Privacy Policy
TRM Labs, Inc. and its Affiliates (as defined herein) (collectively “TRM Labs” or “we”) know that you (“you”) care about how information about you is used and shared, and we take your privacy seriously. “Affiliates” means any entity that directly or indirectly controls, is controlled by, or is under common control with another entity, where “control” means possessing, directly or indirectly, the power to direct or cause the direction of the management, policies and operations of such entity, whether through ownership of voting securities, by contract or otherwise. Please read this Privacy Policy (“Privacy Policy”) to learn how we collect, use, disclose, store, and otherwise process personal information through www.trmlabs.com, www.chainabuse.com, and its related websites and social media pages (“Sites”) and TRM Labs’ products and services, including our SaaS-based offerings (“Solutions”). Collectively, our Sites and Solutions are our “Services.”
Table of Contents:
- Information We Collect
- How We Use Your Information
- How We Disclose Your Information
- Targeted Advertising and Analytics
- Additional Information about Our Data Collection and Disclosure Practices
- Information for Individuals Located in Certain U.S. States
- Information for Individuals Located in the European Economic Area, United Kingdom, or Switzerland
- Participation in the EU-US DPF, UK Extension to the EU-US DPF, and Swiss-US DPF
- Your Options to Control Your Information and Exercise Your Rights
- Contact and Questions
This Privacy Policy applies when you interact with us through our Services. It also applies anywhere it is linked. It does not apply to non-TRM Labs’ websites, mobile applications, or services that may link to our Services or be linked to from our Services. Please review the privacy policies on those websites and applications directly to understand their privacy practices.
We may make changes to this Privacy Policy from time to time. The date at the top of this page indicates when this Privacy Policy was last revised. If we make material changes, we will provide you with additional notice (such as by adding a statement to the Services or sending you a notification). We encourage you to review this Policy regularly to stay informed about our information practices and the choices available to you.
- Information We Collect
- Information We Collect Directly From You.
If you are a client of TRM, we collect the following types of information from you- Contact and demographic information (e.g., names, phone number, company name, job title, email address, address, city, or country).
- Login information.
- Billing information, such as credit card number, expiration date, or security code.
- Any other personal information you choose to provide when you post in our online forums and chatrooms, comment on content posted on our Services, submit as a testimonial or endorsement, complete a survey, contact our support team call, participate in a contest, sweepstakes, or promotional offer, or otherwise contact us.
When you use the Chainabuse service, we collect any information you submit in a report of potential abuse as well as your contact information, including name, email, phone number, country, city, state, postal code.
- Information We Collect From Other Sources
We collect the following types of information from external sources, such as third-party sources or publicly available information.- Contact information, demographic information, and information about your business interests.
- Publicly available information, including information made available to the general public, such as by internet users or through widely-distributed media.
- Other information provided to us by another user of our Services, from publicly-available sources, and from suppliers we have engaged. To the extent you provide us with information about other people, you must have the right to do so.
- Information We Collect Automatically
When you interact with the Services or otherwise with us, we collect the following information about you and/or about devices or technology you may be using automatically.- Usage Information: Analytics about your interaction with our Services, including traffic data, location data, weblogs and other communication data, the resources that you access, and how you reached our Services.
- Device Information: Details regarding the device you use to access our Services, including, but not limited to, your IP address, operating system, and browser type.
- Log File Data: Information automatically generated when you engage in digital or online interactions or transactions, such as online identifiers like usernames or handles, network identifiers such as IP address, date/time of interactions, inferred location, and information about activity conducted.
- Interaction Data: Information about how you interact with our ads and newsletters, including whether you open or click links in any correspondence.
- Information Collected from Web Technologies: We use cookies, web beacons, and other tracking technologies to provide features on our Services. We also partner with other companies that use these technologies to collect information about your use of our Services. For more information about the cookies that we use, how to disable them, and a list of our partners, please see our Cookie Policy.
- Job Applicants
When you apply for a job with us, we collect your contact information (e.g., name, phone number, email address, address, city, or country), professional or employment information (e.g., previous work experience, names of current and previous employers), and other information you choose to provide during your application or interview process. Information may be collected about you in multiple ways: you may provide it to us in connection with your application; we may make observations in the application process or collect information from public information sources; or you may authorize us to collect information from other sources, such as a former employer, reference or a credit reporting agency. In certain circumstances, you may submit your application for employment through a third-party service that displays our job posting. We do not control the privacy practices of these third-party services. Please review their privacy policies carefully prior to submitting your application materials.
