Privacy Policy
This Privacy Policy explains how Trinsfer (operated by Trinsfer Labs, "we", "our", "us") collects, uses and protects your information when you use trinsfer.com, including the file transfer service, the speed test service and the developer API.
On this page
1. Who we are
Trinsfer is an online file-transfer and connectivity-testing service. The data controller for the purposes of the EU GDPR and the UK GDPR is Trinsfer Labs. You can reach our data team at privacy@trinsfer.com.
2. Information we collect
We collect the minimum amount of data needed to provide the service:
- Account data: email, display name, optional avatar, password hash (bcrypt) and OAuth identifiers (Google, Discord, X.com, Telegram, Steam) when you sign in with one of those providers.
- Files & metadata: the files you upload, their original filenames, sizes, MIME types and the share token / password you choose.
- Transfer activity: timestamps, source IP, user-agent and download counts for each transfer.
- Speed test results: download/upload throughput, ping, jitter, approximate location and ISP information returned by Cloudflare.
- Payment information: billing email, plan, payment provider transaction IDs. We never see your card number — payments are processed by PayPal and NOWPayments.
- Technical logs: HTTP request logs (URL, status code, latency, IP, user-agent) retained for 30 days.
3. How we use your information
We process the data above for the following purposes:
- Providing and operating the service (Article 6(1)(b) GDPR — contractual necessity).
- Securing the service: rate limiting, brute-force protection, abuse investigation (Article 6(1)(f) — legitimate interest).
- Sending transactional emails such as verification, password reset, payment receipts and expiry alerts (Article 6(1)(b)).
- Processing payments and complying with tax / financial regulations (Article 6(1)(c) — legal obligation).
- Anonymous, aggregated analytics on how the service is used. We do not run third-party advertising trackers.
4. Data retention
- Account data: stored as long as your account exists. You can delete your account at any time from your dashboard.
- Files: kept until the share token's expiration date, plus a 7-day grace period. They are then permanently deleted from disk.
- Transfer/download analytics: retained for 24 months, then aggregated and anonymized.
- Server logs: 30 days, then purged.
- Payment records: retained for 7 years to comply with EU accounting laws.
5. Sharing & sub-processors
We never sell your data. We share data only with the following processors, strictly to provide the service:
- Cloudflare (USA / global) — CDN, DDoS protection, speed-test edge.
- Brevo (EU) — transactional email delivery.
- PayPal (EU/USA) — credit-card and balance payments.
- NOWPayments (EU) — cryptocurrency payments.
- Our hosting provider (EU data center) — physical infrastructure.
All sub-processors are bound by contract to GDPR-equivalent protections. When data leaves the EU, we rely on Standard Contractual Clauses approved by the European Commission.
6. Your rights
If you are in the EU/UK, you have the right to:
- Access the personal data we hold about you.
- Receive an export of your data (right to portability).
- Request correction or deletion.
- Object to or restrict certain processing.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email privacy@trinsfer.com. We respond within 30 days.
7. Cookies
We use a small number of strictly-necessary cookies (session, theme preference, language). We do not use marketing or advertising cookies. Full details on the Cookie Policy page.
8. Children
Trinsfer is not intended for children under 13. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
9. Changes
If we change this policy materially, we will notify registered users by email and post a clear notice on this page. Older versions are available on request.
Questions about this document? Email us at legal@trinsfer.com.