The short version: our website counts visits without cookies unless you allow one; we use what you send us to respond to you; we keep records of the business contacts we work with or research; we do not sell your information, share it for advertising, or use advertising trackers; and you can ask us to show you, correct, or delete what we hold. Claims data our customers send to the Trestl platform is handled under our agreements with them.
1. Who we are and what this policy covers
Trestl Health Solutions, LLC (“Trestl,” “we,” “us”) is a Pennsylvania limited liability company based in Philadelphia, Pennsylvania. This policy explains how we handle personal information when you visit trestlsolutions.com (the “website”), contact us, receive our emails, or deal with us as a customer, prospect, partner, investor, or vendor contact. For this information, Trestl decides how and why it is used (in privacy law terms, we are the “business” or “controller”).
Claims data is different. When our customers (insurance carriers and their administrators) send us claims, member, and supporting documents to review on the Trestl platform, we process that information on their behalf and under their instructions, as a service provider, processor, or HIPAA business associate. That processing is governed by our agreements with those customers, including business associate agreements where applicable, not by this policy. If you are a member or claimant with a question about your claim information, please contact your insurer or plan administrator; we will assist them as our agreements require.
2. Information we collect
Information you give us
- Demo and contact requests: first and last name, work email, company, organization type, and, if you choose to provide them, job title, phone number, your area of interest, how you heard about us, your message, and whether you want to receive occasional insights emails.
- Correspondence: the contents of emails and messages you send us, our replies, and notes of calls and meetings, including a recording or transcript where a meeting note-taker or recorder is used with everyone’s agreement, deleted within 90 days.
- Customer and platform accounts: for users of the Trestl platform, name, work email, role, and single sign-on identifiers provided by your organization, and security audit records of sign-ins and actions in the platform, including IP address and browser.
Please do not send us health information, claim details, or other sensitive information through the website or by email. We agree a secure route before any such data is exchanged.
Information collected automatically on the website
Our website uses first-party, privacy-first analytics. By default it uses no cookies. For each page view and interaction we record the following (if you are in the EEA, the UK, or Switzerland, only after you accept; see below):
- the page path (without query strings), and for a page view, the external site that referred you (its address without query strings) and any campaign tags in the link (such as utm_source);
- what you did: clicking a call to action, scrolling to 25, 50, 75, or 100 percent of a page, how long the page was visible, starting or submitting a form, downloading a file, or following a link to another site;
- a coarse device class (mobile, tablet, or desktop), your browser and operating system family, and your country as reported by our hosting provider’s network (not a precise location);
- whether your browser sent a Global Privacy Control or Do Not Track signal; and
- a pseudonymous visitor code, explained below.
To count visitors without cookies, our server combines your IP address and browser user-agent string with the date and a random value (a “salt”) that lasts at most 48 hours, and runs the result through a one-way hash. Our analytics records store only the hash, never your IP address or full user-agent string. Each day’s salt is held only in our servers’ memory, never in our database, backups, or logs, and is erased automatically at the end of the following day (midnight UTC), so that activity delayed overnight still counts on the right day. After that, that day’s codes cannot be recalculated from anyone’s IP address and browser; an analytics event that reaches us after its day’s salt is erased gets a one-off code that links to nothing. Our hosting logs record only requests that send us data, such as our contact form; page loads and analytics requests are not logged.
People who share a network address and the same browser version on the same kind of device (the same user-agent string), such as colleagues behind one office connection, produce the same code on the same day, so our cookieless counts treat them as one visitor.
Your IP address is also used, without being stored with your analytics or your request: by our hosting provider’s network to determine your country; to limit abuse of our contact form and analytics endpoint, for which it is held in our server’s memory (on the contact form, together with the email address entered) for at most about 2 hours; and, when bot protection is enabled on our contact page, by Cloudflare (see section 5). On the way to our server, analytics events and requests pass through an encrypted Google Cloud message queue, which normally delivers each message within seconds and deletes it once processed. If our database is paused or unavailable, messages wait until it is back; a message that still cannot be delivered is deleted after 2 days.
Optional cookie. If you choose “Accept” in our privacy banner, we also set a first-party cookie containing a random identifier, so we can recognize a return visit on a later day. If you then submit a request, we can connect it to your earlier visits; when you send one, your browser gets a new identifier, so your later visits are not connected to it. We never set this cookie if your browser sends a Global Privacy Control or Do Not Track signal. Details are in our Cookie Notice.
