Privacy Policy
This Privacy Policy describes how F&D Ventures LLC, doing business as Tormano (“Tormano,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you use our websites (tormano.com, crm.tormano.com, npcrm.tormano.com), applications, APIs, and related services (collectively, the “Service”). By using the Service, you agree to the practices described in this Privacy Policy.
1. Information we collect
1.1 Information you provide
We collect information you provide directly, including: (a) account registration information (name, email address, organization name, password); (b) billing information, collected only if and when you choose to purchase a paid plan. No payment card or other payment details are collected when you register for an account or during a free trial, and where you do purchase, your card details are collected and stored by our payment processor, Stripe, and we do not store payment card numbers; (c) Customer Data you upload or enter into the Service (contacts, companies, deals, donations, activities, communications, documents, and related records); (d) communications you send us (support requests, feedback, survey responses); and (e) information provided during onboarding or setup (industry, organization size, preferences).
1.2 Information we collect automatically
When you use the Service, we automatically collect:
- device and browser information (IP address, browser type, operating system, device identifiers);
- usage data (pages visited, features used, actions taken, timestamps, session duration);
- log data (server logs, error reports, API requests); and
- the cookies and browser storage needed to keep you signed in and to remember your interface preferences. Section 12 and our Cookie Policy list these individually.
1.3 Information from third parties
We may receive information from: (a) third-party integrations you or your organization connect (for example Intuit QuickBooks, Xero, Google Workspace, Microsoft 365, Mailchimp or Eventbrite) as authorized by you; (b) publicly available sources and enrichment providers, where your organization has enabled contact enrichment; and (c) Cloudflare Turnstile, the bot check on our public forms, which tells us only whether a submission passed the challenge and returns no information about you. We do not use an identity-verification or fraud-scoring vendor, and no third party supplies us with a risk score, credit assessment or background check about you.
1.4 Connected mailboxes (email mirroring)
If you connect an email mailbox to the Service, we sign in to that mailbox, read messages in it, and store a copy of them in your organization’s workspace. This is the most sensitive category of information the Service holds, so it is set out here in full rather than folded into 1.1.
How a mailbox is connected, and what we hold in order to do it. There are two ways and they behave differently. (a) Outlook or Microsoft 365, through Microsoft’s own sign-in. When you connect the mailbox we ask Microsoft for four permissions: read your mail, send mail as you, read your basic profile, and maintain the connection when you are not present. When the Service later renews that connection in order to send on your behalf, it asks for a permission that also allows changing and deleting messages in your mailbox. We use it only to read and to send, we do not delete or modify messages in your mailbox, and you can see and revoke exactly what has been granted at the Microsoft links in “How to withdraw access” below. If you separately connect Microsoft calendar or Microsoft Teams, those are separate consents with their own permissions, granted at the time you connect them. Your Microsoft password is never seen by us. (b) Any other provider (Gmail, iCloud, Yahoo, Fastmail, or a mail server you name yourself), over IMAP, using an app password. An app password is a separate credential your provider issues for a single application and that you can revoke on its own. On this path Tormano holds that credential, encrypted, together with your email address and the server addresses you gave us, because an IMAP connection has to re-authenticate each time it runs. We hold it to read the mailbox and to send from it, and for nothing else. Your provider’s ordinary account password is never requested and never stored. Gmail cannot be connected through a Google sign-in; see Section 4.1.1.
What we store for each message. The whole message, not a summary of it: the subject line and the complete message body, in both plain-text and HTML form; the sender’s address and every recipient address in the To, Cc and Bcc fields; the direction of the message and the identifiers your provider gives the message and its conversation thread; whether it is read and whether it is starred; the times it was sent, received and synced by us; and the labels and folders the message carried. Labels include your provider’s own automatic classifications of the message, such as its Personal, Promotions and Updates categories and its important marker, and whether your provider has flagged the message or marked it answered. Those are inferences your provider drew about the message, and in mirroring the message we mirror them as well.
Attachments, stated precisely. We do not store attachment files. No attachment content and no attachment filenames are written to our systems. We do store whether a message had attachments and how many it had, and where the message body points at an embedded image or file, that pointer stays inside the stored body even though we do not hold the file it refers to.
It includes people who are not our users. A mailbox is correspondence, so what we mirror necessarily includes messages written by, and addressed to, people who do not use Tormano. What we do and do not do with information about them is in Section 4.2, and we do not sell or share it (Section 4.2.1).
Who inside your organization can read it. Mirrored mail is not workspace-wide. On every ordinary screen in the product it is visible only to the user whose mailbox it is, and to any colleague your organization has added as an active member of a shared inbox built on that mailbox. It is not visible to other colleagues, to administrators, or to the account Owner, merely by virtue of their role. Two administrative surfaces are exceptions. Both are recorded in the append-only audit log, and a search or export that cannot be recorded is refused rather than performed.
The first exception: searching the mirror by email address. This returns message details (dates, addresses, subjects, whether there were attachments) and never returns message bodies, at any permission level. It requires a dedicated privacy permission that no default role in the Service holds, the account Owner included. It reaches a person only when your organization assigns them the separate Privacy Officer role, which exists for answering privacy requests and carries no other administrative access. Being an administrator does not confer it.
The second exception: the data-subject export. When a contact’s data is exported to answer a data-subject request, mirrored messages involving that contact are included, and by default that export contains the same message details and no message bodies. An administrator (the Owner, a System Administrator or an Organization Administrator) can create an export of that kind, because answering a data-subject request is a legal obligation with a deadline. Releasing message bodies is a separate act needing a separate permission, which again only the Privacy Officer role holds; it additionally requires the request to be narrowed to a date range or to named mailboxes and to carry a stated reason, and every message body released is recorded individually, naming the mailbox it came out of. If those records cannot be written, the bodies are withheld and the export is returned without them.
