legal · privacy

Privacy Notice

This notice explains which personal data Thway uses, why it is used, where billing data is processed, and what happens when an account is deleted.

pre-launch draft

This document requires accountant and legal approval before live purchases are enabled. Missing company details must also be supplied through the deployment environment.

Provider
[LEGAL_COMPANY_NAME not configured]
[LEGAL_CVR not configured]
Contact
[LEGAL_ADDRESS not configured]
01

Who is responsible

The provider identified at the top of this notice is the controller for personal data processed to operate Thway. The final legal entity, address, CVR, privacy contact, and any required data-protection disclosures must be completed before launch.

02

Data we process

  • Account data: name, email address, authentication provider, verification state, and password hash where password sign-in is used.
  • Route data: saved routes, route settings, generated day segments, and share references you create.
  • Billing summaries: Stripe customer, subscription, product, price, invoice identifiers, subscription status, billing period dates, and synchronization timestamps.
  • Support data: messages, contact details, ticket history, and limited hashed technical information used to prevent abuse.
  • Technical data: security, error, and operational logs needed to run and protect the service.

Thway does not receive or store complete card numbers. Payment credentials and detailed payment records are collected directly by Stripe on Stripe-hosted pages.

03

Why we use data

We use personal data to:

  • create accounts and provide route-planning functionality;
  • authenticate users and protect the service from abuse;
  • create Checkout and billing-portal sessions and reconcile Stripe subscription events;
  • respond to support requests and service communications;
  • comply with accounting, consumer, tax, security, and other legal obligations;
  • diagnose faults and improve reliability.

The expected legal bases include performance of a contract, steps requested before entering a contract, legitimate interests in security and service operation, consent where specifically requested, and compliance with legal obligations. Final purpose-by-purpose legal-basis wording requires review.

04

Stripe and other providers

Stripe processes payment and billing data when you subscribe or use the billing portal. Stripe may act as an independent controller for parts of its payment, fraud-prevention, and legal-compliance processing. Review the Stripe Privacy Policy for its current practices.

We also use infrastructure, email, authentication, mapping, and database providers where needed to operate Thway. The final notice must identify categories or providers, international transfer safeguards, and processor arrangements with sufficient specificity after the production stack is confirmed.

05

Retention and account deletion

Account and saved-route data is generally retained while your account exists, then deleted or de-identified when the account is deleted, subject to backups, legal obligations, disputes, and security needs. Support records and technical logs are retained only as long as reasonably necessary for their stated purposes.

Before local account deletion, Thway checks Stripe and immediately cancels active subscriptions. Local billing mappings are then deleted with the account. The Stripe Customer, invoices, and related financial records may be retained by Stripe or Thway where required for accounting, fraud prevention, dispute handling, or law.

Webhook deduplication records retain only limited event identifiers, types, object identifiers, API version, mode, and processing times; complete payment payloads are not stored in that table.

06

Your rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to processing, and to receive certain data in a portable format. Where processing relies on consent, you may withdraw that consent without affecting earlier processing.

Contact us to exercise a right. We may need to verify your identity. You may also complain to Datatilsynet or the competent supervisory authority in your country. The final notice must include the appropriate complaint details and response procedure.

07

Choices and security

You can update profile and billing details through account settings and Stripe's portal, cancel a subscription, or delete your account. Authentication cookies are required to keep you signed in; any non-essential analytics or marketing cookies must not be enabled without the consent required by law.

We use access controls, encrypted transport, signed webhook verification, data minimization, and other safeguards appropriate to the service. No system is completely secure, so please use a unique password and contact us if you suspect misuse.

08

Related terms and updates

Billing-specific information appears in the Subscription Terms, and general service rules appear in the Terms of Service.

We may update this notice when processing changes. Material changes will be communicated as required by law, and the review date will be updated.

Draft reviewed 29 July 2026Questions · contact us