VerbatermBetaVerbaterm is in beta. You may encounter bugs, incomplete features, or unexpected results while we improve reliability.

Privacy policy

Toggl Track

Review these first

Score63.0
Reviewed
Policy typePrivacy policy
Concern findings8
Protections2
Source supportStrong

Source provenance

Verified official source
Retrieved
Last checked
PublishedAutomated refresh
Source URLhttps://toggl.com/legal/privacy/

Canonical URL: https://toggl.com/legal/track/privacy/

What changedMaterial language shifts detected around personal data, privacy, share your, terminate. 57 new line(s), 78 removed line(s).

Snapshot hash e4923b74e9f99bebaf98fbab3049ec18e43325dd728611f2cc21f369bf84f929

Snapshot of the source text at fetch time, not a live mirror of the policy page.

Plain-English summary

The company cannot guarantee absolute safety for your Personal Data, and it may be disclosed to authorities without your knowledge or responsibility for third-party practices. If you fail to provide required data, your service may be canceled. Also, you cannot opt out of essential service messages.

87% confidence

Ask Verbaterm

Follow up on findings with grounded answers from this review. Not legal advice.

Risk Flags

3 findings

Critical issues that need immediate attention. These are often indicators of potential legal or financial risk, or significant privacy concerns.

high95% confidence

No Guarantee of Data Security

The company cannot guarantee that your Personal Data will be absolutely safe from unauthorized or unlawful processing or accidental loss, alteration, or destruction during transmission over the internet, while stored in their systems or those of their service providers, or while otherwise in their care.

Why it matters: Your personal data may be vulnerable to unauthorized access, loss, alteration, or destruction, despite the company's efforts.

However, please be aware that no security measure is perfect. Our efforts notwithstanding, we cannot guarantee that your Personal Data, during transmission over the internet or while stored in our systems or those of our service providers or while otherwise in our care, will be absolutely safe from unauthorised or unlawful processing or accidental loss, alteration or destruction, or that they will indeed be intact and confidential at all times or shortly available after any Service incident.

Personal Data Security, paragraph 1 · Citation strength: strong

medium95% confidence

Data Disclosure Without User Notification

The company may be legally obliged to disclose your Personal Data and may not be permitted to inform you about such disclosure.

Why it matters: Your personal data may be disclosed to authorities without your knowledge or consent, limiting your ability to control your information.

We may find ourselves in a situation where we are legally obliged to disclose some or all of your Personal Data or where we reasonably believe that we are so obliged. This may be the case if we receive an Information request from an authority or there is a law or regulation that requires us to make a disclosure without specific request (e.g., to comply with national or international measures against terrorism or money laundering).

Disclosure of Personal Data, paragraph 1 · Citation strength: strong

medium95% confidence

Responsibility for Third-Party Data Sharing

The company states they are not responsible for the privacy practices, acts, or omissions of third-party service providers with whom your Profile Information or Billing Information may be shared.

Why it matters: If you integrate third-party services, your shared data will be subject to those third parties' privacy practices, and the company will not be responsible for any issues arising from their handling of your data.

And please note that we are not responsible for the privacy practices (or other acts or omissions) of such third-party service providers, so it would be advisable for you to make sure, before the integration, that you trust the service and the provider in question and are satisfied with the provider’s policies.

Disclosure of Personal Data, paragraph 1 · Citation strength: strong

Data Use

3 findings

This section outlines how your data is collected, processed, and shared. It focuses on the purposes for data use, user consent, and data retention policies.

medium95% confidence

Broad Discretion for Anonymous Data Use

If information is anonymous or de-identified, the company may collect, use, disclose, and otherwise process it for any purpose.

Why it matters: The company has broad discretion to use your anonymous or de-identified data for any purpose, which could include various forms of analysis or sharing without specific limitations.

If Information is anonymous or de-identified, we may collect, use, disclose and otherwise process it for any purpose.

Purposes and grounds for Information processing, paragraph 1 · Citation strength: strong

medium90% confidence

Broad Data Sharing During Business Transactions

If the company engages in or is subject to a merger, acquisition, or similar transaction, your Personal Data may be shared with or transferred to their counterparties or other relevant participants, subject to standard confidentiality arrangements.

Why it matters: Your personal data could be shared with or transferred to other entities as part of business transactions like mergers or acquisitions, potentially exposing it to new parties.