What is not mirrored, and the one record that is created. Mirrored message content is held only in the mailbox mirror and is not copied into other parts of your workspace. There is one related record that is not a mirror but is generated: when you send an email from inside the Service, we write a timeline activity on the related record. What that activity contains depends on which send surface you used. If you sent it from a connected mailbox, the activity records the subject line and the addresses you sent to. If you sent it through the Service’s own email or campaign sending, the activity records the full text of the message you sent. Either way that activity is ordinary workspace data, which the mirrored message itself is not: it is visible to colleagues who can see the record, and eligible to be sent to an AI provider under 3.3, which for the sentiment-analysis feature means the whole body.
Artificial intelligence. The content of a connected mailbox is not sent to any AI provider (Section 3.3).
Purpose limitation. We use a connected mailbox for two purposes only: synchronizing its messages into your workspace so that correspondence appears against the right contacts and deals, and sending mail you compose in the Service from your own address. We do not use it for advertising, we do not mine it to build products for other customers, and we do not use it to train AI models.
How to withdraw access. You can disconnect a mailbox at any time in Settings, which deletes the mirrored messages immediately (see Section 7.2). You can also revoke access at the provider, without involving us. If you connected an Outlook or Microsoft 365 mailbox, you may go to account.live.com/consent/Manage (personal Microsoft accounts) or myapps.microsoft.com (work or school accounts) and revoke Tormano’s data access consent at any time. If you connected over IMAP with an app password, revoke that app password in your provider’s security settings. Revoking at the provider stops further access but does not by itself delete what we have already stored; to delete that, disconnect the mailbox in Settings or write to privacy@tormano.com.
2. How we use information
We use the information we collect for the following purposes:
- providing, operating, and maintaining the Service;
- processing transactions and managing your account;
- communicating with you about the Service, including service announcements, security alerts, and support messages;
- sending marketing communications, with your consent where the law requires it;
- improving and developing new features and functionality;
- analyzing usage patterns and trends to improve user experience;
- preventing fraud, abuse, and security threats;
- complying with legal obligations; and
- enforcing our Terms of Service.
3. Artificial intelligence and data processing
3.1 AI features
The Service includes AI-powered features that process certain Customer Data to provide functionality such as smart search, contact scoring, email drafting, donor insights, deal forecasting, report generation, and predictive analytics.
3.2 AI service providers
We currently use Anthropic (Claude API) as our AI service provider for text generation, analysis, scoring, forecasting, and natural language processing. OpenAI (GPT API) is supported by the Service as a fallback provider; no data is transmitted to OpenAI unless that fallback is enabled.
3.3 Data shared with AI providers
What we transmit depends on which AI feature is used. For most features that build their request from your CRM records, the fields are a fixed list rather than a matter of convention, and are limited to: (a) People: a contact’s first and last name, email address, job title, company or employer name and industry, lifecycle stage, how the record was created, the tags on the record, and the date the record was created; (b) Money and pipeline: deal names, amounts, stages, probabilities, pipeline names and expected close dates, donation amounts, dates, gift types and campaign names, and pipeline or organization-level aggregates such as win rates and averages; (c) Activity context: the type, subject line and date of recent activities on the record, plus counts derived from it (number of activities, number of deals, total deal value, days since last activity), and, for the sentiment-analysis feature specifically, the full body text of a contact’s recent email, call, note and meeting activities: that feature scores what was written, so the body of the activity and not merely its subject line is what it reads; and (d) the name of the assigned staff member on a deal. Two boundaries on (c) are worth stating outright. An activity body contains whatever was typed into it, including the activity the Service writes for you when you send an email from inside it, which carries the subject line and the recipient addresses (see 1.4). And the content of a connected mailbox is not in this category and is never sent to an AI provider. A mirrored message and an activity are different records, and no AI feature in the Service reads the mailbox mirror.
3.3.1 Two features that do not use that fixed list
The fixed list in 3.3 governs the features that assemble a request from a record: contact scoring, donor insights, deal forecasting, email drafting and smart search. Two other features build their request from record names rather than from record fields, and do not pass through it. The insights digest summarizes alerts whose titles and descriptions contain deal names, contact names and pipeline stage names as they were typed; phone-number patterns are stripped from it before it is sent. The report summary sends organization-level totals together with the names and values of recent deals, without that phone-number stripping. Neither sends addresses, phone-number fields, or any field outside the record’s name and amount. If someone typed a phone number into a deal name, the report summary would carry it.
3.3.2 Content you submit
Separately from the record fields above, some AI features work on material you hand them directly: your typed prompts and natural-language search queries, a document you upload for classification or field extraction, a meeting transcript or any text you paste in for conversation analysis, message text submitted for sentiment analysis, and narrative text you supply for grant, report or impact-story drafting. Material in this category is transmitted to the AI provider as you supply it. It is not filtered, because we cannot know which part of a document or transcript you need analyzed. It may therefore contain anything you put in it, including street addresses, phone numbers, or identifiers we would never send from a structured record.
3.3.3 Phone numbers
No phone-number field is ever sent. Phone-number fields are excluded by the fixed list described in Section 3.3, and phone-number patterns are additionally stripped from the record-derived free text those requests carry, such as an activity subject line, before the request is sent. The same stripping is applied to the insights digest. It is not applied to the report summary described in 3.3.1, so a phone number typed into a deal name would travel with it, and it cannot extend to material you submit yourself under 3.3.2: if you upload a document or paste a transcript containing a phone number, that phone number reaches the AI provider.
3.3.4 What we never send
Requests we assemble from your CRM records never contain passwords or authentication credentials, payment card numbers, bank account or routing numbers, Social Security or other government identification numbers, health information, street addresses, postal codes, geographic coordinates or dates of birth. That is a property of the fields we assemble, and it is not a property of documents or text you choose to submit under 3.3.2, which are transmitted unfiltered and may contain any of them. Several of those categories are also prohibited by Section 5.4 of our Terms of Service from being put into the Service at all. Independently of the source, the content of a connected mailbox is never sent to an AI provider by any feature.
