Privacy Policy
Last Updated: July 2, 2026
This Privacy Policy describes how Bigstrider Inc. d/b/a Transcodes (“Transcodes,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects information in connection with:
- the website located at transcodes.io and related pages, and
- Transcodes-hosted scripts, SDKs, APIs, and authentication/security services embedded or integrated by customers (collectively, the “Services”).
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, do not access or use the Services.
1. Scope and Roles
This Privacy Policy applies to:
- website visitors,
- account holders and customer administrators,
- end users interacting with customer applications that integrate Transcodes components.
Data Protection Roles
- For end-user data processed through customer applications, the customer is typically the controller/business, and Transcodes acts as processor/service provider.
- For account, billing, security, and operational data related to our direct relationship with users/customers, Transcodes acts as controller/business.
- Customers are solely responsible for providing legally required privacy notices and obtaining required consents for their own end users where applicable.
2. Definitions
- Personal Data: Information relating to an identified or identifiable natural person.
- Usage Data: Technical and telemetry data (e.g., IP address, device/browser metadata, request paths, timestamps, event logs, diagnostics).
- Customer Data: Data submitted to or processed through the Services by or on behalf of a customer.
- Sensitive Data: Data subject to heightened legal protections under applicable law.
3. Categories of Data We Collect
Depending on context, configuration, and use of the Services, we may collect the categories of information described below. The scope of information we may collect, generate, retain, analyze, or otherwise process in connection with the Services is not limited by subscription plan, membership tier, pricing level, or whether you use a free, trial, standard, premium, or other offering. Plan and tier distinctions may affect which product features, capacity limits, or commercial entitlements are available to you, but they do not, by themselves, restrict the categories of operational, security, audit, telemetry, authentication, automation-related, or improvement-related information we may collect where such information arises through your access to or use of the Services, except where mandatory law requires otherwise or where a separate written agreement expressly states a different rule.
Account and Profile Data
Name, email address, organization, role, profile image, country/region, account identifiers.
Authentication, Security, Audit, and Operational Context
In the ordinary course of providing the Services, we collect and maintain information relating to account access, authentication, authorization, security monitoring, and platform activity. This may include login and verification events, passkey and WebAuthn-related metadata, multi-factor authentication activity, session and risk signals, anti-abuse indicators, and audit or activity logs generated when users, administrators, integrations, or automated actors interact with the Services. Depending on how the Services are configured, deployed, and used, such records may be associated with additional technical and contextual information that helps us understand when, how, and from what environment relevant events occur, including information that may relate to network origin, client or device characteristics, application or host context, and general or approximate location signals where such information is generated, transmitted, inferred, or otherwise available in connection with the event. The detail or visibility of certain product features may vary by plan or configuration, but the underlying categories of information described in this Privacy Policy may still be collected across plans where relevant to operation, security, audit, or improvement of the Services, and we may retain, correlate, aggregate, analyze, or otherwise process such information for purposes including security, fraud prevention, compliance, incident response, service reliability, product development, analytics, and continuous improvement of the Services.
Technical, Usage, and Telemetry Data
We may also collect technical and usage information generated through ordinary interaction with our website, console, APIs, SDKs, hosted components, and related tooling, including network and connection data, device and browser characteristics, language and locale settings, referral information, page and event interactions, diagnostic and error information, and performance or reliability metrics, together with any other telemetry that may reasonably arise in connection with operation of the Services.
AI Agents, Automation, and Programmatic Use
Where the Services are used with, through, on behalf of, or in connection with AI agents, coding assistants, autonomous tools, plugins, integrations, or other automated or semi-automated systems, we may collect, generate, receive, store, or derive information relating to those interactions as part of operating, securing, monitoring, and improving the Services. Such information may concern the identity or metadata of the agent, tool, integration, workspace, or execution environment involved, the actions, requests, commands, evaluations, permissions, approvals, denials, or outcomes associated with those interactions, and any surrounding operational, session, audit, diagnostic, or contextual information that may accompany or be linked to them in practice. We may use this information to evaluate platform behavior, refine security and governance features, support research and development, improve reliability and accuracy, and enhance the Services and related offerings over time, and the scope of what is collected in this area may evolve as the Services change and should be understood broadly to include information reasonably related to agent-connected or automated use of the platform.
Commercial and Transaction Data
Billing contacts, subscription details, invoice metadata, and limited payment metadata from payment processors.
Support and Communication Data
Support tickets, communications, feedback, and service-related correspondence.
Cookies and Similar Technologies
Cookies, local storage, pixels, tags, and related tracking technologies.
Information You Voluntarily Provide
Any data submitted via forms, onboarding, support channels, or integrations.
We do not knowingly collect children’s data where prohibited by law.
4. Legal Bases for Processing
Where required by law (including GDPR/UK GDPR), we process Personal Data under one or more of these bases:
- performance of a contract,
- compliance with legal obligations,
- legitimate interests (including security, fraud prevention, service reliability, and improvement),
- consent (where legally required),
- establishment, exercise, or defense of legal claims.
