Legal
Privacy Policy
This Privacy Policy explains how toorow processes personal data when you visit our marketing website, register for the product, or connect your marketing data sources to the toorow platform.
We are a business-to-business marketing-data analytics product. We handle two very different kinds of data: a small amount of account data about the people who register with us, and the marketing and media data our customers choose to connect or send us so we can analyse it on their behalf. This draft describes both. It should be reviewed by qualified legal counsel before you rely on it.
Last updated: 23 July 2026
Who we are
toorow is a business-to-business marketing-data analytics product that connects your marketing sources, governs the business context behind every metric, and delivers cited reports to the AI host you already use.
For any privacy question, or to exercise the rights described below, contact us at privacy@toorow.com. The legal entity operating toorow, its registered address, and the identity of any appointed data protection contact will be confirmed in the final published version of this policy.
What data we process
Account data. When you register or join our mailing list, we process the identifiers you give us — such as your name, work email address, organisation, and the authentication and preference data needed to operate your account.
Customer data you connect. When you link a marketing source, we process the data returned by that source through a governed connector — for example advertising, analytics, and media-delivery metrics — under your instructions.
Data you send us by email. Where you use inbound file ingestion, you send files to a per-datastream address of the form ds_<token>@ingest.toorow.com. We process those files, and the sending metadata attached to them, to load the data into your datastream.
Usage and diagnostic data. We process technical logs and provenance records (such as which pull produced which data, freshness, and error events) so the platform is secure, auditable, and reliable. Cookies and website analytics are covered separately in our Cookie Policy at /cookies/.
Why we process it, and our legal basis
We process account data to provide the service you asked for and to manage our relationship with you — the legal bases are performance of a contract and our legitimate interest in running and securing the product.
We process customer data that you connect or send us as a processor acting on your documented instructions, so that we can deliver the analytics you configured. In that role the customer is the controller and determines the purposes.
We process mailing-list and marketing communications on the basis of your consent, which you can withdraw at any time.
Data residency
We operate toorow on European infrastructure. Our application database runs on Supabase in the eu-west-1 region, inbound email is handled by Mailgun on its EU infrastructure, our compute and storage run on Google Cloud in European regions (europe-west1 / EU multi-region), and our marketing website is served by Firebase Hosting (a Google service).
We design the platform so that customer marketing data stays within the European Union in normal operation. Any exception would be documented and handled under the transfer safeguards described below.
Sub-processors
We rely on a small set of vetted providers to run the service. Today these include Google Cloud (compute and storage) and Firebase Hosting (Google — marketing website hosting), Supabase (application database), Mailgun / Sinch (inbound and transactional email), Nango (managed OAuth connection handling for third-party sources), Klaviyo (mailing-list and marketing communications), and Sanity (content management for this website).
Each sub-processor is engaged under terms that require appropriate confidentiality and security. We will maintain an up-to-date list and give customers a way to be informed of changes.
Retention
We keep account data for as long as you have an account with us, and for a limited period afterwards where we need it to meet legal, accounting, or security obligations.
We keep customer data that you connect or send us for as long as your configuration requires it, and we delete or return it in line with your instructions and our agreement when it is no longer needed. Diagnostic and provenance logs are kept only as long as they are useful for security and reliability.
Your rights
If you are in the European Economic Area or the United Kingdom, you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to receive it in a portable format, to restrict or object to certain processing, and to withdraw consent where processing relies on it.
To exercise any of these rights over your account data, contact privacy@toorow.com. Where the data is customer data that another organisation connected as controller, we will refer your request to that organisation and support them in responding. You also have the right to lodge a complaint with your local supervisory authority.
International transfers
We aim to keep personal data within the European Union. If any processing ever involves a transfer to a country outside the EEA that does not benefit from an adequacy decision, we will put in place an appropriate safeguard — such as the European Commission’s Standard Contractual Clauses — before the transfer takes place.
Security
We protect data with encryption in transit and at rest, scoped access controls, and audit logging of credential use and data pulls. Source credentials are handled through delegated OAuth so that raw third-party tokens are not stored in our analytics database. No system is perfectly secure, but we work to reduce risk and to detect and respond to incidents.
Cookies
Our marketing website uses a small number of cookies and similar technologies. Strictly necessary cookies are always on; analytics and any future advertising cookies run only after you opt in. Full details, and the controls to change your choice, are in our Cookie Policy at /cookies/.
Changes to this policy
We may update this policy as the product and our processing evolve. When we make a material change we will update the “last updated” date above and, where appropriate, tell you directly. Please review this page periodically.
Contact
For any question about this policy or about how we handle personal data, contact privacy@toorow.com. The final published version will also name the operating entity and any appointed data protection contact.