Privacy Policy

Last updated: 9 July 2026

This policy explains what Tollan processes to operate secure device access, what passthrough traffic it does not inspect, how long data is kept, and the rights you have. Tollan (tollan.ie) is the controller for this data; contact us at support@tollan.ie.

What we never see

Passthrough traffic is never decrypted at the relay. We route by TLS SNI without reading a single byte of your payload.

What we process

CategoryWhy
Account (email, hashed password, optional 2FA secret)Authenticate and secure your account
Organization & membershipMulti-tenant access control
Device & route metadataOperate tunnels and identity
Traffic summaries: per-interval byte and connection counters, source IP truncated to its network (never a full address), country-level locationMetering, quotas, and abuse protection — never payload content
Billing details: plan, subscription status, invoicing recordsCharge for paid plans and meet tax and accounting law
Contact-form messages (name, email, message, sender IP)Answer your enquiry and filter abuse
Audit logsSecurity and accountability

Payments

Paid plans are billed through Stripe, our payment processor. Your card details go directly to Stripe; we never see or store full card numbers. We keep the subscription and invoicing records needed to run your plan and to meet legal obligations. Stripe processes payment data under its own privacy policy.

Cookies and tracking

This website sets no cookies and loads no third-party trackers or analytics. The console uses only what is needed to sign you in and keep your session secure.

Legal bases

We process data to perform our contract with you (accounts, tunnels, billing), for our legitimate interests in securing and metering the platform and preventing abuse, to comply with legal obligations (tax and accounting), and with your consent where the law requires it — for example when you write to us first through the contact form.

Sharing

We do not sell personal data. We share it only with the providers needed to run Tollan — payment processing, email delivery, and hosting — under contracts that restrict what they may do with it, and with authorities where the law requires. Where data leaves the European Economic Area, we rely on recognized safeguards such as adequacy decisions or standard contractual clauses.

Retention

Account and configuration data live for the life of the account. After cancellation, data is kept briefly to allow reactivation, then deleted, except where longer retention is legally required — for example invoicing records kept for tax law. Traffic summaries are kept for a limited period for metering and abuse protection, then pruned. Contact-form messages are kept as long as needed to handle the enquiry.

Your rights

Under EU data-protection law (GDPR) you may access, correct, export, delete, or object to the processing of your data. Deleting an organization revokes its certificates, drops its routes, and de-links its audit trail. Contact support@tollan.ie to exercise any right. You may also lodge a complaint with your supervisory authority — in Ireland, the Data Protection Commission.