Privacy Policy

Last updated: 8/8/2026

1. What this covers

This policy explains what information Trellis collects through the Service — Loadr, Ordr, Stockr, Makr, and Dealr — and how we use it. "You" means the organization and individual users of a Trellis account; where we handle information about someone outside your organization (a vendor or counterparty you invite into the portal, for example), that's called out separately below.

2. Information we collect

Account information

When you sign up, we collect your name, company name, phone number, email address, and password (stored as a one-way hash — we never store or can retrieve your actual password). If you sign in with Google, we receive your name and email from Google instead of collecting a password.

Business data you enter

The core of the Service is the business records your organization enters: shipments, purchase orders and vendors, inventory items, work orders, contracts and counterparties, and any documents you upload or that the Service generates (bills of lading, purchase orders, contracts, work order travelers). This may include information about people outside your organization if you enter it — a vendor contact's email, a counterparty's address, and similar.

Information we collect automatically

We use a session cookie to keep you signed in and know which organization and modules you have access to. We keep an accountability log of consequential actions taken in your account (who did what, when) so your team has a record and so we can investigate account security issues.

Vendors and counterparties

If your organization invites a vendor or counterparty to the self-service portal, we collect and use their email address to send a sign-in link and, once they sign in, use a separate portal session cookie to keep them signed in to view the specific purchase orders or contracts your organization has shared with them. We don't use their information for any other purpose.

3. How we use information

We use the information above to operate the Service: creating and running your account, billing you for the modules you've activated, sending transactional email (signup verification, notifications you haven't muted, invoices and quotes), securing your account (login attempt monitoring, optional two-factor authentication), and providing support when you contact us. If you use the "auto-fill from document" feature, the document you upload is sent to our AI provider solely to extract fields into your form — see below.

4. Who we share information with

We don't sell your information. We share it with the service providers we rely on to run Trellis, each only for the purpose of providing their part of the Service:

  • Stripe — payment processing and billing. Stripe receives your payment method details directly; we never see or store your card number.
  • Resend — delivery of transactional email (verification, notifications, invoices, quotes).
  • Anthropic — if you use document auto-fill, the uploaded document is sent to Anthropic's API to extract fields. It is not used to train their models.
  • Vercel — application hosting and file storage for uploaded and generated documents.
  • Neon — our database host, where your account and business records are stored.
  • Twilio and Google — used only if your organization has configured SMS notifications or Google sign-in, respectively; otherwise we don't share anything with them.

We may also disclose information if required by law, or to protect the rights, property, or safety of Trellis, our users, or others.

5. Your organization's own integrations

If your organization configures a webhook endpoint or generates an API key, data flows to and from systems your organization controls, at your organization's direction. That's covered by your own arrangements with those systems, not this policy.

6. Data retention

We keep your account and business records for as long as your account is active. Cancelling a module stops billing for it but doesn't delete its data — it stays readable, and you can reactivate the module later. To request deletion of your account or data, contact us at the email below; we'll delete what we can while retaining what we're legally required to keep (for example, financial records tied to completed transactions).

7. Your choices

You can review and export your data at any time from the dashboard (CSV export is available for every module), and control which categories of email notifications you receive from Settings. You can enable two-factor authentication for your own login from Settings as well.

8. Security

We use industry-standard practices to protect your information — passwords are hashed, not stored in plain text; failed login attempts are rate-limited; and we support optional two-factor authentication. No method of storage or transmission is perfectly secure, and we can't guarantee absolute security.

9. Children's privacy

The Service is intended for business use by adults and is not directed at children. We don't knowingly collect information from anyone under 16.

10. Changes to this policy

We may update this policy as the Service changes. We'll update the date at the top of this page, and notify you of material changes via email or in-app notice.

11. Contact

Questions about this policy, or requests about your data? Contact us at hello@buildontrellis.com.

← Back to sign up