Legal
Privacy
Last updated:
Read or download the October 4, 2026 legal documents. The dated archive preserves this release; your order or acceptance record identifies the documents that apply to you.
Timastra.com does not use advertising trackers. We count visits with first-party, aggregate statistics built from our hosting logs, without analytics scripts or cookies of our own. Pricing pages load Paddle's scripts only after you choose to request local prices; checkout pages load them when a payment is requested. The homepage loads payment recovery only after you choose to open it. These services may use their own cookies or similar technologies (see Payments and checkout providers below). You can browse without creating an account.
Information handled by this website
Timastra LLC, 5830 E 2nd St, Ste 7000 #38687, Casper, WY 82609, US, is responsible for the information described here. This policy covers timastra.com, central Timastra sign-in at auth.timastra.com, support correspondence and the support portal, and the account and purchase information Timastra handles to administer its products. Each Timastra product has product-specific privacy information describing the data it handles, its purpose, permissions, retention and deletion process. Customer organizations control their own workspace records; Timastra processes those records under the data processing agreement.
Our hosting and security provider, Cloudflare, processes routine request information, including IP address, browser details, requested URL and timestamps, to deliver, protect and diagnose the website. Our request logs leave out URL query strings. If a page fails, our operations service records only that an error occurred, not the page address or visitor details, so we can fix it.
Site traffic statistics
Once a day, our operations service turns the hosting provider's request records into aggregate statistics: request counts, pages requested, visitor countries and the names of the networks requests came from, such as an internet provider or hosting company. We use them to understand which pages are useful and to spot automated or abusive traffic.
To name a network, the service briefly looks up each requesting IP address in Team Cymru's public IP-to-network directory, which receives the address as a DNS query. IP addresses are not stored in the statistics or included in the report. Each daily summary is kept for no more than 30 days and is emailed to Timastra through Resend, our email delivery provider. The statistics are not used to identify or profile individual visitors.
Appearance preference
When you choose light or night mode, this browser saves your choice in local storage on your device so it can be used on your next visit. This setting is not sent to Timastra or used for tracking. You can change it with the appearance switch or remove it by clearing this website's site data in your browser. Without a saved choice, the site follows your device's appearance preference.
Email communications
If you email us, we receive your message, attachments, email address and message metadata. We use them to reply, keep necessary business records, protect our rights and meet applicable legal obligations. Share only what is needed for your request; leave out payment credentials and sensitive personal records.
Central Timastra sign-in
Timastra runs auth.timastra.com for products that use a shared sign-in account. Timastra controls the account information needed to register you, authenticate you, maintain secure sessions, connect the products you authorize and handle account recovery and privacy requests. This is separate from the records a customer organization controls inside its workspace.
Sign-in handles your email address, profile and verification status, authentication credentials and security settings enabled for the account, session and authorized-product information, and security activity such as request times and IP addresses. Sign-in and recovery messages use your address and necessary delivery information. The particular sign-in features depend on the service configuration.
Sign-in runs on Timastra's servers in Singapore, behind Cloudflare, and service email is delivered through Resend. Deleting one product's records does not automatically delete a central sign-in account used by other products. Email support@timastra.com to request account access, correction or deletion. We verify authority, identify linked products and explain any records that must remain. Product workspace records, purchases, support cases and backups have separate deletion and retention rules.
Support portal
At support.timastra.com, we receive your email address, product, request category, message and optional app/device details or files. We use them to answer and manage your request. A secure email link and an essential session cookie let you view your own conversations. Private operator notes and other customers' requests are not shown to you. We do not use this cookie for advertising.
Cloudflare hosts the portal, case database and private file storage; the database and files use its Asia-Pacific region. Uploaded images are re-encoded to remove metadata, and files remain unavailable for download until malware scanning passes. Scanning runs on our netcup server in Singapore without retaining a separate file copy. Resend delivers support messages and sign-in links. Incoming support email is also forwarded to the owner's Google Gmail mailbox so it can be handled if import fails; email attachments should be replaced with private portal uploads where appropriate.
After you verify your support email, an operator may request limited read-only context from the product: current authorized workspace membership, role, plan and subscription status. The product independently checks your verified account and membership. This does not grant access to your bookings, financial records or account credentials. Leave out passwords, tokens, recovery keys and sensitive personal records.
Interactive demos
This website links to interactive demos and sample walkthroughs. It no longer collects manual demo requests. Demos use sample records and run on a separate test server Timastra rents from OVHcloud in Canada. That server's access logs record visitor IP addresses, browser details and requested pages; we use them to secure the demos and to count demo visits. Each demo application explains its own data handling. Use sample records when exploring a demo.
Payments and checkout providers
This website does not collect card or bank details. Where a product uses Paddle checkout, the Paddle entity named in your checkout and receipt is the merchant of record for that order: it sells the product to you, processes the payment, handles sales tax and issues approved refunds. Paddle's buyer terms identify the contracting entity according to the buyer's location. For checkout, Paddle is an independent controller of the details you give it.
Paddle's script (Paddle.js) loads on timastra.com/pay when a product sends you to complete a payment. On product pricing pages, choosing "Show local prices with Paddle" loads the script to request a quote. Reading a pricing page alone does not contact Paddle for a quote. On the homepage, choosing "Open Paddle payment recovery" loads Paddle Retain, including scripts delivered through Paddle's ProfitWell infrastructure. Reading the homepage alone does not load that recovery service. This lets customers returning from a recovery email update their payment method. When these scripts load, Paddle receives your IP address and browser details; it also uses approximate country for local prices and taxes and information needed to prevent fraud. If you check out or update a payment method, Paddle also receives the billing and payment information you provide. Paddle may use its own cookies or similar technologies to run checkout and payment recovery. See Paddle's privacy notice.
