Privacy Policy
Effective 2026-08-20
This Privacy Policy explains what Toastfield (“we,” “us”) collects through Toastfield Outreach (the “Service”), why, and what control you have over it. It covers both Service users (people who sign in and use the product) and leads (the businesses our users contact through the Service). See Section 6 if you’re the latter.
1. Information we collect
Account information: email address, display name, and profile photo (from Google sign-in, if you use it), and your role within your workspace.
Workspace information: your workspace name, sending domain, uploaded logo/branding, and plan/usage data. If you connect a mailbox, we store your SMTP/IMAP server address and credentials so the Service can send and receive email on your behalf. See Section 4 on how these are protected.
Lead and campaign data: the businesses you discover or import (name, category, phone, website, email, address), and the campaign content, sends, and replies associated with them.
Usage and security records: an audit log of sensitive actions (who did what, when, from what IP address), kept for security and support purposes.
Cookies: a single first-party session cookie used to keep you signed in. We don’t use third-party advertising or analytics trackers.
2. How we use information
- To operate the Service: authenticate you, run your campaigns, and enforce your plan’s limits;
- To enforce compliance safeguards, such as suppression-list checks and unsubscribe processing;
- To provide support and investigate abuse or security issues;
- To communicate with you about your account (service emails, not marketing, unless you separately opt in).
3. How we share information
We do not sell your data. We share it only with:
- Google Cloud / Firebase: our infrastructure provider for the database and, for Google sign-in, identity verification;
- Your own mail provider: sending and receiving happens through the SMTP/IMAP mailbox you connect, not a shared relay we operate;
- Law enforcement or other parties, if required by law or to protect the rights and safety of the Service and its users.
4. Data security
Data is stored in Google Cloud Firestore, encrypted at rest, and accessed only through server-side code, never a client application talking directly to the database. Mailbox credentials are stored per-workspace and are never shown to any other workspace. No system is perfectly secure, and we can’t guarantee absolute security.
5. Data retention
We keep account and workspace data for as long as your workspace is active. Audit and security logs are kept indefinitely for accountability. You can delete individual leads, campaigns, and outreach records at any time from the product; to delete an entire workspace, contact us at legal@toastfield.com.
6. If you’re a lead, not a user
If you received an email from an Toastfield Outreach customer, your business contact information (found via public sources like OpenStreetMap, or supplied by the sender) is being processed by that customer, who is responsible for the content and legality of their outreach to you. Toastfield Outreach is the platform they used to send it. Every email sent through the Service carries a working unsubscribe link; clicking it immediately and permanently suppresses future sends to that address from that workspace. To request removal from our underlying lead database entirely, contact legal@toastfield.com with the email address and the sender’s workspace name (from the email footer).
7. Your rights and choices
Depending on where you’re located, you may have rights to access, correct, or delete your personal information, or to object to certain processing. To exercise these rights, contact legal@toastfield.com. We’ll respond within a reasonable time and may need to verify your identity first.
8. Children’s privacy
The Service is intended for business use by adults and is not directed at children under 16.
9. International data transfers
Our infrastructure provider may process and store data in regions other than your own. Where required, we rely on appropriate safeguards, such as standard contractual clauses, to protect data transferred internationally. By using the Service, you consent to this transfer.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes require every workspace to re-accept before continuing to use the Service, the same as changes to our Terms of Service.
11. Contact
Questions about this policy: legal@toastfield.com, 1500 Harbor Bay Pkwy, Suite 220, Alameda, CA 94502.