Privacy Policy
How TranzBox protects your data
This policy explains the information we collect, how we use TikTok lead data, and the security controls we apply across the TranzBox trading platform.
Effective date: 22 December 2025
1. Data we collect
TranzBox collects account registration details, trading preferences, compliance attestations, telemetry on platform usage, and communications with our support teams. We also store analytics for fraud prevention such as IP ranges, device fingerprints, and time-on-page.
If you connect brokerage or banking data, we store tokenized references provided by the custodian—never your raw credentials.
2. How we use information
Data powers portfolio recommendations, ticket routing, personalization of dashboards, service notifications, and legal compliance records.
Aggregated telemetry helps us detect latency regressions, suspicious trading patterns, and bugs before they affect clients.
3. TikTok lead data handling
TikTok Lead Ads send prospect information (name, email, company, campaign metadata) to TranzBox through a secure TikTok API connection. We store these leads inside our marketing automation system for up to 18 months while we nurture, qualify, and onboard potential customers.
Lead data is never sold. It is only used to follow up on the marketing request, schedule demos, and complete onboarding paperwork when the prospect becomes a customer.
We log every TikTok payload, encrypt it at rest, and restrict access to trained growth and onboarding staff only.
4. Sharing + security
We only share personal information with service providers who help us run the platform (cloud hosting, customer success tools, auditors) under strict confidentiality terms.
TranzBox uses AES-256 encryption at rest, TLS 1.3 in transit, hardware security modules for key custody, and continuous penetration testing. Access to production data requires hardware MFA and SOC 2 controls.
5. Retention + your rights
We retain account data for as long as you are a customer and for the period required by FINRA/SEC recordkeeping obligations. Marketing leads are stored for up to 18 months unless you opt out sooner.
Residents covered by GDPR, UK GDPR, or CCPA can request access, correction, deletion, or opt-out by emailing privacy@tranzbox.au. We respond within 30 days and never discriminate against opt-out requests.
6. Compliance statements
TranzBox processes data as a controller under GDPR and as a business under CCPA. We maintain SCCs, DPAs, and vendor diligence files for every subprocesser.
For TikTok data, we follow TikTok's Lead Ads Terms, limit usage to marketing-to-onboarding workflows, and delete data once it is no longer needed for that workflow.