Who we are
This notice applies to the IndexToast website, dashboard, integrations, and MCP service. It explains the information used to provide the service and the choices available to account holders.
Information we use
We use account details such as your name and email address; the domains and URLs you connect or submit; content identifiers, content type, title, timestamps, usage records, technical diagnostic results, MCP token prefixes, permissions and last-used timestamps; and messages you send to support.
We do not ask the WordPress connector to send post bodies, passwords, drafts, private content, password-protected content, or website credentials. MCP access secrets are shown once and stored as a cryptographic digest.
Why we use it
We use this information to create and secure an account, connect a website you authorise, provide submissions and technical checks, show usage and history, prevent abuse, respond to support requests, and send the notifications you choose.
Where applicable, we process service data to perform our agreement with you, meet legal obligations, and protect the security and reliability of the service. Optional product updates are controlled in account notification settings.
Service providers
We use carefully selected providers for hosting and infrastructure, payments, email delivery, analytics, and technical data processing. They may process data only as needed to provide their service to us and subject to appropriate safeguards.
Payment card details are handled by the payment provider, not stored by IndexToast. Product analytics uses named product events, respects browser Do Not Track, uses sampled privacy-masked session replay, error diagnostics and page-speed measurements, and measures public page paths, referral sources, campaign tags, and product actions. Analytics excludes submitted customer URLs, URL query strings, content titles, passwords, website tokens, and credentials. Signed-in activity uses an internal user identifier rather than your email address. Replay masks customer text and hides forms, tables and credentials; authentication and private shared pages are excluded. Automated replay analysis helps identify visible navigation problems.
Retention and security
We retain information while an account or connected website is active, then only for as long as needed for legitimate operational, legal, accounting, security, or dispute-resolution purposes. Account sessions can remain active for up to 60 days unless you sign out or they are revoked.
We use technical and organisational measures designed to protect service data. Keep your account password, WordPress administrator access, and MCP tokens secure, and revoke credentials you no longer use.
Your choices
You can update your profile and notification preferences in the dashboard, disconnect a website, and request account data export or deletion through the account support area. Some information may need to be retained where the law requires it or to resolve a security or billing issue.
Changes and contact
We may update this notice as the product or applicable requirements change. If a material change affects how we use personal information, we will update this page and, where appropriate, notify account holders. For a privacy request, sign in to your IndexToast account and use the account support route, or email hello@indextoast.com.