1. What we collect
We collect only what the service needs to work. We do not use advertising pixels or behavioural advertising trackers.
| Data | Why we hold it |
|---|---|
| Email address | Sign-in by one-time code, order notifications, support replies |
| Messenger identity (platform, account id, username) | Signing in and receiving orders through a Telegram or WWChat bot |
| Google or Apple sign-in data | Signing in when you choose that provider |
| TRON addresses you enter or pay from | Delivering rented resources and matching incoming payments to orders |
| Orders, quotes, balances and transaction hashes | Providing the service, showing your history, accounting |
| Payment record (provider, transaction id, amount, currency and status) | Crediting service units, receipts, support, refunds, tax and fraud prevention |
| Interface language | Showing the site and messages in the language you chose |
| Session cookie and hashed session token | Keeping you signed in |
| API keys (stored hashed) | Authenticating programmatic access |
| Server logs | Security, abuse prevention and diagnosing failures |
| Mobile notification registration (Firebase token, random installation id and public wallet addresses) | Optional notifications about confirmed incoming and outgoing transactions |
We never ask for, receive or store seed phrases, private keys or wallet passwords. If anyone claiming to be Tronteo asks you for them, it is not us.
In the mobile app, wallet names, recovery phrases and private keys stay in protected storage on your device. Camera images used to scan a QR code are processed on the device and are not uploaded. Biometric authentication is handled by the operating system; Tronteo does not receive biometric data.
2. What we do not collect
- No identity documents, and no KYC file — the service does not require one to rent resources.
- No full card number or security code. Paddle, Apple or Google processes payment details; Tronteo receives only the transaction record needed to verify and provide the service.
- No advertising or behavioural profiles, and no data sold or licensed to anyone.
- No advertising profiles and no sale of personal data.
3. Cookies
Tronteo uses the necessary tronteo_session cookie. It holds a session token, is HttpOnly and Secure, uses SameSite=Lax and expires after 14 days. Paddle checkout may use storage needed to process a purchase and prevent fraud under Paddle's privacy policy.
4. Legal basis
- Performance of a contract — to accept an order, deliver resources and keep your account and balance.
- Legitimate interests — to keep the service secure, prevent abuse and diagnose faults.
- Legal obligation — where accounting or law-enforcement rules require us to keep or disclose records.
5. Who else sees it
We share personal data only with processors that make the service run, and only what each one needs:
- Our hosting and infrastructure provider, which stores the database and serves the site.
- Our transactional email provider, which delivers sign-in codes and order notifications.
- Paddle, acting as Merchant of Record for purchases through its checkout and processing billing data under https://www.paddle.com/legal/privacy.
- Apple App Store or Google Play, when you make an in-app purchase; each store processes payment and sends us the transaction identifier and product needed for verification.
- Google or Apple, when you choose their sign-in option.
- Firebase Cloud Messaging, which delivers optional mobile notifications using a device registration token.
- TRON infrastructure providers, which process public wallet addresses and signed transactions needed to read or submit blockchain activity.
- The messenger platform you chose to sign in with, which necessarily knows you are using a bot.
- Competent authorities, where we are legally required to disclose.
We do not sell personal data and we do not share it for anyone's marketing.
TRON addresses, amounts and transaction hashes are recorded on a public blockchain by the network itself. That record is outside our control and cannot be deleted by us or by you.
6. Where it is stored and for how long
Data is processed on servers operated for OPSoft Inc, and may be transferred outside your country of residence. Where that happens we rely on contractual safeguards with our providers.
- Account data: for as long as the account exists, and up to 90 days after you ask us to delete it.
- Orders, payments and financial records: up to 7 years after the transaction, to meet accounting, tax, refund and fraud-prevention obligations.
- Sign-in codes: minutes — they expire quickly and are then discarded.
- Server logs: up to 12 months.
- Mobile notification event details: 30 days; invalid registrations are disabled and account-deletion requests remove the remaining registration data.
7. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our use of it. You can also ask for it in a portable form.
Write to support@tronteo.com from the address on the account. Email is the only channel for data requests. We respond within 30 days. If you believe we have handled your data badly, tell us first — we would rather fix it — and you retain the right to complain to a supervisory authority.
Records we are legally required to keep, such as completed order accounting, survive a deletion request. We delete everything else.
8. Security
- Traffic is encrypted in transit with HTTPS and HSTS.
- Sign-in codes, session tokens and API keys are stored hashed, never in plain text.
- There is no Tronteo password: sign-in uses a one-time code, messenger identity, Google or Apple.
- Access to production data is limited to people who need it to run the service.
9. Children
The service is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a minor has given us data, contact us and we will delete it.
10. Changes and contact
We may update this policy; the effective date below always reflects the current version. Questions, requests or complaints: support@tronteo.com, +1 302 499 33 02, or by post to 30 N Gould St, Ste R, Sheridan, WY 82801, United States.