Last updated: July 2026
Tous Connect is operated by Grid IT Solutions. Questions? Email connect@thetous.com.
This policy explains what personal information Tous Connect (operated by Grid IT Solutions) collects, how we use it, and the choices you have. It covers our business customers (the people who sign up and use the platform) and explains how we handle the data those businesses process about their own customers.
We do not sell your data, and we do not sell or share your contacts with third parties for their own marketing. We do not use the content of your customer conversations to train AI models.
Data is stored in Supabase (PostgreSQL), hosted in the Singapore region. The application is hosted on Vercel. Data is encrypted in transit (TLS) and at rest. Access is restricted to authorised personnel and segregated per tenant using row-level security, so one business can never read another’s data.
When you connect a WhatsApp Business number, messages pass through Meta’s WhatsApp Business Platform. We process those messages on behalf of your business — you are the data controller for your conversations and we act as your processor.
For the end consumers your business messages, Meta’s own privacy policy and the WhatsApp terms apply to the handling of their data inside WhatsApp. We do not control Meta’s processing. If a consumer wants their data removed from your records, contact us or manage it directly from your contacts page.
When you scan a business card, the image is sent to Groq for AI text extraction. Only the extracted fields (name, phone, email, company) are saved to your contacts. The image is not stored permanently after extraction. We do not use your scans to train models.
We use session cookies for authentication only — they keep you signed in and secure your session. We do not use advertising cookies, third-party tracking pixels, or cross-site behavioural profiling. Blocking these cookies will prevent you from signing in.
You may, at any time:
To exercise any of these, email connect@thetous.com. We respond within 30 days. We may need to verify your identity before acting on a request.
We share data with these processors strictly to run the Service:
Each processes data under its own terms and applicable data-protection obligations.
We use TLS encryption, hashed credentials, row-level tenant isolation, scoped API keys, and signature verification on payment and webhook endpoints. No system is perfectly secure; if a breach affects your data we will notify you promptly and without undue delay.
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect personal information from children.
We may update this policy. Material changes will be notified in-app or by email at least 14 days before taking effect, and the “last updated” date above will change.
For any privacy question or request: Grid IT Solutions — connect@thetous.com