Legal
Privacy Policy
Last updated: August 25, 2026 · TeamLinkUp by Tona Digital
1. Who we are
TeamLinkUp is a shared calendar product operated by Tona Digital (“we”, “us”). This policy explains what personal data we process when you use the Service.
2. Data we collect
- Account data: name, email, password hash, preferences (language, timezone, theme), optional 2FA secrets (encrypted).
- Calendar data: calendar titles, events, notes, attachments metadata, team memberships, share-link metadata (token hashes only).
- Technical data: IP address, user agent, session identifiers, rate-limit counters, security audit events, error logs.
- Billing data: Stripe customer/subscription identifiers and status (card details are handled by Stripe, not stored on our servers).
- Contact form: name, email, topic, message, IP (for abuse prevention).
- Cookies: essential session cookies; optional preference cookie for cookie-banner consent.
3. How we use data
- Provide and secure the Service (authentication, permissions, rate limiting, 2FA);
- Send transactional email (password reset, invites, optional notifications);
- Process Premium subscriptions via Stripe;
- Respond to support requests;
- Improve reliability and prevent abuse.
We do not sell your personal data.
4. Legal bases (where GDPR applies)
Performance of a contract (providing the Service), legitimate interests (security, abuse prevention, product improvement), consent (optional cookies/marketing if ever introduced), and legal obligations where applicable.
5. Sharing
We share data only with processors needed to run the Service, for example:
- Hosting provider (e.g. Hostinger) for servers and email;
- Stripe for payments;
- Cloudflare Turnstile if captcha is enabled;
- Authorities if required by law.
6. International transfers
Depending on hosting and processors, data may be processed in the EU or other regions. We take reasonable steps to use appropriate safeguards where required.
7. Retention
Account and calendar data are kept while your account is active. Logs and rate-limit data are retained for a limited operational period. You may request deletion of your account; residual backups may persist for a short period.
8. Security
We use industry-standard measures including hashed passwords, CSRF protection, prepared SQL statements, encrypted 2FA secrets, and access controls. No method of transmission or storage is 100% secure.
9. Your rights
Depending on your location, you may have rights to access, rectify, delete, restrict, or port your data, and to object to certain processing. Contact us via the Contact page. You may also lodge a complaint with a supervisory authority.
10. Children
The Service is not directed at children under 16. Do not register if you are under the age required in your jurisdiction.
11. Changes
We may update this policy. The “Last updated” date will change when we do. Continued use after changes constitutes acceptance where permitted by law.
12. Contact
Privacy inquiries: Contact form or admin@tonadigital.com.