- Information We Collect Directly From You.
- How We Use Your Information
We may use the information we collect about you for the following purposes.- Provide, maintain, and improve our Services
To provide you with our products and services (including through authorized partners), including to process payments, fulfill orders, ship product, detect, prevent, and report potential abuse, send you technical notices, updates, alerts, and service communications, provide news and information we think will be of interest to you; provide maintenance and support, professional services, and/or access to subscription services; identify, report, and repair errors that impair the functionality of our products and services; conduct general business operations such as accounting, recordkeeping, and audits; and to develop new products and services. - Analytics
To create data that allows us to improve and grow our business, including to measure the effectiveness of ads, understand how our Services are being used, understand our customer base and purchasing trends, understand the effectiveness of our marketing; and market our products. - Personalization and Ads
Including to personalize the Services to your preferences, send you personalized marketing and advertising about our products and services, and deliver personalized advertising to you online, which may be based on your preferences or interests across services and devices. - Security and Legal Compliance
Including to protect and secure our Services, assets, network, and business operations; to detect, investigate, and prevent activities that may violate our policies or be fraudulent, illegal, or involve potential threats to the physical safety of any person; comply with legal process, such as warrants, subpoenas, court orders, and lawful regulatory or law enforcement requests; assist governmental entities in detecting and preventing fraud and investigating potential fraud or other unlawful or wrongful conduct; defend against or pursue claims, disputes, or litigation; and to comply with legal requirements regarding our Services. - Jobs
To manage your job application. - Consent
According to your consent.
- Provide, maintain, and improve our Services
- How We Disclose Your Information
- Advertising Partners
We partner with companies that assist us in advertising our Solutions online. See “Targeted Advertising and Analytics.” These companies may use tracking technologies on our website to collect or receive information from our Sites and elsewhere on the internet and then use that information to target ads to you. We also disclose personal information to third parties for their own marketing purposes and to expand the reach and effectiveness of our own marketing campaigns. Depending on where you reside these activities may constitute “sales,” “sharing,” or use of personal information for “targeted advertising” and you may have the right to opt out of these disclosures. - Vendors and Service Providers
We engage vendors, service providers, contractors, and consultants to perform functions on our behalf, and they may receive information about you. The business functions our vendors support include services that support the Solutions, customer service, billing and collection, auditing and accounting, professional services, analytics services, security, information technology services, and marketing. Our service providers also support our systems status reporting, our backend operations, and our career portal. - Social Media Platforms
If you interact with us on social media platforms, the platform may collect information about you and your interaction with us. If you interact with social media “widgets” on our Services (for example, by clicking on a Facebook “like” button), both the platform and your connections on the platform may be able to view that activity. To control this disclosure of information, please review the privacy policy of the relevant social media platform. - In Response to Legal Process
We share data when we believe in good faith that we are lawfully authorized or required to do so to respond to lawful subpoenas, warrants, court orders, or other regulatory or law enforcement requests. - To Protect the Rights of TRM Labs and Others
We disclose personal information if we believe that an individual’s actions are inconsistent with our user agreements or policies, if we believe that someone has violated the law, or if we believe it is necessary to investigate and/or protect the rights, property, and safety of TRM Labs, our users, the public, or others. For example, we share reports made on our Chainabuse service with law enforcement when the person submitting the report consents to our doing so. Similarly, we may disclose personal information in connection with investigating, establishing, exercising, and/or defending legal rights or claims. - Professional Advisors
We disclose personal information to our legal, financial, insurance, and other professional advisors where necessary to obtain advice or otherwise protect and manage our business interests. - Change of Ownership or Corporate Organization
We may transfer to another entity or its affiliates or service providers some or all information about you in connection with, or during negotiations of, any merger, acquisition, sale of assets or any line of business, change in ownership control, or financing transaction. - Corporate Affiliates
Personal information is disclosed between and among TRM Labs and our parents, affiliates, subsidiaries, and other companies under common control and ownership.
