LEGAL

Privacy Policy

Last updated: August 26, 2026

1. Who this policy covers

This policy explains how FomoToast handles information when you visit fomotoast.com, create an account at app.fomotoast.com, connect a website or commerce integration, or load a FomoToast notification on a customer website. Businesses that install FomoToast are responsible for their own privacy notices and for having a lawful basis to send customer activity to FomoToast.

2. Information we collect

  • Account information: name, email address, password credential, email-verification status, sessions, and workspace membership.
  • Website configuration: website name and URL, display paths, theme choices, Toast messages, and integration settings.
  • Commerce activity: the event type, customer name, country or location when supplied by the provider, product name, quantity, amount, currency, and event time. FomoToast does not put customer email addresses or payment details in the public website payload.
  • Visitor analytics: a random browser identifier stored in local storage, its keyed pseudonymous hash, page path, page-view identifier, and Toast impressions, hovers, and clicks. We do not store visitor IP addresses for this metering.
  • Billing information: plan, purchase status, Stripe customer, Checkout Session, and Payment Intent identifiers. Stripe processes card details; FomoToast does not store them.
  • Support communications: messages and account details you send when asking for help.

3. How we use information

We use this information to operate and secure accounts, verify email addresses, reset passwords, connect commerce sources, publish Toasts on the websites you configure, calculate analytics, enforce plan limits, process purchases and refunds, answer support requests, prevent abuse, and maintain the service.

4. Local storage and consent

The install script uses fomotoast:visitor, a randomly generated local-storage value, to count a browser once per calendar month. A website can load the script with storage disabled or call window.FomoToast.consent(false) to remove that value. In storage-free mode, a fresh per-page identifier is used for plan metering and cannot link the visitor across page loads; as a result, separate page loads may each count as a visitor. The website owner is responsible for presenting any consent choice required by local law.

5. Retention

  • Raw Toast interaction telemetry is kept for 30 days.
  • Commerce source events are kept for 90 days.
  • Pseudonymous monthly visitor records are kept for four months so the 90-day analytics range remains accurate.
  • Daily aggregate Toast metrics are kept for 13 months.
  • Account, configuration, integration, and billing records are kept while the account or legal obligation remains active. Deleting an account removes workspaces where that user is the only member; shared workspaces remain for their other members.

Backups and fraud, tax, dispute, or legal records may persist for a limited additional period where reasonably necessary.

6. Service providers and transfers

FomoToast uses Cloudflare for edge hosting, queues, security, and transactional email; Neon for PostgreSQL hosting; Stripe for payments and Stripe connections; and connected WooCommerce stores for order events. These providers process data under their own terms and may handle it in countries other than yours. Integration credentials are encrypted before storage.

7. Sharing and sale

We share information with service providers only to operate FomoToast, with workspace members according to their access, when you direct us to connect a provider, or when required to protect rights, comply with law, or complete a business transfer. We do not sell personal information or use customer activity for third-party advertising.

8. Security

We use encrypted transport, hashed passwords, encrypted integration credentials, signed webhook verification, scoped workspace access, and Cloudflare infrastructure controls. No system is perfectly secure, so please use a unique password and report suspected account compromise promptly.

9. Your choices and rights

You can update your password, revoke other sessions, disconnect integrations, and delete your account from Settings. Depending on where you live, you may also request access, correction, deletion, restriction, portability, or an objection to processing. Email privacy@fomotoast.com. We may need to verify your identity before completing a request.

10. Children

FomoToast is a business service and is not directed to children. Do not submit information about children through commerce events or Toast messages.

11. Changes

We may update this policy as the service changes. The updated date will appear at the top, and material changes will be communicated through the service or by email where appropriate.

12. Contact

Questions about privacy can be sent to privacy@fomotoast.com.