Privacy Policy
Table of Contents (13 Sections)▼
Todoal respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information Todoal collects, why we collect it, how we use it, who may receive it, how long we keep it, and the rights available to you under applicable privacy laws including the European Union General Data Protection Regulation (GDPR).
1. Who Controls Your Data
Todoal is the data controller for personal data processed through the Todoal website and application.
For privacy questions, data protection requests, or complaints, contact us at:
If you believe your data protection rights have been violated, you may also lodge a complaint with the relevant data protection authority in your country of residence or where the alleged infringement occurred.
2. Information We Collect
Depending on how you use Todoal, we may process the following information:
Account Information
Your email address, name, Firebase authentication identifier, and account information.
Productivity Information
Tasks, reminders, goals, completion information, and other planning information that you voluntarily enter into Todoal.
Timezone Information
Your IANA timezone such as America/New_York, Asia/Kolkata, or Asia/Shanghai.
Your timezone allows Todoal to determine your local date and time so scheduled emails can be delivered according to your local timezone.
Email Preferences
Your email notification preferences and scheduled email times.
Subscription Information
Subscription status, billing interval, Paddle customer identifiers, Paddle subscription identifiers, and related billing information. Todoal does not store complete payment card details.
Feedback Information
Feedback submitted through Todoal may be securely transmitted to our internal support channel through Telegram and is not intentionally stored as a separate feedback database record.
Technical Information
We may process technical information necessary for security, reliability, debugging, and operation of the service including authentication information, device information, browser information, IP address, and technical logs where applicable.
3. How We Use Your Information
We may process personal data to:
- Create and maintain your Todoal account
- Provide tasks, reminders, goals, and daily planning functionality
- Deliver scheduled email notifications according to your selected timezone and schedule
- Process and manage Todoal Pro subscriptions
- Provide customer support
- Respond to feedback
- Maintain application security
- Detect, prevent, and investigate abuse
- Maintain service reliability
- Comply with legal obligations
- Protect our rights and prevent fraud
We do not sell your personal data. We do not use your private productivity information for unrelated advertising purposes.
4. Legal Bases for Processing
Where the GDPR applies, Todoal processes personal data using an appropriate lawful basis depending on the purpose:
- Contract: Processing necessary to provide Todoal and fulfil the services you request.
- Legitimate Interests: Processing necessary for security, fraud prevention, service improvement, technical operation, and protection of our legal rights where our interests are not overridden by your rights.
- Consent: Processing where consent is legally required, including certain non-essential analytics and tracking technologies.
- Legal Obligation: Processing necessary to comply with applicable laws, regulations, or lawful requests.
5. Cookies and Analytics
Todoal may use strictly necessary cookies or similar technologies required for authentication, security, and essential application functionality.
Where enabled, Todoal may also use analytics or product measurement services such as Google Analytics, Google Tag Manager, or Microsoft Clarity. Non-essential analytics technologies will be used according to applicable consent requirements. You can learn more in our Cookie Policy.
6. Third Party Service Providers
Todoal uses trusted third-party providers to operate parts of the service:
- Firebase: for authentication
- Supabase: for application infrastructure and database services
- Paddle: for subscription billing and payment processing
- Brevo: for transactional and productivity product emails
- Telegram: for internal feedback delivery
- Google Analytics / Tag Manager: where enabled
- Microsoft Clarity: where enabled
Where a provider acts as a processor, Todoal uses appropriate contractual arrangements where required by applicable law.
7. International Data Transfers
Some service providers used by Todoal may process personal data outside the European Economic Area. Where personal data is transferred outside the EEA, Todoal will use an applicable lawful transfer mechanism where required, such as an adequacy decision, Standard Contractual Clauses, or another legally permitted transfer mechanism.
8. Data Retention
Todoal retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy. Account and productivity information may be retained while your account remains active.
Certain information may be retained after account closure where necessary for legal obligations, fraud prevention, security, legitimate business records, or the establishment, exercise, or defence of legal claims.
9. Your Privacy Rights
Depending on applicable law, you may have the right to:
- Access your personal data
- Correct inaccurate or incomplete information
- Request deletion of your personal data
- Restrict certain processing
- Object to certain processing
- Receive certain personal data in a portable format
- Withdraw consent where processing is based on consent
- Object to certain direct marketing
- Lodge a complaint with a competent data protection authority
You can exercise your applicable rights by contacting contact@todoal.com.
10. Data Security
Todoal uses reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. Security measures may include authentication controls, access restrictions, encryption, secure APIs, database security controls, and server-side validation.
11. Children
Todoal is not intended for children below the minimum age required to use the service under applicable law. If you believe that a child has provided personal data to Todoal without appropriate permission, contact us at contact@todoal.com.
12. Changes to This Privacy Policy
Todoal may update this Privacy Policy when our services, technology, processing activities, or legal requirements change. When material changes are made, Todoal will provide appropriate notice where required by applicable law.
13. Contact Us
For privacy questions, data protection requests, or concerns regarding your personal data, contact:
Todoal
Email: contact@todoal.com
Questions regarding this policy?
Contact our legal & compliance team at contact@todoal.com