Visitors in the EEA, the UK, and Switzerland. If our hosting provider’s network reports that you are connecting from the European Economic Area, the United Kingdom, or Switzerland, we measure nothing about your visit until you choose “Accept” in our privacy banner: no page view or interaction is recorded, and no cookie is set except the one that remembers your choice. If you accept, we measure your visits as described above and set the optional cookie, unless your browser sends a Global Privacy Control or Do Not Track signal, in which case we measure nothing. You can withdraw your acceptance at any time with “Your privacy choices” in the website footer. If you send us a request without accepting, we keep the request, but we have recorded nothing of your visit to keep with it. We go by the country the network reports for your connection, which a VPN can change; if it reports no country, we treat you as outside these countries.
Your request and your visit. When you submit a request, we keep it with a record of the visit in which you sent it, if we recorded one, so we understand what brought you to us: the pages and interactions recorded under the same daily visitor code in the activity leading up to your request (a visit ends after 30 minutes without activity), the form submission itself, and, if you accepted the optional cookie, your earlier visits. Because people on the same network address and user-agent string share the daily code, this record can occasionally include their activity in the same visit. About a day after your request (normally within 27 hours; later if our database was paused, or if you, or someone using the same network and browser, sent another request soon after), once late-arriving records can no longer change it, we cut your request’s links to our usage records: the daily visitor code and, if you accepted the optional cookie, its identifier. The record of your visit stays with your request; our other usage records no longer carry a code or identifier that points to it. If our systems were unavailable when you visited, parts of this record can be missing: activity, or a request, that reaches us after its day’s salt is erased gets a one-off code instead of the daily code, and activity that reaches us more than 26 hours late is stored without the optional cookie’s identifier.
Emails about your request. Our team is notified of each request by email, and we send you a confirmation email, through our business email provider (Google Workspace). When your request is passed on to our systems for storage, the notification contains your company, organization type, and area of interest, the page you sent it from, the time, and a reference number linking to the request, rather than your name or contact details; if we cannot confirm that it was passed on, a second notification carries the full request so that it is not lost. The confirmation we send you (to your email address; it may include your first name) remains in our sent mail. To limit misuse of the form, we may skip the confirmation when we have sent one to the same address shortly before. We keep these emails as business correspondence and delete them when you ask us to delete your information.
Server logs. To operate and secure the service, our hosting provider records standard request logs (IP address, user-agent string, requested address, referring page, and time) only for requests that send us data, such as our contact form; page loads and analytics requests are not logged. These logs are kept for 30 days. Separately, records of requests our firewall blocks (suspected attacks, and visitors who exceed our request-rate limit) are kept for up to 7 years as security records.
Information from other sources
Our customers provide the names and work contact details of their staff who use the platform or work with us. We may also receive business contact details from colleagues, partners, and other business contacts who introduce or refer you to us, and we collect business information about people at organizations we work with or are considering working with from publicly available professional sources, such as company websites, published biographies, and LinkedIn profiles. Our business-contact records can include your name, title, organization, work contact details, professional profile links, working relationships (for example, who introduced us or whom you report to), notes of our interactions, and where and when each detail was found.
Partners we pay
If you are a broker or other partner we pay (for example, commissions), we collect what we need to pay you and to meet tax reporting duties: your legal name, entity type, taxpayer identification number (stored encrypted), postal address, and a copy of your IRS Form W-9. We do not ask you for your bank details. You enter them with our banking provider, Mercury, through a secure request it sends you, and Mercury keeps them in our account, where our staff can see them, so that we can send your payments. If you referred a customer to us, that customer’s administrators can see your name and commission rate on its contract with us. They cannot see your tax details or your signed agreement.
3. How we use information
- To respond to your request, arrange conversations and demonstrations, and follow up on them.
- To provide, support, secure, and administer the Trestl platform for our customers and their users.
- To understand how the website is used and improve its content and design.
- To send occasional insights emails if you ask to receive them. You can unsubscribe at any time.
- To protect our website and services from fraud, abuse, and security threats, including checking that form submissions come from people.
- To research, build, and manage our business relationships with customers, prospective customers, partners, and investors.
- To pay partners and meet our tax reporting obligations (for example, IRS Form 1099).
- To keep records, meet our legal obligations, and establish or defend legal claims.
4. Legal bases (visitors in the EEA, UK, and Switzerland)
Where these laws apply, we rely on:
- Steps before a contract, or a contract, to respond to requests and work with customers and partners;
- Consent for website analytics, which in these countries run only after you choose “Accept” (including the optional cookie), and for insights emails. You can withdraw consent at any time, with “Your privacy choices” in the website footer or the unsubscribe link in an email;
- Legitimate interests in securing our services and in business communications with professional contacts; and
- Legal obligations where the law requires us to keep or disclose information.
