§PLegal · Privacy

Privacy Policy

This policy explains what ToolRoster processes, why it processes it, the roles of Eastbase Studio and customers, and the choices and rights available to individuals.

Effective July 30, 2026 · Last updated July 30, 2026

DocumentPrivacy Policy · v2

1. Scope and operator

ToolRoster is operated by Eastbase Studio. This policy applies to the ToolRoster website, service, support, and related operational communications. Contact support@eastbase.studio for privacy questions or requests.

2. Our privacy roles

Eastbase Studio acts as a controller for account, billing, security, support, and product-operation data because it determines why and how those data are processed.

Customers generally determine the purposes and means for processing workspace member, employee, contractor, vendor, and customer data. ToolRoster processes workspace data on the customer’s documented instructions to provide, secure, support, and maintain the service. The Data Processing Terms govern that processing.

3. Data we process

Account and authentication data. Name, email address, password hash, email-verification state, sessions, and authentication metadata. If Google or GitHub OAuth is enabled and chosen, we receive the basic profile, email, provider identifier, and tokens needed for sign-in.

Workspace and service data. Workspace and member details; registry entries; vendor and risk fields; data-use rules; requests and decisions; policy versions and acknowledgments; audit events; review dates; branding; exports; and billing/subscription references.

Operational data. IP address and request metadata used for hosting, authentication, rate limiting, abuse prevention, support, and security; transactional email delivery metadata; billing records; and minimized error and performance diagnostics.

Optional analytics. If you accept analytics, ToolRoster may process scrubbed page paths, device and browser metadata, and an opaque account identifier through PostHog, Vercel Web Analytics, and Speed Insights. Query strings, autocapture, session replay, and PostHog browser persistence are disabled.

4. What ToolRoster does not intentionally collect

ToolRoster does not connect to your AI tools or intentionally collect AI prompts, external browsing history, or private employee activity outside ToolRoster. ToolRoster records actions taken within the service because registry changes, requests, decisions, policy acknowledgments, and administrative events form part of the audit trail.

ToolRoster does not use an AI provider, train AI models on customer data, sell personal data, or use personal data for cross-site advertising.

5. Purposes and legal bases

  • Contract: to create accounts, provide workspace features, process subscriptions, deliver requested communications, support users, and enforce the Terms.
  • Legitimate interests: to secure the service, prevent abuse and fraud, diagnose errors, maintain records, improve reliability, and understand essential service operation, balanced against individual rights.
  • Consent: for optional analytics where consent is required. Consent can be rejected or withdrawn through Privacy preferences without affecting essential service features.
  • Legal obligation: to retain or disclose information required for tax, accounting, legal process, fraud prevention, and dispute handling.

6. Customer responsibilities and free-text fields

Customers are responsible for the rights, notices, authority, and legal basis required to process employee, contractor, vendor, and customer data through ToolRoster and to respond to individuals whose data they control.

Do not enter AI prompts; credentials, keys, tokens, or passwords; customer content or source code; sensitive HR, health, payment, or regulated data; or unnecessary personal data into tool names, notes, requests, policies, audit comments, or other free-text fields.

AI vendor terms, training practices, retention, certifications, ownership, security controls, and product behavior can change. Customers must keep registry entries and review dates current and must independently assess the vendors they approve.

7. Providers and subprocessors

The following providers are wired into ToolRoster. Optional providers receive data only when their feature is configured, chosen, or consented to. Lemon Squeezy and OAuth providers may also act as independent controllers under their own terms for transactions or authentication.

