Data Processing Addendum

Last updated: June 28, 2026

This Data Processing Addendum (“DPA”) supplements our Terms of Use and Privacy Policy. It describes how Toasted processes personal data on behalf of artists who use the platform to manage their client relationships.

1. Roles

When you use Toasted to collect client information, you are the data controller. You determine what client data is collected and why. Toasted acts as a data processor, storing and processing that data only as necessary to provide the services you use.

Your clients’ personal data belongs to your business relationship with them. Toasted does not have an independent relationship with your clients and does not use their data for our own marketing or commercial purposes.

2. Data We Process on Your Behalf

The following categories of personal data are processed by Toasted on behalf of artists:

  • Client contact information (name, phone number, email address)
  • Booking and appointment history
  • Payment method tokens and transaction records (via Stripe)
  • SMS message content between artist and client (via Twilio)
  • Client preferences, skin tone notes, and consultation data you enter
  • SMS consent records (required for TCPA compliance)
  • Signed spray tan service agreements (typed name, agreement text snapshot, timestamp)

3. How We Use Client Data

We process client data solely to provide the Toasted service. This includes:

  • Storing client profiles for your CRM
  • Sending automated SMS messages on your behalf (confirmations, reminders, rinse-off texts)
  • Processing bookings and payments
  • Displaying booking history and client records within your app
  • Retaining signed service agreements for your legal records

We do not sell, rent, or share client personal data with third parties for their own marketing purposes.

4. Your Responsibilities as Data Controller

By using Toasted to communicate with clients, you confirm that:

  • You have obtained valid SMS consent from clients before any text messages are sent
  • You comply with applicable privacy laws including TCPA (for SMS) and CCPA or GDPR where applicable
  • You will honor client requests to delete their data, access their data, or opt out of communications
  • You will notify Toasted promptly if you become aware that a client’s consent has been revoked

5. Subprocessors

Toasted uses the following subprocessors to deliver the service. Each is bound by data processing agreements consistent with this DPA:

  • Supabase: database, authentication, and file storage
  • Stripe: payment processing and card tokenization
  • Twilio: SMS delivery and phone number provisioning
  • Resend: transactional email delivery
  • Vercel: web hosting and edge functions

We will notify you of any material changes to our subprocessors with reasonable advance notice.

6. Security

Toasted implements technical and organizational measures to protect personal data, including:

  • Row-level security (RLS) on all database tables, so artists can only access their own data
  • Encrypted data in transit (TLS) and at rest via Supabase
  • Authentication required for all artist data access
  • No plain-text storage of payment card data (tokenized via Stripe)

7. Data Retention

We retain client data for as long as your Toasted account is active. If you cancel your subscription, your data is retained for 45 days after your final billing period ends and is then permanently deleted from our systems. Before deletion, we send two reminder emails to the address on file, one 14 days before deletion and another 7 days before deletion, so you have time to export anything you need. Full details are in the Data Retention section of our Privacy Policy. You may request an export of your client data before deletion by contacting support@toastedtanz.com.

8. Security Incidents

In the event of a data breach affecting your clients’ personal information, we will notify you within 72 hours of becoming aware of the incident, provide details of what occurred and what data was affected, and cooperate with any investigation or regulatory notification requirements.

9. Data Subject Requests

If a client contacts you requesting access to, correction of, or deletion of their personal data, we will assist you in fulfilling those requests within a reasonable timeframe. Contact support@toastedtanz.com to initiate a data subject request.

10. Changes

We may update this DPA to reflect changes in our subprocessors, legal requirements, or service features. Material changes will be communicated with advance notice. Continued use of the platform constitutes acceptance.