Privacy Policy
Effective 2026-07-11 · v0-draft-1
Who we are
Mortar provides done-for-you business automations. The data controller for this service is Mortar, reachable at mortarautomation.com. For any privacy question or to exercise your rights, contact privacy@mortarautomation.com.
What we collect and why
The table below is generated from our internal data map. It lists each place personal data lives where Mortar acts as the controller, the categories involved, how long we keep it, and the lawful basis we rely on.
| Data categories | Record | Retention | Lawful basis |
|---|---|---|---|
| account_identity | usermodel.User | For the life of the account; deleted within 30 days of account deletion | Contract (service provision) |
| account_identity | mainapp.TeamMembership | For the life of the account; deleted within 30 days of account deletion | Contract |
| account_identity | mainapp.TeamInvitation | 90 days after acceptance/expiry | Contract |
| credential_values | mainapp.TeamInvitation | 90 days after acceptance/expiry | Contract |
| support_comms account_identity | mainapp.TeamInvitation | 90 days after acceptance/expiry | Contract |
| support_comms account_identity | mainapp.ContactSubmission | 24 months | Legitimate interest (support) |
| billing | mainapp.BillingCustomer | Statutory retention (7y NL fiscal) | Legal obligation |
| billing | mainapp.BillingEventLog | Statutory retention (7y NL fiscal) | Legal obligation |
| billing usage_metrics | mainapp.BillingSubscription | Statutory retention (7y NL fiscal) | Legal obligation |
| credential_values | mainapp.GoogleCredential | Until disconnected by client | Contract |
| credential_metadata | mainapp.GoogleCredential | Until disconnected by client | Contract |
| credential_metadata | mainapp.ResourceConnection | Until disconnected by client | Contract |
| credential_values credential_metadata | mainapp.TeamWindmillBinding | Life of tenant binding | Contract |
| credential_values credential_metadata | mainapp.TeamResidencyProfile | Life of tenant residency profile | Contract |
| credential_values | mainapp.UserOTPProfile | Life of account | Contract |
| credential_values | mainapp.WebhookEndpoint | Life of endpoint | Contract |
| credential_metadata | mainapp.WebhookEndpoint | Life of endpoint | Contract |
| usage_metrics | mainapp.SignupAttribution | 13 months | Legitimate interest (attribution) |
| usage_metrics | mainapp.UsageMeter | For the life of the account; deleted within 30 days of account deletion | Contract |
| usage_metrics error_diagnostics | mainapp.AgentAction | 24 months | Legitimate interest (audit) |
| support_comms account_identity | mainapp.OnboardingSession | 180 days from call date; purged by purge_onboarding_sessions command | Legitimate interest (support) |
| support_comms | mainapp.HumanMinutesEntry | 24 months | Legitimate interest (service improvement) |
| sop_knowledge | mainapp.Proposal | Life of service | Legitimate interest (service improvement) |
| error_diagnostics | mainapp.Proposal | Life of the proposal record | Legitimate interest (governance audit) |
| error_diagnostics | mainapp.AsyncJob | 90 days | Legitimate interest |
| credential_values credential_metadata | usermodel.PersonalAccessToken | Life of token; until revoked | Contract |
| credential_metadata usage_metrics | usermodel.ApiAccessLog | 90 days rolling | Legitimate interest (security audit) |
| account_identity billing credential_values end_customer_leads usage_metrics | — | 35 days rolling | Contract / legal obligation |
| billing account_identity | — | Per Paddle DPA | Contract |
Subprocessors
We use a small number of vetted third parties to operate the service (payment processing and connected Google services). Each is bound by a data-processing agreement. See the current list on our subprocessors page.
Your rights
Subject to applicable law, you have the right to access, rectify, erase, and port your personal data, and to object to or restrict certain processing. To make a request, email privacy@mortarautomation.com. Where Mortar processes end-customer data on a client's behalf, we act as a processor and route such requests to the client (controller).
Cookies
We use only session and CSRF cookies required to operate the service; no tracking cookies.