Privacy Notice
Tomorrowfy website, business contacts, and service account users
Tomorrowfy GmbH · Version 1.0 · Effective 20 August 2026
1. Who is responsible
The controller for the processing described in this notice is Tomorrowfy GmbH, Isarwinkel 2, 81379 Munich, Germany, Commercial Register of the Local Court of Munich, HRB 305176.
- Website: www.tomorrowfy.com
- Privacy contact: privacy@tomorrowfy.com
- Security contact: security@tomorrowfy.com
- General support: support@tomorrowfy.com
This address is a privacy contact and is not described as an appointed data protection officer. If Tomorrowfy appoints a data protection officer, this notice will be updated.
2. Scope
This notice applies when you visit tomorrowfy.com, contact Tomorrowfy, act as a prospect or business contact, or use a Tomorrowfy service account on behalf of a Customer.
It does not govern personal data that Tomorrowfy processes only on behalf of a merchant Customer about that merchant’s shoppers or subscribers. For that data, the merchant is normally the controller and its privacy notice applies. Please contact the relevant merchant first; Tomorrowfy will assist the merchant under its Data Processing Agreement.
3. Data we process and why
Website delivery and security
When you access the website, the hosting service processes technical request information such as IP address, date and time, requested path, referrer, browser, device, and diagnostic information. Processing is necessary to deliver and secure the website and to investigate misuse. The legal basis is Article 6(1)(f) GDPR — Tomorrowfy’s legitimate interests in operating a secure and reliable website.
Website performance measurement
Tomorrowfy uses Vercel Speed Insights in production to measure real-world website performance. It reports performance data points such as route or URL, network speed, browser, device type and operating system, country, Web Vitals, SDK information, and the server-received event time. Vercel states that the data points are not tied to an individual visitor or IP address and cannot be used to reconstruct a browsing session across pages. The legal basis is Article 6(1)(f) GDPR — Tomorrowfy’s legitimate interest in monitoring and improving website performance.
Business communications and sales
If you email or otherwise contact Tomorrowfy, it processes your name, email address, company, role, message, attachments, and related correspondence to answer the request, prepare or perform a contract, and maintain business records. The legal bases are Article 6(1)(b) GDPR for pre-contractual or contractual steps and Article 6(1)(f) GDPR for general business communications and relationship management.
Customer accounts and support
For Customer administrators and authorized users, Tomorrowfy processes account identifiers, business contact details, role and permissions, authentication and session information, usage and support information, and security records to provide, administer, secure, and support the service. The legal bases are Article 6(1)(b) GDPR where you are the contracting person and Article 6(1)(f) GDPR where the contract is with your organization.
Legal, billing, and security obligations
Tomorrowfy may process contract, billing, transaction, audit, and communication records to comply with tax, accounting, commercial, sanctions, security, and legal obligations, to establish or defend legal claims, and to prevent fraud or abuse. The legal bases are Article 6(1)(c) and, where applicable, Article 6(1)(f) GDPR.
Consent
Where Tomorrowfy asks for consent for a specific purpose, the legal basis is Article 6(1)(a) GDPR. You may withdraw consent at any time for future processing without affecting earlier lawful processing.
4. Sources
Tomorrowfy receives data from you, your organization, service account administrators, connected platforms such as Shopify, public business sources, and the technical systems used to deliver and secure the website and services.
5. Recipients and international transfers
Tomorrowfy shares personal data only where necessary with authorized personnel, professional advisers, public authorities where legally required, and service providers. Relevant providers include Google Workspace for business communications, Vercel for website and application hosting and analytics, Google Cloud for service infrastructure, GitHub for development operations, and other providers required for a requested service function.
Some providers and their subprocessors process data outside the EEA, including in the United States. Where required, transfers are protected by an adequacy decision, the European Commission’s 2021 Standard Contractual Clauses, or another valid Chapter V GDPR safeguard, together with supplementary measures where appropriate. Current service-vendor details are available in Tomorrowfy’s Subprocessor and Data Location List.
6. Retention
Tomorrowfy retains personal data only as long as needed for the relevant purpose and then deletes or anonymizes it, unless law requires longer retention. The period depends on the type of record, the contract or inquiry, security needs, limitation periods, and statutory tax, accounting, or commercial-record duties. Website and service logs follow configured operational and provider retention periods. Support and business correspondence is retained while needed for the relationship, issue history, legal obligations, and the establishment or defense of claims.
7. Required data
Technical request data is necessary to deliver the website. Contract and account information is required to enter into and administer a service relationship. If required information is not provided, Tomorrowfy may be unable to respond, create an account, or provide the requested service.
8. Automated decisions
Tomorrowfy does not make decisions about website visitors or business contacts based solely on automated processing that produce legal or similarly significant effects. Product analytics and AI-assisted service features may generate recommendations or summaries for authorized Customer users, but the Customer determines how to use them.
9. Your rights
Subject to the legal conditions, you may request:
- access to and a copy of your personal data;
- correction of inaccurate or incomplete data;
- deletion or restriction of processing;
- data portability for data processed by automated means on consent or contract;
- withdrawal of consent for future processing; and
- objection to processing based on legitimate interests, including direct marketing.
Send requests to privacy@tomorrowfy.com. Tomorrowfy may need to verify identity and may retain information required by law or for legal claims. If Tomorrowfy processes the data only for a merchant Customer, it may refer the request to that Customer and assist it.
10. Complaints
You may complain to a data-protection supervisory authority, including the authority responsible for Tomorrowfy: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
11. Security and updates
Tomorrowfy uses technical and organizational safeguards appropriate to the risk. No internet service can guarantee absolute security. Please send suspected security issues to security@tomorrowfy.com.
Tomorrowfy may update this notice when services, providers, or law change. The effective date and version at the top identify the current text. Material changes will be communicated through an appropriate channel.
