ToastWall
Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains what ToastWall (“we”, “us”) collects, why we collect it, how long we keep it, and who processes it on our behalf. By using toastwall.com, you acknowledge this policy. For contract terms, see our Terms of Service.
1. Age requirement (COPPA)
The Service is intended for users 13 years of age and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us data, contact privacy@toastwall.com and we will delete it.
2. What we collect
- Host account: Google account identifiers and email when you Sign in with Google to manage events. Legacy events may still have an old organizer password hash until claimed; we do not store plaintext passwords.
- Event data: event title, URL slug, theme, settings, and Event Code (used for private guest/venue access — not marketed as a “token” to users).
- Guest data: optional nickname; device cookies that identify this phone for one event; Event Code access cookies.
- Uploads: photos, videos, and text guests submit, plus related metadata (time, toast prompt, file type/size).
- Payments: when checkout is enabled, payment processors (e.g. Square) process card data; we receive payment status and related metadata, not full card numbers.
- Technical logs: basic request and error logs needed to operate and secure the Service (IP address, user agent, and similar diagnostics may be processed by our hosting provider).
We do not require email signup for guests. If you use Drop us a note on the homepage, we collect the email you enter so we can reply about trying ToastWall. Help form submissions go to our support inbox.
3. Why we collect it
- Operate the live wall, album, moderation, and guest flows
- Keep events private via Event Codes on public links
- Let hosts download and manage media (Sign in with Google)
- Process pay-to-open checkout and coupons when enabled
- Respond when someone asks to try ToastWall or contacts Help
- Prevent abuse, debug issues, and improve Early Access
- Comply with law and respond to deletion or DMCA requests
4. Retention after Event over
After a host marks Event over, we keep event media and the album for up to 14 days. Hosts should download the album ZIP in that window. A prepared ZIP file is kept about 7 days (ZIP expiry does not by itself remove the live album during the album window). We do not promise long-term archival. When retention enforcement is enabled, media may be purged after the window. Live events are not auto-deleted solely for being live. Early Access may gently extend availability until purge is enforced — that is not a forever-storage promise. Cookie identifiers expire on the schedules described in our product (typically days, not years).
5. Sharing and third-party processors
We use infrastructure processors to host the app and store media. Current categories include:
- Cloudflare — application hosting (Workers), database (D1), and object storage (R2) for media files
- Google — host authentication (Sign in with Google)
- Payment processor — card checkout when pay-to-open is enabled (e.g. Square)
Processors act on our instructions to provide the Service. We do not sell personal information. We may disclose data if required by law or to protect the Service and users.
6. Cookies and similar technologies
We use essential cookies: host session (Google), guest identity for an event, and Event Code access so private links keep working after the first open. These are not advertising cookies. Blocking cookies may prevent joining an event.
7. Your choices (GDPR / CCPA)
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information, and to opt out of certain processing. Guests can delete their own uploads in-product where available. Anyone can request deletion by emailing privacy@toastwall.com with a link to the content or enough detail to locate it. We aim to complete deletion requests within 30 days. California residents may also contact us to exercise CCPA rights; we do not sell personal information as defined by CCPA.
8. Consent
Hosts accept our Terms when creating an event. Guests consent to processing when they add their name (they are told that continuing means they are 13 or older and okay with uploads appearing on the live wall and album). That consent is stored once for the guest, not on every upload.
9. Security
We use industry-standard measures appropriate to Early Access (HTTPS, Google host auth, hashed legacy passwords where still present, Event Codes on public links). No method of transmission or storage is 100% secure.
10. International transfers
The Service is hosted on global cloud infrastructure. If you access it from outside the United States, your data may be processed in the United States or other countries where our processors operate.
11. Changes
We may update this policy. The “Last updated” date will change when we do. Continued use after updates means you acknowledge the revised policy.
12. Contact
Privacy and deletion requests: privacy@toastwall.com.