If we engage in or are subject to a merger, acquisition, division, transformation, public offering of our securities, obtaining financing, divestiture of all or substantially all of our assets or a significant part of such assets, transfer of the enterprise or a part of the enterprise to which your agreement with us pertains, or a similar transaction or proceeding, or if we take steps in contemplation of such activities (e.g., submit to due diligence), your Personal Data may, subject to standard confidentiality arrangements, be shared with, or transferred to, our counterparties or other relevant participants in the respective transaction or proceeding.

Disclosure of Personal Data, paragraph 1 · Citation strength: strong

low95% confidence

Sharing Profile and Billing Information within an Organization

If you invite another User to your Organization or join someone else’s Organization, you are instructing the company to display certain of your Profile Information (which may include your name, address, email address, profile picture, country of residence, time zone, and telephone number) and, if applicable, Billing Information (including your name, billing address, billing email address, VAT number, and the last four digits of your credit card number) within the Organization, allowing other Users access based on their privileges.

Why it matters: When you join or invite others to an Organization, your profile and billing details, including the last four digits of your credit card, may be visible to other Users within that Organization.

If you invite another User to your Organization or join someone else’s Organization, you are instructing us to display certain of your Profile Information (which may include your name, address, email address, profile picture, country of residence, time zone and telephone number) and, if applicable, Billing Information (including your name, billing address, billing email address, VAT number and the last four digits of your credit card number) in the Organization such that other Users may or will have access to them (depending on their User privileges).

Disclosure of Personal Data, paragraph 1 · Citation strength: strong

Cancellation and Renewal

1 finding

This section examines the policies related to account cancellation, service termination, and subscription renewals, including any associated costs or notice periods.

medium95% confidence

Cancellation of Service Due to Failure to Provide Data

If you fail to provide Personal Data when requested, particularly data required by law or under contract, the company may not be able to perform or enter into the relevant contract, and they may have to cancel a product or service you have with them.

Why it matters: Failure to provide requested personal data may lead to the cancellation of your products or services, potentially disrupting your use.

Where we need to collect your Personal Data by law or under the terms of a contract we have with you, or in order to enter into such a contract, and you fail to provide those data when requested, we may not be able to perform or enter into the relevant contract (which may be a contract for the provision of the Service or some other benefit). Should that be the case, we may have to cancel a product or service you have with us, but we shall let you know at the time if that applies.

Failure to provide Information, paragraph 1 · Citation strength: strong

Gotchas

1 finding

Unexpected or less-than-obvious clauses that could be disadvantageous to the user. These often include limitations of liability, disclaimers, or terms that might surprise users.

medium95% confidence

Inability to Opt-Out of Essential Service Messages

There are some Service Messages that are part of the Service and which you cannot opt out of receiving unless you unsubscribe from the Service.

Why it matters: You may be required to receive certain service-related communications, and the only way to stop them is to cancel your subscription to the service entirely.

There are, however, some Service Messages that form part of the Service and which you cannot opt out of receiving unless you unsubscribe from the Service.

Other Information, paragraph 2 · Citation strength: strong

Protections

2 findings

Safeguards and rights that benefit the user, enhancing their privacy, security, and control over their data.

Protection95% confidence

No Known Collection of Data from Children Under 13

The Services are not directed to children, and the company states they do not knowingly collect personal data from children under 13 (or under the higher minimum age of digital consent where required by local law, which in the EEA/UK can be up to 16).

Why it helps: This commitment helps protect the privacy of children by explicitly stating that the service is not intended for them and that data from those under the specified age is not knowingly collected.

Our Services are not directed to children. We do not knowingly collect personal data from children under 13 (or under the higher minimum age of digital consent where required by local law, which in the EEA/UK can be up to 16).

Table of Contents, paragraph 3 · Citation strength: strong

Protection95% confidence

Commitment to Data Deletion Upon Request for Children's Data

If you believe that a child has provided us with personal data, the company will take appropriate steps to delete such data.

Why it helps: This provides a mechanism for parents or guardians to request the deletion of a child's personal data if it was inadvertently provided, adding an extra layer of protection for minors.

If you believe that a child has provided us with personal data, please contact us and we will take appropriate steps to delete such data.

Table of Contents, paragraph 3 · Citation strength: strong

Report an issue

Flag a citation problem, stale policy text, or incorrect company match.

Verbaterm boundaries

This public review is informational only and is not legal advice. Verbaterm shows only findings tied to the cited source snapshot above.