- Advertising Partners
- Targeted Advertising and Analytics
We engage others to provide analytics services, serve advertisements, and perform related services across the web and in mobile apps. These entities may use cookies, web beacons, SDKs, device identifiers and other technologies to collect information about your use of the Services and other websites and applications, including your IP address and other identifiers, web browser and mobile network information, pages viewed, time spent on pages or in apps, links clicked, and conversion information. This information is used to deliver advertising targeted to your interests on other companies’ sites or mobile apps and to analyze and track data, determine the popularity of certain content, and better understand your online activity. Some of the activities described in this section may constitute “targeted advertising,” “selling,” or “sharing” personal information under some laws. See “Sales, Sharing, and Targeted Advertising” below to learn how to opt out of these activities. You can also learn more about interest-based ads and opt out of having your web browsing information used for behavioral advertising purposes by companies that participate in the Digital Advertising Alliance by visiting www.aboutads.info/choices. Your device may also include a feature that allows you to opt out of having certain information collected through apps used for behavioral advertising purposes.
- Additional Information about Our Data Collection and Disclosure Practices
- Retention Periods
We retain information for different periods of time depending on the nature of the information and our legal obligations. In general, we will retain your personal information to fulfill the purposes for which it was collected, as necessary to comply with our business requirements, legal obligations, resolve disputes, protect our assets, and enforce our agreements. We may also retain cached or archived copies of your personal information for a reasonable period of time in accordance with applicable law. - Disclosure of Aggregated or De-Identified Information
We may use and disclose at our discretion information that has been aggregated (information that has been compiled into summaries or statistics) or de-identified (information that has been stripped of all unique identifiers such that it cannot be linked to a particular individual). We will not attempt to re-identify such information, except as permitted by law. - Cross-border Transfer of Data
If you use our Services outside of the United States, we may collect, process, and store your information in the United States and other countries. The laws in the United States regarding information may be different from the laws of your country. Any such transfers will comply with safeguards as required by relevant law, such as the Standard Contractual Clauses. - Our Practices Regarding Information Belonging to Children
The Services are intended for users age 18 and older. TRM Labs does not knowingly collect information from children. If we discover that we have inadvertently collected information from anyone younger than the age of 18, we will delete that information.
- Retention Periods
- Information for Individuals Located in Certain U.S. States
- California Shine the Light
We may share your personal information with our business partners their direct marketing purposes. You may opt-out of such sharing by contacting us using the contact information below. - For Residents of Certain U.S. States
Certain states, including California, have enacted consumer privacy laws that grant their residents certain rights and require additional disclosures (“State Laws”). This section explains the information and rights that might be available to you under those State Laws.- Collection, Use, and Disclosure of Personal Information
The following table summarizes the categories of personal information we collect, and in the preceding 12 months have collected, and whether we disclose or sell those categories of information to service providers or third parties, respectively. The categories we use to describe personal information are those enumerated in the California Consumer Privacy Act, and additional information about the specific types of personal information we collect are described above in “Information We Collect.” We collect each type of personal information for the purposes described in the “Uses of Information” section above. More information about the entities to which we disclose or sell personal information is described in “How We Disclose Your Information” above.
