Version 2
Effective date September 10, 2026
This Privacy Policy explains how Trampoline AI Inc. collects, uses, discloses, and protects personal information in its public website, marketing, business relationships, and Cloud Services. It also explains when Trampoline acts for its own purposes and when it processes data only on a customer's instructions.
Trampoline AI Inc. is located at 5715 rue Marquette, Montreal, Quebec H2G 2X8, Canada. Questions and rights requests may be sent to our Privacy Officer at privacy@trampoline.ai.
1 Scope and Our Role
This Policy applies to trampoline.ai and related public pages, forms, events, social channels, communications, recruitment activities, account administration, and Trampoline-hosted Cloud Services. It does not apply to a third-party site or service that publishes its own privacy notice.
Trampoline is a controller when it decides why and how to use website visitor data, Account Data, billing records, business communications, marketing information, support administration, recruitment data, and security information used for Trampoline's own purposes.
Trampoline is generally a processor when it handles Customer Content through Cloud Services on a customer's instructions. The customer determines what data enters its Workflows, why it is processed, where it is sent, and how long it should be kept. If your information was submitted by a Trampoline customer, please contact that organization first. Our processing of Customer Content is governed by the Data Processing Addendum.
2 Personal Information We Collect
Category | Examples | How we receive it |
Contact and business data | Name, work email, telephone number, company, role, professional profile, communication preferences. | From you, your organization, event partners, referrals, and lawful business sources. |
Account and identity data | Email, user identifier, organization, role, authentication events, multi-factor status, session and access metadata. | From you, your administrator, identity provider, and authentication service. |
Commercial and billing data | Orders, plan, usage entitlements, invoices, payment status, tax and procurement information. | From you, your organization, resellers, and payment or procurement processes. |
Website and device data | IP address, browser, device, operating system, pages, referral source, approximate location, cookie identifiers, interactions, and performance events. | Automatically from browsers, devices, cookies, tags, logs, and analytics tools. |
Communications and support | Emails, form submissions, demo requests, meeting details, support messages, diagnostic information, and feedback. | From you, account users, scheduling tools, email providers, and support systems. |
Recruitment data | Resume, work history, education, portfolio, interview notes, references, and legally permitted screening information. | From applicants, recruiters, references, and professional networks. |
Customer Content | Documents, records, prompts, Customer Code, data sources, credentials, Workflow instructions, files, and generated output that may contain personal information. | From customers, Authorized Users, connected systems, and customer-directed integrations. |
Service and security data | Usage events, Run status, token and compute consumption, latency, error records, audit logs, access attempts, and security alerts. | Automatically from Cloud Services and connected infrastructure. |
Please do not send more personal information than necessary. Customer Content may contain categories not listed here because customers control what they process. Special-category or highly sensitive data should be used only where the applicable Cloud Service and agreement expressly support it.
3 Why We Use Personal Information
Purpose | Data commonly used | Typical legal basis |
Provide and administer accounts, Cloud Services, support, and professional services | Contact, account, commercial, communications, Customer Content, service data | Contract; legitimate interests; customer instructions |
Run and secure the website and Cloud Services; prevent fraud, abuse, and unauthorized access | Website, device, account, service, security, and limited diagnostic data | Legitimate interests; legal obligations |
Measure reliability, troubleshoot, plan capacity, and improve usability | Service, error, performance, and de-identified or aggregated usage data | Legitimate interests; contract |
Respond to inquiries, schedule meetings, and manage customer and supplier relationships | Contact, business, commercial, scheduling, and communications data | Contract steps; legitimate interests |
Send product news, event invitations, and business marketing | Contact, business, preference, and engagement data | Consent where required; legitimate interests where permitted |
Measure public-site campaigns and show relevant professional advertising | Website, cookie, device, referral, and campaign interaction data | Consent where required |
Recruit and evaluate candidates | Contact, recruitment, communications, and legally permitted screening data | Contract steps; legitimate interests; legal obligations; consent where required |
Comply with law, enforce agreements, protect rights, and handle transactions | Relevant records from the categories above | Legal obligations; legitimate interests |
Where we rely on legitimate interests, we consider the purpose, necessity, and impact on individuals. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing. We may use information for another compatible purpose or provide a new notice when required.
