document.

13. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Revised" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.

14. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, you may email us at support@trim-hq.com or contact us by post at:
TrimHQ
Lagos, Nigeria
Lagos, Lagos 100001
Nigeria

15. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

You have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, please fill out and submit a data subject access request.