DRAFT for counsel review — not yet in force for production Community launch. Product requirements from TrustRouting MK2.1; not legal advice.
Draft dated 25 August 2026 — replaces trial/device-era language; counsel review required before production.
This Privacy Policy explains how ENQUIRELINK INC. ("Enquirelink", "TrustRouting", "we", "us", "our") collects, uses, discloses, and protects information when you use the TrustRouting platform, including:
- the TrustRouting Android application/agent ("App" or "Android Agent");
- the TrustRouting web interface / admin portal ("Admin Panel");
- trustrouting.com and related websites, documentation, and services (collectively, the "Platform").
If you do not agree with this Privacy Policy, do not use the Platform.
1. WHO WE ARE (CONTROLLER / OPERATOR)
The TrustRouting Platform is owned and operated by:
ENQUIRELINK INC.
Registered in Ontario, Canada
Email: [email protected]
Website: https://trustrouting.com
2. PLAN TYPES AND DATA TREATMENT
How we treat your information depends on your plan and deployment type. This section summarizes product behavior described in MK2.1; counsel must confirm lawful basis and jurisdictional requirements before production launch.
2.1 Community Plan and Remote Plan (public SaaS)
Community Plan ($0) and Remote Plan (currently $99/month per workspace) are public SaaS offerings. Both use your own devices and SIMs. Customer Data you upload or generate may include records eligible as Community Observations for the purposes in Section 5.2. Remote Plan adds a larger workspace-wide allocation of Remote Access Minutes but does not, by itself, change Community Observation eligibility unless you move to a Private offering under separate terms.
Your devices are never shared with or controlled by other customers. Isolation is enforced at the workspace and access-control layer.
2.2 Private Workspace
Private Workspace plans (including MNO Assurance and other contract plans) treat Customer Data as private by default. Such data is excluded from shared research, Community Observations, and Derived Intelligence unless separately agreed in writing.
2.3 Private Installation
Private Installation deployments run under separate contract, often on customer-controlled or dedicated infrastructure. Customer Data in those deployments is excluded from shared research and Derived Intelligence by default unless separately agreed in writing. Private Installation deployments may not use public Community or Remote billing unless explicitly configured.
3. IMPORTANT PRINCIPLES
3.1 Bring-your-own device and SIM
TrustRouting does not provide SIM cards, phone numbers, or connectivity. You supply devices and SIMs.
3.2 No synthetic traffic generation
TrustRouting does not generate SMS, voice calls, RCS, or chat traffic. The Platform collects and processes records observed on your linked device(s), including notification-derived chat records where you enable that feature.
3.3 Not a carrier
We are not a mobile network operator, carrier, or termination provider.
3.4 Dedicated test device recommended
Because the App may collect message and call content/metadata from the linked device, you should use a dedicated test device and SIM if you do not want personal, sensitive, or unrelated communications captured.
4. INFORMATION WE COLLECT
We collect information in the following categories. Some data is collected automatically when you use the Platform; other data is collected when you provide it or when your device records it.
4.1 Account and identity information
- Email address (used for authentication and account administration)
- Magic-link authentication tokens and session information
- Workspace, plan, and role information
- Optional profile or organization information you provide (for example, company name)
4.2 Billing and subscription information
- Plan type (Community, Remote, Private, or other), subscription status, invoices, payment timestamps, and billing history for paid plans
- Remote Access Minutes usage and quota events
- Payment processing is handled by Stripe (or another payment processor). We do not store full payment card numbers. Stripe may collect and process payment details according to its own privacy practices.
4.3 Device, SIM, and app configuration data
- Device identifiers (for example, Android ID and/or device ID), device model, manufacturer, OS version
- SIM slot information and related carrier/operator indicators available to the device
- App version, settings related to sync, remote access, and operational status
- Diagnostic events (for example, app crashes or error reports), and logs if you choose to upload them for debugging
4.4 Communications records (Customer Data) collected via your linked device(s)
Depending on permissions you grant and device capabilities, the App may collect and transmit records such as:
SMS:
- sender/recipient numbers, timestamps, direction (incoming/outgoing), message text/content
- delivery timing signals such as received_time, sent_time, delivery_delay (where available)
- enrichment fields such as SMSC number, SMSC validity, operator/country inference (where available)
Calls:
- caller/callee numbers, timestamps, direction, duration, call type (for example, incoming/outgoing/missed)
- related metadata available through call logs (call audio is not recorded by the App)
RCS:
- sender/recipient identifiers, timestamps, direction, message content and related metadata
- attachment indicators/metadata (and, if captured by device/system capabilities, attachment content)
WhatsApp / Viber / Telegram notifications:
- notification-derived sender name, conversation title, timestamp, message preview/content, and OTP candidate metadata
- captured only for new Android notifications when you enable notification access and the relevant capture toggle
- full chat history is not imported
4.5 Remote access session data
When you use remote access features, we may process session metadata (for example, start/end time, device identifiers, workspace identifiers, bandwidth or quality signals, and security logs). Whether screen content traverses a relay, peer-to-peer path, or other architecture; whether sessions are recorded; and how long any recordings or relay artifacts are retained are described in our Security Pack and confirmed by implementation. Those details may be updated as the product evolves. Do not rely on this draft alone for a technical security assessment.