3.4 AI provider data retention
Third-party AI providers may temporarily retain data in accordance with their own privacy policies. Anthropic’s and OpenAI’s published API terms state that data submitted through their APIs is not used to train their models, and we rely on those published terms. We have not signed a separate agreement with either of them; the note on our subprocessors page says the same of every provider we use.
3.5 AI Transparency
The Service provides an AI Transparency dashboard. It does not yet cover every AI feature. Some AI features record their actions there and others do not. For a recorded action the dashboard shows what the feature did, the output it generated and a confidence score where the feature produces one, and offers an undo for a limited period after the action. It does not display the full request sent to the provider. If you need to know what was sent for a particular action, ask us at privacy@tormano.com.
3.6 Opt-out
AI features are enabled by default. An administrator can turn them off for your entire organization from the AI Transparency page in Settings, without asking us first. The control belongs to an Owner, a System Administrator or an Organization Administrator; everyone else is shown whether AI is on or off as a status, not as a switch they can move. It takes effect on the next AI request, and it covers pages, background jobs and scheduled tasks alike, whether Tormano is paying for the AI or your organization has connected its own provider key. Nothing is deleted when you switch it off. Everything already generated stays where it is, and turning AI back on resumes the same features with the same settings. The page carrying the switch lists, feature by feature, what stops working.
3.6.1 Two things that switch does not stop
The first is connecting your own AI provider key. When an administrator saves or replaces your organization’s own Anthropic or OpenAI key, we send that provider a test request to confirm the key works before we store it, and we do that even while AI is switched off. It carries none of your data, and it happens only at the moment an administrator saves a key, never on a schedule and never in the background. The second is contact enrichment. Enrichment providers are not AI providers, they are described separately in Section 5 and on our subprocessors page, and this switch does not govern them. Enrichment runs only where your organization has connected its own enrichment provider key, and it has its own on and off control; turning AI off does not turn it off, and you should turn it off separately if that is what you want. Sentiment analysis, separately again, keeps its own toggle in the Service’s settings, so that one feature can be switched off while the rest of AI keeps running.
3.6.2 You can still ask us instead
The switch does not replace writing to us, and we have not withdrawn that route. If you would rather we turned AI off for your organization, or you want to ask what the switch covers before you use it, write to privacy@tormano.com and we will disable AI features for your organization. Disabling AI features, by either route, may reduce the functionality available.
4. How we share information
We do not sell personal information. We may share information in the following circumstances: (a) Service Providers: with vendors, consultants, and other service providers who need access to perform services on our behalf, subject to contractual confidentiality obligations; (b) Third-Party Integrations: with third-party services you choose to connect, based on the permissions you grant; (c) Legal Requirements: when required by law, regulation, legal process, or governmental request; (d) Protection of Rights: to enforce our agreements, protect our rights, privacy, safety, or property, and that of our users and the public; (e) Business Transfers: in connection with a merger, acquisition, reorganization, or sale of assets, with notice to affected users; and (f) With Consent: with your explicit consent or at your direction.
4.1 Google User Data (Limited Use)
When you connect a Google account for Google Calendar or Google Drive, Tormano’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the features you connect it to; we do not use it for advertising; we do not sell it; we do not transfer it to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to you; and we do not allow humans to read it except with your affirmative consent for specific messages, where necessary for security or to comply with law, or where the data has been aggregated and anonymized.
4.1.1 Gmail is not one of them
Tormano does not request Gmail permissions from Google, and there is no way to connect a Gmail mailbox through a Google sign-in: the Service refuses the attempt. You can still connect a Gmail mailbox, over IMAP, using a Google app password, and when you do, Tormano reads and stores your mail exactly as described in Section 1.4. That path requests no Google API scope and calls no Google API, so Google grants Tormano nothing and the Limited Use framework above does not govern it; what governs it is Section 1.4, Section 4.2 and Section 7.2 of this policy.
4.1.2 Gmail data we still hold from before that change
Tormano did previously offer a Gmail connection through Google sign-in. That path has been withdrawn and no new Gmail account can be connected through it, but mailbox content collected through it while it operated is still stored. The Limited Use commitments in 4.1 continue to apply to that historical data in full, for as long as we hold it: it is used only to provide the features it was connected to, it is not used for advertising, it is not sold, it is not transferred except as 4.1 permits, and it is not read by our staff except in the narrow circumstances 4.1 lists. It is also subject to the retention and deletion rules in Section 7.2, and you may have it deleted at any time by disconnecting the account in Settings or by writing to privacy@tormano.com.
4.2 Information About People Who Are Not Our Users. A connected mailbox contains messages from and to people who do not use Tormano and who have no relationship with us: the other side of your correspondence. Their names, their email addresses and the full text of what they wrote are stored in your organization’s workspace along with everything else in that mailbox. We use contact information and other information we receive about non-users through your mailbox and your other Customer Data only to provide the Service to you, and we will not use it to contact, advertise to, or market to those individuals. We do not build a profile of them for our own purposes, we do not add them to any Tormano mailing list, and we do not make them available to any other customer.
4.2.1 We do not sell or share personal information
Tormano does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA. That applies to every category of personal information described in this policy, and it applies specifically to information about people who are not our users received through a connected mailbox. We could not begin selling or sharing personal information without amending this section, notifying you under Section 16, and offering the people concerned an opt-out first. We do not knowingly collect personal information from children (Section 14), and we do not sell or share it.
