Back to home

Privacy Policy

Updated 3rd June, 2026

This Privacy Policy explains how Toaast collects, uses, stores, and protects personal data when you use our Service. By accessing or using Toaast, you agree to this Privacy Policy. Toaast is designed for professional, adult users. It is not intended for children under 16.

Contact information:CastlePlan AB ("Toaast", "we", "us", or "our")Borås, SwedenService: Toaast — group cards for the workplaceWebsite: https://toaast.co

Definitions

What we collect

Data you provide

When you create an account or use Toaast, you may provide:

Data from contributors

When someone signs a card via a public link, we collect their name, their email address, and the message, GIF, and stickers they add to the card. This data is provided directly by the contributor and is associated with the card it was added to.

Usage data

We collect usage information about how you interact with Toaast, such as logins and timestamps, device information, IP address, session and performance metrics, feature usage, and error diagnostics. This helps us operate, secure, and improve the Service.

How we use personal data

We process Personal Data to:

We do not use your content to train AI models.

Legal bases (GDPR)

If you reside in the EEA/UK, we process Personal Data on the following bases:

Sharing personal data

We share data only as necessary to operate Toaast:

We never sell Personal Data.

Subprocessors

We use the following trusted third parties to operate the Service:

Each subprocessor processes data only on our instructions under data processing agreements that meet GDPR requirements.

International transfers

Toaast is operated from Borås, Sweden. Data is processed within the EU or in the US. For EEA/UK users, transfers rely on Standard Contractual Clauses (SCCs) and other legally recognized mechanisms.

Data retention

We keep Personal Data only as long as necessary to provide the Service, meet legal and regulatory requirements (e.g. Swedish accounting law requires 7 years of payment records), resolve disputes, and enforce agreements. When no longer needed, data is deleted or anonymized.

If you delete your account, your data will be removed within 90 days, except where law requires longer retention.

Security

We use industry-standard technical and organizational measures, including:

No system is 100% secure; we cannot guarantee absolute protection.

Your rights

Depending on your jurisdiction, you may have rights to:

To exercise your rights, email support@toaast.co.

Children's privacy

Toaast is not intended for children under 16. If we become aware of unintended collection, we will delete the data.

Cookies

We use cookies and similar technologies to operate and improve the Service:

You can manage cookies through your browser or our cookie consent banner.

Changes to this policy

We may update this Privacy Policy periodically. The "Updated" date will indicate the latest version.

Contact us

CastlePlan ABBorås, SwedenEmail: support@toaast.co