Last updated 2 September 2026

Privacy Policy

1. Who is responsible

Throughline Ltd, company number 13063175, registered office C E M E Innovation Centre, Marsh Way, Rainham, England, RM13 8EU, is the controller for personal data processed to run the ThroughlineOps service and this website. Contact: privacy@throughlineop.co.uk.

For the business data inside your workspace — your orders, your customers’ contact details, your documents — you are the controller and we process it on your instructions to provide the service. This policy covers both roles and says which is which.

2. What we collect, and why

Account data — your name, email address and password (stored as a hash), and the workspace you belong to. Used to run your account. Legal basis: performing our contract with you.

Workspace data— the business records you and your integrations put into the service: orders, products, suppliers, documents, and the business contact details inside them (a buyer’s name on a purchase order, a delivery address on an order). Processed on your instructions as the service’s whole purpose. Here we act as your processor.

Billing data — invoices we issue you, and the billing contact you nominate. We are paid by bank transfer and never take or store card details. Legal basis: contract and legal obligation (accounting records).

Operational logs — sign-ins, actions taken in a workspace (the audit trail your workspace can see), API activity, and errors. Used for security, support and making the product work. Legal basis: legitimate interests in running a secure service.

Support messages — what you send to our support addresses. Legal basis: legitimate interests in answering you.

We do not use your data for advertising, and we do not sell it.

3. Cookies

The application sets the cookies needed to keep you signed in and to secure the session, and nothing else. There are no advertising or third-party analytics cookies, which is why there is no cookie banner.

4. Who processes data for us

Our sub-processors, and what each does:

Supabase — database and authentication. Our databases are hosted in the AWS London region (eu-west-2), so workspace data rests in the UK. Vercel — application hosting.

Resend — email in both directions. Outbound: invites, invoices, purchase orders including their PDF attachments, and — where you dispatch to a warehouse by email — the dispatch instruction, which contains the delivery address. Inbound: if you use the emailed-purchase-order address, Resend receives and stores those messages and their attachments until we collect them.

Google (Gemini API) — the optional assistant and document-understanding features. Two different things are sent, and they are not the same size. When Throughline reads a text purchase order to work out what kind of document it is and what it contains, the extracted text is sent. When the document is a scan or photograph with no selectable text, the whole file is sent to be read — letterhead, signatures and handwriting included. When you use the in-app assistant, the order records needed to answer your question are sent, and those include customer names and order references. Nothing is sent to Google unless one of those features is used, and no data is sent for advertising.

Some of these providers are US companies; where data leaves the UK we rely on the safeguards in their terms — the UK extension to the EU–US Data Privacy Framework or standard contractual clauses, as applicable to each.

If you would rather no workspace content left our own infrastructure, you can switch these features off yourself, at any time, in Settings under “Acting Without You”. With them off, nothing from your workspace is sent to the AI provider — the assistant and document understanding decline instead of calling out — and everything else in Throughline works without them. If you would rather we did it for you, or want it set before you start, tell us at privacy@throughlineop.co.uk.

Separately, the integrations you connect — sales channels, marketplaces, warehouses, accounting systems — receive and send data on your instructions. They are your providers, under your agreements with them, not our sub-processors.

5. How long we keep it

Workspace data is kept while your workspace is live, and made available for export for a reasonable period after termination before deletion. Invoices and accounting records are kept for the six years UK law requires. Operational logs are kept only as long as they are useful for security and support.

6. Your rights

Under UK GDPR you can ask for access to your personal data, correction, deletion, restriction, portability, or to object to processing based on legitimate interests. Write to privacy@throughlineop.co.ukand we will respond within a month. If the data sits in a customer’s workspace where we are the processor, we may need to route your request through them as controller.

You can also complain to the Information Commissioner’s Office (ico.org.uk), though we would rather you told us first.

7. Changes

When this policy changes materially we will notify workspace owners by email or in the application. The date at the top is the date the content last changed. Our Terms of Service say how the service itself is provided.