5. Subprocessors
We use the following categories of subprocessors to deliver the Service: Infrastructure and Hosting: Hetzner Cloud (production hosting in the United States). Payment Processing: Stripe (PCI DSS Level 1 compliant), engaged when your organization purchases a paid plan and when your organization accepts online donations or payments through the Service; because we collect no payment details at signup, no personal data is sent to Stripe when you register an account or during a free trial. Where your organization connects its own Stripe account to accept donations or payments, your organization is the merchant of record for those transactions and Stripe processes payer data as your organization’s own payment processor under your organization’s agreement with Stripe. Email Delivery: SendGrid (transactional and campaign email). Inbound Text Messages: Twilio. Artificial Intelligence: Anthropic; OpenAI (fallback only, if enabled). File Storage and Backups: Backblaze B2. Error Monitoring: Sentry (PII-scrubbed before transmission). Bot Protection: Cloudflare Turnstile. Geocoding: Mapbox, which receives contact postal addresses and returns map coordinates, both when the Service geocodes records in the background and when you open the contact map or look up external data for a record. The U.S. Census Bureau receives a resolved latitude and longitude, and no name, address or identifier, when the Service looks up the census tract for a record; it is a federal agency publishing open data rather than a subprocessor, and it is described on the subprocessors page. Optional Contact Enrichment: People Data Labs, Hunter.io, Apollo.io and Lusha. None of them receives anything unless your organization has connected that provider’s own API key in the Service, each is used only by the organization that connected it, and connecting one does not connect the others. What we send is narrow. To People Data Labs, Apollo.io and Lusha we send a contact’s email address, and that is the only value from your records the request carries. To Hunter.io we send a contact’s email address, to check whether it is deliverable, and separately a company’s web domain, to look that company up. No name, postal address or phone number, and no donation, deal or activity record, is included in any of those requests. When an administrator tests one of these keys before saving it, we send the provider a fixed placeholder address that belongs to nobody, or ask only about the account itself, so testing a key transmits none of your data. These are not AI providers: the organization-level AI switch described in Section 3.6 does not govern them, and enrichment has its own separate control. Customer-Initiated Integrations (engaged only when you connect your own account, and governed by that provider’s own terms): Intuit QuickBooks, Xero, Google Workspace, Google Sheets, Microsoft 365, Microsoft Teams, Slack, Mailchimp, Constant Contact, Eventbrite, Calendly, Zoom, Zapier, Double the Donation (matching-gift screening, which receives a donor’s name, email address, phone number and full mailing address), and Meta Platforms, Inc. (the WhatsApp Business Platform, used only if your organization connects its own Meta Business account).
The authoritative, current list of subprocessors, including purpose, processing location, and compliance posture for each, is maintained at tormano.com/subprocessors. Before we engage a new subprocessor to process personal data, we email you at least 30 days before it begins processing, naming the specific subprocessor being added, and at the same time we publish the change on that page with a revised “Last Updated” date and a dated entry in its change history. That email goes to your account Owner’s address and to every address on the subprocessor notification list. We do not treat publishing that page as a substitute for telling you, and you do not have to watch it to be notified. To add an address to the list, or remove one, email privacy@tormano.com with the subject line “Subprocessor Notifications”. If your organization has accepted our Data Processing Agreement, Section 6.3 of that agreement gives you 30 days to object.
6. Data security
We use technical and organizational measures appropriate to the risk to protect personal information:
- Encryption. Everything travelling between you and the Service is encrypted, on every page and every endpoint. Backups are encrypted and stored off site. Passwords are stored using a modern one-way hashing algorithm and cannot be recovered, even by us.
- Access control. Signing in requires a signed session credential. Within an organization, what each person can see and change is set by their role, module by module. Sign-in attempts are rate limited, and repeated failed attempts against our servers are blocked automatically.
- Audit logging. Changes to data are written to an audit log.
- Application protections. The Service is protected against requests made in your name by another site and against content injected into a page by a third party, and it instructs your browser to apply further protections when it loads.
- Backups. Databases are backed up automatically every day and stored off site, on the rotation described in Section 7.
- Assessment. We carry out regular security audits and vulnerability assessments.
No method of transmission or storage is 100% secure. While we strive to protect personal information, we cannot guarantee absolute security. Our security overview describes this in more detail.
7. Data retention
We retain personal information for as long as your account is active or as needed to provide the Service. Specific retention periods include: (a) Customer Data: retained while your account remains open, except for mirrored mailbox content, which is deleted on a rolling window while your account is open; see Section 7.2, which overrides this paragraph for that data, including during a free trial and during the Subscription Term; after termination, Customer Data is retained for 90 days, during which it remains available for export, and is then deleted from live systems, except where retention is required by law (see the Data Processing Agreement, Section 11). A workspace that is restricted because a free trial ended without a purchase is on the same 90-day clock, counted from the date of restriction: the data stays and remains exportable for 90 days, we send reminders before the deadline, and it is then deleted; (b) Audit Logs: retained for at least 7 years, and an administrator may set a longer period but cannot set a shorter one; (c) Account Information: retained as long as your account exists; (d) Billing Records (which exist only where a purchase has been made): retained for 7 years for tax and legal compliance; and (e) Aggregated/Anonymized Data: retained indefinitely. You may configure custom retention periods through the Service’s Data Retention settings.
7.1 Data from withdrawn features
When we withdraw a feature from the Service, the records it had already created are retained rather than deleted: they remain your organization’s Customer Data, they remain available for export, and they remain subject to the retention periods in this Section and to the rights described in Sections 8 through 11. No new records are added to them. This applies to records created by the features we have withdrawn: the electronic-signature feature, including the signer names, email addresses, IP addresses, browser details and timestamps recorded in a signature audit trail; the help-desk ticket queue, including ticket subjects, message bodies, and the names and email addresses of the people who raised them; proposals and contracts previously created in the Service; the in-browser telephone softphone and its call-recording control; and the live-chat widget and its automated support agent. The Service can no longer record a telephone call or host a chat conversation, and we hold no call recordings and no chat transcripts. You can still log a call yourself as an activity on a record; that is ordinary Customer Data of the kind described in Section 1.1(c), and it contains whatever you put in it. If you would prefer data from a withdrawn feature to be deleted rather than retained, write to privacy@tormano.com and we will delete it, except where we are required to retain it by law.
7.2 Mirrored mailbox content
Mirrored mailbox content described in Section 1.4 is not retained for as long as your account stays open, and this paragraph overrides 7(a) for that data. By default we delete a mirrored message 365 days after it was sent or received, whether or not your account is open and whether or not anyone has asked us to. The deletion runs automatically every day and is not something an organization has to switch on.
