1. Scope and operator
ToolRoster is operated by Eastbase Studio. This policy applies to the ToolRoster website, service, support, and related operational communications. Contact support@eastbase.studio for privacy questions or requests.
2. Our privacy roles
Eastbase Studio acts as a controller for account, billing, security, support, and product-operation data because it determines why and how those data are processed.
Customers generally determine the purposes and means for processing workspace member, employee, contractor, vendor, and customer data. ToolRoster processes workspace data on the customer’s documented instructions to provide, secure, support, and maintain the service. The Data Processing Terms govern that processing.
3. Data we process
Account and authentication data. Name, email address, password hash, email-verification state, sessions, and authentication metadata. If Google or GitHub OAuth is enabled and chosen, we receive the basic profile, email, provider identifier, and tokens needed for sign-in.
Workspace and service data. Workspace and member details; registry entries; vendor and risk fields; data-use rules; requests and decisions; policy versions and acknowledgments; audit events; review dates; branding; exports; and billing/subscription references.
Operational data. IP address and request metadata used for hosting, authentication, rate limiting, abuse prevention, support, and security; transactional email delivery metadata; billing records; and minimized error and performance diagnostics.
Optional analytics. If you accept analytics, ToolRoster may process scrubbed page paths, device and browser metadata, and an opaque account identifier through PostHog, Vercel Web Analytics, and Speed Insights. Query strings, autocapture, session replay, and PostHog browser persistence are disabled.
4. What ToolRoster does not intentionally collect
ToolRoster does not connect to your AI tools or intentionally collect AI prompts, external browsing history, or private employee activity outside ToolRoster. ToolRoster records actions taken within the service because registry changes, requests, decisions, policy acknowledgments, and administrative events form part of the audit trail.
ToolRoster does not use an AI provider, train AI models on customer data, sell personal data, or use personal data for cross-site advertising.
5. Purposes and legal bases
- Contract: to create accounts, provide workspace features, process subscriptions, deliver requested communications, support users, and enforce the Terms.
- Legitimate interests: to secure the service, prevent abuse and fraud, diagnose errors, maintain records, improve reliability, and understand essential service operation, balanced against individual rights.
- Consent: for optional analytics where consent is required. Consent can be rejected or withdrawn through Privacy preferences without affecting essential service features.
- Legal obligation: to retain or disclose information required for tax, accounting, legal process, fraud prevention, and dispute handling.
6. Customer responsibilities and free-text fields
Customers are responsible for the rights, notices, authority, and legal basis required to process employee, contractor, vendor, and customer data through ToolRoster and to respond to individuals whose data they control.
Do not enter AI prompts; credentials, keys, tokens, or passwords; customer content or source code; sensitive HR, health, payment, or regulated data; or unnecessary personal data into tool names, notes, requests, policies, audit comments, or other free-text fields.
AI vendor terms, training practices, retention, certifications, ownership, security controls, and product behavior can change. Customers must keep registry entries and review dates current and must independently assess the vendors they approve.
7. Providers and subprocessors
The following providers are wired into ToolRoster. Optional providers receive data only when their feature is configured, chosen, or consented to. Lemon Squeezy and OAuth providers may also act as independent controllers under their own terms for transactions or authentication.
