Privacy Policy
Last updated: September 20, 2026
This Privacy Policy explains how Trailing Comma, Inc., a company incorporated in Delaware, USA, doing business as Jsonify ("Jsonify", "we", "us", or "our"), collects, uses, and protects personal data when you visit our website or use our platform, products, APIs, and Services (collectively, the "Services"). Our operations are run from Lisbon, Portugal; our postal address is in Section 13.
This Privacy Policy applies to:
- Visitors to our website;
- Users of the Jsonify platform;
- Representatives of customers, partners, and vendors;
- Individuals whose data may be incidentally collected during Jsonify’s online data collection.
1. Roles and Scope
Depending on the context:
- Jsonify acts as a data controller for personal data relating to website visitors, customer accounts, billing, communications, platform administration, and the data Jsonify collects for its own business purposes.
- Jsonify acts as a data processor when processing data (including personal data) on behalf of self-serve customers through customer-configured pipelines, under the Data Processing Addendum.
- Where a signed agreement with a customer sets out different roles, that agreement governs for the processing it covers.
This distinction is important under applicable data protection laws, including the EU General Data Protection Regulation ("GDPR").
2. Personal Data We Collect
2.1 Data You Provide Directly
We may collect the following categories of personal data:
- Name, email address, company name, role, and contact details;
- Account credentials and authentication information;
- Billing and payment information;
- Communications with us (emails, support requests, feedback);
- Any information you voluntarily submit through forms or correspondence.
2.2 Data Collected Automatically
When you use the Services or visit our website, we may automatically collect:
- IP address;
- Device, browser, and operating system information;
- Usage data, logs, timestamps, and interaction metadata;
- Cookies and similar technologies (see Section 8).
2.3 Data Collected from Public Websites and Apps
Jsonify collects publicly available commercial data from websites and mobile apps — product listings, prices, availability, menus, and similar information — to build datasets for its customers. Jsonify may also collect public commercial data to build datasets it offers to more than one customer; such datasets are built from Jsonify’s own pipelines, not from rows delivered to a customer. This collection targets products and services, not people.
Personal data can be incidentally included in what a public page shows: for example, a username attached to a product review. Where that happens:
- What is collected: the content the public page displays, such as review text, a display name or username, a rating, and a date;
- Where from: the public websites and apps configured in the relevant pipeline;
- Who receives it: the customer that commissioned the dataset, and the subprocessors listed on our subprocessors page that host and process data on our behalf;
- How long: for as long as the dataset it belongs to remains in service for the relevant customer or use case, after which it is deleted or refreshed; see Section 6.
Raw fetched content may be cached for a limited period and shared across pipelines so that sources are requested fewer times; that cache describes pages, and rows built from it go only to the customer that commissioned them. In most cases this data does not enable Jsonify to identify individuals directly. Collection targets commercial fields, reads only public content, and pipelines may not be used to profile individuals; removal requests are honoured. Pseudonymisation and filtering of personal-data fields can be configured into a pipeline. To ask about or object to data collected about you, see Section 7 and our privacy request form.
2.4 Customer-Provided Data Processed via the Services
Our business customers may configure our Services to process data sourced from third-party websites or documents. Such data may include personal data.
In this context:
- The customer determines the purpose and means of processing;
- Jsonify processes such data solely on the customer's documented instructions.
3. How We Use Personal Data and on What Lawful Bases
If you are a website visitor or a platform user, we process your analytical data to operate our website and platform and ensure its stability and availability. We rely on our legitimate interest in providing a functional Service.
We may also measure traffic on our service, determine the source of visits, evaluate the effectiveness of our marketing campaigns, and personalize the ads you may encounter on the web. In these cases, we rely on your consent. To do so we may use cookies and similar technologies (see Section 8).
If you are a user of our platform or a representative of customers, partners, and vendors, we may process your personal data to: provide, operate, and maintain the Services; manage accounts, authentication, and billing; communicate with you; and provide customer support. In such cases, we rely on the performance of the contract between Jsonify and you.
We may send product news and marketing to business contacts based on our legitimate interest; you can opt out at any time. Requests to Jason and pipeline configurations are processed by large language models operated by our subprocessors; messages and emails from Jason are generated by AI.
We also work towards improving and securing our Services and preventing fraud, abuse, or security incidents. In such cases, we rely on our legitimate interest to improve the operation of our Services, their functionality, and their security, as well as to protect our legitimate interests, such as safeguarding our databases and our information systems.
When we collect public commercial data as described in Section 2.3, we may incidentally collect personal data. Collection targets commercial fields and reads only public content, and removal requests are honoured. These operations are carried out based on our legitimate interest in operating a data-collection service for business customers.
We may also have to process any of your personal data to comply with our legal obligations; for example, in response to an administrative authority or court order, or a request by you or your representative to exercise your rights.
We do not use customer data to train models, create aggregated datasets from customer data, or for unrelated commercial purposes. Jsonify may generate de-identified, aggregated operational metrics about the Services (such as source counts and repair statistics) that do not reveal customer data or personal data.
Jsonify owns its pipeline code, including extractors, and technical knowledge of website and app structures. Extractors built on credentials a customer supplies are not reused for other customers. These platform assets exclude customer schemas, source lists, rows delivered to customers, credentials, personal data and confidential business information. This ownership distinction does not change our processing instructions or data-protection obligations. See Customer Data and Platform Ownership.
4. Data Sharing and Disclosure
We may share personal data with:
- Service providers and subprocessors (hosting, payment processing, analytics, support tools, and the large-language-model providers described in Section 9) — see our subprocessors page;
- Customers, where personal data is incidentally included in a dataset collected for them (see Section 2.3);
- Professional advisers (legal, accounting);
- Authorities where required by law.