<table class="legal-table_component"><thead class="legal-table_head"><tr class="legal-table_row"><th class="legal-table_header">Category of Personal Information</th><th class="legal-table_header">Categories of Entities to which We Disclose Personal Information for Business Purposes</th><th class="legal-table_header">Categories of Entities to which We Sell or Share Personal Information for Targeted Advertising</th><th class="legal-table_header">Uses of Personal Information</th></tr></thead><tbody class="legal-table_body"><tr class="legal-table_row"><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>Personal Identifiers</p><ul role="list"><li>Contact information (name, phone number, address)</li></ul></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><ul role="list"><li>Corporate Affiliates</li><li>Service Providers</li></ul></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>N/A</p></div></td><td rowspan="5" class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><ul role="list"><li>Process payments, fulfill orders, ship product, </li><li>Send you technical notices, updates, alerts, and service communications, </li><li>Provide news and information we think will be of interest to you, </li><li>Provide maintenance and support, professional services, and/or access to subscription services, </li><li>Identify, report, and repair errors that impair the functionality of our products and services, </li><li>Conduct general business operations such as accounting, recordkeeping, and audits, </li><li>Develop new products and services.</li><li>Understand our customer base and purchasing trends</li><li>Understand the effectiveness of our marketing, and market our products.</li><li>Manage your job application.</li></ul></div></td></tr><tr class="legal-table_row"><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>Commercial Information</p><ul role="list"><li>Billing and payment records</li><li>Order history</li><li>Log file data</li></ul></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><ul role="list"><li>Corporate Affiliates</li><li>Service Providers</li></ul></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>N/A</p></div></td></tr><tr class="legal-table_row"><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>Internet or Other Electronic Network Activity Information, including:</p><ul role="list"><li>IP address</li><li>Device identifier (e.g., MAC)</li><li>Information provided in URL string (e.g., search keywords)</li><li>Cookie or tracking pixel information</li><li>Information about your interaction with our website, app, or email correspondence</li><li>Publicly available data</li><li>Log file data</li></ul></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><ul role="list"><li>Corporate Affiliates</li><li>Service Providers</li><li>Advertising Partners</li></ul></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>Advertising Partners</p></div></td></tr><tr class="legal-table_row"><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>Geolocation</p></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><ul role="list"><li>Corporate Affiliates</li><li>Service Providers</li></ul></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>N/A</p></div></td></tr><tr class="legal-table_row"><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>Content You Provide</p><ul role="list"><li>Content in correspondence</li><li>Content posted to forums</li><li>Content submitted to chat functions</li><li>Survey responses</li></ul></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><ul role="list"><li>Corporate Affiliates</li><li>Service Providers</li></ul></div></td><td class="legal-table_cell"><div class="legal-table_rich-text w-richtext"><p>N/A</p></div></td></tr></tbody></table><br>
- Sales, Sharing, and Targeted Advertising
The State Laws require that we provide transparency about, and allow consumers to opt out of, any “sales” or “sharing” of their personal information, or use of their personal information for “targeted advertising,” which for the purposes of the State Laws, broadly means scenarios in which TRM Labs has shared personal information with third parties in exchange for valuable consideration or shared personal information for cross-context behavioral advertising or targeted advertising. TRM Labs does not sell personal information for money. However, certain cookies used on the TRM Labs site and apps may share personal information for the purpose of engaging in advertising activities, and this may be considered “selling” or “sharing” of personal information for targeted advertising under the State Laws. In the preceding 12 months, these cookies may have “sold” or “shared” the categories of personal information, or used the categories of personal information for “targeted advertising” as identified above. You can see our Cookie Policy for more information about cookie use. You have the right to opt out of any sale or sharing of your personal information for targeted advertising. To opt-out of our sales, sharing, and targeted advertising, use the “Manage Cookie Preferences” link in the footer on our site, or visit our Services with a legally-recognized opt-out preference signal enabled (such as the Global Privacy Control).
- Privacy Rights
Depending on where you reside, you may have the right to (1) request to know more about and access your personal information, including in a portable format, (2) request correction of inaccurate personal information, and (3) request deletion of your personal information.
You may submit a request to exercise any of your rights using the contact information below. We may have a reason under the law why we do not have to comply with your request or may comply with it in a more limited way than you anticipated. If we do, we will explain that to you in our response.
California residents may authorize another individual or a business registered with the California Secretary of State, called an authorized agent, to make requests on your behalf through these means. If you would like to submit a request as an authorized agent, we may request proof of your authorization such as a valid power of attorney or signed permission. Please do not provide any sensitive personal information in connection with this request, such as a driver’s license or other government-issued ID. In some cases, we may be required to contact the individual who is the subject of the request to verify their own identity or confirm that you have permission to submit the request.
In order to process your request, we must verify your identity to protect your and others’ information.- If you have an account with us, we will use your account credentials to authenticate you. This will result in faster processing of your request.
- If you do not have an account with us, we verify your identity by asking you to provide personal identifiers we can match against information we may have collected from you previously. We will also confirm your request using the email or telephone account stated in the request.
We will not use personal information we collect in connection with verifying or responding to your request for any purpose other than responding to your request.
If we deny your request, you may have the right to appeal our decision by contacting us at [email protected]. If you have concerns about the result of an appeal, you may contact the attorney general in the state where you reside.
- Nondiscrimination
We will not discriminate against you for exercising your privacy rights.
