Privacy Policy
TMC555, LLC respects your privacy. This policy explains what information we collect on tmc555.com and through our services, why we collect it, who we share it with, and the control you have over it.
- Effective
- July 20, 2026
- Last updated
- July 20, 2026
- Governing law
- Wyoming, USA
01
Scope of this policy
This policy covers personal information handled by TMC555, LLC(“TMC555,” “we,” “us”) when you visit tmc555.com, contact us, engage us for consulting or development work, or pay us. It applies to prospective clients, clients, and site visitors.
It does not cover third-party websites we link to, or systems belonging to your own vendors that we may configure on your behalf. Where we handle personal data belonging to your customers as part of an engagement, Section 11 applies.
02
Information we collect
2.1 — Information you give us
| Category | Examples |
|---|---|
| Contact details | Name, email address, company name, phone number if you provide it |
| Inquiry content | The message you submit through our contact form, and any documents or business details you send us by email |
| Engagement information | Business goals, systems inventory, operational details and other information shared during a consulting or development engagement |
| Billing details | Billing name, business address, billing email, tax identifiers where required for invoicing |
| Account credentials | Access you delegate to us for third-party systems, held only for the duration of the engagement |
2.2 — Information collected automatically
| Category | Examples |
|---|---|
| Device and connection | IP address, browser type and version, operating system, screen size, referring URL |
| Usage | Pages viewed, time on page, clicks, scroll depth, and the path taken through the Site |
| Session replay | Anonymized recordings of mouse movement, clicks and scrolling on the Site, and aggregate heatmaps (see Section 07) |
| Security logs | Request logs kept by our hosting provider for abuse prevention and diagnostics |
2.3 — What we do not collect
We do not collect Social Security numbers, government identification numbers, health information, biometric data, or precise geolocation. We do not knowingly collect information from children. We never receive or store your full payment card number or CVV — see Section 03.
03
Payment information & Stripe
3.1 — Stripe processes our payments
All payments to TMC555 are processed by Stripe, Inc., a payment processor certified to PCI DSS Service Provider Level 1 — the most rigorous certification level in the payments industry. Your card details are entered directly into Stripe’s secure fields and are transmitted to Stripe, not to our servers.
3.2 — What we receive
- Your name and billing email address
- Billing country, postal code and business address where provided
- The transaction amount, currency, date, description and status
- The card brand and last four digits, and the payment method type
- A Stripe customer and payment identifier used to reconcile invoices
- Fraud signals such as the IP address and risk score associated with the transaction
3.3 — What we never receive or store
Full card numbers, CVV/CVC security codes, PINs, full bank account numbers, and card authentication credentials are never transmitted to or stored on TMC555 systems.
3.4 — How payment data is used
Solely to process and confirm your payment, issue receipts and invoices, maintain accounting and tax records, service subscriptions and refunds, investigate disputes and chargebacks, and detect fraud. We do not use payment data for advertising or profiling, and we do not sell it.
3.5 — Stripe’s own terms
Stripe processes your data as an independent controller for fraud prevention and legal compliance under its own Privacy Policy. For questions about a specific charge, contact us first at hello@tmc555.com; for issues with Stripe’s processing infrastructure you may also contact support.stripe.com.
04
How we use information
- Respond to inquiries and prepare proposals, estimates and statements of work.
- Deliver the consulting, integration, development and subscription services you engage us for.
- Invoice you, process payments and refunds, and keep accurate financial records.
- Provide support, communicate about your engagement, and send service and security notices.
- Operate, secure, debug and improve the Site and our services.
- Detect, investigate and prevent fraud, abuse and unauthorized access.
- Comply with tax, accounting, and other legal obligations, and establish or defend legal claims.
- Send occasional business updates where you have asked for them — every such email has a one-click unsubscribe, and unsubscribing never affects service communications.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it to train third-party AI models.
05
Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (delivering services you ordered and billing for them); legitimate interests (site security, fraud prevention, service improvement, and responding to business inquiries); legal obligation (tax and accounting retention); and consent (optional analytics and marketing email, which you may withdraw at any time).
08
How long we keep information
| Data | Retention period |
|---|---|
| Contact-form inquiries that do not become engagements | 24 months, then deleted |
| Client engagement records and deliverables | Duration of the engagement plus 7 years |
| Invoices, payment and tax records | 7 years minimum, as required for tax and accounting compliance |
| Subscription account data after cancellation | Exportable for 30 days, then deleted or anonymized |
| Site analytics and session replay | Retained by Microsoft Clarity for up to 13 months |
| Server and security logs | Up to 12 months |
We delete or anonymize information once it is no longer needed for the purpose it was collected for, unless a longer period is required by law or to resolve an ongoing dispute.
09
How we protect information
- All traffic to and from the Site is encrypted in transit with TLS.
- Client data at rest in our databases is encrypted, with row-level access controls limiting who can read what.
- Payment card data never touches our infrastructure — it is handled by Stripe's PCI Level 1 environment.
- Access to client systems and credentials is limited to personnel who need it for an active engagement, is stored in an encrypted secrets vault, and is revoked when the engagement ends.
- Administrative accounts require multi-factor authentication.
- We keep dependencies patched and run automated security scanning against our infrastructure.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any required regulator without undue delay and within the timeframes applicable law requires. If you believe your information has been compromised, contact hello@tmc555.com immediately.
10
Your privacy rights
Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate information; request deletion; obtain a portable copy; object to or restrict certain processing; withdraw consent; and opt out of sale or sharing — which does not apply here, because we do neither.
To exercise any of these rights, email hello@tmc555.com. We will verify your request through the email address on file and respond within 30 days (45 days where permitted, with notice). We will never deny you service, charge a different price, or provide a lesser quality of service because you exercised a privacy right.
Some information is subject to mandatory retention — financial and tax records in particular — and cannot be deleted on request until the statutory period ends. We will tell you if that applies to your request and what we are retaining. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
11
Client data we process on your behalf
During an engagement we may access or process personal data belonging to your customers, employees or contacts — for example, when we migrate a CRM, configure a booking system or build an integration. For that data, you are the controller and TMC555 is a processor.
- We process such data only on your documented instructions and only for the engagement.
- We do not use it for our own purposes, and never to train AI models.
- We apply the security measures in Section 09 and bind our subprocessors to comparable obligations.
- We assist you in responding to data-subject requests that reach us through your systems.
- On termination we return or delete the data at your direction, subject to legal retention obligations.
Where your compliance program requires one, we will sign a Data Processing Agreement — request it at hello@tmc555.com.
12
International transfers
TMC555 operates in the United States, and our providers store and process data in the United States. If you access the Site or engage us from outside the United States, your information is transferred to and processed in the United States, which may have different data-protection laws than your country. Where required for transfers from the EEA, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, which our providers incorporate in their agreements with us.
13
Children's privacy
Our Site and services are directed to businesses and are not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact hello@tmc555.com and we will delete it promptly.
14
Changes to this policy
We will update this policy as our services and providers change. The “Last updated” date at the top of this page reflects the current version. For material changes affecting how we use information about active clients, we will notify you by email at least thirty (30) days before the change takes effect.
15
Contact us
TMC555, LLC
TMC555, LLC · 737 Huntington Ave · Boston, MA 02115 · United States
hello@tmc555.com — privacy requests, billing questions and general inquiries
We respond to privacy inquiries within two (2) business days of receipt.
Questions? Email hello@tmc555.com or write to TMC555, LLC · 737 Huntington Ave · Boston, MA 02115 · United States.
Terms of ServicePrivacy PolicyRefund & Cancellation PolicyContact