Privacy policy
Last updated: October 10, 2026
This policy explains what personal data TrustPlug handles, why, on what legal basis, and your rights. It applies to our website and to our plugins wherever they run — today, the Framer plugins Testimonials, Social Feed, Gatekeeper, Pathfinder, Standby Mode, Landmark, Open Hours, Feedback and FAQ.
It is written to match what the code does today, not what we might do one day. Our plugins are still in development and the site has no accounts or payments yet, so some of what you might expect to find here simply does not exist.
1. Data we collect
- Website visitors: nothing beyond what any web host sees. This website has no accounts, sets no cookies and loads no analytics or advertising scripts. Our hosting provider (Cloudflare) sees your IP address and the pages you request, as every web host does, to deliver the site and protect it from abuse.
- Waitlist, contact and suggestion forms: when you use one, the form sends what you typed to our own server (a Cloudflare Worker with a Cloudflare D1 database) and we store it: your email address and the plugin you asked about for the waitlist, plus your name, subject and message for the contact and suggestion forms, with the time. For rate limiting we also keep a salted hash of your IP address — never the address itself — that cannot be turned back into it. If the form cannot reach our server, the page offers to send the same text from your own email app instead; nothing is sent until you press send there.
- Plugin settings: each plugin's settings (layout, colors, rules, texts…) live in the site owner's own Framer project. Our servers only receive the few values a plugin needs to do its job on a given request: a Google Place ID, an Instagram handle, a street address, a Google Calendar ID or calendar (iCal) address, or a webhook address.
- Third-party public content: public reviews and opening hours from Google Places, public events from Google Calendars their owners made public or from an iCal address they supplied, and public Instagram posts fetched through Apify. This content is cached on Cloudflare's network so widgets load fast: 24 hours for reviews and Instagram posts, 6 hours for opening hours, 5 minutes for calendar events.
- Feedback and votes: what a visitor chooses to send through the Feedback plugin (or a FAQ "Was this helpful?" vote) — see section 8.
- Accounts and payments: not available yet. Plans are still being finalized, nothing can be bought, and we hold no payment or account data. Before accounts or billing open, we will update this policy and name the payment processor.
2. Legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Running the plugins a site owner configured (fetching reviews, hours, maps, feeds; geolocating a visit for a rule) | Legitimate interest, and performance of the owner's request |
| Spam and abuse protection (rate limits, honeypot) | Legitimate interest |
| Answering your emails | Legitimate interest |
| Telling you when a plugin you asked about launches (waitlist) | Your consent, given by ticking the box on the waitlist form — withdraw it at any time with the unsubscribe link or by writing to us |
| Keeping the website secure | Legitimate interest |
3. Who is responsible for what
Controller. TrustPlug is the controller of the data described in section 1 for our own website and inbox. Contact for any privacy request: [email protected].
Two roles. For anything a plugin does on a published site — showing reviews, checking a visitor's country, collecting feedback — the site owner is the controller and we act as their processor, on their documented instructions (their settings). The site owner is responsible for giving their own visitors any privacy notice, and for any consent their jurisdiction requires. A data-processing addendum is available on request.
4. Reviews, opening hours & calendar (Testimonials, Open Hours)
Testimonials fetches the public Google reviews of the place you connect (review text, rating, the author's display name and photo as published by Google, and the date). Open Hours fetches that place's opening hours, and — if you connect one — the events of a Google Calendar made public, or of any calendar whose iCal (.ics) address you give us. We retrieve all of it server-side, using our own Google keys, which are never placed in your published page.
Requests your published page makes. The widget calls our API (a Cloudflare Worker) and nothing else on our side:
| Request | Why | What is sent |
|---|---|---|
| /google-reviews | Load the reviews to display | The Google Place ID you configured |
| /business-hours | Load weekly hours and the next days' exceptions, holidays included | The Google Place ID you configured |
| /calendar-events | Load closures or special openings from a calendar | The Google Calendar ID, or the iCal address, you configured |
These values are the site owner's, not the visitor's. There is no per-visitor check, no IP geolocation, no counter and no profile for these two plugins. Like any web server, our API receives the visitor's IP address in order to answer; our code does not store it or write it to a log. One thing to know: reviewers' profile photos are loaded by the visitor's browser straight from Google's servers, so Google can see that request.
5. Instagram (Social Feed)
Social Feed fetches the public posts of the Instagram account you connect (the image or video link, caption and post link). We retrieve them through Apify, a third-party scraping service, and cache them for 24 hours so we do not re-fetch on every page view. We never ask for, receive or store an Instagram password, and the plugin does not log in to Instagram. Only connect an account you own or are authorized to represent, and make sure you have the right to show its content on your site.
We do not copy the pictures or videos to our servers. The visitor's browser loads them directly from Instagram's content network, so Instagram (Meta) can see that request — including the visitor's IP address. If you need to avoid that, do not use this plugin on your site, or mention it in your own privacy notice. Our API itself performs no per-visitor check and sets no cookie.
6. Maps (Landmark)
Landmark sends the address you typed to our API, which builds the address of a Google Maps embed and returns it. The map itself is Google's: the visitor's browser loads it from Google, so Google receives the visitor's IP address and may read or set its own cookies, under Google's privacy policy. The Maps Embed API itself is free for us; the key it needs is restricted to that one product. If the embed cannot load, the plugin falls back to a plain link to Google Maps. If your jurisdiction requires consent before loading Google content, you can place the plugin behind your own consent banner.
