Source
Legal notice — Toggl Plan
Checked for Toggl Plan on 5 Oct 2026
- Page
- https://toggl.com/legal/track-privacy-policy
- Checked
- 5 Oct 2026, 05:08 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:a9db03c32ade9702e8b75da7273c3c9f25090d0d783664fbcbda6cd6e130fd52
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Processing location Report an error
“all data processing operations relevant to that relationship have been delegated to Toggl OĆ (a company based in Estonia, with its processing operations also in Estonia).”
-
Timeline autotracker Report an error
“Certain features of the Service (specifically, Timeline and Autotracker), if enabled, will automatically record (Timeline) or monitor (Autotracker) what other applications you use or which websites you visit during your Service sessions”
-
API token Report an error
“an application programming interface token (API token) is automatically generated and stored under your User Account (this is an authentication token that you can use for accessing the Service through other software)”
-
Google API policy Report an error
“When accessing Google user data, Toggl's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.”
-
Payment storage Report an error
“if you give the payment service provider credit card details, the last four digits of the credit card number are stored in the Organization under subscription billing info.”
-
Retention financial Report an error
“contract and billing records relevant to our accounting or taxation (which is likely to be the case upon some of the Personal Data under the Profile Information and Billing Information categories) are generally kept for at least seven years after the primary purpose for their processing ceases to apply”
-
Retention logs Report an error
“Backups, system, and application logs are retained for shorter operational periods (usually up to 90 days unless required for security investigations or the establishment and defence of legal claims).”
-
Deletion on expiry Report an error
“Once the applicable retention period expires, Personal Data is securely deleted or irreversibly anonymised.”
-
International transfers Report an error
“we rely on one or more of the following mechanisms: (1) adequacy decisions, where the European Commission has determined that the recipient country ensures an adequate level of protection, including participation in the EU-U.S. Data Privacy Framework, as applicable; (2) where no adequacy decision applies, the European Commission Standard Contractual Clauses, appropriately supported by transfer impact assessments and supplementary measures; (3) in limited cases, we may rely on another legal basis for transfer permitted by law (e.g., your explicit Consent).”
-
Marketing optout Report an error
“As for Marketing Messages, you can always opt out of receiving these, but the variety of procedures for doing so may depend on the nature of the message and whether you have a User Account.”
-
Retention consents Report an error
“Marketing-related consents are kept until withdrawn.”
9 facts read from this page are not shown because they could not be confirmed on the page as captured.