From Paddle or another payment processor, we may receive limited transaction information such as a customer name, contact details, billing address, country, payment status, amount, currency, card brand and last four digits, but never a complete card number or security code.
Requesting a quote, checkout or payment recovery requests that feature; it does not give consent to unrelated advertising or analytics. You can browse product descriptions and published list prices without loading these optional payment scripts. Provider-specific storage, duration and purposes follow the provider's notice and the feature used; contact us if you need that information before proceeding.
If your product's checkout names Creem or Dodo Payments, that provider handles your purchase under its own buyer terms and privacy notice. It receives the billing, transaction and device information needed for payment, tax, fraud prevention and subscription management, and shares purchase and subscription status with Timastra to administer access and support. See Creem's privacy notice and Dodo Payments' privacy notice. These providers are used only where the product offers that checkout; this website does not load their checkout scripts merely because you visit this policy.
Financial-account connections
Where a product offers an optional financial-account connection, it explains the provider, purpose, data categories, requested accounts and access duration before connection and obtains any required consent. We request only the access needed for the feature, never ask you to email bank credentials, and provide a way to request disconnection or deletion where applicable.
How information may be shared
We may share information with service providers that host, secure, communicate for, or support the site, including Cloudflare (hosting and security), Resend (email delivery), netcup and OVHcloud (server hosting) and Team Cymru (network name lookups); with Paddle when its pricing, checkout or payment-recovery scripts load or you use those features; when you direct us to; or when required to protect rights, prevent abuse, or comply with law. We do not sell personal information or share it for cross-context behavioral advertising.
Legal bases
Where laws such as the EU or UK GDPR apply, we rely on:
- legitimate interests to run, secure and improve the website, reply to general enquiries and keep business records, including request logs and aggregate traffic statistics;
- contract to answer requests you make before an order, and to provide orders, access and support;
- legal obligation to keep tax, accounting and other records the law requires; and
- consent where we ask for it. You can withdraw consent at any time without affecting earlier processing.
International transfers
Timastra LLC is a United States company managed from the United States and the Philippines. Our hosted products run on servers in Singapore (netcup), behind Cloudflare, with encrypted backups in Cloudflare R2's Asia-Pacific region. Service email is sent through Resend from its Tokyo, Japan region. Demos run on a server in Canada (OVHcloud). Cloudflare, Paddle and Resend also process information in the United States and other countries. See the sub-processor list.
Where EU, UK or Swiss transfer rules apply, an applicable transfer mechanism must be established before the affected transfer. Depending on the actual parties, roles and destinations, this may require the European Commission's standard contractual clauses, a UK transfer instrument, applicable Swiss adaptations and a transfer assessment, or another legally permitted mechanism. This notice does not establish that a particular customer's instruments or assessment have been completed. Ask support@timastra.com for applicable information and, where relevant, how to obtain a copy of the safeguards. The data processing agreement describes the requirements for workspace transfers.
Retention
- Website request logs: kept in Cloudflare Workers Logs for up to 7 days, as set by Cloudflare's log retention. Cloudflare may keep its own security and network records under its own policies.
- Site traffic statistics: no more than 30 days.
- Enquiry and support emails: kept while the conversation or customer relationship continues, then deleted within 24 months of the last contact, unless a record must be kept longer for tax, accounting, legal claims or to show how a privacy request was handled.
- Support portal case content and files: our retention policy is 180 days after closure for ordinary cases and 730 days for security or account-recovery cases. Removal is reviewed by an operator. A documented legal, security or dispute hold suspends removal. Minimal audit records remain without the removed message content. Mailbox copies follow the separate email retention above; provider recovery copies may persist for their recovery period. Restoring a backup invalidates old sign-in authority and reconciles current retention and holds before use.
- Order and billing records: kept for as long as tax and accounting laws require.
- Appearance preference: stays in your browser until you clear it.
- Central sign-in: account information supports your active account and its security; closing an account requires a separate review of linked products, security and privacy-request records, and backup copies. The published policy does not currently specify fixed periods for every account, security-audit and backup category. A deletion response identifies the affected records, required retention grounds and expected disposal; ask support for the applicable schedule before providing information that requires a fixed deadline.
Security
We use technical and organizational safeguards appropriate to the information we handle. See Data & security for the website's safeguards and how to report a security issue.
Your choices and rights
Visit Account & data deletion for a direct email request path, or Product support for other help. You do not need a website account to contact us.
Depending on where you live, you may have rights to ask about, access, correct, delete, or restrict certain uses of your personal information, to object to processing based on legitimate interests, and to receive a copy of information you gave us. You may also withdraw consent where processing depends on consent. We answer within one month, extendable where the law allows. We may need to verify a request and may retain information when law permits or requires it.
If you are in the EU or UK, you can also complain to your local data protection supervisory authority, such as the authority in the country where you live or work. In the UK, that is the Information Commissioner's Office. We would appreciate the chance to address your concern first.
Where the Philippine Data Privacy Act applies, you may also lodge a complaint with the Philippine National Privacy Commission. You do not have to obtain Timastra's permission to contact a competent authority.
Changes
We update this page when our data practices materially change and revise the date above.
Questions
Email Timastra's data protection contact at support@timastra.com.