Privacy policy
Last updated 14 August 2026
The short version: we hold your name, your email, and daily totals calculated from the accounts you choose to connect. We do not sell anything to anyone, we do not use your business data to train models, and you can have all of it deleted by asking.
Who is responsible
Throughline is operated by [company name not set] , [registered address not set]. For anything in this policy, write to privacy@analyzebusinessdata.com.
For data you upload or connect, we are a processor acting on your instructions; you remain the controller of your own customers’ data. For your account itself — your name, your email, your billing record — we are the controller.
What we collect
Three things, and nothing else.
- Your account. Name, email address, a bcrypt hash of your password (never the password), and the times you signed in. If you sign in with Google or Microsoft we store the provider’s identifier for you, not their password.
- What you connect. Read-only credentials for the services you link, encrypted at rest with AES-256-GCM under a key that is not stored in the database.
- Figures derived from those services. Described precisely in the next section.
There is no advertising or analytics tracking on the signed-in application, no session recording, and no third-party cookies. The cookies we set are the session itself, the pending two-step verification cookie, short-lived state cookies during a connection flow, and your light or dark theme preference.
What connecting an account actually reads
Connections are read-only in both directions that matter: the credentials we ask for cannot write, and we never write back.
- Stripe. Successful charges from roughly the last thirteen months — the amount, any refunded amount, the date, the billing country, and whether the payer was a first-time or returning customer. We reduce these to daily totals as we read them. We do not store your customers’ names, email addresses, card details or individual transactions.
- Google Analytics 4. Sessions, total users, new users and key events, by day, and broken down by the dimensions shown in the app. These are already aggregated when Google returns them; we never request user-level data and hold no Analytics identifiers.
You can disconnect either at any time from the Data sources page. Disconnecting deletes our copy of the credentials and, for a Stripe connection made through Stripe’s own authorisation screen, revokes our access at Stripe.
Artificial intelligence
Briefings and answers are generated by OpenAI. When a briefing is written or you ask a question, the aggregated figures relevant to it — the daily totals described above — and your question are sent to OpenAI’s API to produce the answer.
Because those figures are aggregates, no individual customer of yours is described in what we send. OpenAI does not train on data submitted through its API. We do not train any model on your data, and we do not use one customer’s data to answer another’s question.
Who else sees it
Only the services below, each doing one job. We do not sell personal data, and we do not share it for advertising.
| Service | What for | Where |
|---|---|---|
| OpenAI | Generates briefings and answers questions. Receives the aggregated figures relevant to a question, and the question itself. | United States |
| Stripe | Takes subscription payments, and — where you connect it — is the source of your revenue data. Card details go to Stripe directly and never reach our servers. | United States, Ireland |
| Optional sign-in, and — where you connect it — the source of your Google Analytics data. | United States | |
| Resend | Delivers transactional email: confirmations, password resets, invitations, alerts. | United States |
| Our hosting provider | Hosts the application and its database. | European Union |
Several of these are in the United States, so your data is transferred there. Those transfers rely on the standard contractual clauses in each provider’s data processing agreement.
We will also disclose data where the law requires it. If we are served with a request for your data and are permitted to tell you, we will.
How long we keep it
- Your account and its data stay until you delete the account or ask us to.
- Sign-in, reset and confirmation tokens are single-use and expire within an hour to a day; failed sign-in records are pruned automatically.
- Deleting your account removes your businesses, connected sources, stored figures, conversations and reports. Billing records are kept for as long as tax law requires, which is generally six years.
- Backups may hold deleted data for a short period before they roll over, after which it is gone.
Your rights
If you are in the UK or the EU, you have the right to see the data we hold about you, correct it, delete it, take it elsewhere in a portable form, object to how we use it, and complain to your data protection authority — in the UK, the Information Commissioner’s Office.
You don’t have to be in the UK or the EU to use any of them. Email privacy@analyzebusinessdata.com and we will answer within 30 days. We won’t charge you for it, and we won’t make it a condition of anything.
Security
Passwords are hashed with bcrypt. Connector credentials are encrypted with AES-256-GCM. Everything travels over TLS. Optional two-step verification is available on every account from Settings, and we recommend turning it on.
More detail, including how to report a vulnerability, is on the security page. If a breach affects your data we will tell you, and the relevant regulator, within the 72 hours the law allows.
Children
Throughline is a tool for businesses and is not directed at anyone under 16. We don’t knowingly collect their data; if we learn that we have, we delete it.
Changes
When this policy changes materially — a new subprocessor, a new category of data — we will email account holders before it takes effect. The date at the top always reflects the last change.