Privacy policy
Last updated 21 September 2026
This explains what personal data Toastly holds, why, and who else touches it. The controller is Toastly, whose details are under Contact below.
Who is responsible for what
For your own account — your email address, your business details and your billing — we are the controller.
For your customers’ details — their names, addresses, contact details, visit notes and photographs — you are the controller and we are your processor. You decide what to record and how long to keep it. We only process it to run Toastly for you.
What we collect
From you: name, business name, email address, country, and the subscription and payment status Stripe reports back to us. We never see or store your card number.
From your use of the site and app: pages viewed, features used, and technical error reports. Cookies and local storage keep you signed in. On the signup pages and the page shown after checkout, and nowhere else, Meta’s pixel and Google’s advertising tag set their own cookies so we can tell which ads led to a signup; see Advertising measurement below, including how to opt out.
About your customers: whatever you enter, plus the payment status of their invoices. A customer opening a pay link, a quote or an autopay link is identified only by that link’s token.
Why we are allowed to hold it
To perform our contract with you, to meet our legal obligations such as keeping billing records, and for our legitimate interest in keeping the product working, secure and understood.
Who processes it for us
- SupabaseDatabase, authentication and file storage. The project is hosted in London.
- StripeSubscription billing for your Toastly plan, and payment processing for your customers on your own Stripe account.
- ResendSending email: sign-in links, invoices, reminders and receipts.
- PostHogProduct and marketing analytics, hosted in the EU.
- SentryError reporting from the app and from our server functions.
Each of these is bound by a data processing agreement. Where data leaves the UK or EEA it is transferred under the UK International Data Transfer Addendum or standard contractual clauses.
Advertising measurement
To learn which of our ads work, two advertising platforms receive events from the signup pages and the page shown after checkout, and from nowhere else on the site or in the app. Nothing about your customers is ever sent to either.
- MetaWhich ad led to a signup. Receives the signup step and the purchase with its amount, its own pixel cookies, the click id from the ad, your IP address, your browser’s user agent and your email address hashed with SHA-256, sent from your browser and again from our server so that each event counts once.
- GoogleWhich ad led to a signup. Receives the signup step, the checkout click and the purchase with its amount, each with a reference so it counts once, its own click id and cookie, and your email address hashed with SHA-256, from your browser on the signup pages and the page after checkout.
Both use what they receive under their own terms as well as their data terms with us. To opt out, turn on the Global Privacy Control setting in your browser, or install an extension that sends it: when your browser sends that signal we load neither tag, set no advertising cookie and send nothing about you to Meta or Google, from the browser or from our server, and nothing else changes. You can also email privacy@toastly.ai and we will delete the identifiers we hold.
How long we keep it
While your account is active, and for 90 days after cancellation so you can return or export. Billing records are kept for as long as tax law requires. Error reports are kept for 90 days.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Email privacy@toastly.ai and we will respond within one month. If you are not satisfied you can complain to the Information Commissioner’s Office at ico.org.uk.
If you are one of our users’ customers, contact that business directly: they decide what is held about you. We will help them act on your request.
United States
This section applies if you are in the United States. Where a US state privacy law gives you rights, the sections above describe the data and this section describes how to use those rights.
What we collect and why. The categories are the ones listed above: identifiers such as your name and email address, commercial information such as your plan and payment status, and internet activity such as the pages you use and the errors the app reports. We use them to provide Toastly, to bill you, to keep the service working and secure, and to measure our own advertising. We do not sell your personal information. We do share identifiers and internet activity with Meta and Google to measure our advertising, as described under Advertising measurement above, which California law treats as sharing for cross-context behavioral advertising; how to opt out is described there. We do not use or disclose sensitive personal information for any purpose other than providing the service.
Your customers’ bank details. When a customer sets up ACH Direct Debit, their bank account is verified and stored by Stripe on your Stripe account. Toastly holds only the last four digits, the bank name and the account type, so the app can name the method. Their authorization and its date are recorded so you can show it if asked.
Your rights. You can ask what personal information we hold about you, ask for a copy, ask us to correct or delete it, and you will not be treated differently for asking. Email privacy@toastly.ai and we will respond within 45 days. You can appeal a decision by replying to it. You may use an authorized agent; we will ask for proof that they act for you.
California notice. If you are a California resident, the paragraphs above are our notice at collection under the California Consumer Privacy Act. In the preceding twelve months we have shared identifiers and internet activity with Meta and Google for advertising measurement, and have not sold personal information. Your right to opt out of sharing is honored through the Global Privacy Control signal, which we treat as a valid opt-out request with no further steps and no difference in service, and by email as described above. We do not respond to the older “Do Not Track” signal.
Where the data lives. Our systems are hosted in the United Kingdom and the European Union, so your data is transferred out of the United States to be processed. The processors and the advertising platforms are the ones listed above, under the same agreements.
Children. Toastly is for businesses and is not directed at anyone under 16. If you believe a child has given us personal information, email us and we will delete it.
Your customers. If you are the customer of a business that uses Toastly, that business is responsible for your personal information. Contact them first; we will help them act on your request.
Changes
We will post changes here and, if they are material, email you before they take effect.
Contact
Toastly. Privacy questions: privacy@toastly.ai. Anything else: support@toastly.ai.