01 Who we are
Triple S & M LLC is a privately held, diversified holding company registered in the State of New Mexico, United States. We are the data controller responsible for processing the personal data described in this policy.
1209 Mountain Road PL NE #4377
Albuquerque, NM 87110, USA
Privacy contact: privacy@triplesm.com
02 Brands and operations covered by this policy
Triple S & M LLC operates two principal business pillars. This policy applies to all products, websites, services and operations under both pillars.
Pillar 1 — Digital brands & technology
- Witrey Agency (witrey.com) — Full-service digital agency
- Gueswi (gueswi.com) — Omnichannel customer service SaaS platform
- Wihosters (wihosters.com) — Web hosting and cloud infrastructure
- TreyBoat (treyboat.com) — Digital platform
- Dolartrey (dolartrey.com) — Financial services and digital platform
- TreyBook (treybook.com) — Digital platform
- Wolotrey (wolotrey.com) — Digital platform
- Lottotrey (lottotrey.com) — Consumer-facing digital platform
Pillar 2 — Wholesale & distribution
- Amazon FBA wholesale operations
- B2B sourcing, distribution and e-commerce activities conducted by Triple S & M LLC
Any new brand, website, product or service launched by Triple S & M LLC will automatically be covered by this policy unless a separate policy is explicitly provided.
03 Data we collect
Depending on which brand or service you interact with, we may collect:
- Identification data: name, job title, company or organization
- Contact data: email address, phone number (including WhatsApp number), postal address
- Account data: username, password (hashed), account preferences
- Usage data: pages visited, actions taken, timestamps, device activity
- Messaging data: content of messages sent or received via WhatsApp Business, email, SMS, live chat and voice calls handled through our platforms
- Voice data: call recordings and transcripts when using voice-based services (e.g. Gueswi voice AI)
- Technical data: IP address, device type, browser, operating system, language
- Payment data: billing address and transaction metadata. Full card data is processed directly by Stripe; we do not store card numbers or CVV
- Business partner data (wholesale): supplier contact info, tax IDs, purchase orders, shipping and logistics information
- Communications with us: inquiries submitted via contact forms or email
04 Legal basis for processing (GDPR)
Where GDPR, UK GDPR or equivalent laws apply, we rely on one or more of the following legal bases:
- Contract (Art. 6(1)(b)): processing necessary to provide a service you contracted with us
- Consent (Art. 6(1)(a)): for optional marketing communications and non-essential cookies
- Legal obligation (Art. 6(1)(c)): tax, accounting, AML/KYC compliance
- Legitimate interest (Art. 6(1)(f)): service improvement, fraud prevention, network and information security
- Pre-contractual steps (Art. 6(1)(b)): when you request information before signing up
You have the right to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
05 How we use your data
We use data exclusively to:
- Provide, operate and personalize the services you have contracted
- Send messages via WhatsApp Business, email or SMS strictly related to the contracted service
- Manage accounts, sessions, billing and customer support
- Improve our products using aggregated and anonymized usage data
- Comply with legal, tax and regulatory obligations
- Protect against fraud, abuse, or security threats
- Manage business relationships with suppliers, distributors and commercial partners (wholesale operations)
06 WhatsApp Business & Meta
Several of our products — notably Gueswi, Witrey Agency and TreyBoat — integrate the WhatsApp Business Platform provided by Meta Platforms, Inc.
When you communicate with any of our brands via WhatsApp:
- Messages are routed through Meta's infrastructure under Meta's own Terms and Privacy Policy
- We only initiate contact with phone numbers you have voluntarily provided, and only for the business purpose you consented to
- We use Meta-approved message templates for business-initiated conversations
- You may revoke consent at any time by replying "STOP" (or an equivalent opt-out) to any of our messages; we will stop sending messages promptly
When you message one of our brands through WhatsApp, both Meta and Triple S & M LLC act as independent data controllers for their respective purposes. Meta's privacy practices are governed by Meta's own privacy policy, available at meta.com.
07 Third-party service providers (subprocessors)
We rely on selected third parties to operate our services. Each has its own privacy practices:
Messaging & communications
- Meta Platforms, Inc. — WhatsApp Business API
- Twilio, Inc. — telephony, SMS, voice infrastructure
- VAPI — voice AI orchestration
- Postmark — transactional email delivery
- Resend — transactional email delivery (alternate)
Artificial intelligence
- Anthropic, PBC — Claude language models
- OpenAI, OpCo LLC — GPT language models
- ElevenLabs — text-to-speech
Payments & identity
- Stripe, Inc. — payment processing (PCI DSS Level 1)
- Didit — identity verification (KYC)
Cloud & infrastructure
- Contabo GmbH — VPS hosting
- Neon, Inc. — managed PostgreSQL database
- Google LLC — Maps and Calendar APIs
This list may evolve as our services change. Material updates will be reflected in this policy. A complete and current list of subprocessors is available on request for B2B customers.