4 Customer Content and AI Processing
We process Customer Content only to provide, secure, support, and maintain the Cloud Services; comply with law; and follow the customer's documented instructions. We do not use Customer Content or Customer Output to train or improve a general-purpose model, a model shared across customers, or another customer's service unless the customer gives express written opt-in consent identifying the data and purpose.
Workflows may send content to model providers or connected services chosen by the customer or included in Trampoline's service. Provider identity, processing location, and retention depend on the selected model, account, region, and configuration. We do not make a blanket zero-retention claim. Where a no-retention or regional feature is contractually available and enabled, it applies only to the covered provider, endpoint, and configuration.
AI and agentic systems can produce inaccurate or unexpected output and can take actions when a customer authorizes tools. Customers are responsible for testing Workflows, assigning least privilege, selecting approval gates, validating output, and providing human review where a result could materially affect a person or regulated process.
5 How We Disclose Personal Information
We disclose personal information only as reasonably necessary for the purposes described in this Policy:
- To cloud hosting, authentication, observability, model inference, document conversion, support, analytics, communication, security, and other service providers that act under contract.
- To customer-selected integrations and model providers when an Authorized User configures a Workflow or supplies provider credentials.
- Within the customer's organization and to people or systems the customer authorizes.
- To professional advisers, auditors, insurers, financing sources, and parties to a proposed or completed corporate transaction under appropriate confidentiality controls.
- To courts, regulators, law enforcement, or other parties where disclosure is required by law or reasonably necessary to protect rights, safety, and service integrity.
The Subprocessor Register identifies providers that may process Customer Personal Data on Trampoline's behalf. A customer-directed service may instead process data under the customer's agreement with that provider.
6 Website Technologies and Providers
Our public website uses cookies, local storage, tags, pixels, server logs, and similar technologies. Essential technologies support security, routing, consent records, form delivery, and core functionality. Analytics and advertising technologies are used according to the consent choices required in the visitor's region.
Provider or technology | Purpose | Information and activation |
Vercel Analytics and Speed Insights | Website hosting analytics and performance measurement | Technical request, page, device, and performance data. Operational collection may occur when the site loads, subject to configuration and applicable law. |
Google Tag Manager Google Analytics and Google Ads | Tag management, audience measurement, conversion reporting, and advertising | Cookie identifiers, device and browser data, pages, referrals, and campaign events. Analytics or advertising storage is consent-dependent where required. |
Umami | First-party or hosted website analytics | Page and interaction events, device or request metadata, and configured identifiers. Loaded when analytics consent is given where configured. |
Meta Pixel | Advertising measurement and audience services | Cookie and device identifiers, page visits, referrals, and conversion events. Loaded when marketing consent is given and the tag is configured. |
LinkedIn Insight Tag | Business advertising measurement and audiences | Cookie and device identifiers, page visits, referrals, and conversion events. Loaded when marketing consent is given and the tag is configured. |
Snitcher | Business visitor analytics and lead attribution | Request, company inference, page, referral, and interaction data. Loaded when marketing consent is given and the tag is configured. |
Cal.com | Meeting scheduling and calendar coordination | Contact, scheduling, time zone, meeting, device, and cookie data when a scheduling experience is opened or submitted. |
Resend | Delivery of website form and transactional emails | Contact details and the content submitted through relevant forms. |
Sanity | Website content management and delivery | Technical request data when public content or media is retrieved. |
Cloudflare | Security and traffic delivery where configured | IP address, request headers, device and security signals used for routing, bot defense, and attack mitigation. |
The technologies actually enabled can vary by environment and campaign. The cookie preference centre is the most direct way to see and change optional categories. Rejecting optional cookies does not prevent essential service operation, but some measurement or personalization features will be unavailable.
7 Cookie Choices and Advertising
You can accept or reject optional categories through our cookie controls and later change your choice. You can also delete or block cookies in your browser. Browser settings may not remove information already received by a provider. We honor legally required opt-out signals where supported and applicable.
We do not sell Customer Content or Cloud Service data. We do not sell personal information for money. Under some United States state laws, disclosing public-site identifiers to advertising partners for cross-context behavioral advertising may be called sharing, targeted advertising, or a sale even when no money changes hands. Where those laws apply, we provide consent or opt-out choices and do not use Customer Content for advertising.
