Back to ToastTi

Legal document · Private Pilot

Privacy for Private Pilot operations.

A plain-language privacy overview for ToastTi's Private Pilot workspace, connected marketplaces, operational records, logs, sessions, sharing boundaries, and legal-review status.

This privacy page is a current beta overview, not final legal advice. It should be reviewed by qualified counsel before broader customer rollout.

01

Data collected

ToastTi may collect account, organization, marketplace connection, inventory, listing, order, pricing, warehouse, support, billing-readiness, usage, and log data needed to run the current beta product.

02

Account data

Account data can include names, email addresses, authentication identifiers, organization membership, roles, permissions, invitations, and login/session state.

03

Marketplace connection data

Marketplace data can include provider account metadata, sync timestamps, capability evidence, connection status, and read/write readiness state for Shopify, StockX, and GOAT/Alias.

04

Provider tokens stored encrypted

Connected-account credentials and provider tokens are intended to be stored encrypted server-side. Public pages should never ask for or display provider secrets.

05

Operational inventory and order data

ToastTi workspaces may store products, stock items, images, SKUs, sizes, conditions, costs, listings, orders, sale reconciliation records, warehouse locations, bins, receiving records, pick/pack state, reports, and activity history.

06

Usage and log data

ToastTi may record application events, audit logs, sync activity, safety-gate decisions, support requests, browser-safe diagnostic metadata, usage-fee estimates, and billing-readiness evidence.

07

Cookies and sessions

ToastTi uses first-party cookies for authentication, session continuity, idle-timeout controls, and beta access. Authentication cookies use SameSite=Lax and HTTPS-only delivery in production. Browser storage is used for limited interface preferences; ToastTi does not use this beta application for advertising tracking.

08

Data sharing

ToastTi does not use public legal pages to sell operational data. Data may be shared with service providers needed for hosting, authentication, payments, support, and marketplace integrations when configured.

09

Network and sharing workflows

ToastTi Network and wholesale-style workflows are opt-in or private by default. Sellers control selected inventory sharing and should avoid publishing sensitive cost or provider evidence to buyers.

10

Exports and access

Signed-in organization owners and authorized administrators can generate redacted organization exports after a recent-session security check. Exports are generated on demand, scoped to the current organization, logged, and sent with private no-store cache controls.

11

Deletion and privacy requests

A signed-in user can submit an account deletion request from Settings. The request creates an audited support case; it does not automatically delete an account or organization data. ToastTi support must verify the requester and determine applicable retention or legal obligations before destructive work.

12

Imports and support attachments

CSV inventory imports are parsed in the browser and limited to CSV-compatible file types and 2 MB. Support tickets currently accept text and safe diagnostic labels only; file attachments are not uploaded. Users should never include passwords, cookies, access tokens, or customer-sensitive records in support text.

13

Service providers

ToastTi may use configured providers for hosting, authentication and database services, error monitoring, payments, email, and marketplace connections. Those providers receive only the data needed for the enabled feature. Marketplace credentials and tokens are stored in encrypted server-side fields and are redacted from exports and support output.

14

Retention and contact path

Operational and audit records are retained while needed for the Private Pilot, security, support, accounting, and legal obligations. Final production retention periods are not yet published. Privacy or data-handling questions should start through the Contact page or the signed-in support workflow.