- Collection, Use, and Disclosure of Personal Information
- California Shine the Light
- Information for Individuals Located in the European Economic Area, United Kingdom, or Switzerland
If you are located in the European Economic Area (“EEA”), the United Kingdom (“U.K.”), or Switzerland, the following section applies to you.
Legal Basis of Processing
When we process your personal data as described above, we do so in reliance on the following lawful bases:
- To perform our responsibilities under our contract with you (e.g., processing payments for and providing the products and services you requested).
- When we have a legitimate interest in processing your personal data to operate our business or protect our interests (e.g., to provide, maintain, and improve our products and services, conduct data analytics, and communicate with you).
- To comply with our legal obligations (e.g., to maintain a record of your consents and track those who have opted out of marketing communications).
- When we have your consent to do so (e.g., when you opt in to receive marketing communications from us). When consent is the legal basis for our processing your personal data, you may withdraw such consent at any time.
Data Subjects Requests
If you are in the EEA, U.K., or Switzerland, you have certain rights. You may:
- Request from us access to information held about you or request transmission of certain data you have provided to a third party.
- Request that we rectify inaccurate or incomplete information we hold about you.
- Request that we erase data when such data is no longer necessary for the purpose for which it was collected, when you withdraw consent and no other legal basis for processing exists, or when you believe that your fundamental rights to data privacy and protection outweigh our legitimate interest in continuing the processing.
- Request that we restrict our processing if there is a dispute about the accuracy of the data, if the processing is unlawful, if the processing is no longer necessary for the purposes for which it was collected but is needed by you for the establishment, exercise or defense of legal claims, or if your request to object to processing is pending evaluation.
- Object to processing of your personal data based on our legitimate interests or for direct marketing (including profiling). We will no longer process the data unless there are compelling legitimate grounds for our processing that override your interests, rights, and freedoms, or for the purpose of asserting, exercising, or defending legal claims.
You may submit a request to exercise any of your rights using the contact information below.
If you have a concern about our processing of personal data that we are not able to resolve, you have the right to lodge a complaint about our data collection and processing actions with your data protection authority. Contact details for data protection authorities are available here.
- Participation in the EU-US DPF, UK Extension to the EU-US DPF, and Swiss-US DPF
TRM Labs complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) as set forth by the U.S. Department of Commerce. TRM Labs has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (“EU-U.S. DPF Principles”) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. TRM Labs has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (“Swiss-U.S. DPF Principles”, and collectively with the EU-U.S. DPF Principles, the “Principles”) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, TRM Labs commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF should first contact TRM Labs at [email protected].
Further, TRM Labs commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to the International Centre for Dispute Resolution (“ICDR”), an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https:/go.adr.org/dpf_irm.html for more information or to file a complaint. The services of ICDR are provided at no cost to you. To invoke binding arbitration by ICDR, please provide a written notice to [email protected] and follow the procedures set forth in Annex I of the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, as applicable.
The Federal Trade Commission has jurisdiction over TRM Labs’ compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. In accordance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, TRM Labs remains responsible for the processing personal data received under the Principles that is subsequently transferred to third parties acting as agents on TRM Labs’ behalf.
- Your Options to Control Your Information and Exercise Your Rights
You can manage the information we collect about you in the following ways. Please see our U.S. and EEA disclosures for information about your rights under their laws.
- Note about our role as a data “processor” to our corporate clients
When TRM Labs provides its Solutions to its corporate clients, it may collect information that is considered personal information under applicable law. If you seek to exercise the rights you may have under various privacy laws with us, we may direct you to our client instead because we may have a legal and contractual obligation to do so. - Your Account
If you are a corporate customer of TRM Labs, please visit your account portal to update your contact information, and other preferences. - Email Unsubscribe
If at any time you would like to unsubscribe from receiving future emails, you can click the unsubscribe link at the bottom of any email you receive from us or email us at [email protected]. Please be aware that your choice to unsubscribe will not affect our transactional communications with you. - Cookies
You may use your browser’s settings to block or limit cookies on our Sites. If you delete your cookies or if you set your browser to limit or block cookies, some features of the Services may not be available, work, or work as designed.
- Note about our role as a data “processor” to our corporate clients
- Contact and Questions
If you have any privacy- or security-related questions, please contact us by sending an email to [email protected] or you can write to us at:
TRM Labs, Inc.
Attention: Privacy
450 Townsend Street
San Francisco, CA 94107