DRAFT — pending legal review. Effective 2026-07-11 · v0-draft-1

Privacy Policy

Effective 2026-07-11 · v0-draft-1

Who we are

Mortar provides done-for-you business automations. The data controller for this service is Mortar, reachable at mortarautomation.com. For any privacy question or to exercise your rights, contact privacy@mortarautomation.com.

What we collect and why

The table below is generated from our internal data map. It lists each place personal data lives where Mortar acts as the controller, the categories involved, how long we keep it, and the lawful basis we rely on.

Data categories Retention
account_identity For the life of the account; deleted within 30 days of account deletion
account_identity For the life of the account; deleted within 30 days of account deletion
account_identity 90 days after acceptance/expiry
credential_values 90 days after acceptance/expiry
support_comms account_identity 90 days after acceptance/expiry
support_comms account_identity 24 months
billing Statutory retention (7y NL fiscal)
billing Statutory retention (7y NL fiscal)
billing usage_metrics Statutory retention (7y NL fiscal)
credential_values Until disconnected by client
credential_metadata Until disconnected by client
credential_metadata Until disconnected by client
credential_values credential_metadata Life of tenant binding
credential_values credential_metadata Life of tenant residency profile
credential_values Life of account
credential_values Life of endpoint
credential_metadata Life of endpoint
usage_metrics 13 months
usage_metrics For the life of the account; deleted within 30 days of account deletion
usage_metrics error_diagnostics 24 months
support_comms account_identity 180 days from call date; purged by purge_onboarding_sessions command
support_comms 24 months
sop_knowledge Life of service
error_diagnostics Life of the proposal record
error_diagnostics 90 days
credential_values credential_metadata Life of token; until revoked
credential_metadata usage_metrics 90 days rolling
account_identity billing credential_values end_customer_leads usage_metrics 35 days rolling
billing account_identity Per Paddle DPA

Subprocessors

We use a small number of vetted third parties to operate the service (payment processing and connected Google services). Each is bound by a data-processing agreement. See the current list on our subprocessors page.

Your rights

Subject to applicable law, you have the right to access, rectify, erase, and port your personal data, and to object to or restrict certain processing. To make a request, email privacy@mortarautomation.com. Where Mortar processes end-customer data on a client's behalf, we act as a processor and route such requests to the client (controller).

Cookies

We use only session and CSRF cookies required to operate the service; no tracking cookies.