Subprocessors are bound by contractual obligations to protect personal data and act only on our instructions.
We do not sell personal data.
5. International Data Transfers
Trailing Comma, Inc. is incorporated in Delaware, USA, and operates internationally. Personal data may be processed in the United States and in the European Economic Area.
Where required, we rely on appropriate safeguards for international transfers, such as adequacy decisions or Standard Contractual Clauses approved by the European Commission. You can request a copy of these safeguards by emailing us at paul@jsonify.com.
6. Data Retention
We retain your personal data only for as long as is necessary for the purposes for which it was collected:
- Account and business-contact data is retained for the duration of our contractual relationship, and for up to 3 years after the relationship ends where we have an ongoing business-development interest;
- Billing records are retained as long as applicable accounting law requires (up to 10 years in some jurisdictions);
- Payment data is retained as long as needed to process the payment and handle disputes, and no longer than applicable payment regulations require;
- Website and platform analytics data is retained for a maximum of 13 months from collection;
- Public commercial data collected for datasets, including incidental personal data, is retained for as long as the dataset remains in service, and is deleted or refreshed when it no longer is; incidental personal data is not kept independently of its dataset.
7. Your Rights
Depending on your location and the applicable circumstances, you may have rights including:
- Right of access: to obtain confirmation that your data is being processed and to receive a copy of it.
- Right to rectification: to request the correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): to request the deletion of your data.
- Right to restriction of processing.
- Right to data portability: to receive your data in a structured, commonly used, and machine-readable format.
- Right to object: to object to the processing of your data based on our legitimate interest.
- Right to withdraw consent: at any time, when processing is based on your consent.
- In France, the right to set instructions regarding the handling of your data after your death.
- Right to lodge a complaint with a supervisory authority — in the EU, the data protection authority of your member state (in Portugal, the CNPD); in the UK, the Information Commissioner's Office.
If you believe information relating to you has been included in datasets we collect from public sources, submit a request through our privacy request form or the contact details below. Provide enough information to identify the relevant data — for example a username, the website concerned, or other context. We will take reasonable steps to determine whether your personal data is being processed and respond within one month, extendable where the law allows, in accordance with our role as controller or processor. Where a customer controls the data, we may refer your request to them and will tell you when we do.
8. Cookies and Analytics
Our website uses cookies and similar technologies for:
- Operation: keeping the site and platform functional and secure;
- Analytics: measuring traffic and usage (Google Analytics, PostHog);
- Advertising: measuring campaigns and personalising ads (Google Ads);
- Visitor identification: recognising business visitors for sales outreach (Apollo).
Non-essential tags load only after you accept them in the cookie banner, and only on our public hostnames. You can change your choice at any time through the "Cookie settings" link in the page footer, or control cookies through your browser settings.
9. Security and Service Providers
Security. We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and logging. No system is perfectly secure; we will notify affected parties of personal-data breaches as applicable law requires.
Credentials. Account authentication is handled by our identity provider. Where an enterprise agreement provides for source credentials, they are stored encrypted, used only for the agreed collection, and never shared across customers.
Connected AI assistants. When you connect an assistant to Jsonify, the connector returns information needed for your requests from the organisations you authorise: organisation name; workspace names and identifiers; pipeline, dataset, run and conversation identifiers; pipeline status and schedules; row counts and allowance or run estimates; dataset schemas and the dataset rows you request; Jason replies and prepared briefs; and links, pagination and action-confirmation tokens. During onboarding it also returns the private preparation token described below. Dataset rows may contain personal data collected from your chosen sources. Your assistant provider receives these tool responses and processes them under its own terms and privacy policy. We do not return account passwords, OAuth access or refresh tokens, stored source credentials or payment details in connector tool results.
AI assistant onboarding tokens. When you prepare a brief through a connected AI assistant, Jsonify returns a private preparation_token and conversation identifier to that assistant, including the token in the signup link. This token is a random possession proof scoped to that onboarding conversation, not a password, API key or OAuth access or refresh token, and it is not signed. Possession allows access to the preparation and transfer into browser signup, so keep the token and link private. The token expires after 24 hours if the preparation remains unclaimed; after it creates a workspace, access requires the authenticated workspace owner. MCP requests separately require OAuth sign-in. Jsonify stores a hash of the random secret to verify the token. The assistant provider receives the token as part of the tool response and processes it under its own terms and privacy policy.
Language models. Jsonify uses third-party large language models to build and repair pipelines. Content from configured sources may be processed by these providers as subprocessors, under terms that do not permit them to train models on it. See the subprocessors page.
10. US State Privacy Rights
Residents of certain US states (including California) may have rights to know, access, correct, and delete personal information, and to opt out of sales or sharing of personal information. Jsonify does not sell personal information of its website visitors or platform users. For data we process on customers' behalf, we act as a service provider under our Data Processing Addendum. To exercise these rights, use the contact details below; we will not discriminate against you for doing so.
11. Children's Data
The Services are for business use and are not directed to anyone under 18. We do not knowingly hold personal data of children as account holders, and our terms prohibit collecting personal data relating to children.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised "Last updated" date, and material changes affecting account holders are notified by email.
13. Contact Us
If you have questions or requests regarding this Privacy Policy or personal data processing, please contact:
Trailing Comma, Inc. (d/b/a Jsonify)
1111b South Governors Avenue
Dover, DE 19904, United States
Email: paul@jsonify.com