Marketing emails include an unsubscribe mechanism. Transactional, security, billing, and service messages may continue when necessary to provide an account or comply with law.
8 International Processing
Trampoline is based in Canada and uses providers and personnel that may process information in Canada, the United States, Europe, and other locations disclosed for the relevant service. Cloud Service region and data residency may be set in an Order or configuration, but support access, model calls, customer-selected connectors, and business administration can involve other jurisdictions.
Before transferring personal information, we assess the purpose, sensitivity, safeguards, and destination as required by applicable law, including Quebec privacy impact assessment requirements where applicable. We use recognized safeguards such as adequacy decisions, contractual protections, Standard Contractual Clauses, and the United Kingdom transfer addendum when required.
9 Retention
Information | Retention approach |
Customer Content | Kept according to customer configuration and instructions during the service term, then returned or deleted as stated in the Data Processing Addendum and Order. Isolated backups expire through the normal backup cycle. |
Account and commercial records | Kept while the account or business relationship is active and afterward as reasonably needed for support, disputes, tax, accounting, and legal obligations. |
Security audit and service logs | Kept for periods proportionate to security, reliability, fraud prevention, investigation, and legal needs, then deleted or de-identified under retention controls. |
Support and communications | Kept while needed to resolve the request, maintain an appropriate service history, protect legal rights, and meet recordkeeping requirements. |
Marketing contacts | Kept until opt-out, invalidity, or inactivity under applicable retention rules, with limited suppression records retained to honor the opt-out. |
Recruitment records | Kept for the recruitment process and a reasonable period afterward for legal, reporting, and future-opportunity purposes where permitted. |
Cookies and website identifiers | Session technologies expire when the session ends; persistent technologies last for the period set by the provider or until deletion, withdrawal, or browser expiry. |
We may retain information longer where required by law, subject to a litigation hold, needed to investigate abuse or a security event, or necessary to establish, exercise, or defend legal claims. We may retain de-identified information where it cannot reasonably be reidentified.
10 Security
We use administrative, technical, and physical safeguards proportionate to the nature of the information and risk. Measures for Cloud Services include encryption in transit and at rest, role-based access, least privilege, logical tenant segregation, logging and monitoring, secure development practices, incident response, backup and recovery processes, and subprocessor review. No method of storage or transmission is completely secure.
11 Your Privacy Rights
Depending on your location and our role, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information; withdraw consent; opt out of targeted advertising or certain disclosures; and complain to a privacy or data protection authority. You may also have a right not to be discriminated against for exercising a right.
Send a request to privacy@trampoline.ai and describe your relationship with Trampoline. We may verify identity and authority before acting. If we process the information for a customer, we will direct the request to that customer and assist it as required. We will respond within the period required by applicable law and explain any lawful denial or extension.
You may lodge a complaint with the Commission d'accès à l'information du Québec, the Office of the Privacy Commissioner of Canada, an EEA or United Kingdom supervisory authority, or another authority responsible for your location. We encourage you to contact us first so we can try to resolve the concern.
12 Automated Decisions
Trampoline does not use public-site or Account Data to make solely automated decisions that produce legal or similarly significant effects about individuals. Customers may configure Workflows that analyze personal information or support decisions. In those cases, the customer determines the purpose and safeguards and must comply with the Agreement, the Acceptable Use Policy, and applicable transparency, assessment, human-review, and contestability requirements.
13 Children
Our website and Cloud Services are designed for organizations and are not directed to children. We do not knowingly collect personal information directly from children for our own purposes. Customers must not process children's data through the Cloud Services unless the use is lawful, the applicable service and Order support it, and appropriate safeguards and consents are in place.
14 Changes to This Policy
We may update this Policy to reflect changes in law, technology, providers, or our practices. We will post the updated version and its effective date. If a change materially affects registered users or how we use previously collected personal information, we will provide additional notice where required.
15 Contact
Privacy Officer
Trampoline AI Inc.
5715 rue Marquette
Montreal, Quebec H2G 2X8
Canada
privacy@trampoline.ai
Legal questions may be sent to legal@trampoline.ai. Product and support requests may be sent to support@trampoline.ai.