TMC555BUSINESS MANAGEMENT SOLUTIONS

Privacy Policy

TMC555, LLC respects your privacy. This policy explains what information we collect on tmc555.com and through our services, why we collect it, who we share it with, and the control you have over it.

Effective
July 20, 2026
Last updated
July 20, 2026
Governing law
Wyoming, USA

01

Scope of this policy

This policy covers personal information handled by TMC555, LLC(“TMC555,” “we,” “us”) when you visit tmc555.com, contact us, engage us for consulting or development work, or pay us. It applies to prospective clients, clients, and site visitors.

It does not cover third-party websites we link to, or systems belonging to your own vendors that we may configure on your behalf. Where we handle personal data belonging to your customers as part of an engagement, Section 11 applies.

02

Information we collect

2.1 — Information you give us

CategoryExamples
Contact detailsName, email address, company name, phone number if you provide it
Inquiry contentThe message you submit through our contact form, and any documents or business details you send us by email
Engagement informationBusiness goals, systems inventory, operational details and other information shared during a consulting or development engagement
Billing detailsBilling name, business address, billing email, tax identifiers where required for invoicing
Account credentialsAccess you delegate to us for third-party systems, held only for the duration of the engagement

2.2 — Information collected automatically

CategoryExamples
Device and connectionIP address, browser type and version, operating system, screen size, referring URL
UsagePages viewed, time on page, clicks, scroll depth, and the path taken through the Site
Session replayAnonymized recordings of mouse movement, clicks and scrolling on the Site, and aggregate heatmaps (see Section 07)
Security logsRequest logs kept by our hosting provider for abuse prevention and diagnostics

2.3 — What we do not collect

We do not collect Social Security numbers, government identification numbers, health information, biometric data, or precise geolocation. We do not knowingly collect information from children. We never receive or store your full payment card number or CVV — see Section 03.

03

Payment information & Stripe

3.1 — Stripe processes our payments

All payments to TMC555 are processed by Stripe, Inc., a payment processor certified to PCI DSS Service Provider Level 1 — the most rigorous certification level in the payments industry. Your card details are entered directly into Stripe’s secure fields and are transmitted to Stripe, not to our servers.

3.2 — What we receive

  • Your name and billing email address
  • Billing country, postal code and business address where provided
  • The transaction amount, currency, date, description and status
  • The card brand and last four digits, and the payment method type
  • A Stripe customer and payment identifier used to reconcile invoices
  • Fraud signals such as the IP address and risk score associated with the transaction

3.3 — What we never receive or store

Full card numbers, CVV/CVC security codes, PINs, full bank account numbers, and card authentication credentials are never transmitted to or stored on TMC555 systems.

3.4 — How payment data is used

Solely to process and confirm your payment, issue receipts and invoices, maintain accounting and tax records, service subscriptions and refunds, investigate disputes and chargebacks, and detect fraud. We do not use payment data for advertising or profiling, and we do not sell it.

3.5 — Stripe’s own terms

Stripe processes your data as an independent controller for fraud prevention and legal compliance under its own Privacy Policy. For questions about a specific charge, contact us first at hello@tmc555.com; for issues with Stripe’s processing infrastructure you may also contact support.stripe.com.

04

How we use information

  • Respond to inquiries and prepare proposals, estimates and statements of work.
  • Deliver the consulting, integration, development and subscription services you engage us for.
  • Invoice you, process payments and refunds, and keep accurate financial records.
  • Provide support, communicate about your engagement, and send service and security notices.
  • Operate, secure, debug and improve the Site and our services.
  • Detect, investigate and prevent fraud, abuse and unauthorized access.
  • Comply with tax, accounting, and other legal obligations, and establish or defend legal claims.
  • Send occasional business updates where you have asked for them — every such email has a one-click unsubscribe, and unsubscribing never affects service communications.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it to train third-party AI models.

06

How we share information

We share personal information only with service providers who process it on our instructions, and only as needed to run the business:

RecipientPurpose
Stripe, Inc.Payment processing, invoicing, subscription billing and fraud screening
Vercel Inc.Website hosting, content delivery and request logging
Supabase, Inc.Database, authentication and file storage for our applications
Formspree, Inc.Delivery of contact-form submissions to our inbox
Microsoft Corporation (Clarity)Site analytics, heatmaps and anonymized session replay
Email and productivity providersBusiness correspondence and document delivery
Accountants and legal advisorsTax filing, audit and legal advice, under professional confidentiality duties
Tax and regulatory authoritiesWhere required by law
Law enforcementOnly in response to valid legal process, and narrowly scoped

If TMC555 is involved in a merger, acquisition or sale of assets, personal information may transfer to the successor entity; we will notify affected clients and the successor remains bound by this policy or a policy at least as protective. We never sell, rent or trade personal information for marketing.

