Skip to main content

Privacy and storage

Privacy and storage.

This notice separates browser storage from information recorded on Trillo's servers when you enquire, create an account, request a quote or continue through a customer workflow.

Effective: 2 August 2026Version: public-privacy-2026-08-02

Scope

Public and customer-facing flows.

The browser-storage inventory below covers this public website, public checkout and customer-facing flows, the sign-in page, and the named email-connection cookies.

Authenticated operational workspaces can keep additional interface preferences and working records. Those internal workspace records are outside this public-browser inventory, but personal information held on Trillo's servers is addressed below.

Server-side records

Information created when you continue.

Simply reading a public page is different from sending an enquiry or proceeding through a customer workflow.

Enquiries and contact details

A rental, sales or contact enquiry can record the name, phone number, email address, message, selected vehicle and source page supplied with it. These details let the Trillo team identify and answer the request.

Trip, quote and booking records

Checkout and reservation workflows can record the vehicle, journey dates, collection details, pricing, customer details and the resulting quotation, reservation or booking reference.

Account and security records

Sign-in and customer-account workflows use identity, account, session and security records to authenticate access, apply tenant permissions, protect public forms and investigate failed or unusual activity.

Documents and payment status

Where the applicable workflow requests them, the application can keep verification documents, quotations, agreements, invoices and payment references or status. A selected payment provider processes the payment step under its own service and privacy terms.

Use, access and retention

The purpose follows the workflow.

Why records are used

To answer enquiries, prepare quotes, check and administer requested bookings, support account access and security, process the selected payment workflow, supply documents and maintain the related operational record.

Who may receive them

Authorised Trillo workspace users can access records needed for their work. Relevant information can also pass to providers used for hosting, email delivery, document storage or the payment method you select.

How long they remain

The application does not publish one duration for every server-side record. Retention depends on the enquiry, account or transaction lifecycle and applicable operational, security, dispute and recordkeeping needs. Ask for information about a specific record.

Advertising and analytics

No advertising or analytics trackers are currently loaded on the public website. Essential storage is not presented as optional marketing consent.

Verified browser record

Five public/customer-facing storage purposes.

Duration and removal depend on the purpose described for each record.

01

Signed-in sessions

Session cookies

The session cookie carries the signed-in workspace session. The separate client_session cookie carries a client-portal session. Both are HTTP-only, use SameSite Lax, and are marked Secure in production. The client-portal session is issued for 24 hours; the workspace session uses the expiry returned by the sign-in process.

02

Connection checks

Temporary OAuth state

When an authenticated user starts a Google or Outlook email connection, google_auth_state or outlook_auth_state is set as an HTTP-only cookie for up to one hour. It is marked Secure in production and is used to match the connection response to the request that started it.

03

Current browser tab

Checkout progress

sessionStorage under the key trillo-checkoutholds the selected vehicle, trip and pricing fields, customer details entered into checkout, and a reservation response when one exists. This storage belongs to the browser tab's session.

04

Your device

Remembered sign-in email

The sign-in page uses localStorage under uxlogic.login.rememberEmail when “Remember my email” is selected. Turning that selection off removes the stored email. Passwords are not placed in this key.

05

Notice state

Storage-notice acknowledgement

Selecting “Understood” on the site-storage notice writes trillo.public.storage-notice.v1 to localStorage. It records that the notice was acknowledged so it does not need to appear on every visit. If browser storage is blocked, the notice can be dismissed for the current page but may appear again later.

Control and requests

Ask about information linked to you.

Who controls the customer record

Trillo Rentals operates this customer-facing website and determines how rental, sales-enquiry and booking records in its tenant workspace are handled. The contact page is the request channel for information submitted through this website.

Access, correction and deletion requests

You can ask what information is held about you, request a correction, or ask for deletion or restriction. Trillo may need to verify your identity and may need to retain a record for an active transaction, security, dispute or recordkeeping requirement. If a request cannot be completed, ask for the reason.

Security and shared devices

No internet service can promise absolute security. Do not send passwords, PINs, one-time codes or card security codes through an enquiry. On a shared device, sign out and use browser controls to remove cookies, sessionStorage and localStorage. Removing checkout storage also removes progress kept in that browser tab.

Changes to this notice

This notice is effective 2 August 2026. Material updates should be shown by changing the effective date and version at the top of this page.