At Transfilio, we believe transparency is the foundation of trust. This policy explains how we collect, use, and protect your data.
Welcome to Transfilio (transfilio.com). Transfilio is a business-to-business (B2B) file transfer platform operated by Transfilio, Inc. ("Transfilio," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our application, or engage with our services.
By accessing or using Transfilio, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this policy, please do not access or use our services.
This policy applies to all users of Transfilio, including workspace administrators, team members, and recipients of shared files. For enterprise customers with custom data processing agreements, those agreements will take precedence where applicable.
We collect information necessary to provide, maintain, and improve our file transfer services. The types of information we collect include:
Important: We process file content as needed to store and deliver transfers. Access is limited by account authorization and the controls configured on each share link.
We use the information we collect for the following purposes:
To provide, operate, and maintain our file transfer platform, including processing uploads, managing shares, and delivering files to recipients.
To understand how our services are used, identify trends, and improve the user experience, performance, and reliability of our platform.
To send transactional emails (transfer notifications, security alerts), respond to support requests, and provide service updates.
To detect and prevent fraud, abuse, and unauthorized access. To enforce our Terms of Service and comply with legal obligations.
To process subscription payments, manage invoices, and handle billing-related inquiries through our payment processor (Stripe).
To generate aggregated, anonymized analytics that help us understand usage patterns and deliver workspace usage dashboards to administrators.
We take the security of your data seriously and employ industry-leading measures to protect it at every stage of processing.
Storage Controls
Files are stored in the local or S3-compatible backend selected by the deployment. Storage-provider safeguards depend on that configuration.
HTTPS in Transit
Production browser and API traffic uses HTTPS. The deployment edge manages certificate and protocol negotiation.
Deployment Boundaries
Application, database, background jobs, and file storage are separated behind explicit service boundaries.
Application Controls
Two-factor authentication, login lockout, rate limits, audit events, and configurable retention protect common workflows.
Additional measures include role-based authorization, audit events, API-key hashing and rotation, share-link access controls, and configurable cleanup. Passwords are hashed using bcrypt and never stored in plaintext.
We retain your information only as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements.
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 30 days after deletion request |
| Transferred files | Per your plan settings (7-90 days), or until manually deleted |
| Usage & analytics data | 24 months, then aggregated or anonymized |
| Billing records | 7 years (as required by tax and accounting regulations) |
| Audit logs | 12 months (or longer for enterprise compliance plans) |
| Support communications | Duration of account + 12 months after closure |
When data reaches the end of its retention period, it is securely deleted or irreversibly anonymized. Enterprise customers may negotiate custom retention schedules via their Data Processing Agreement (DPA).
Transfilio operates globally, and your information may be transferred to, stored, and processed in countries other than the one in which you reside. These countries may have data protection laws that are different from those in your jurisdiction.
When we transfer personal data across borders, we implement appropriate safeguards to ensure your information remains protected:
File and account data are stored in the region selected by the operator's deployment. Contact support before uploading if a particular storage location is required.
Depending on your location, you may have certain rights regarding your personal information. We respect and facilitate these rights regardless of where you are based.
Under the General Data Protection Regulation
Under the California Consumer Privacy Act
To exercise any of these rights, please contact us at privacy@transfilio.com. We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA). We will never discriminate against you for exercising your privacy rights.
Transfilio is a business-to-business service and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information promptly.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@transfilio.com and we will work to remove it from our systems.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:
Your continued use of Transfilio after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, we encourage you to reach out. Our privacy team is committed to addressing your inquiries promptly.
Privacy Inquiries
privacy@transfilio.comGeneral Support
support@transfilio.comWebsite
transfilio.comFor GDPR-related inquiries, you also have the right to lodge a complaint with your local Data Protection Authority (DPA) if you believe your data protection rights have been violated.