The window can be changed, in both directions. An administrator may set the window anywhere from 7 days to 2,555 days, which is 7 years. Shortening it means we delete sooner. Lengthening it means we keep your correspondence, and your correspondents’ correspondence, for up to 7 years, and an administrator can make that choice on behalf of everyone whose mail is in the mailbox. No setting permits indefinite retention: 7 years is a ceiling that cannot be raised from within the Service.
Disconnecting a mailbox deletes its messages immediately. When you disconnect a mailbox in Settings, the mirrored messages for that mailbox are deleted at that moment rather than at the next scheduled run.
Abandoned mailboxes. Separately, we delete the mirrored messages of a mailbox that has been abandoned. A mailbox counts as abandoned only when both conditions hold: it is not currently active (you switched it off, or its sign-in stopped working and was not repaired) and 90 days have passed since the later of its last successful sync and the moment we told you its sign-in had failed. Dating the 90 days from when you were notified, rather than from the last sync, is deliberate: a broken connection is something you can repair, and you should not lose your archive for a fault you were told about last week. An active mailbox is never treated as abandoned no matter how long ago it last synced. When this happens the mailbox’s own settings are kept; only the messages are deleted.
Backups. Mirrored mailbox content is included in our encrypted, off-site backups, which are taken daily and stored with Backblaze B2. Deleting a message from our live systems does not delete it from those backups at the same moment. Backup copies are encrypted, are not accessible from the application, and are not restored into live systems except to recover from a failure of those systems. They age out on more than one schedule: daily database backups and the transaction-log archive are deleted after 35 days; a monthly database snapshot is taken on the first of each month and kept for 12 months. So a deleted record can persist in backup storage for up to about 13 months, depending on when it was deleted relative to the monthly snapshot. Separately, encrypted configuration archives and archived application logs are retained indefinitely; those hold IP addresses and request metadata rather than Customer Data. This applies to every category of personal information we hold, not only mirrored mail.
If you delete a message in your own mailbox at your provider, our mirrored copy does not disappear with it. If you need a mirrored message gone, use one of the controls above: the retention window, disconnecting the mailbox, or a request to privacy@tormano.com.
8. Your rights under the GDPR (EEA and UK)
If you are located in the European Economic Area or the United Kingdom, you have the following rights under the GDPR and UK GDPR:
- Access. To obtain a copy of the personal data we hold about you.
- Rectification. To have inaccurate personal data corrected.
- Erasure. To have your personal data deleted.
- Restriction. To have our processing of your personal data restricted.
- Data portability. To receive your personal data in a portable format.
- Objection. To object to our processing of your personal data.
- Withdrawal of consent. To withdraw consent where our processing rests on it.
- Complaint. To lodge a complaint with your local data protection authority.
How to exercise these rights
Submit requests to privacy@tormano.com. We will respond to your request without undue delay and in any event within one month of receipt, as required by Article 12(3) of the GDPR. This period may be extended by up to two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay. There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.
Where we act as a processor
Much of the personal data we hold is Customer Data that an organization using the Service uploaded or connected: its contacts, donors, volunteers and correspondents. For that data the organization is the controller and Tormano is its processor, so we act on that organization’s instructions. If you contact us about data of that kind, we will tell you which organization holds it and either refer your request to that organization or, where the organization instructs us to, act on it directly. This does not reduce your rights; it identifies who must answer them.
Legal bases for processing
We rely on the following legal bases for the purposes listed in Section 2:
- Performance of a contract, for providing, operating and maintaining the Service, processing transactions and managing your account.
- Legitimate interests, for improving and developing the Service, analyzing usage patterns, and preventing fraud, abuse and security threats.
- Consent, for marketing communications and for optional analytics, where the law requires it.
- Legal obligations, for complying with the law and enforcing our Terms of Service.
International data transfers
Personal data is transferred to and processed in the United States. We rely on the Standard Contractual Clauses approved by the European Commission (Decision 2021/914), the UK International Data Transfer Addendum for transfers subject to the UK GDPR, those same Standard Contractual Clauses as adapted for transfers subject to the Swiss Federal Act on Data Protection (with the Swiss Federal Data Protection and Information Commissioner as the competent authority and Switzerland substituted where the Clauses refer to a Member State), and supplementary technical and organizational measures. Tormano does not rely on the EU-U.S., UK Extension or Swiss-U.S. Data Privacy Framework. The same mechanisms are set out in Section 10 of our Data Processing Agreement.
9. Your rights under the CCPA and CPRA (California)
9.1 When this Section applies to us, and when it does not
Tormano is a business under the CCPA, as amended by the CPRA, for the personal information we collect about our own account holders and website visitors. For the Customer Data an organization uploads or connects, meaning its contacts, donors, volunteers and correspondents, that organization is the business and Tormano is its service provider (see Section 13 of our Data Processing Agreement). If you ask us to exercise a right over information of that kind, we will identify the organization that holds it and either refer your request to it or act on the request at its direction, and we will tell you which we have done. Nothing in this Section reduces your rights; it identifies who is required to answer them.
9.2 Your rights
If you are a California resident you have the right to: (a) know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties to whom we disclose it; (b) delete personal information we have collected from you, subject to the exceptions in Civil Code section 1798.105(d); (c) correct inaccurate personal information; (d) opt out of the sale or sharing of personal information: we do not sell or share personal information, so there is nothing to opt out of; (e) limit the use and disclosure of sensitive personal information (see 9.6); and (f) not be discriminated or retaliated against for exercising any of them. We will not deny you goods or services, charge you a different price, or provide a different quality of service because you exercised a right.
