← TribeROI beta

Privacy Notice

Applies to the TribeROI application at beta.triberoi.com(the “Service”).

Version
1.0
Effective
2026-07-30
Last updated
2026-07-30

Scope of this notice

This notice covers the TribeROI application at beta.triberoi.com only.

The TribeROI marketing website at triberoi.com is a separate property with separate hosting, separate storage, and no shared data. It has its own privacy notice.

1. Who we are

TribeROI Inc
971 US Highway 202N, Suite N
Branchburg, NJ 08876
United States

Privacy contact: privacy@triberoi.com

EU representative (Article 27 GDPR): not yet appointed. We will publish the name and address here on appointment.

UK representative (Article 27 UK GDPR): not yet appointed. We will publish the name and address here on appointment.

2. The two roles we hold, and why it matters to you

The Service measures the health of communities. That means we handle two very different kinds of personal data, and our responsibilities differ for each.

We are the controller of data about our own users and prospects. If you signed up for our waitlist, hold an account, or contacted us, we decide how your data is used and this notice tells you how. Sections 3 to 8 apply to you.

We are a processor of data about community members. Our customers are community organizers. They upload member data or connect platforms they administer, and we analyze it on their instruction. If you are a member of a community that uses the Service, the organizer is the controller of your data and we are not. Section 9 explains what that means and where to direct a request.

Part A: Where we are the controller

Sections 3 to 8 apply to our own users, waitlist signups, and prospects.

3. What we collect

When you join the waitlist

Email address, first name, last name, company name, and community size.

When you hold an account

Email address, account identifier, display name, role within your organization, and which organization you belong to. Authentication is handled by Google Firebase Authentication. If you sign in with a third-party provider, we receive the profile information that provider releases.

When you use the application

Records of which recommended actions you open, comprising your account identifier, the action, and a timestamp. We use this to understand which features are useful.

Notes you write

If you write a note about a community member, we store the note, your account identifier, and the timestamp.

Server logs

Standard application logs. Email addresses are masked at the point of writing.

What we do not collect

We run no analytics, advertising, tracking, session replay, or error reporting service in this application. We do not build advertising profiles and we do not sell or share personal data.

4. Why we use it, and on what legal basis

WhatWhyLegal basis
Waitlist detailsTo assess and respond to your request for accessLegitimate interests: responding to a request you made
Account detailsTo provide the service under our agreement with your organizationContract
Feature usage recordsTo understand which features are used and improve the serviceLegitimate interests: improving a service we provide
Server logsSecurity, fault diagnosis, and abuse preventionLegitimate interests: keeping the service secure and working
Transactional emailTo confirm your waitlist submission and tell you when access is approvedLegitimate interests, or contract where you hold an account

You may object to any processing based on legitimate interests. Write to privacy@triberoi.com.

We send no marketing email from this application. Every message it sends is transactional: confirmation that your submission was recorded, and notification that access was approved. There is no marketing list to unsubscribe from.

5. How long we keep it

DataPeriod
Waitlist and prospect records24 months from our last contact with you
Account recordsFor as long as your organization’s agreement is in force, then deleted within 30 days
Feature usage recordsFor as long as your account is active
Administrative and access records24 months. Records of erasure actions are kept longer to demonstrate that we honoured the request; these hold no direct identifiers
Server logs30 days
Database backups7 days, on a rolling cycle

6. Who we share it with

We use the following providers. Each processes data on our instruction under a written data protection agreement.

ProviderWhat they doWhere
Google CloudHosting, databases, secrets management, loggingUnited States
Google Firebase AuthenticationSign-in and account authenticationGoogle-managed
ResendSending transactional emailUnited States
AnthropicGenerating written summaries of results. Receives no member names, email addresses, or member free textUnited States

Our current list is maintained at beta.triberoi.com/sub-processors.

We also disclose personal data where required by law, and to professional advisers under confidentiality obligations.

7. Where your data goes

We process and store all data in the United States, in the us-central1 region.

Where data is transferred from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK Addendum where applicable. Our providers are covered by equivalent clauses in their own agreements with us, and one of them additionally holds an EU-US Data Privacy Framework certification.

