Privacy policy
What we collect, why we collect it and the choices you have. Written to be read.
Last updated 1 October 2026 · Trabbly Technologies Pvt Ltd, 662, JMD Megapolis, Sohna Road, Sector 48, Gurugram, Haryana, India
1.Who we are
Trabbly Social is a social media management service for agencies and multi-brand teams, operated by Trabbly Technologies Pvt Ltd ("we", "us"). This policy explains what personal information we collect through this website and the Trabbly Social app, why, and what you can do about it.
Our registered address is 662, JMD Megapolis, Sohna Road, Sector 48, Gurugram, Haryana, India. For anything in this policy, including a grievance about how your information is handled, contact us at support@trabbly.com.
When an agency or business uses Trabbly Social to manage its own brands, clients and team, that organisation decides what goes into its workspace. For that content we act on the organisation's instructions (as its processor), and it is the right first contact for questions about it.
2.What we collect
On this website:
- Demo and access requests: your name, work email, company, website if you give one, the number of brands you manage, what you'd like to manage, any plan you were looking at, and the page you sent the request from.
- Spam protection: a one-way hash of your IP address and your browser's user agent, stored with a request so we can limit abuse. We don't keep the raw IP address with the request.
- Analytics, only if you accept: pages viewed, approximate location, device and browser, through Google Analytics.
In the Trabbly Social app:
- Account details: name, email address, a hashed password, your organisation, the brands you can access and your role on each.
- Content you and your team create: drafts, posts, captions, media, comments, review decisions and schedules.
- Connected social accounts: the account or page name and identifier, and the access tokens the network issues when you sign in on its own page. Tokens are stored encrypted. We never ask for, or store, a social media password.
- What networks report back: whether a post was published and, where analytics is enabled for a network, the figures that network reports for your account.
- Client reviewers: name, email and the approvals or change requests they give.
- Billing: your plan and subscription status. Card payments are handled by our payment provider; we don't see or store full card numbers.
- Security and audit records: sign-ins, important changes and who made them.
3.Why we use it
| Purpose | Legal basis |
|---|---|
| Providing the service you or your organisation signed up for: accounts, publishing, approvals, support | Contract |
| Replying to demo and access requests | Legitimate interests (responding to people who ask us to) |
| Keeping the service secure, preventing abuse and keeping audit records | Legitimate interests |
| Understanding how this website is used | Consent (analytics cookies, off until you accept) |
| Billing, tax and accounting records | Contract and legal obligation |
We don't sell personal information, and we don't use your content to train AI models.
5.International transfers
We are based in India, and some of our providers store or access information in other countries, including the United States. Where information moves between countries we rely on the safeguards the applicable law recognises, such as adequacy decisions or standard contractual clauses.
6.How long we keep it
- Account and workspace content: for as long as the organisation's account is open. When an account is closed we delete or anonymise it within a reasonable period, except records we must keep by law.
- Demo and access requests: for as long as we're in conversation with you, and no longer than 24 months after our last contact.
- Sign-in sessions: these end after two hours without activity.
- Security and audit records, and billing records: for as long as needed for security, legal and tax purposes.
8.How we protect it
- Connections are encrypted in transit, and social access tokens are encrypted at rest.
- Passwords are stored as one-way hashes.
- Each organisation's data is kept separate, and access inside an organisation follows the roles its owners set, brand by brand.
- Our own staff sign in on a separate address with two-step verification, and their actions are logged.
No system is perfectly secure. If we learn of a breach that affects you, we'll tell you and the relevant regulator as the law requires.
9.Your rights
Depending on where you live, you can ask us to:
- give you a copy of the personal information we hold about you;
- correct it, or delete it;
- restrict or object to how we use it;
- move it to another service;
- stop using analytics cookies, by changing your cookie settings.
Email support@trabbly.com and we'll reply within one month. If your information was added by an organisation that uses Trabbly Social, we may pass your request to that organisation.
If you're not satisfied with our reply, you can complain to your data protection authority: in India the Data Protection Board of India, in the UK the Information Commissioner's Office (ico.org.uk), and in the EU the authority in your country.
10.Children
Trabbly Social is a business tool. It isn't intended for anyone under 18, and we don't knowingly collect their information.
11.Changes to this policy
If we change this policy we'll update the date at the top. For significant changes we'll tell account owners by email or in the app.