What TRIVOX collects
Depending on how you use the site, TRIVOX may process your name, business email, account credentials through Supabase Auth, website URLs you ask us to audit, audit results, workspace project history, collaborator invitations, scheduled-monitoring settings, shared-report link metadata, and messages submitted through the acquisition-map form.
If you choose to connect Google Search Console, TRIVOX receives read-only access to Search Console properties and search-performance data that your Google account is allowed to view.
Why the data is used
- Provide and secure your TRIVOX workspace.
- Run requested website and SEO audits.
- Save audit history and compare re-scans.
- Run deeper background crawls you explicitly start.
- Run scheduled Trust/SEO monitoring you enable.
- Let authorized collaborators access shared website projects and create revocable report links.
- Display Search Console information you explicitly connect.
- Respond to enquiries and acquisition-map requests.
- Protect the service against abuse, unsafe network targets and excessive automated requests.
Service providers
The current TRIVOX architecture uses Netlify for hosting/functions, Supabase for authentication and workspace storage, and Google when you connect Search Console or when optional Google-hosted fonts/API services are loaded. Form submissions currently use the existing Formspree integration. If subscription billing is enabled, Stripe handles checkout and billing-portal interactions; TRIVOX stores Stripe customer/subscription identifiers and status, not card numbers.
Search Console tokens
Google Search Console uses a read-only OAuth scope. Refresh tokens are stored encrypted on the server and are not exposed to browser JavaScript. You can disconnect Search Console from the workspace.
Cookies
The workspace uses essential secure session cookies described in the Cookie Policy. The current code does not add advertising cookies. If analytics or marketing trackers are introduced later, this notice and consent behavior must be updated before they are enabled where consent is required.
Retention and deletion
Workspace data is kept while it is needed to provide the service. The current workspace includes self-service account deletion. Deleting the authentication account cascades through TRIVOX-owned workspace records configured for that user; active Stripe subscriptions must be cancelled first so billing cannot continue after account removal. Legal, security, fraud-prevention, payment or backup obligations may require limited retention by TRIVOX or its service providers in some cases.
