Privacy Notice

Last updated: 2026-09-21 · Tripoli

1. Who is responsible

The business responsible for the personal information described here is:

  • Responsible party: Moisés Monraz Escoto, sole proprietor
  • Doing business as: Tripoli Media
  • Tax ID (RFC): MOEM000520NK2
  • Address: Av. de las Rosas 585 int. 2, Chapalita Oriente 45040, Zapopan, Jalisco, Mexico
  • Email: contacto@tripoli.media
  • Phone: 33 1234 5678

Because we operate from Mexico, your information is handled there and by the service providers listed in Section 4, most of them in the United States.

2. What we collect

2.1 From the account owner and the operators

  • Full name
  • Email address
  • Phone number
  • Business name and tax identification number, where an invoice requires it
  • Billing address
  • Payment details: these are handled directly by Stripe, Inc. and are not stored by Tripoli Media. We only keep a reference to your Stripe customer id, to manage the subscription.

2.2 From people who ask for the student rate

Only from whoever asks for that rate:

  • Full name and contact email
  • School and current term
  • Proof of enrollment, provided by the applicant to show current enrollment

The document is used for one purpose only — checking current enrollment — and is deleted as soon as the check is done. No copy is kept: we only record that the check happened, when, and which term was confirmed. We do not ask for, and you should not send, sensitive personal information.

2.3 About your own contacts (your leads and clients)

Whatever you enter about your business contacts, including:

  • Full name
  • Phone number
  • Email address
  • Company name
  • Mailing address, when you choose to enter it. It is turned into coordinates to place the contact on the client map, as described in Section 4
  • Commercial data (deal value, pipeline stage, tags, notes)
  • Communication history (emails, WhatsApp messages) when you turn those integrations on

Important: you are responsible for the personal information of your own contacts. You must have a lawful basis to hold it and must meet the obligations the law places on you where you operate. Tripoli Media acts as your service provider (processor) for that information, uses it only to run the Service for you, and does not sell it or use it for its own purposes.

2.4 Information generated by use

  • Activity records (sign-ins, actions taken inside the CRM)
  • Settings (visual theme, dashboard layout, working hours)
  • Aggregate usage metrics (number of leads, sales recorded, messages sent)

3. Why we use it

3.1 To run the Service

  • Delivering the CRM: storing, organizing and showing your commercial data.
  • Authentication and access control: confirming who is signing in.
  • Payments: managing subscriptions, charges and invoices through Stripe.
  • Operational messages: system notifications, appointment alerts, task reminders and confirmations.
  • Support: answering your requests and fixing problems.
  • Legal compliance: responding to lawful requests from authorities and meeting our own obligations.

3.2 Optional purposes

  • Usage analysis to improve the Service.
  • Commercial messages about updates, new features or related services from Tripoli Media.
  • Anonymized aggregate statistics that cannot identify anyone.

If you would rather we did not use your information for the optional purposes, write to contacto@tripoli.media with the subject «Opt out».

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

4. Who we share it with

To run the Service, your information may reach these providers:

Supabase, Inc. (United States)

Database storage, user authentication and file storage.

What is shared: all of the CRM data, including contacts, attachments and encrypted authentication credentials.

Vercel, Inc. (United States)

Web application hosting and server functions.

What is shared: data in transit while the application is used. Vercel does not store your data persistently.

Stripe, Inc. (United States)

Payment processing and subscription management.

What is shared: cardholder name, billing details and payment methods. Stripe is certified PCI DSS Level 1.

Google LLC (United States)

Google Calendar and Gmail integration — only when you choose to link your Google account.

What is shared: calendar events, email messages and contacts belonging to the linked account.

Meta Platforms, Inc. (United States)

WhatsApp Business API integration — only when you choose to connect your WhatsApp Business account.

What is shared: text and media messages, phone numbers and contact names.

OpenStreetMap Foundation (United Kingdom)

Turning addresses into coordinates and drawing the client map — only when you enter an address on a client record.

What is shared: the address you entered (street, number, neighborhood, postal code, city and state), without the person's name, phone or email. The lookup runs once per address from our servers and the result is stored so it is not repeated.

Resend, Inc. (United States)

Sending the system's transactional email (notifications, alerts, reminders).

What is shared: recipient email addresses and the content of those notifications.

Each of these providers is bound by contract to use the information only to provide its service to us. Information may be processed in countries other than the one you live in, including Mexico and the United States.

5. How we protect it

We apply administrative, technical and physical safeguards against loss, alteration, destruction and unauthorized access:

  • Encryption in transit: everything between your browser and our servers travels over HTTPS/TLS.
  • Encryption at rest: stored data is encrypted using Supabase's native PostgreSQL encryption.
  • Secure authentication: passwords are stored as cryptographic hashes (bcrypt). Sessions use JWT tokens that expire and renew automatically.
  • Row Level Security: every database table carries row-level policies, so each user only reaches their own data.
  • Single-tenant isolation: each customer has their own database and application environment, so data is physically separated between customers.
  • Secure third-party tokens: access tokens for Google and WhatsApp are stored encrypted and expire and renew automatically.
  • Role-based access: roles (owner, admin, manager, rep) limit what each person can open.

6. Your privacy rights

Depending on where you live, you may have the right to:

  • Know and access the personal information we hold about you and how we use it.
  • Correct information that is wrong or out of date.
  • Delete your personal information, within the limits the law allows.
  • Obtain a copy of your information in a portable format.
  • Opt out of the optional purposes in Section 3.2.
  • Not be discriminated against for exercising any of these rights.

To exercise any of them, write to contacto@tripoli.media with:

  1. Your full name.
  2. The email address on your CRM account.
  3. A clear description of what you are asking for.
  4. Enough information for us to confirm it is really you. We ask for the least we can, and use it only to verify the request.

We answer within thirty (30) calendar days. Where the request is complex, we may take another thirty (30) days and will tell you before the first period ends. An authorized agent may make a request on your behalf with written proof of authority. Requests are free unless they are manifestly unfounded or excessive.

About your own contacts (your leads and clients): since you are responsible for that information, requests from those people go to you, not to us. We will help you answer them when you need it.

7. Cookies and tracking

The Service uses:

  • Session cookies (essential): needed to sign you in and keep your session open. Without them the CRM cannot work.
  • Preference cookies: they remember your visual theme (light or dark).

The Service uses no third-party advertising or tracking cookies.

More detail in our Cookie Policy.

9. Changes to this notice

We may update this notice. Substantive changes are announced at least thirty (30) calendar days in advance, by email to the address on your account and with a notice inside the CRM. The date at the top always shows the current version.

10. Where to complain

Write to us first at contacto@tripoli.media: most questions are settled there.

If you are not satisfied, you may complain to the data protection or consumer protection authority where you live. In Mexico, that is the authority in charge of personal data held by private parties; in the United States, the attorney general of your state or the Federal Trade Commission.