For visitors elsewhere, the cookieless measurement described in section 2 runs by default, relying on our legitimate interest in understanding how our website is used where the law asks for a legal basis; the optional cookie is set only with your consent.
We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
5. How we share information
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it for targeted advertising. We do not use advertising or third-party analytics trackers on the website. We disclose personal information only to:
- Service providers that process it for us: Google Cloud (hosting, database, messaging, and logging), Google Workspace (email, meetings, and documents), and GitHub (hosting our code, documents, and internal work tracking). For customers and partners we pay, we also use Mercury for banking and payments, including matching customer payments to our invoices, and for partners we pay, any tax-filing service we use for their tax forms.
- AI assistant providers: Anthropic, OpenAI, and Cursor, whose AI assistants we use for research, drafting, and building our software. They process what we send them under their own terms. We turn off the settings that would let these AI assistants train on our data, and our policies do not allow health information to be sent to any of these tools.
- Your organization, if you use the Trestl platform through it: its administrators can see your account details and the audit records of your actions in the platform, including IP address and browser.
- The customers we work with, for the business-contact records we keep under their organization in our contact directory: their administrators can see each record’s name, title, role, work email, and phone. These can include people at partners and other organizations connected to that customer, such as a broker.
- The customer you referred, if you are a broker or other partner we pay: see “Partners we pay” in section 2 for what its administrators can see.
- Cloudflare, when bot protection (Turnstile) is enabled on our contact page. From the moment the page opens, Cloudflare’s script receives your IP address and browser signals to check that a submission comes from a person, and Cloudflare processes them under its own terms and privacy policy.
- Professional advisers such as lawyers and accountants, under confidentiality obligations;
- Authorities where required by law or to protect rights, property, or safety; and
- A successor in a merger, acquisition, or sale of assets, subject to this policy.
6. How long we keep information
| Information | How long |
|---|---|
| Salt used for the daily visitor code | Held only in memory and erased at the end of the following day (midnight UTC), at most 48 hours; never stored in our database, backups, or logs |
| Links between your request and our usage records (the daily visitor code and, if you accepted it, the cookie identifier) | Removed about a day after your request, normally within 27 hours (the record of your visit stays with your request) |
| Website usage records without a cookie identifier | 25 months, for trend analysis, then deleted; once the day’s salt is erased, their codes cannot be recalculated from your IP address and browser |
| Optional visitor cookie identifier | Removed from our records within 13 months of the first visit it was recorded with. When you send us a request, your browser gets a new identifier, and the old one is removed from our records about a day after the request is stored. The cookie itself expires within 13 months. |
| Demo and contact requests, with the linked visit record | 3 years after our last contact with you |
| Emails about your request, and our correspondence | As long as needed for our business correspondence with you; deleted when you ask us to delete your information |
| Meeting recordings, transcripts, and AI meeting notes | Deleted within 90 days of the meeting, unless we must keep them for a legal claim or investigation |
| Unsubscribe list | Kept as long as needed to honor your choice (stored as a one-way hash of your email address) |
| Records of privacy requests | 24 months |
| Analytics events and requests in transit (including your IP address and user-agent string) | Deleted once processed: normally within seconds, or when our database is back if it is paused; undelivered messages after 2 days |
| Hosting request logs (requests that send us data, such as form submissions) | 30 days (page loads and analytics requests are not logged) |
| Records of requests blocked by our firewall (suspected attacks and request-rate limits) | Up to 7 years, as security records |
| Platform security audit records (sign-ins and actions, with IP address and browser) | At least 7 years |
| Customer, contract, and billing records | For the relationship and as long as law and our record-keeping policies require |
| Business-contact and relationship records (from you, our customers, your colleagues, partners and other business contacts, or public professional sources) | Deleted 36 months after the last activity involving you, your connections, or an organization you are connected to, unless you are an active contact of one of our current customers, in which case we keep them while that relationship lasts; you can ask us to delete them sooner (see section 7). Records of changes to them in our security audit log are kept for at least 7 years; they name the details that changed, and older records can include the details themselves. Records of the materials we send to named people (who received, acknowledged, signed, or approved what, with notes) are kept as evidence and are not deleted on request |
| Partner payment and tax details, including taxpayer identification numbers | For the relationship and as long as tax law requires us to keep them |
When we delete information from our database or cut a link between records, encrypted backup copies hold the earlier state until they are replaced: we keep the 7 most recent daily backups, so normally for about 7 days. When we move our database to new infrastructure, we also keep the old database and its backups for a period after the move, and then a final copy of it in restricted, encrypted storage as evidence of the move until we no longer need it (the old database from our September 2026 move is being kept this way). These copies are not changed when we delete information.
