TriMatchSign in  ·  Create a workspace

Privacy Policy

Last updated October 9, 2026 · Version 2026-10-09

Summary

This policy explains what personal information Joaqim Ndiema, trading as TriMatch ("we") handles when businesses use TriMatch, why, and the choices people have. TriMatch is a business tool. Most personal information in it is put there by our customers about their own staff and vendors, and we process it for them.

Our role

  • For customer data (invoices, purchase orders, vendor and team details in a workspace), the customer decides how it is used. The customer is the controller or business, and we act as its processor or service provider. If you are a vendor or employee of one of our customers, please contact that customer first; we will help them answer you.
  • For our own records (account sign-up details, billing contacts, support conversations, security logs), we are the controller.

What we collect

  • Account details: name, work email, company name, password (stored only as a one-way hash), optional phone number, two-factor settings, and when you accepted these terms.
  • Customer data: vendor contact details, invoices and the documents uploaded with them, purchase orders and receipts, payment records and bank payment instructions, W-9 and tax ID details, approval decisions, comments and messages.
  • Phone numbers for texts: numbers an admin enters for approvers and receivers, with a record that the person agreed to receive operational texts.
  • Security and usage records: sign-in events, IP address, browser user agent, and a tamper-evident audit trail of who did what in a workspace.
  • Billing: plan, subscription status and the last four digits and brand of the card. Lemon Squeezy, our merchant of record, collects and holds the payment details themselves.
  • Support: what you tell us when you contact us.

We do not use advertising or analytics trackers, and we do not sell or rent personal information.

Why we use it, and legal bases

Where laws such as the GDPR or UK GDPR apply, we rely on these legal bases:

  • To provide TriMatch (create accounts, match and route invoices, send approval emails and texts, prepare payment and accounting files): performance of our contract with the customer, and for customer data, the customer's instructions.
  • To keep TriMatch secure (sign-in protection, bot checks at sign-up, audit trails, fraud prevention, backups): our legitimate interest in protecting the service and our customers.
  • To bill and keep records required for tax and accounting: legal obligation and contract.
  • To text people about approvals and deliveries: the person's consent, confirmed by the customer when the number is added. People can withdraw it at any time by asking their admin to remove the number or untick the consent.
  • To support and improve TriMatch (answering questions, fixing problems): legitimate interest. We do not use customer documents to train AI models.

Who we share it with

We share personal information only with service providers who help us run TriMatch, under contracts that limit their use of it, and with integrations a customer switches on. See the full list of subprocessors. In short: Render (hosting), Backblaze B2 (encrypted backups), Lemon Squeezy (payments), Resend (email), Twilio (text messages), Anthropic (AI reading of invoices, only if enabled), and Intuit QuickBooks or Xero (only when a customer connects them).

We may also disclose information if the law requires it, to protect rights and safety, or as part of a merger or sale of our business, in which case the buyer must honour this policy.

International transfers

TriMatch is hosted in the United States (Render, Oregon) and backups are stored in the United States (Backblaze B2). Some service providers may process data in other countries. If you are in the UK, the European Economic Area, Canada, Australia or elsewhere, your information will be transferred to the United States. Where the law requires it, we use appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses and the UK addendum.

How long we keep it

  • Customer data is kept while the workspace exists, including while it is read-only after non-payment. We do not delete it because a payment failed.
  • When a customer asks us to delete a workspace, an admin first downloads an export, then the live data is deleted through a confirmed, audited process. Encrypted backups are kept for a limited period and then expire, so deleted data can remain in backups until they do. Backups are not restored except to recover from a disaster.
  • Audit and sign-in records are kept with the workspace as evidence of what happened.
  • Billing records are kept as long as tax and accounting law requires.
  • Sign-in sessions expire automatically and are removed.

Security

We use encryption in transit (HTTPS) and at rest for sensitive fields and uploaded documents, separate encryption keys for each company, two-factor sign-in, strict separation between workspaces, a tamper-evident audit trail, and encrypted offsite backups. No system is perfectly secure; see our Security Overview. If a breach affects personal information, we will notify affected customers without undue delay as required by law.

Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict some uses, to withdraw consent, and to complain to a data protection authority. California residents have rights under the CCPA, including to know, delete and correct, and not to be discriminated against for using them; we do not sell or share personal information for advertising.

To use these rights, email support@trimatchap.com. If your information is in a customer's workspace, we will pass your request to that customer and help them respond. We may need to confirm your identity first.

Children

TriMatch is for businesses and is not directed at children. We do not knowingly collect information from anyone under 16.

Changes to this policy

We will post any changes here and update the date at the top. For material changes we will tell account admins by email or in the app before they take effect.

Contact

Joaqim Ndiema, trading as TriMatch
Email: support@trimatchap.com