How Troy collects, uses, protects, and shares information — and the choices and rights you have over your data.
Last updated: June 15, 2026 · Effective: June 15, 2026
Troy ("Troy," "we," "us," or "our") is an all-in-one business operations platform operated by Fashqua Holdings LLC, located at 875 Industrial Hwy, Unit 8, Cinnaminson, NJ 08057, United States. This Privacy Policy explains how we handle personal information in connection with the Troy website at meettroy.ai (the "Site") and the Troy application and related services (together, the "Service").
This policy applies to people who visit our Site, sign up for or use Troy, and individuals whose information is entered into Troy by our customers. By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
Troy is a tool that businesses use to run their operations, so we handle two different categories of data in two different roles:
We do not sell your personal information, and we do not use Customer Data to train AI models or for advertising.
Where the GDPR applies, we rely on: contract (to provide the Service you signed up for), legitimate interests (to secure, improve, and operate the Service in ways that do not override your rights), consent (where required, such as certain communications), and legal obligation (to meet our compliance duties). For Customer Data processed on a customer's behalf, the customer is responsible for establishing the legal basis.
We share personal information only as described here. We do not sell it. We use a small set of trusted service providers ("sub-processors") that process data on our behalf under contractual confidentiality and security obligations:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase (hosted on AWS) | Database, authentication, and file storage | Account Data & Customer Data |
| Netlify | Website & application hosting, serverless functions | Usage/log data |
| Anthropic | Powers the in-app AI assistant | The prompts you submit to the assistant |
| Resend | Sending transactional & notification email | Recipient name & email, message content |
| Stripe | Subscription billing & payments | Billing details; card data handled by Stripe (PCI DSS Level 1) |
We may also disclose information to comply with law, respond to lawful requests, protect the rights and safety of people and our Service, or in connection with a merger, acquisition, or sale of assets (with notice where required).
We will provide reasonable advance notice of new sub-processors to customers who ask to be notified, so they can object where they have the right to.
We keep Account Data for as long as your account is active and as needed to provide the Service. Customer Data is retained according to the customer's instructions and their use of the product. When an account is closed, we delete or de-identify personal data within a commercially reasonable period (typically within 90 days), except where we must retain it to meet legal, tax, accounting, or security obligations, or to resolve disputes.
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing or withdraw consent.
You may exercise the rights above and lodge a complaint with your local supervisory authority. We will respond within the timeframes the law requires.
You have the right to know what personal information we collect and how we use and disclose it, to request deletion or correction, and to not be discriminated against for exercising your rights. We do not sell or "share" personal information as those terms are defined under California law.
To make a request, email hello@meettroy.ai. We will verify your identity before acting. If your information is held in Troy by a business that uses our Service (Customer Data), we will refer your request to that business as the controller.
Troy uses only the cookies and browser storage necessary to operate the Service — primarily to keep you signed in and remember basic preferences. We do not use third-party advertising cookies. If we add optional analytics in the future, we will update this policy and, where required, ask for consent.
We apply technical and organizational safeguards including encryption in transit and at rest, database-enforced tenant isolation, scoped access controls, and secret management. Full detail is on our Security page. No method of transmission or storage is 100% secure, but we work continuously to protect your information and to notify affected parties of incidents as required by law.
We are based in the United States and our providers may process data in the U.S. and other countries. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Troy is a business product not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you through the Service or by email. Your continued use after changes take effect constitutes acceptance.
Questions or requests about this policy or your data: