Privacy Policy

Tonomo Privacy Policy

Effective Date: July 16, 2025

1. IntroductionThis Privacy Policy ("Policy") describes how Tonomo, operated by Autonomo LLC ("we," "our," or "us"), collects, uses, and discloses information in connection with your use of our website and online services (collectively, the "Service"). By using the Service, you agree to the terms of this Policy. If you do not agree with this Policy, please do not access or use the Service.

For the purposes of the General Data Protection Regulation (GDPR), Autonomo LLC is the Data Controller of your Personal Data.

2. Information We Collect We collect various types of information, including data that can identify or relate to you ("Personal Data").

2.1 Information You Provide We collect information you voluntarily provide, including:

  • Personal Data: Name, email address, phone number.
  • Account Registration Information: Credentials and details used to create and manage your account.
  • Profile Information: Information you choose to add to your user profile.
  • Communication Content: Messages, posts, and any other content you share through the Service.
  • Payment Information: While we do not directly store your payment card details, this information is processed by third-party payment processors to complete transactions.
  • Customer Service Communications: Records of your interactions with our customer support.

2.2 Automatically Collected InformationWhen you use the Service, we automatically collect certain information, which may include Personal Data:

  • Usage Data: Information on how you access and use the Service, such as pages visited, features used, and time spent on the Service.
  • Device Information: Details about the device you use to access the Service, including device type, operating system, unique device identifiers, and mobile network information.
  • IP Address: Your Internet Protocol address.
  • Browser Information: Browser type and version.
  • Date and Time of Visits: Timestamps of your access to the Service.

2.3 Cookies and Similar TechnologiesWe use cookies and similar tracking technologies (collectively, "Cookies") to collect information and ensure the proper functioning and security of our Service. These technologies may collect Browse behavior, preferences, and session information.

Types of Cookies We Use:

  • Essential / Strictly Necessary Cookies: These cookies are fundamental for the website to function correctly and securely. They enable core functionalities such as user login, session management, and security features. These cookies are automatically placed on your device as they are exempt from consent requirements under GDPR.
  • Google Analytics Cookies: We use Google Analytics cookies to collect anonymized statistical data about how users interact with our Service. This helps us understand user behavior, measure the performance of our Service, and identify areas for improvement. We do not use Google Analytics for advertising purposes.

You can manage your cookie preferences through your browser settings.

3. How We Use Your Information

How we use Google user data: We only use Google user data for booking and scheduling appointments for your business.We do not share any Google user data with third-party sources.

We use the collected information, including Personal Data, for the following purposes and based on the following legal bases:

  • To Provide and Maintain the Service (Performance of a Contract): To operate, maintain, and provide the features and functionalities of the Service, including account management, processing transactions, and fulfilling your requests.
  • To Personalize Your Experience (Legitimate Interests): To tailor the Service content and features to your interests and preferences.
  • To Communicate with You (Performance of a Contract or Legitimate Interests): To send you transactional communications (e.g., updates, security alerts, support messages).
  • To Send Promotional Materials (Consent): We may send you newsletters and special offers if you have explicitly opted-in to receive such communications. You can withdraw your consent at any time.
  • To Analyze Service Usage and Trends (Legitimate Interests): To understand how users interact with our Service, identify usage trends, and improve our Service's performance, features, and user experience.
  • To Ensure Security and Prevent Fraud (Legal Obligation, Legitimate Interests): To detect, prevent, and respond to potential security incidents, fraudulent activities, or other illegal or prohibited activities.
  • To Comply with Legal Obligations (Legal Obligation): To adhere to applicable laws, regulations, legal processes, or governmental requests.
  • For Business Transfers (Legitimate Interests): In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company, where Personal Data held by us about our Service users is among the assets transferred.
  • For Other Purposes with Your Consent (Consent): For any other purpose disclosed to you at the time of collection or for which we obtain your consent.

4. How We Share Your InformationWe may share your information, including Personal Data, in the following circumstances:

  • With Service Providers (Data Processors): We engage third-party companies and individuals to facilitate our Service, provide Service-related services, perform Service analysis, payment processing, email communication, and search functionality. These third parties act as our Data Processors and are contractually obligated to protect your information and use it only for the purposes for which we disclose it to them.
  • With Other Users: As part of the Service's functionality, certain information (e.g., profile information, public posts) may be visible to other users.
  • For Legal Purposes: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order, subpoena, or government agency request), or when we believe such action is necessary to comply with a legal obligation, protect and defend our rights or property, prevent or investigate possible wrongdoing in connection with the Service, protect the personal safety of users or the public, or protect against legal liability.
  • For Business Transfers: In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • With Your Consent: We may share your personal information for any other purpose with your explicit consent.

We do not sell your personal information to third parties for their marketing purposes.

5. Your Rights and ChoicesDepending on your location and applicable data protection laws, you may have certain rights regarding your Personal Data.

5.1 General Rights and Choices:

  • Accessing Your Information: You may have the right to request access to the Personal Data we hold about you.
  • Correcting Inaccurate Information: You may have the right to request that we correct any incomplete or inaccurate Personal Data we hold about you.
  • Deleting Your Information: You may have the right to request the erasure of your Personal Data under certain circumstances.
  • Opting Out of Certain Data Practices: You may have the right to opt out of certain data processing activities, such as receiving promotional communications.
  • Withdrawing Consent: Where we rely on your consent as a legal basis for processing your Personal Data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.

To exercise these rights, please contact us using the information provided in the "Contact Us" section. We may ask you to verify your identity before responding to such requests.

6. Data Retention and SecurityWe retain your Personal Data for as long as necessary to fulfill the purposes for which it was collected, to provide the Service, to comply with our legal obligations (e.g., tax, accounting, or legal requirements), resolve disputes, and enforce our agreements.

We implement reasonable technical and organizational security measures to protect your Personal Data from unauthorized access, use, disclosure, alteration, or destruction. However, please be aware that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

7. Children's PrivacyThe Service is not intended for children under 13 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child without parental consent, we will take steps to remove that information from our servers.

8. International Data TransfersYour information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

For users in the European Economic Area (EEA), please note that your Personal Data may be transferred to and processed in the United States, where our primary operations are located. The United States has data protection laws that may not be as comprehensive as those in the EEA.

When we transfer Personal Data outside the EEA, we implement appropriate safeguards to ensure that your data receives an adequate level of protection, such as:

  • Transferring data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
  • Using Standard Contractual Clauses (SCCs) approved by the European Commission, which provide specific data protection obligations for the data importer and exporter.
  • Implementing other legally approved mechanisms that ensure an adequate level of data protection.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

9. Changes to This Policy We may update this Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. The updated version will be indicated by an updated "Effective Date" at the top of this Policy. We will notify you of any material changes by posting the new Privacy Policy on this page, and where appropriate, by email or through a prominent notice on our Service prior to the change becoming effective. We encourage you to review this Policy periodically.

10. Contact Us If you have any questions about this Policy or our privacy practices, please contact us at:

Tonomo (Autonomo LLC)9450 SW Gemini Dr # 26494Beaverton, Oregon 97008-7105United StatesEmail: john@tonomo.io

11. Additional Information for Specific Jurisdictions

California ResidentsUnder the California Consumer Privacy Act (CCPA), California residents have additional rights regarding their personal information. These rights include:

  • The right to know: What personal information we collect, use, disclose, and sell.
  • The right to request deletion: Of personal information.
  • The right to opt-out of the sale of personal information: Please note that Tonomo does not sell your personal information.
  • The right to non-discrimination: For exercising your CCPA rights.

To exercise these rights, please contact us using the information in the "Contact Us" section.

Nevada ResidentsNevada residents may have the right to opt out of the sale of their covered information. To exercise this right, please contact us using the information in the "Contact Us" section.

European Economic Area (EEA) Residents If you are in the EEA, you have specific rights under the General Data Protection Regulation (GDPR) as a Data Subject. We are committed to upholding these rights:

  • Right to be informed: You have the right to be informed about the collection and use of your Personal Data. This Privacy Policy serves to fulfill this right.
  • Right of access: You have the right to obtain confirmation as to whether or not Personal Data concerning you is being processed, and, where that is the case, access to the Personal Data and certain information about its processing.
  • Right to rectification: You have the right to obtain the rectification of inaccurate Personal Data concerning you without undue delay and to have incomplete Personal Data completed.
  • Right to erasure ('right to be forgotten'): You have the right to obtain the erasure of Personal Data concerning you without undue delay when certain conditions apply (e.g., the data is no longer necessary for the purposes for which it was collected, or you withdraw consent and there is no other legal ground for processing).
  • Right to restriction of processing: You have the right to obtain from us restriction of processing where certain conditions apply (e.g., you contest the accuracy of the Personal Data, or the processing is unlawful but you oppose erasure).
  • Right to data portability: You have the right to receive the Personal Data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format and have the right to transmit that data to another controller without hindrance from us, where the processing is based on consent or a contract and carried out by automated means.
  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to processing of Personal Data concerning you which is based on legitimate interests or the performance of a task carried out in the public interest, including profiling. You also have the right to object to the processing of Personal Data for direct marketing purposes.
  • Rights in relation to automated decision-making and profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless certain exceptions apply.

To exercise any of these GDPR rights, please contact us at john@tonomo.io. We will respond to your request within the timeframe required by GDPR.

You also have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or place of the alleged infringement if you believe that the processing of Personal Data relating to you infringes GDPR.

Detailed Information on the Processing of Your Personal DataWe use the following third-party service providers who may process your Personal Data:

  • Analytics:
    • Google Analytics: A web analytics service that tracks and reports website traffic. Google's processing of data is governed by their Privacy Policy. We use Google Analytics solely for website analytics and do not utilize its advertising features.
    • LogRocket: A session replay and product analytics tool that helps us understand user behavior and identify issues on our Service. LogRocket's processing of data is governed by their Privacy Policy. We ensure that personally identifiable information (PII) is appropriately masked within LogRocket recordings to protect your privacy.
  • Email Communication:
    • SendGrid: An email delivery service that we use to manage and send emails to you, including transactional emails and, if you have consented, marketing communications. SendGrid's processing of data is governed by their Privacy Policy.
  • Search Functionality:
    • Algolia: We use Algolia to provide fast and relevant search functionality within your user portal on our Service. Algolia's processing of data is governed by their Privacy Policy.

Google APIs Data obtained from Google APIs, including Restricted and Sensitive Scopes, will be used and transferred in compliance with the Google API Services User Data Policy, including the Limited Use requirements. For more information, please refer to the Google API Services User Data Policy.

By using our Service, you acknowledge that you have read and understood this Privacy Policy.

Subscribe to our newsletter

Book a call with our product specialist and we’ll show you how Tonomo can get you more bookings and boost team efficiency.

Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.