Privacy Policy
Last updated: August 19, 2026
Who we are
Trifecta (“we”, “us”) is a board operating system for Entrepreneurs’ Organization (EO) chapters. It helps chapter boards track member health, engagement, renewals, and revenue. Trifecta is operated from Dallas, Texas. Questions or requests about this policy: membership@gettrifecta.com.
Data we process
Chapter data. Chapters provide member rosters, engagement records, CRM exports, sponsor lists, and board correspondence (email sent or copied to the chapter’s Trifecta mailbox). This data belongs to the chapter; we process it to provide the service to that chapter’s board.
Account data. Name, email address, and role for board members who sign in, plus routine security logs.
Google sign-in. If you sign in with Google we receive your name, email address and profile photo to identify your account. Trifecta does not request access to your Gmail, Drive, Calendar or any other Google service.
Google account access
Trifecta uses Google only as a sign-in method. When you sign in with Google we receive your name, email address and profile photo — the standard sign-in scopes. That is all.
We do not request access to your Gmail, Drive, Calendar, Contacts or any other Google service, and Trifecta cannot read, search, draft or send mail from your account. Where Trifecta prepares a suggested message, it opens a pre-filled compose window in your own Gmail; you review, edit and send it yourself, and nothing is created in your mailbox until you do.
Earlier versions of Trifecta offered optional Gmail access for inbox scanning and draft creation. Those features were withdrawn, and the corresponding permissions are no longer requested. Any access tokens held under them have been deleted.
Subprocessors
We use a small set of infrastructure providers to run the service: Vercel (hosting), Supabase (database), Anthropic (AI processing), Resend (email delivery), and Cloudflare (inbound mail routing and DNS). Each processes data only to provide its service to us. A chapter’s own CRM (for example HubSpot) is connected only at that chapter’s direction, using credentials the chapter controls.
Security
Every chapter’s data is isolated with row-level security; secrets and OAuth tokens are encrypted at rest and readable only by server-side service processes; data is encrypted in transit; outbound email systems are gated behind explicit switches; and inbound email is authenticated (SPF/DKIM/DMARC) and rate-limited.
Retention and deletion
Chapter data is retained while the chapter uses Trifecta and deleted on the chapter’s request when it leaves. Individuals may request access to or deletion of their personal data at membership@gettrifecta.com; we respond within 30 days.
Cookies
Trifecta uses only the session cookies required to keep you signed in. There are no advertising or cross-site tracking cookies.
Changes
If we change this policy we will update this page and the date above; material changes affecting Google user data will be communicated to connected users before they take effect.