5. How We Use Data
We use collected data to:
- provide, operate, maintain, and improve the Services;
- authenticate users and enforce access controls (including passkeys, RBAC, session controls, and logging);
- detect, prevent, investigate, and remediate fraud, abuse, and unauthorized access;
- process subscriptions, billing, and account administration;
- provide support and essential service communications;
- perform analytics, diagnostics, monitoring, and quality assurance;
- satisfy legal, regulatory, tax, accounting, and compliance obligations;
- enforce contractual rights and protect legal interests.
Service Improvement, Analytics, and Consent by Use
We may analyze, correlate, aggregate, de-identify, or otherwise process information collected through the Services in order to understand patterns of use, evaluate product performance, detect anomalies, prioritize development, refine security controls, and improve the overall quality, reliability, security, and usefulness of the Services and related products. This may include information relating to who accessed or attempted to access the Services and in what capacity, session and account identifiers and the duration, timing, sequence, or frequency of activity, user or member profile and organizational context where relevant to an event, device and client characteristics, browser or application environment, network origin and connection context, general or approximate location-related signals where available or inferable from technical data, timestamps and temporal metadata associated with actions or events, audit and activity records, policy or enforcement outcomes, and information relating to AI agents or other automated use, together with any other operational, security, or telemetry information that may reasonably arise in connection with providing, securing, or improving the Services.
Because many of these processing activities are closely connected to how the Services operate in practice, certain collection and use may occur automatically when you register for an account, enable integrations, deploy hosted components, or otherwise access or continue using the Services, regardless of subscription plan or membership tier, and the descriptions in this Privacy Policy are intended to be read in a broad and inclusive manner to the extent permitted by applicable law, subject only to any narrower interpretation that mandatory law may require in a particular jurisdiction. The categories, sources, methods, and purposes of collection and use described in this Privacy Policy, including in this section and elsewhere, may be updated, expanded, or otherwise modified from time to time as the Services evolve, and you should review this Privacy Policy periodically for such changes.
To the fullest extent permitted by applicable law, by creating an account, continuing to access the Services, or using any feature that generates operational, security, audit, automation-related, or improvement-related records, you acknowledge that such information may be collected and used as described in this Privacy Policy and you implicitly agree to that collection and use for service operation, security, analytics, research, development, and improvement purposes, including as those descriptions may change over time to the extent permitted by applicable law. Your continued use of the Services after any update to this Privacy Policy may constitute continued implicit agreement to the revised terms of collection and use where permitted by law. If you do not agree, you should not register for or continue using the Services and should discontinue use promptly, recognizing that ceasing use is the appropriate way to withdraw from this operational framework subject to any retention obligations described elsewhere in this Privacy Policy or required by law. Nothing in this section is intended to override separate consent requirements that may apply where mandatory law requires a distinct legal basis for particular processing activities.
We do not sell Personal Data for monetary consideration.
6. Security and Embedded Scripts
We apply commercially reasonable technical and organizational safeguards, including measures such as encryption in transit, access controls, monitoring, and security logging.
Transcodes delivers embedded scripts/components intended for lawful security and authentication use. We do not intentionally include malicious code designed to damage systems, create unauthorized backdoors, or unlawfully access customer databases.
No system is absolutely secure. The Services are not guaranteed to be uninterrupted, error-free, or immune from all threats.
No Liability; Customer-Controlled Environment
To the fullest extent permitted by applicable law, Transcodes assumes no responsibility and shall have no liability for customer-side implementation, configuration, permissioning, policy decisions, infrastructure, or operational practices.
This includes, without limitation, vulnerabilities or incidents caused by customer code, third-party code, credential compromise, endpoint compromise, network misconfiguration, or other systems outside Transcodes’ reasonable control.
7. Data Sharing and Disclosure
We may disclose data to:
- hosting, cloud, analytics, monitoring, communication, and payment vendors acting as service providers/subprocessors;
- affiliates and corporate group entities;
- legal, accounting, audit, and other professional advisors;
- law enforcement, regulators, courts, or authorities where required by valid legal process or law;
- counterparties in mergers, acquisitions, financing, reorganization, bankruptcy, or asset transfers.
We require appropriate confidentiality and data-protection obligations where applicable.
8. Third-Party Services Disclaimer
The Services may integrate with third-party tools, plugins, SDKs, payment processors, analytics services, hosting providers, and external platforms. Their data practices are governed by their own policies and terms.
To the maximum extent permitted by law, Transcodes bears no liability for third-party acts, omissions, downtime, breaches, data handling, or security failures outside Transcodes’ direct control.
9. International Data Transfers
Your information may be processed in jurisdictions different from your own. Where legally required, we implement recognized transfer safeguards (including contractual protections and supplementary measures as appropriate).
10. Data Retention and Deletion
We retain Personal Data and other information only for as long as we reasonably consider necessary for providing the Services, maintaining security and operational integrity, meeting legal and compliance obligations, resolving disputes, enforcing our agreements, and pursuing the other purposes described in this Privacy Policy. Retention periods may vary by data type, legal requirements, backup systems, and the nature of the information involved, and we may retain aggregated, de-identified, or otherwise transformed information for lawful business purposes even after underlying records are deleted or anonymized where permitted by law.