07

Cookies & analytics

7.1 — What we use

The Site uses a small number of strictly necessary cookies for security and basic operation, and Microsoft Clarity for analytics. Clarity sets first-party cookies to distinguish sessions and records anonymized interaction data — clicks, scrolling, mouse movement and page performance — which we use to find usability problems and broken pages.

7.2 — What Clarity does not capture

Clarity masks text input by default: keystrokes entered into form fields, including the contact form, are not recorded. We do not use Clarity, or any other analytics tool, for advertising or to build marketing profiles. Microsoft processes this data under its own privacy statement.

7.3 — Your choices

You can block or delete cookies in your browser settings, and enable Global Privacy Control or Do Not Track — we honor GPC signals as opt-out requests where applicable law requires. Blocking analytics cookies does not affect your ability to use the Site or contact us.

08

How long we keep information

DataRetention period
Contact-form inquiries that do not become engagements24 months, then deleted
Client engagement records and deliverablesDuration of the engagement plus 7 years
Invoices, payment and tax records7 years minimum, as required for tax and accounting compliance
Subscription account data after cancellationExportable for 30 days, then deleted or anonymized
Site analytics and session replayRetained by Microsoft Clarity for up to 13 months
Server and security logsUp to 12 months

We delete or anonymize information once it is no longer needed for the purpose it was collected for, unless a longer period is required by law or to resolve an ongoing dispute.

09

How we protect information

  • All traffic to and from the Site is encrypted in transit with TLS.
  • Client data at rest in our databases is encrypted, with row-level access controls limiting who can read what.
  • Payment card data never touches our infrastructure — it is handled by Stripe's PCI Level 1 environment.
  • Access to client systems and credentials is limited to personnel who need it for an active engagement, is stored in an encrypted secrets vault, and is revoked when the engagement ends.
  • Administrative accounts require multi-factor authentication.
  • We keep dependencies patched and run automated security scanning against our infrastructure.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any required regulator without undue delay and within the timeframes applicable law requires. If you believe your information has been compromised, contact hello@tmc555.com immediately.

10

Your privacy rights

Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate information; request deletion; obtain a portable copy; object to or restrict certain processing; withdraw consent; and opt out of sale or sharing — which does not apply here, because we do neither.

To exercise any of these rights, email hello@tmc555.com. We will verify your request through the email address on file and respond within 30 days (45 days where permitted, with notice). We will never deny you service, charge a different price, or provide a lesser quality of service because you exercised a privacy right.

Some information is subject to mandatory retention — financial and tax records in particular — and cannot be deleted on request until the statutory period ends. We will tell you if that applies to your request and what we are retaining. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

11

Client data we process on your behalf

During an engagement we may access or process personal data belonging to your customers, employees or contacts — for example, when we migrate a CRM, configure a booking system or build an integration. For that data, you are the controller and TMC555 is a processor.

  • We process such data only on your documented instructions and only for the engagement.
  • We do not use it for our own purposes, and never to train AI models.
  • We apply the security measures in Section 09 and bind our subprocessors to comparable obligations.
  • We assist you in responding to data-subject requests that reach us through your systems.
  • On termination we return or delete the data at your direction, subject to legal retention obligations.

Where your compliance program requires one, we will sign a Data Processing Agreement — request it at hello@tmc555.com.

12

International transfers

TMC555 operates in the United States, and our providers store and process data in the United States. If you access the Site or engage us from outside the United States, your information is transferred to and processed in the United States, which may have different data-protection laws than your country. Where required for transfers from the EEA, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, which our providers incorporate in their agreements with us.

13

Children's privacy

Our Site and services are directed to businesses and are not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact hello@tmc555.com and we will delete it promptly.

14

Changes to this policy

We will update this policy as our services and providers change. The “Last updated” date at the top of this page reflects the current version. For material changes affecting how we use information about active clients, we will notify you by email at least thirty (30) days before the change takes effect.

15

Contact us

TMC555, LLC
TMC555, LLC · 737 Huntington Ave · Boston, MA 02115 · United States
hello@tmc555.com — privacy requests, billing questions and general inquiries

We respond to privacy inquiries within two (2) business days of receipt.

Questions? Email hello@tmc555.com or write to TMC555, LLC · 737 Huntington Ave · Boston, MA 02115 · United States.

Terms of ServicePrivacy PolicyRefund & Cancellation PolicyContact