ToolRoster providers and subprocessors
ProviderPurposeData processedRequired / optionalRegion note
VercelApplication hosting, content delivery, deployment, and optional web analytics and performance measurementHTTP request metadata, IP address, app responses, and optional usage/performance metricsRequired for hosting; analytics optionalGlobal edge network; provider is US-based
NeonManaged PostgreSQL database hostingAccount, workspace, registry, request, policy, acknowledgment, audit, and subscription-reference dataRequiredConfigured database project: AWS US East
ResendTransactional email deliveryRecipient address and the content and delivery metadata of each emailRequired when transactional email is enabledProvider is US-based
Lemon SqueezyHosted checkout, subscriptions, tax handling, and refunds as merchant of recordBilling identity, transaction, subscription, tax, and payment-related dataRequired for paid plansInternational processing under Lemon Squeezy's buyer terms
PostHogOptional product analyticsConsent-gated page paths without query strings, device metadata, and opaque user identifiersOptional; disabled until analytics consentUS cloud
SentryError monitoring and performance diagnosticsScrubbed error, stack-trace, route, device, and runtime diagnosticsOptional operational providerProvider is US-based; processing may occur internationally
UpstashDistributed rate limiting and abuse preventionHashed rate-limit identifiers, counters, and expiry timesOptional but recommended in productionGlobal service; selected database region applies
Cloudflare TurnstileBot verification on sign-up and password-reset requestsChallenge token, request hostname, IP address, and browser/device signalsOptional but recommended in productionCloudflare global network
Google OAuthOptional Google account sign-inOAuth identifier, name, email, profile image, and authentication tokensOptional; only when enabled and chosenGoogle's global infrastructure
GitHub OAuthOptional GitHub account sign-inOAuth identifier, name, email, profile image, and authentication tokensOptional; only when enabled and chosenGitHub's global infrastructure

8. Cookies, analytics, and diagnostics

Essential cookies keep users signed in, remember the active workspace, protect authentication flows, and store the analytics preference. These are required to provide requested features and remember a rejection.

Optional analytics do not initialize or send events until a user accepts analytics. Before consent, ToolRoster does not initialize PostHog, create PostHog cookies or local storage, identify the user, or mount Vercel Web Analytics or Speed Insights. Users can choose “Accept analytics,” “Reject non-essential,” or reopen “Privacy preferences” from the footer.

PostHog autocapture and session replay are off, query strings are removed, browser persistence is disabled, and only opaque user IDs are used. Tool names, notes, policy text, request text, and emails are not deliberately sent to PostHog. Server-side PostHog events are disabled for all users, including after a rejection.

Sentry is used for necessary error diagnostics when configured. It is configured to minimize and scrub personal and workspace data, including query strings, request bodies, authorization headers, cookies, email addresses, user-entered free text, and detailed error messages. No error-monitoring configuration can eliminate every disclosure risk, so access and retention are kept limited.

9. Public approved-tools pages

A /t/[slug] page is intentionally public only when a workspace admin enables it. Published content may be indexed, cached, copied, screenshotted, or stored by third parties. Admins must not publish confidential assessments, security findings, private restrictions, personal data, or unauthorized content. Disabling a page cannot remove third-party copies.

10. Retention, deletion, and append-only records

We retain active account and workspace data while the service is used. After a verified account or workspace deletion request, we target deletion or anonymization from active systems within 30 days. Backups and security, delivery, and diagnostic logs may persist for approximately 90 days before rotation.

Billing, tax, accounting, fraud, and dispute records may be kept longer where required or reasonably necessary. Provider-side retention may also apply under provider terms and legal obligations.

Audit events, policy versions, and acknowledgments are append-only by design. Where an event must remain for record integrity, ToolRoster retains the event but deletes, anonymizes, or tombstones the former actor’s identifying account information where feasible. Workspace content controlled by a customer may remain with that workspace after an individual member’s account is anonymized.

To request account or workspace deletion, email support@eastbase.studio from the account address. We verify identity and admin authority and may require an admin transfer or subscription cancellation first.

11. International processing

ToolRoster is operated from Vietnam. Some providers process data in other countries, including the United States, and data-protection laws may differ. Where required, we use appropriate contractual or other lawful safeguards for international transfers.

12. Individual rights

Depending on applicable law, individuals may have rights to access, correct, export, delete, restrict, or object to processing and to withdraw consent. Workspace admins can correct and export much of their workspace data directly. For other requests, contact support@eastbase.studio.

If the request concerns data controlled by a customer workspace, we may direct the individual to that customer and assist the customer under the Data Processing Terms. Individuals may also complain to a competent data-protection authority.

13. Security

ToolRoster uses access controls, signed sessions, password hashing, transport encryption, server-side authorization, rate limiting, provider access controls, backups, and audit records appropriate to the service. No system is perfectly secure. Report suspected privacy or security issues to support@eastbase.studio.

14. Children

ToolRoster is a workplace service and is not directed to children under 16.

15. Changes and contact

We may update this policy as the service, providers, or law changes. We will update the date above and provide notice of material changes where appropriate. ToolRoster is operated by Eastbase Studio. Contact support@eastbase.studio.