9.3 Categories of personal information we collect, and why
In the preceding 12 months we have collected: identifiers (name, email address, postal address, telephone number, IP address, and account and organization identifiers); customer records described in Civil Code section 1798.80(e) (name, address, telephone number); commercial information (subscription plan and billing history, donation and payment records, deals and transactions); internet or other electronic network activity (pages visited, features used, API requests, server logs, timestamps); geolocation data (latitude and longitude derived from a postal address for the contact map, and nothing derived from a device: we never collect location from your browser or device); professional or employment information (job title, employer, industry); audio, electronic or visual information, only where a user uploads it or connects a conferencing provider that produces it; inferences (contact and lead scores, sentiment scores, forecasts and other AI-generated assessments); and sensitive personal information as described in 9.5. We collect it for the purposes listed in Section 2 and for no other purpose. We do not collect biometric information, genetic data, education records, or information about health, sex life or sexual orientation, and we do not collect protected-classification characteristics such as race, ethnicity, religion or union membership. Where an organization using the Service enters information of one of those kinds into its own workspace, we hold it only as that organization’s service provider and never use it for our own purposes.
9.4 Sources, recipients, and the fact that we do not sell or share
We collect personal information from you; from the organization whose workspace you appear in, including its imports and its own records; from services you or your organization connect, including a connected mailbox, calendar, accounting system or marketing platform; automatically from your browser or device when you use the Service; and from publicly available sources and enrichment providers, where your organization has enabled that. We disclose personal information for business purposes to the subprocessors listed in Section 5 and at tormano.com/subprocessors; to the third-party services you or your organization choose to connect; to professional advisers under confidentiality obligations; and to law enforcement, regulators or other parties where compelled as described in Section 4. We have not sold personal information, and have not shared it for cross-context behavioral advertising, in the preceding 12 months, and we do not do so now, including the personal information of consumers we know to be under 16.
9.5 Sensitive personal information, identified
Two categories of what we hold are sensitive personal information under Civil Code section 1798.140(ae). (a) Account log-in credentials, section 1798.140(ae)(1)(B). This is your Tormano password, which we store only as a one-way hash and never in readable form, and, if you connect a mailbox over IMAP, the app password your provider issued for that mailbox, which we store encrypted because an IMAP connection must re-authenticate on every run (Section 1.4). (b) The contents of mail and email, section 1798.140(ae)(1)(E). If a mailbox is connected to the Service, we store complete message bodies, and we are not the intended recipient of that correspondence. Section 1.4 describes exactly what is stored, who can read it and how to stop it; Section 7.2 describes how long it is kept and when it is deleted. We do not ourselves collect any other category of sensitive personal information, and no field in the Service asks for one: we collect no government identification numbers (our Terms of Service prohibit submitting them), no precise geolocation from a device, no racial or ethnic origin, religious or philosophical beliefs or union membership, no genetic or biometric data, and no information about health, sex life or sexual orientation. That is a statement about what we ask for and what we assemble, and it has one limit: a connected mailbox is correspondence and a free-text note is free text, so where someone has written information of one of those kinds into a message or a record, we hold it because we hold the message or the record. We do not extract it, index it as a characteristic, or use it. As set out in 9.1, information of that kind inside a customer’s workspace is held by us only as that customer’s service provider.
9.6 Right to limit the use of sensitive personal information
The right to limit constrains uses of sensitive personal information that go beyond those permitted by 11 CCR section 7027(m): performing the service requested, security and integrity, short-term transient use, and processing at the direction of the business we serve. We use and disclose sensitive personal information only for those permitted purposes. We do not use it to infer characteristics about you, we do not disclose it for any other purpose, and no AI feature reads a connected mailbox (Sections 1.4 and 3.3). There is therefore no use for the right to limit to reach. We could not begin using sensitive personal information for any other purpose without first amending this Section and offering the right to limit before the change took effect. If you would like us to confirm this position for your own records, or you disagree with it, write to privacy@tormano.com and we will respond within the deadline in 9.8.
9.7 How long we keep each category
We keep personal information no longer than is reasonably necessary for the purpose it was collected for. Specifically: account information and identifiers for as long as the account exists; Customer Data, including commercial, professional and inference categories, while the account remains open and for 90 days after termination, during which it remains available for export, and then deleted from live systems; mirrored mailbox content (the sensitive category in 9.5(b)) for 365 days from the date of the message by default, adjustable by an administrator between 7 and 2,555 days, and deleted immediately when the mailbox is disconnected (see Section 7.2); account credentials (the sensitive category in 9.5(a)) for as long as the account or the mailbox connection exists, and deleted when it is closed or disconnected; internet and network activity in audit logs for at least 7 years, which an administrator may extend but cannot shorten; geolocation derived from an address for as long as the underlying contact record is retained; billing records, which exist only where a purchase was made, for 7 years for tax and legal compliance; records of your acceptance of our legal documents and of any messaging consent or opt-out for as long as we may need them to evidence that agreement or to avoid contacting you again; and aggregated or de-identified data, which no longer identifies anyone, indefinitely. Deleted records persist in encrypted, off-site backups for up to about 13 months after deletion, as described in Section 7.2.
9.8 How to exercise these rights, and when we will answer
Email privacy@tormano.com. We will confirm receipt within 10 business days and tell you how we will process the request, and we will respond substantively within 45 calendar days of receiving it. Where reasonably necessary we may extend that period once by a further 45 days, and we will tell you within the first 45 days that we are doing so and why. There is no charge. A request to know covers the 12 months before the request; for personal information collected on or after January 1, 2022 we will look back further if you ask, unless doing so would be impossible or would involve a disproportionate effort, in which case we will explain why. Before we act we must verify that you are who you say you are, to the standard the request calls for; if we cannot verify you we will tell you so and explain what is missing rather than simply refusing.
9.9 Authorized agents
You may use an authorized agent. The agent should email privacy@tormano.com and provide written permission signed by you. We may also ask you to verify your own identity with us directly and to confirm that you gave the agent permission, both of which the CCPA regulations allow us to require. Neither is required where the agent holds a power of attorney under sections 4000 to 4465 of the California Probate Code. An agent acting for a business rather than for you individually must additionally show its authority to act.