Deletion upon request. Subject to applicable law, you may request deletion of Personal Data we hold about you in our role as controller or in connection with your direct relationship with Transcodes. Upon receiving a verifiable request, we will take reasonable steps to delete such information from our active systems, or to de-identify or anonymize it where full deletion is not immediately practicable, except where retention is permitted or required by law, regulation, legal process, dispute resolution, fraud prevention, security, backup and disaster recovery practices, or the establishment, exercise, or defense of legal claims. Deletion may not be instantaneous and may not extend to information we are required to retain, information contained in archived backups for a limited period, information we must preserve to comply with legal obligations, or information relating to end users of a customer’s application where the customer, rather than Transcodes, is the controller and the request should be directed accordingly. Where we act only as processor/service provider for customer-controlled data, we will assist the customer as required by applicable law and any applicable DPA, but the customer’s instructions and legal obligations may govern the outcome of such requests.
11. User Rights
Subject to applicable law, data subjects may have rights to access, rectify or correct, delete, restrict processing, object, portability, withdraw consent where applicable, and lodge complaints with a competent supervisory authority. We may verify identity before responding and may deny or limit requests where permitted by law, including where we must retain information for legal, security, accounting, audit, backup, or dispute-related reasons, or where we process the information solely on behalf of a customer that acts as controller.
If you wish to exercise a deletion or other privacy right relating to information we control directly, you may contact us using the details in Section 19. We will review and respond to eligible requests within the timeframes required by applicable law, and where deletion is granted we will handle it in accordance with Section 10, recognizing that complete erasure from all systems, backups, logs, or derived records may not always be immediately or fully achievable except where mandatory law requires a different result.
12. Cookies and Tracking Technologies
We use cookies and related technologies for:
- essential functionality,
- security and fraud prevention,
- service performance and analytics,
- session continuity and preferences.
Where legally required, we request consent for non-essential cookies. Disabling cookies may affect functionality.
The Services may not respond to “Do Not Track” signals unless explicitly stated otherwise.
13. Customer Obligations
Customers represent and warrant that they have lawful basis to collect and share data with Transcodes, provide required notices and obtain required consents, configure Services in compliance with law and internal policies, and handle end-user rights requests when acting as controller/business, including deletion, access, and correction requests directed to the customer rather than to Transcodes where the customer controls the underlying data. Customers are solely responsible for their own application behavior, content, and business decisions.
14. Incident Response and Operational Logs
We may collect, generate, retain, and use operational logs — including audit records, security events, authentication and authorization traces, integration activity, and associated contextual metadata such as IP address, device or client characteristics, and location-related signals where available — for security monitoring, abuse detection, troubleshooting, incident investigation, legal compliance, enforcement of platform rules, and improvement of the Services. The content and retention of such logs may vary by feature, configuration, and legal requirement, and may be interpreted broadly to include information reasonably related to the events being logged.
15. Limitation of Liability (Privacy-Related Claims)
To the maximum extent permitted by law, the Services are provided on an “as is” and “as available” basis, without warranties except as expressly required by applicable law or written agreement.
To the fullest extent permitted by law:
- Transcodes disclaims liability for indirect, incidental, special, consequential, exemplary, or punitive damages;
- Transcodes is not liable for loss of profits, revenue, goodwill, business opportunities, or data arising from or related to privacy/security events not directly caused by Transcodes’ gross negligence or willful misconduct;
- any aggregate liability shall not exceed the liability cap set forth in the applicable Terms of Service, Order Form, or other governing agreement.
Except where prohibited by law, Transcodes shall have no liability beyond the contractually agreed limits.
16. Changes to This Privacy Policy
We may update this Privacy Policy at any time. Updates will be posted on this page with a revised “Last Updated” date. Where appropriate, we may provide additional notice through the Services.
Continued use of the Services after an update becomes effective constitutes acceptance of the updated Privacy Policy to the extent permitted by law. Where required, renewed consent will be requested.
17. California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Opt-Out: You have the right to opt-out of the sale or sharing of your personal information. We do not sell personal information as defined by CCPA.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of sensitive personal information.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your privacy rights.
Categories of Personal Information Collected: As described in Section 3 of this Privacy Policy.
How to Exercise Your Rights: To exercise any of these rights, including deletion, please contact us at hello@bigstrider.co. We will verify your identity before processing your request and will handle eligible deletion requests in accordance with Section 10, subject to exceptions permitted by law. Plan or tier level does not determine whether information may have been collected, but your statutory rights, where applicable, remain available regardless of plan.
Do Not Sell or Share My Personal Information: We do not sell or share personal information for cross-context behavioral advertising purposes.
18. Governing Documents and Claims
This Privacy Policy should be read together with the Terms of Service, Data Processing Addendum (if applicable), and any executed commercial agreement. In case of conflict, the governing agreement controls to the extent permitted by law.
Any claim related to this Privacy Policy is subject to the dispute resolution, venue, arbitration, class-action waiver, indemnity, warranty disclaimer, and limitation-of-liability provisions in the governing agreement, except where prohibited by law.
19. Contact
For privacy-related inquiries: hello@bigstrider.co