You may request a copy of the relevant safeguards from privacy@triberoi.com.

8. Your rights

Where we are the controller of your data, you have the right to:

  • Access the personal data we hold about you
  • Rectify data that is inaccurate
  • Erase your data, in the circumstances the law provides
  • Restrict our processing
  • Object to processing based on legitimate interests
  • Portability: receive your data in a structured, machine-readable format
  • Withdraw consent, where we rely on consent
  • Complain to a supervisory authority

How to exercise them. Write to privacy@triberoi.com. We will acknowledge within five business days and respond within 30 days. If a request is complex we may extend by up to two further months and will tell you why.

Verifying who you are. We will normally reply to the email address we hold on record. If your request comes from a different address, we will ask you to confirm from the address on record before we act.

Part B: Where we are a processor

9. If you are a member of a community that uses the Service

Your community organizer is the controller of your data. They decided to use the Service, they decide what data enters it, and they decide how long it stays. We act only on their instructions and we cannot act on yours.

What we hold on their behalf.Depending on what the organizer connects or uploads: your name and email address; your username or handle on platforms such as their forum, code repository, or publishing site; profile details such as location, biography, or photograph; your registration and attendance at their events; survey responses including free text; titles and links of posts you authored on their platforms, without the content itself; records of interactions between you and other members; and notes the organizer’s staff may write about you.

Where it comes from. Files the organizer uploads, and platforms the organizer connects using their own administrative credentials.

What we do with it. We calculate measures of community health. We generate written summaries of the results using an AI provider. Those summaries are produced from aggregated figures. Your name, email address, and survey text are never sent to that provider. This is enforced by an automated test.

We do not use your data for our own purposes, sell or share it, combine it with data from other sources, or use it to train machine learning models.

How to exercise your rights. Contact your community organizer. They can access, export, correct, restrict, and erase your record through the application.

If you contact us instead, we will acknowledge within five business days, tell the organizer that you have been in touch, and direct you to them. We will not act on your request ourselves, because doing so would mean altering a customer’s data without their instruction.

If you do not know who the organizer is, write to privacy@triberoi.com with the name of the community and we will help you identify the right contact.

Part C: Applies to everyone

10. Cookies

The application sets three cookies. All are first-party and all are necessary for it to work. We set no advertising, analytics, or tracking cookies, and there is nothing here to consent to or opt out of.

CookiePurposeLifetime
triberoi_sessionKeeps you signed in. Holds your authentication token, is not readable by scripts, and is cleared when you sign outAbout one hour, refreshed while you are active
Onboarding nameRemembers the first name you entered during setup so we do not ask againOne year
Onboarding stateRemembers that you skipped a setup stepUntil you close your browser

Our authentication provider also stores sign-in information in your browser’s local storage so that you stay signed in. This is functional and is cleared when you sign out.

Do Not Track and Global Privacy Control. We do not read these signals. Since we run no tracking, there is nothing for them to switch off.

11. How we protect data

We separate every customer’s data at the database level and verify that separation automatically on every change to our code. Data is encrypted in transit and at rest. Access requires a verified identity and passes two independent checks. Administrative actions are logged. Credentials for connected platforms are held in a dedicated secrets service and are never written to logs.

A fuller description, including the limits of each measure, is available to customers in our technical and organisational measures annex.

12. Children

The Service is a business tool and is not directed at children. We do not knowingly collect data from anyone below the age at which consent applies in their country. Community organizers undertake not to submit such data. If you believe we hold data about a child, write to privacy@triberoi.com.

13. Automated decision-making

We calculate scores and lifecycle states for individual members and present them to the community organizer. No decision producing legal or similarly significant effects is made automatically. Any action taken on the basis of a score is taken by the organizer.

14. Changes to this notice

We will post any change here and update the date at the top. Where a change is significant, we will tell account holders by email.

15. Complaints

Write to privacy@triberoi.com first and we will try to resolve it.

You may also complain to a supervisory authority: in the EU, the authority in your country of residence, workplace, or where the issue arose; in the UK, the Information Commissioner’s Office.

Related documents The Terms of Service govern use of the application. The Data Processing Agreement governs our processing of community member data on a customer’s behalf.