4.6 Website and Admin Panel usage data
- IP address, browser type, operating system, device type, language settings
- pages viewed, timestamps, navigation events, and performance or error signals necessary to operate the service
- security logs (login events, access logs, suspicious activity detection)
4.7 Support communications
- messages you send to [email protected]
- information you provide during troubleshooting (screenshots, logs, device details)
5. HOW WE USE INFORMATION
5.1 Core Platform operations
We use collected information to:
- provide and operate the Platform (link devices, sync data, display records, run searches, generate exports, and deliver remote access);
- provide enrichment and processing features (for example, SMSC/operator signals where available);
- meter Remote Access Minutes and enforce workspace quotas;
- operate the Testing Library and related in-product reference materials;
- maintain security, prevent fraud, enforce access controls, and investigate abuse or prohibited conduct;
- provide customer support and troubleshooting;
- improve reliability, performance, and features;
- comply with legal obligations and respond to lawful requests.
5.2 Community Observations and Derived Intelligence (Community and Remote plans)
For Community Plan and Remote Plan workspaces, eligible Customer Data may be used as Community Observations and to create Derived Intelligence for purposes including:
- service recognition and catalog enrichment;
- anti-abuse and anti-fraud research;
- SMSC, operator, routing, and delivery-intelligence development;
- aggregated analytics and quality benchmarking that do not expose your devices or workspace identity to other customers.
Counsel review required: before production Community launch, lawful basis, consent, notice, opt-out, and regional requirements for Community Observations must be confirmed. This draft describes intended product behavior, not a final legal conclusion.
5.3 Private exclusions
Customer Data in Private Workspace and Private Installation deployments is excluded from shared research, Community Observations, and Derived Intelligence by default unless separately agreed in writing.
6. LEGAL BASES (IF GDPR / UK GDPR APPLIES)
Where applicable, we process personal data under one or more of the following bases. Final basis selection for Community Observations requires counsel confirmation:
- Contract: to provide the Platform you request and manage your plan.
- Legitimate Interests: to secure, operate, and improve the Platform; prevent abuse; develop non-identifying Derived Intelligence where permitted; and protect our rights.
- Consent: where required (for example, certain cookies or optional features) or where you actively provide optional data.
- Legal Obligation: to comply with laws and lawful requests.
7. HOW WE SHARE INFORMATION
We do not sell your personal information. We may share information as follows:
7.1 Service providers (processors)
We may share data with vendors that help us run the Platform, such as hosting and infrastructure providers, database and search tools, email and authentication delivery providers, payment processors (for example, Stripe), edge security providers, and customer support tools. These providers are authorized to process data only as needed to perform services for us under contractual safeguards.
7.2 Derived Intelligence
We may use Community Observations to create Derived Intelligence used within the Platform and to improve TrustRouting services. Derived Intelligence is not shared in a form that gives other customers access to your devices or identifiable workspace records.
7.3 Legal and safety
We may disclose information if we believe it is reasonably necessary to comply with law, regulation, legal process, or governmental request; enforce our Terms; protect rights, property, or safety; or detect, prevent, or address fraud, abuse, security, or technical issues.
7.4 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction (subject to applicable law).
8. DATA RETENTION
We retain information as long as necessary for the purposes described above, including:
- while your account or workspace is active and you use the Platform;
- for legitimate business needs such as security, fraud prevention, backup, and service integrity;
- for billing, tax, and accounting compliance;
- to resolve disputes and enforce agreements;
- for Derived Intelligence and aggregated datasets that no longer identify you, where permitted by law.
Retention periods for remote session artifacts, relay logs, and any recordings are defined in the Security Pack and implementation and may change with notice where appropriate.
9. DEVICE DEACTIVATION AND DELETION
9.1 Deactivation is not erasure
Deactivating or unlinking a device stops new collection from that device going forward. It does not by itself erase historical cloud records already stored for your workspace.
9.2 No self-service permanent deletion in public UI
The public Admin Panel does not provide a self-service control to permanently delete all historical cloud records. Permanent deletion or broader erasure requests must be submitted to [email protected] and are handled subject to applicable law and operational requirements.
9.3 Retained records
We may retain limited information where required by law or for legitimate purposes (for example, security logs, billing records, abuse investigations, and dispute resolution).
10. SECURITY
We use reasonable administrative, technical, and organizational safeguards to protect information, including access controls, encrypted transport where appropriate, and least-privilege internal access. However, no method of transmission or storage is completely secure. You are responsible for securing your devices, credentials, and exported files. Technical architecture details, including remote access paths and retention, are documented in our Security Pack.
11. YOUR CHOICES AND RIGHTS
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of certain personal data, and to withdraw consent where processing is based on consent.
To exercise rights, contact [email protected]. We may request verification of identity and account ownership. We will respond within timeframes required by applicable law.
12. INTERNATIONAL DATA TRANSFERS
We are based in Canada and may process or store data in Canada and other countries where our service providers operate. These countries may have different data protection laws than your jurisdiction. We use reasonable safeguards for cross-border transfers where required by law.
13. CHILDREN
The Platform is not intended for children and must not be used by anyone under the age of majority in their jurisdiction.
14. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will post the updated version on the Website with a new effective date. Your continued use of the Platform after the effective date means you accept the updated policy, unless applicable law requires a different process.
15. CONTACT
Privacy questions and requests: [email protected]
ENQUIRELINK INC., Ontario, Canada