| Provider | Purpose | Data processed | Required / optional | Region note |
|---|---|---|---|---|
| Vercel | Application hosting, content delivery, deployment, and optional web analytics and performance measurement | HTTP request metadata, IP address, app responses, and optional usage/performance metrics | Required for hosting; analytics optional | Global edge network; provider is US-based |
| Neon | Managed PostgreSQL database hosting | Account, workspace, registry, request, policy, acknowledgment, audit, and subscription-reference data | Required | Configured database project: AWS US East |
| Resend | Transactional email delivery | Recipient address and the content and delivery metadata of each email | Required when transactional email is enabled | Provider is US-based |
| Lemon Squeezy | Hosted checkout, subscriptions, tax handling, and refunds as merchant of record | Billing identity, transaction, subscription, tax, and payment-related data | Required for paid plans | International processing under Lemon Squeezy's buyer terms |
| PostHog | Optional product analytics | Consent-gated page paths without query strings, device metadata, and opaque user identifiers | Optional; disabled until analytics consent | US cloud |
| Sentry | Error monitoring and performance diagnostics | Scrubbed error, stack-trace, route, device, and runtime diagnostics | Optional operational provider | Provider is US-based; processing may occur internationally |
| Upstash | Distributed rate limiting and abuse prevention | Hashed rate-limit identifiers, counters, and expiry times | Optional but recommended in production | Global service; selected database region applies |
| Cloudflare Turnstile | Bot verification on sign-up and password-reset requests | Challenge token, request hostname, IP address, and browser/device signals | Optional but recommended in production | Cloudflare global network |
| Google OAuth | Optional Google account sign-in | OAuth identifier, name, email, profile image, and authentication tokens | Optional; only when enabled and chosen | Google's global infrastructure |
| GitHub OAuth | Optional GitHub account sign-in | OAuth identifier, name, email, profile image, and authentication tokens | Optional; only when enabled and chosen | GitHub's global infrastructure |
8. Cookies, analytics, and diagnostics
Essential cookies keep users signed in, remember the active workspace, protect authentication flows, and store the analytics preference. These are required to provide requested features and remember a rejection.
Optional analytics do not initialize or send events until a user accepts analytics. Before consent, ToolRoster does not initialize PostHog, create PostHog cookies or local storage, identify the user, or mount Vercel Web Analytics or Speed Insights. Users can choose “Accept analytics,” “Reject non-essential,” or reopen “Privacy preferences” from the footer.
PostHog autocapture and session replay are off, query strings are removed, browser persistence is disabled, and only opaque user IDs are used. Tool names, notes, policy text, request text, and emails are not deliberately sent to PostHog. Server-side PostHog events are disabled for all users, including after a rejection.
Sentry is used for necessary error diagnostics when configured. It is configured to minimize and scrub personal and workspace data, including query strings, request bodies, authorization headers, cookies, email addresses, user-entered free text, and detailed error messages. No error-monitoring configuration can eliminate every disclosure risk, so access and retention are kept limited.
9. Public approved-tools pages
A /t/[slug] page is intentionally public only when a workspace admin enables it. Published content may be indexed, cached, copied, screenshotted, or stored by third parties. Admins must not publish confidential assessments, security findings, private restrictions, personal data, or unauthorized content. Disabling a page cannot remove third-party copies.
10. Retention, deletion, and append-only records
We retain active account and workspace data while the service is used. After a verified account or workspace deletion request, we target deletion or anonymization from active systems within 30 days. Backups and security, delivery, and diagnostic logs may persist for approximately 90 days before rotation.
Billing, tax, accounting, fraud, and dispute records may be kept longer where required or reasonably necessary. Provider-side retention may also apply under provider terms and legal obligations.
Audit events, policy versions, and acknowledgments are append-only by design. Where an event must remain for record integrity, ToolRoster retains the event but deletes, anonymizes, or tombstones the former actor’s identifying account information where feasible. Workspace content controlled by a customer may remain with that workspace after an individual member’s account is anonymized.
To request account or workspace deletion, email support@eastbase.studio from the account address. We verify identity and admin authority and may require an admin transfer or subscription cancellation first.
11. International processing
ToolRoster is operated from Vietnam. Some providers process data in other countries, including the United States, and data-protection laws may differ. Where required, we use appropriate contractual or other lawful safeguards for international transfers.
12. Individual rights
Depending on applicable law, individuals may have rights to access, correct, export, delete, restrict, or object to processing and to withdraw consent. Workspace admins can correct and export much of their workspace data directly. For other requests, contact support@eastbase.studio.
If the request concerns data controlled by a customer workspace, we may direct the individual to that customer and assist the customer under the Data Processing Terms. Individuals may also complain to a competent data-protection authority.
13. Security
ToolRoster uses access controls, signed sessions, password hashing, transport encryption, server-side authorization, rate limiting, provider access controls, backups, and audit records appropriate to the service. No system is perfectly secure. Report suspected privacy or security issues to support@eastbase.studio.
14. Children
ToolRoster is a workplace service and is not directed to children under 16.
15. Changes and contact
We may update this policy as the service, providers, or law changes. We will update the date above and provide notice of material changes where appropriate. ToolRoster is operated by Eastbase Studio. Contact support@eastbase.studio.