7. Visitor checks (Gatekeeper, Pathfinder, Standby Mode)
When a rule depends on where the visitor is, the page asks our API for the visitor's approximate location. Our servers answer from the data Cloudflare attaches to the connection (country, and where available region, city and whether the country is in the EU). The IP address is used for that lookup only. Nothing is stored and there is no individual record of the visit. No automated decision produces legal or similarly significant effects: the check only decides which page a browser shows.
- VPN and proxy detection (an option in Gatekeeper and Pathfinder) sends the visitor's IP address to a VPN-detection provider, vpnapi.io. This option is built but not switched on at the time of writing; until it is, nothing is sent to that provider and VPN rules never match. We will update this page the day it is switched on.
- Standby Mode and the Feedback whitelist ask our API for the visitor's own IP address and compare it, in the visitor's browser, with the list of addresses you entered. Because of that, the list is part of your published page's code: only add addresses you are comfortable having there.
- Pathfinder remembers, in the visitor's own browser, that a suggestion banner was dismissed so it does not nag. Standby Mode keeps, in the visitor's own browser, the moment its "starts now" countdown began. This is functional storage only; it is not shared with us and not used for tracking.
8. Feedback & FAQ votes
Feedback asks a visitor how well the site helped them, and optionally to report a problem, suggest an idea or write a message. A visitor can answer with a single click, with no email and no text. Each answer is sent to our API, which checks it and forwards it to the destination the site owner chose.
- What a submission contains: the rating or choice, the category, the message and email only if the visitor typed them, the site name you set, and a timestamp. If the site owner turns on "Add page info", it also contains the page address and title, the device type (mobile or desktop), the window size and the browser language.
- Where it goes: to the webhook address the site owner entered — Slack, Discord, Microsoft Teams, Zapier, Make, n8n or a Google Sheet (via Apps Script). The destinations we accept are limited to a fixed list of hosts. We do not read or keep the content afterwards. The site owner is responsible for the destination service.
- Storage: optional storage of answers (so a site can show its average rating) exists in the code but is not switched on today, so we keep no copy of feedback. If we switch it on, answers will be kept for up to 180 days, and we will say so here.
- Spam protection: a hidden field that only bots fill in, and a limit of 6 submissions per 10 minutes. The limit is a counter held in Cloudflare's cache under a key made from the visitor's IP address and the site name, and it disappears after 10 minutes.
- FAQ votes ("Was this helpful?"): if the site owner enables votes and enters a webhook, a vote carries the question, the answer given and the page address, and is sent the same way. A visitor's votes and their last answer or "not now" are remembered in their own browser so they are not asked again straight away.
9. The live demos on this website
Each plugin page runs the real plugin. To do that, your browser calls our API with the demo's public values: a public Google Place ID (Testimonials, Open Hours), a public address (Landmark), and the @nasa Instagram account (Social Feed). The demo for Feedback sends nothing: its submit action is switched off on this site. Gatekeeper, Pathfinder and Standby Mode run in preview mode with a simulated visitor, so no real location lookup is made for them. The same rules as above apply to what the API sees.
10. How we use data
Only to run the service: fetching and caching what a plugin displays, applying a rule, relaying an answer, protecting against abuse, and answering you. We never sell or rent personal data, we do not use it for advertising, and we do not build profiles of site owners or their visitors.
11. Processors & international transfers
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Website hosting, our API (Workers), edge cache, rate-limit counter, visitor country | EU / USA |
| Google (Places, Maps Embed, Calendar) | Reviews, hours, maps and public calendar events | USA |
| The calendar provider you connect (iCal address) | Fetching the events of the calendar whose address you gave us (Apple, Microsoft, Proton, Nextcloud…) | Depends on the provider |
| Apify | Retrieval of public Instagram posts | EU / USA |
| Instagram / Meta | Delivers the images and videos a visitor's browser loads | USA |
| vpnapi.io | VPN and proxy detection — not switched on today | — |
| The destination you choose (Slack, Discord, Teams, Zapier, Make, Google Sheets…) | Receives Feedback answers and FAQ votes | Depends on the service |
| Gmail (Google) | Our support inbox | USA |
Where a provider is outside the EU/EEA, transfers rely on the safeguards that provider offers under the GDPR (an adequacy decision or Standard Contractual Clauses). We use these providers only for the purposes above.
12. Retention & deletion
Cached reviews and Instagram posts expire after 24 hours, opening hours after 6 hours, calendar events after 5 minutes. The rate-limit counter lasts 10 minutes. We do not keep visitor IP addresses. Waitlist addresses are kept until the plugin you asked about launches and we have written to you once, or until you unsubscribe or ask us to delete them; contact and suggestion messages are kept for 12 months after the last exchange. The hash of your IP address used for rate limiting is kept with the entry it belongs to and deleted with it. Every mail we send carries a one-click unsubscribe link, and an address can be erased entirely, messages included, on request. To have your data deleted, write to us at the address below; we answer within 30 days, except for records we must keep by law.
13. Your rights
Under the GDPR and similar laws you can ask to access, correct, delete, restrict or object to the use of your data, to receive it in a portable format, and to withdraw consent where processing relies on it. Email [email protected]. You can also complain to your data protection authority — in France, the CNIL. If your data was handled by a plugin on a site you visited, send your request to that site's owner (the controller); they can instruct us as their processor.
15. Security
Everything is served over HTTPS. Our Google and Apify keys are held only on our servers and are never placed in a published page. Webhook destinations are restricted to a fixed list of hosts, and messages relayed to chat tools are escaped so they cannot trigger mentions. No system is perfectly secure; if a breach affects you, we will tell you and the relevant authority as the law requires.
16. Changes & contact
Our plugins are still in development, and this policy describes how the code behaves today. We will update it — and the date above — whenever that changes, in particular before accounts, billing, VPN detection or stored feedback go live. Questions or requests: [email protected].