Subprocessor / Third Party Services Policy
Table of Contents (15 Sections)▼
Todoal uses selected third-party service providers to operate, maintain, secure, and improve the Todoal service. These providers may process limited personal information on behalf of Todoal where necessary to provide their specific services. Todoal does not sell user personal data to third-party service providers.
1. Purpose
This policy explains the categories of third-party providers Todoal may use and the types of information they may process. Third-party providers only receive information reasonably necessary for the service they provide.
2. Authentication
Todoal uses Firebase Authentication (Google Cloud) to provide account authentication and user identity services. Firebase may process information required to authenticate users and maintain secure account access, including email address and authentication identifiers.
3. Database and Application Infrastructure
Todoal uses Supabase for database and backend infrastructure. Supabase may process information required to operate Todoal including account information, tasks, Permanent Reminders, reminder completion records, Yearly Goals, email scheduling, subscription information, application settings, and security records. Access is strictly controlled through Row Level Security (RLS) and backend authorization.
4. Payment Processing
Todoal uses Paddle for payment processing and subscription management. Paddle may process information required to complete purchases, manage recurring plans, handle taxes, and manage customer billing. Todoal does not directly store full credit card details.
5. Email Delivery
Todoal uses third-party email delivery infrastructure (such as Brevo / Sendinblue) to send scheduled Pro notifications and necessary service communications. Email providers process recipient email addresses, delivery timestamps, message contents, and technical metadata required for transmission.
6. Telegram Feedback Delivery
Todoal uses Telegram Bot infrastructure to receive feedback submitted through the Todoal application. Feedback is sent through the Todoal backend rather than being permanently stored in the application database.
7. Hosting and Infrastructure
Todoal uses cloud hosting infrastructure (including Vercel Inc.) to operate application servers, APIs, Edge Functions, and frontend delivery networks.
8. Analytics
If analytics services are enabled, Todoal may use Google Analytics, Google Tag Manager, or Microsoft Clarity to understand website interactions. Consent is obtained before non-essential tracking is activated.
9. International Data Transfers
Where third-party providers process data outside the EEA, Todoal implements standard contractual safeguards, adequacy decisions, or other legally recognized transfer mechanisms.
10. Data Protection Agreements
Where required by applicable law, Todoal enters into appropriate Data Processing Addenda (DPAs) with subprocessors to bind them to strict confidentiality and security standards.
11. Security
Todoal takes reasonable technical and organizational measures to protect information processed through third-party services, including authentication controls, database RLS, rate limiting, and encrypted API communications.
12. Changes to Third Party Providers
Todoal may add, remove, or replace third-party service providers as the product develops. Material changes affecting data processing will be reflected in this policy.
13. User Rights
You may exercise statutory rights to access, correct, delete, or restrict processing of your personal data by contacting contact@todoal.com.
14. Relationship With the Privacy Policy
This policy should be read together with the Todoal Privacy Policy, Cookie Policy, and Terms of Service. If there is a conflict between this policy and applicable law, applicable law controls.
15. Contact
For questions regarding subprocessors or data practices, contact:
Todoal
Email: contact@todoal.com
Questions regarding this policy?
Contact our legal & compliance team at contact@todoal.com