9.10 If you are not satisfied
Write to privacy@tormano.com and we will review the decision. You may also complain to the California Privacy Protection Agency at cppa.ca.gov or to the California Attorney General at oag.ca.gov/privacy.
10. Your rights under the Virginia VCDPA
If you are a Virginia resident, you have the following rights under the Virginia Consumer Data Protection Act (VCDPA): (a) Right to Access your personal data; (b) Right to Correct inaccuracies in your personal data; (c) Right to Delete your personal data; (d) Right to Data Portability (obtain a copy of your personal data in a portable, readily usable format); and (e) Right to Opt Out of targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell personal data or engage in targeted advertising based on personal data.
How to Exercise Your Rights. Submit requests to privacy@tormano.com. We will respond within 45 days. You may designate an authorized agent to submit a request on your behalf.
Right to Appeal. If we decline to take action on your request, you have the right to appeal our decision. To appeal, email privacy@tormano.com with the subject line “VCDPA Appeal” and include a description of the original request and the basis for your appeal. We will respond to appeals within 60 days. If your appeal is denied, you may file a complaint with the Virginia Attorney General.
Sensitive Data. As the controller of information about our own account holders and website visitors, we do not process sensitive personal data as the VCDPA defines it, and if that ever changes we will obtain opt-in consent first. Where we hold information as a processor for an organization using the Service, we process it on that organization’s instructions, and it is that organization’s responsibility to obtain any consent the Act requires. To place contacts on a map, the Service converts a contact’s postal address into latitude and longitude and stores the result. That is precise geolocation within the meaning of the Act. It is derived from an address the organization already holds and never from a device: we never collect location from your browser or device. It is used only to display the map.
11. Other U.S. state privacy rights
Residents of Colorado (Colorado Privacy Act), Connecticut (Connecticut Data Privacy Act), Utah (Utah Consumer Privacy Act), Texas (Texas Data Privacy and Security Act), Oregon (Oregon Consumer Privacy Act), Montana (Montana Consumer Data Privacy Act), and other states with comprehensive privacy laws may have similar rights to those described in Sections 9 and 10 above, including the rights to access, correct, delete, and port personal data, and to opt out of the sale of personal data, targeted advertising, and certain profiling.
To exercise any rights available under your state’s privacy law, contact privacy@tormano.com. We will verify your identity and respond within the time required by applicable law (typically 45 days, with extensions where permitted). We will not discriminate against you for exercising your rights. If we decline to act on your request, we will inform you of your right to appeal (where applicable under your state’s law) and provide instructions for doing so.
Data Protection Assessments. Colorado, Connecticut, Virginia and several other states require a controller to complete a documented assessment before a processing activity that presents a heightened risk of harm: targeted advertising, the sale of personal data, certain profiling, and the processing of sensitive data. For the Customer Data an organization holds in the Service, that organization is the controller and the assessment is its responsibility; our role is to give it the information it needs to complete one, which we commit to in Section 12.1 of our Data Processing Agreement and will do on request. For the personal information we control ourselves, that of our own account holders and website visitors, none of those triggers currently applies: we do not conduct targeted advertising, we do not sell personal data, we do not profile in furtherance of decisions producing legal or similarly significant effects, and we do not process sensitive data of that group. If a trigger begins to apply to us, we will complete and document an assessment before beginning the activity.
12. Cookies, tracking technologies and Do Not Track
We use cookies and browser storage sparingly, in four categories.
- Keeping you signed in. Your session, when it expires, a copy of your own user record (name, email address, role and organization), and a portal credential if you use a client or donor portal. These are essential: without them you could not sign in or stay signed in.
- Getting you back where you were. Three values that last only until you close the tab: the page you were heading to before signing in, a counter that stops a sign-in loop, and, on the registration page, the site you arrived from.
- Your interface preferences. Theme, display density and which one-time notices you have dismissed. On our marketing site, your cookie consent choice and which audience version of the page you read.
- Analytics, on our public marketing pages only, and only if you accept. We use Google Analytics 4 at tormano.com. Analytics is disabled by default for every visitor wherever they are, and loads only after you click Accept on the cookie banner, with IP anonymization enabled. Google’s advertising consent signals are set to denied before any Google script loads, and accepting the banner does not enable them. The application itself, at crm.tormano.com and npcrm.tormano.com, contains no analytics cookies.
If you donate through a form belonging to an organization that has connected Double the Donation, that provider’s employer-lookup widget stores your employer selection in your browser so the form can submit it with your gift. We do not use third-party advertising cookies, tracking pixels from ad networks, or cross-site tracking. Email campaigns may include open-tracking pixels and click-tracking links, which you may disable by opting out of marketing communications. Our Cookie Policy lists every cookie and storage key by name, with its purpose and how long it lasts.
Do Not Track Signals. Some web browsers transmit “Do Not Track” (DNT) signals to websites. Because there is no universally accepted standard for how to respond to DNT signals, we do not currently alter our data collection and use practices in response to DNT browser signals. However, we do not engage in cross-site tracking, third-party advertising tracking, or behavioral advertising, and we do not sell personal information to third parties. You may use the privacy controls described in this Privacy Policy to manage your data preferences.
13. Communication preferences
13.1 Transactional communications
Transactional messages about your account cannot be opted out of while your account is active.
13.2 Marketing communications
You can opt out of marketing at any time, through the unsubscribe link in any marketing email, in your account settings, or by contacting privacy@tormano.com. We honor requests within 10 business days.
13.3 Text message (SMS) communications
Tormano does not send text messages from its own account. We do not send marketing, promotional, transactional or recurring text messages from our own telephone number, and we are not enrolling anyone to receive text messages from us. The opt-in form we previously offered is no longer accepting sign-ups. We continue to hold a registered telephone number that can receive text messages, and we continue to answer the standard carrier keywords on it: if you text HELP, STOP or START to it you will receive the single automated reply described in Section 13.7. Those keyword replies are the only text messages we send on our own account, and we send them because the carrier messaging rules require us to answer them.
