TonnaBaseTerms of Service

Privacy Policy

Version 2026-09-15-draft · effective September 15, 2026

Draft, pending review by counsel. It describes what the Service does today.

What we collect

Your name, work email, company and role when you request access or are invited; your password (stored only as a hash by our authentication provider) and your authenticator enrolment; the pages you open and when (to enforce the inactivity sign-out and to understand which parts of the record are used); a hash of your network address on the request form, to limit abuse; and anything you enter into the Service yourself.

What we do with it

We use it to run your seat, to keep the Service secure, to answer you, and to bill your organisation. We do not sell it, and we do not use one subscriber’s inputs to produce anything shown to another subscriber.

Who else sees it

Our hosting and authentication providers (Vercel, Supabase), our email provider (Resend) and, for paid subscriptions, our payment provider — each only to provide their service to us. Card details go to the payment provider directly and never reach our servers.

Public record about people

The Service records the names and public roles of elected and appointed officials, and of company officers and registered agents, exactly as they appear in public filings, with the source cited. If a record about you is wrong, tell us and we will check it against the source.

Keeping and deleting

Account data is kept while the seat exists and for a short period after, then deleted except where the law requires longer. Your own inputs are deleted on request within thirty days. Page-view records are kept for twelve months.

Your choices

You can change your name, password and second factor in Settings, remember or forget a device, and ask us for a copy or deletion of your data at chad@tonnabase.com.