This page describes our current operational approach to security and data handling. It is maintained by Tandem DNA Marketing LLC and is not an independent certification or audit. We update this page as the product and our security program develop. Where details are still being formalized, we say so plainly.
Data we collect
TrainerDNA collects the account information you provide when creating a workspace, the business data you enter (such as leads, clients, payments, content notes), and information from third-party services you choose to connect. We do not collect data from services you have not connected.
Purpose of collection
We use the information you provide to operate the features visible to you in the app: organizing your business, surfacing actions that may need attention, and showing your business signals on your dashboard. We do not sell personal data.
Connected-service permissions
Each integration uses the provider's standard authorization flow. You see and approve the specific permissions before a connection is established. The integrations page on this site lists what each connection accesses and what it enables.
Account authentication
Accounts are created and authenticated through TrainerDNA's standard sign-up and sign-in flows. We recommend using a strong, unique password and enabling any account-protection options your email provider offers.
Data storage
TrainerDNA is hosted on established cloud infrastructure. Business data is stored in managed databases scoped to your workspace. Additional details about our hosting and infrastructure will be published here as our security program develops.
Encryption in transit
Traffic to trainerdna.com and the TrainerDNA application is served over HTTPS using current TLS standards offered by our hosting providers.
Employee and administrator access
Access to production systems is restricted to authorized personnel and used only for support, maintenance, and abuse-prevention purposes. Access to your workspace data is limited to what is necessary to operate the service or to respond to a request you initiate.
Third-party processors
TrainerDNA relies on established providers for hosting, authentication, email delivery, and payment processing. These processors operate under their own terms and security practices. We do not transfer customer data to providers other than those required to operate the service.
Data retention
We retain workspace data for as long as your account is active or as needed to provide the service. Specific retention and deletion behavior is governed by our Privacy Policy and Data Deletion documents linked below.
Account deletion
You can request deletion of your account and connection data at any time using the process described on our Data Deletion page.
Incident reporting
If we determine that an incident materially affects your data, we will notify affected users via the email associated with their account, in accordance with applicable law.
Responsible disclosure
We welcome reports of potential security issues. Please contact security@trainerdna.com with a clear description and reproduction steps. Please do not test against accounts that are not your own, and do not retrieve or expose data that does not belong to you.
Security contact
Report a potential security issue to security@trainerdna.com. For general support, use support@trainerdna.com.
Domain inboxes are configured progressively. If a security message does not receive a reply within five business days, please also email support.