13.3.1 Messages an organization sends on its own telephone account
The paragraph above is about messages from Tormano. It is not a statement that no text message can originate from the Service at all. An organization using the Service may connect its own telephone-messaging account, and where it does, the Service can send messages on that organization’s account, from that organization’s number, at that organization’s direction and cost. In that case the organization is the sender and the party responsible for consent, for opt-outs, and for compliance with the Telephone Consumer Protection Act and carrier rules; Tormano processes the message on that organization’s behalf, as described in Section 13.9. Our own platform sending is switched off and stays off. Our handling of them follows the Telephone Consumer Protection Act (TCPA), the CTIA Messaging Principles and Best Practices, and the U.S. A2P 10DLC registration requirements.
13.4 Message frequency
We do not send recurring messages, so there is no ongoing message frequency. You will receive a text message from us only when you text one of the keywords in Section 13.7 to the Tormano number you previously received messages from, and then only one reply to each message you send.
13.5 Message and data rates
Message and data rates may apply. Tormano does not charge you for the keyword replies described in Section 13.3; your mobile carrier’s standard messaging and data rates apply both to any message you send us and to our reply. Carriers are not liable for delayed or undelivered messages.
13.6 We do not share mobile information or messaging consent
Mobile phone numbers and text-messaging consent are not sold, rented, or shared with any third parties or affiliates for their marketing or promotional purposes. No mobile information is shared with third parties for any purpose other than delivering the messages you asked for: we disclose your mobile number to the telecommunications provider that transmits the message on our behalf (Twilio Inc., listed in Section 5 and at tormano.com/subprocessors), which acts as our service provider and is not permitted to use it for its own marketing. We may also disclose it where compelled by law, as described in Section 4.
13.7 How to get help and how to stop
Text HELP to the Tormano number you previously received messages from, or email support@tormano.com. Text STOP to that number to unsubscribe; STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, OPTOUT and REVOKE are all honored, in any capitalization, and are acted on immediately. You will receive one reply confirming that you have been unsubscribed, and nothing after that. You may also withdraw consent by any other reasonable means, including by emailing privacy@tormano.com. Texting START records that you are willing to hear from us again; because we do not currently send text messages, it will not result in any message other than the reply confirming it.
13.8 Records of messaging consent
We are not collecting new messaging consent. Where you gave it previously, we recorded the mobile number you provided, the exact wording of the consent statement you were shown, the action you took, the date and time, the IP address the consent came from, and your browser’s user-agent string, and we still hold that record. We retain that record for as long as we may need it to demonstrate that you asked to receive messages, and after you unsubscribe we retain it as the record of your opt-out so that we do not message you again. You can request a copy of your record, or ask questions about it, at privacy@tormano.com.
13.9 Consent is not transferable
Consent you give to Tormano applies only to messages from Tormano. We do not pass it to, and it does not authorize messages from, any customer organization that uses our Service. Separately, where a customer organization collects text-messaging consent from its own contacts through our Service, that consent is given to that organization, for that organization’s own messages; Tormano processes it on that organization’s behalf as described in Section 5 and does not use it to send you messages of our own.
14. Children’s privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 13 (or under 16 where required by applicable law, including the Virginia VCDPA). If we become aware that we have collected personal information from a child without appropriate parental or guardian consent, we will delete that information promptly. Contact privacy@tormano.com if you believe a child has provided personal information to us.
15. Data breach notification
In the event of a data breach affecting personal information, we will: (a) notify the applicable supervisory authority within 72 hours of becoming aware of the breach where required by GDPR Article 33, and notify state attorneys general and other regulators as required by applicable law; (b) notify affected users without undue delay, consistent with GDPR Article 34 and applicable U.S. state breach notification laws; (c) provide information about the nature of the breach, categories and approximate number of individuals affected, likely consequences, and remedial measures taken or proposed; and (d) take immediate steps to contain, investigate, and remediate the breach. We become aware of a breach at the point we have a reasonable degree of certainty that a security incident affecting personal data has occurred; a short investigation to reach that point does not postpone the deadlines above once it has been reached. Where we hold the affected personal data as a processor on an organization’s behalf, we notify that organization rather than the supervisory authority, on the terms set out in Section 9 of our Data Processing Agreement.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The current version is always published at tormano.com/privacy, and every version carries an Effective Date at the top of the page and names the version it replaces, so you can tell at a glance whether it has changed since you last read it. When we update this policy, this is how you hear about it and what changes for you.
- An in-app notice, on every change. Every update produces a notice in the Tormano notification center of every user of every account, naming the new Effective Date, naming the version it replaces and linking to the updated policy. It cannot be switched off in notification preferences and is not withheld by a quiet-hours setting.
- An email, for a material change. Where we consider the change material, we additionally send that notice by email to the address associated with your account. That email is a transactional legal notice, not marketing: unsubscribing from marketing or newsletter email does not stop it.
- When they are sent. Both are sent when the updated policy is published. This Section does not promise a fixed period of advance warning.
- When a change takes effect. On the Effective Date printed on the updated policy. It is not retroactive: it does not change how we were permitted to handle personal information before that date.
- Information we already hold. Where a change would materially expand how we use or disclose personal information we have already collected, we will not apply it to that information without first obtaining your consent where applicable law requires consent, and where the law instead requires an opportunity to opt out, we will provide that opportunity before the change takes effect for you. This is what Section 4.2.1 relies on when it says we could not begin selling or sharing personal information quietly.
Continued use of the Service after a change has taken effect constitutes acceptance of the updated Privacy Policy.
17. Contact us
F&D Ventures LLC
8401 Mayland Drive #5368, Richmond, VA 23294, USA
Privacy: privacy@tormano.com
Legal: legal@tormano.com
Support: support@tormano.com
For Virginia residents: you may contact the Virginia Attorney General’s office for privacy-related complaints.
For California residents: you may contact the California Attorney General’s office for privacy-related complaints.
For EU and UK residents: you may contact your local supervisory authority regarding data protection matters.