7. Your rights and choices
Depending on where you live, you may have the right to know what personal information we hold about you and how we use it, to receive a copy (in a portable format where the law provides for one), to correct it, to delete it, to object to or restrict certain uses, and to withdraw consent. You can make these requests wherever you live, including about information we hold about you as a business contact, and we handle them as described below.
- To make a request, email douglask@trestlsolutions.com. We will confirm receipt, verify your request using information we already hold (usually by replying to the email address on record), and respond within 45 days, or sooner where the law that applies to you requires it (for example, one month under the GDPR or UK GDPR, and 30 days under Swiss law), or explain if we need longer as the law allows.
- Authorized agents may submit a request for you with your signed permission; we may ask you to confirm it.
- Appeals. If we decline your request, you may appeal by replying to our decision. We will respond to an appeal within the time your state’s law requires; if you are not satisfied, you may contact your state attorney general.
- No discrimination. We will not treat you differently for exercising your rights.
- Emails: every insights email includes an unsubscribe link.
- Cookies: use “Your privacy choices” in the website footer, or send a Global Privacy Control signal.
In the EEA, UK, or Switzerland you may also complain to your data protection authority, though we would welcome the chance to address your concern first.
8. Additional information for California residents
In the past 12 months we have collected the following categories of personal information, for the purposes in section 3:
| Category | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, work email, phone, postal address (partners we pay), IP address (hosting, security, and platform audit logs), optional cookie identifier | Service providers (hosting, email and meetings, code and work tracking; for partners we pay, banking and any tax-filing service); AI assistant providers; your organization (platform users’ account details and audit records); the customers we work with (business-contact records we keep under their organization); for partners we pay, tax authorities and the customer you referred (your name) |
| Professional information | Company, organization type, job title, professional profile links, working relationships | Service providers (hosting, email and meetings, code and work tracking); AI assistant providers; the customers we work with (title and role on business-contact records we keep under their organization); the customer you referred (partners we pay: commission rate) |
| Commercial information | The Trestl services you ask about or discuss with us, such as the area of interest in a request | Service providers (hosting, email and meetings, code and work tracking); AI assistant providers |
| Sensitive personal information | Taxpayer identification number (partners we pay), used for tax reporting | Service providers (hosting and any tax-filing service we use); AI assistant providers; tax authorities, as the law requires |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Bank account details (partners we pay), which you enter with our banking provider | Service providers (banking); AI assistant providers |
| Internet or network activity | Pages viewed and interactions on our website; sign-ins and actions in the platform | Service providers (hosting); AI assistant providers; your organization (platform users’ audit records) |
| Geolocation data | Country only, as reported by our hosting provider’s network (not a precise location) | Service providers (hosting); AI assistant providers |
| Audio, electronic, visual, or similar information | Recordings or transcripts of meetings, where a meeting note-taker or recorder is used with everyone’s agreement | Service providers (meetings); AI assistant providers |
We collect this information from you, from your device, from our customers, from your colleagues, partners, and other business contacts, and from publicly available professional sources. We have not sold or shared personal information, we do not knowingly collect the personal information of consumers under 16, and we do not use sensitive personal information for purposes that would require a right to limit.
9. Where information is processed
We are based in the United States. Our website and platform run in US Google Cloud regions, and our email, meetings, and documents are provided by Google Workspace. If you contact us from outside the United States, your information will be transferred to and processed in the United States, where data protection law may differ from the law where you live. Where the law requires a safeguard for personal information from the EEA, the UK, or Switzerland, we rely on the standard contractual clauses approved by the European Commission, with the UK and Swiss adjustments, which are part of our data processing terms with Google for Google Cloud and Google Workspace. The other providers named in section 5 process information under their own terms.
10. Security
We protect personal information with administrative, technical, and physical safeguards, including encryption in transit and at rest, role-based access controls, audit logging, and incident response procedures. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Our Security page describes our program.
11. Children
Our website and services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children. If you believe a child has given us personal information, email douglask@trestlsolutions.com and we will delete it.
12. Changes to this policy
We may update this policy as our practices or the law change. We will post the updated version here with a new “last updated” date and, for material changes, give additional notice on the website or by email where appropriate. If we want to use personal information we already hold in a materially different way from what this policy described when we collected it, we will ask for your consent where the law requires it.
13. Contact us
Trestl Health Solutions, LLC, Attn: Privacy, 149 Osborn St, Philadelphia, PA 19128. Email: douglask@trestlsolutions.com.