08 B2B customers — controller vs. processor
Certain products — notably Gueswi — are SaaS platforms used by business customers to communicate with their own end-users. In those scenarios:
- As a Controller, Triple S & M LLC processes the personal data of our B2B customer's account holders (signup, billing, platform usage, support)
- As a Processor, Triple S & M LLC processes personal data of our B2B customer's end-users on behalf of, and strictly under the documented instructions of, that B2B customer, who remains the Controller of such data
Our B2B customers are responsible for the lawful basis of collecting and processing their end-users' data and for informing those end-users as required by applicable law. A separate Data Processing Agreement (DPA) is available on request for B2B customers.
09 International data transfers
Triple S & M LLC is established in the United States. When you use our services from outside the United States — including the European Economic Area (EEA), the United Kingdom, Switzerland, or Latin America — your personal data may be transferred to, and processed in, the United States or in other countries where our subprocessors operate.
For transfers from the EEA, UK or Switzerland, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Addendum where applicable
- Supplementary technical, contractual and organizational measures
- Your explicit consent where appropriate
10 Data retention
We retain personal data only as long as necessary:
- Active account data: duration of the service + 12 months after termination
- Demo / trial sessions: 48 hours to 30 days depending on the product
- WhatsApp and messaging logs: up to 36 months, unless longer retention is required by law or by the B2B customer
- Voice call recordings and transcripts: up to 12 months, unless configured otherwise by the B2B customer
- Billing and tax records: 7 years, as required by US tax law
- Audit and security logs: 36 months
- Wholesale and supplier records: duration of business relationship + 7 years for tax compliance
After these periods, data is permanently deleted or irreversibly anonymized.
11 Security
We apply industry-standard technical and organizational measures, including:
- TLS 1.2+ / HTTPS encryption for all data in transit
- Encryption at rest for sensitive databases
- Salted password hashing (bcrypt / argon2)
- Session tokens with automatic expiration
- Principle of least privilege for internal access
- Access logging and event auditing
- Encrypted backups with controlled retention
- Documented incident response procedures
Despite these measures, no system is 100% secure. If a data breach occurs that is likely to result in a risk to your rights, we will notify you and the competent authorities within the timeframes required by applicable law.
12 Your rights
Subject to applicable law, you have the following rights:
Under GDPR / UK GDPR (EEA and UK users)
- Access, rectification, erasure, restriction, portability, objection
- Withdrawal of consent at any time
- Right to lodge a complaint with a supervisory authority
Under CCPA / CPRA (California residents)
- Right to know what personal information is collected and how it is used
- Right to delete personal information
- Right to opt-out of "sale" or "sharing" (we do not sell or share personal information for cross-context behavioral advertising)
- Right to limit the use of sensitive personal information
- Right to non-discrimination for exercising any of these rights
To exercise any of these rights, write to privacy@triplesm.com from the email address associated with your account. We respond within 30 calendar days (GDPR) or 45 days (CCPA), extendable by an additional period where permitted by law.
13 Children's privacy
Our services are not directed to children under the age of 16, and we do not knowingly collect personal information from children under 16 (or under 13 for purposes of the US Children's Online Privacy Protection Act, "COPPA").
If you are a parent or guardian and believe that a child has provided personal data to us, please contact privacy@triplesm.com and we will promptly delete the data.
14 Business partners and wholesale operations
In connection with our wholesale and Amazon FBA operations, we maintain business relationships with:
- Product suppliers, manufacturers, distributors and brand owners
- Logistics providers, freight forwarders and third-party warehouses (3PL)
- Online marketplaces (including Amazon) and e-commerce platforms
- Accountants, auditors and legal counsel
In the course of these relationships, we process contact details, tax identification numbers (EIN, VAT, RFC, NIT), bank and payment information, and order and shipping data. The legal basis is contractual necessity and legitimate interest. This data is retained for the duration of the business relationship plus applicable tax retention periods (typically 7 years in the US).
We do not share business partner data outside what is strictly necessary to operate the relationship.
15 Cookies and similar technologies
Our websites use:
- Strictly necessary cookies — session, authentication, security, load balancing. Cannot be disabled
- Functional cookies — preferences such as language selection. Can be disabled in your browser
- First-party analytics — to understand how visitors use our websites. No third-party trackers
We do not use third-party advertising cookies or cross-context behavioral tracking. You can manage cookies via your browser settings. Note that disabling strictly necessary cookies will break core functionality.
16 Changes to this policy
We may update this policy from time to time. When we make material changes, we will notify you through the service, by email, or by prominent notice on our websites. The date of the last update is always shown on this page. Continued use of our services after an update constitutes acceptance of the updated policy.
17 Governing law and jurisdiction
This Privacy Policy is governed by the laws of the State of New Mexico, United States of America, without regard to conflict-of-law principles. Nothing in this policy overrides mandatory rights you may have under the consumer-protection laws of your jurisdiction.
18 Contact
Data controller:
Albuquerque, NM 87110
United States
Privacy officer: privacy@triplesm.com