[1]The short version
This website collects nothing about you. No analytics script, no measurement endpoint, no cookies, no tracking pixels, no fingerprinting. That is unusual enough that clause [2] spends its whole length on it.
Throughline itself is fictional, so it has no users and no user data. But a policy that stopped there would show you nothing, so clauses [3] through [8] lay out what a real product of this shape would have to disclose: what it collects, on what legal basis, for how long, and what you could do about it.
[2]This website ships no analytics at all
Most privacy policies describe what is collected and hope you stop reading before the list ends. This one gets to be shorter. This site sends nothing, to anyone:
- No third-party scripts. No tag manager, no analytics vendor, no session recording, no A/B testing, no social pixels. View the page source: the only scripts are the site's own.
- No first-party measurement either. There is no analytics endpoint of our own. Page views are not counted. We cannot see that you were here.
- No cookies. None, first-party or third-party, session or persistent. There is no consent banner because there is nothing to consent to.
- One local preference. If you use the theme toggle, your choice of light or dark is kept in your browser's localStorage. It never leaves your device and identifies nothing.
[2.1]Enforced, not promised
The site's Content-Security-Policy header sets connect-src 'self'. Your browser enforces that rule: it refuses any network request from this page to any other origin. Nothing can beacon out, even by accident, even from a bug. You can check this yourself: open your browser's developer tools, watch the network panel, and browse. Every request goes to this site.
The reasoning, including what the choice costs (no visitor counts, no field performance data), is recorded in the project's decision log. It stands until this site needs to prove conversion behaviour rather than demonstrate craft.
[2.2]Hosting
The site is static files served by a hosting platform (Vercel). Like any host, it keeps standard, short-lived access logs (IP address, URL requested, user agent) to operate and secure its network. That is a property of being on the web, not a choice this site adds to, and those logs are governed by the host's own privacy policy.
[3]What a real product would collect
A real Throughline would be a business tool processing business data. The categories below are the honest shape of that disclosure; every specific is [illustrative]. Its policy would separate two roles, because the law does:
- Data we would control. Account and billing data: your name, work email, role, and authentication identifiers; support conversations; invoices. Collected directly from you and used to run your account.
- Data we would process for the customer. Shipment records: carrier references, order numbers, addresses on shipping documents, and the names and business contact details of the people on those documents. For this data the customer is the controller and Throughline the processor, acting only on documented instructions under the data processing addendum.
[4]Lawful basis
For the data a real Throughline would control:
- Contract. Account data, billing, and support: needed to provide the service the customer signed up for.
- Legitimate interest. Service security, abuse prevention, and product improvement, balanced against your rights and documented in an assessment you could request.
- Consent. Marketing email only: opt-in, withdrawable at any time, and never a condition of using the service.
Shipment data processed for a customer runs on the customer's own lawful basis and instructions; the processor does not need, and does not claim, a separate one.
[5]Retention
Data is kept only as long as the reason for keeping it, then deleted:
| Data | Kept for | Why |
|---|---|---|
| Account data | Life of the contract, plus 30 days | The export window promised in the terms |
| Shipment data | Life of the contract, plus 30 days | Deleted after the export window, with written confirmation |
| Support conversations | 24 months after the ticket closes | Context for recurring issues |
| Invoices and billing records | 7 years | Statutory bookkeeping obligations |
| Marketing consent records | Until withdrawn, plus 12 months | Proof the consent existed |
[6]Your rights
A real Throughline would honour the full set of data-subject rights and apply them to everyone, rather than run two grades of privacy by jurisdiction:
- Access. A copy of what is held about you.
- Rectification. Correction of anything wrong.
- Erasure. Deletion, where the law does not require keeping it.
- Portability. A machine-readable export. The product itself exports CSV and Parquet; the policy should not be shier than the product.
- Restriction and objection. Including to any legitimate-interest processing, which then stops unless the interest demonstrably overrides.
- Complaint. To your supervisory authority, and the policy would tell you which one applies rather than make you find out.
Requests would be verified, answered within 30 days, and free.
[7]Contact
Questions about this policy, or about the demonstration itself:
privacy@throughline.example [illustrative]
The .example domain is reserved for exactly this purpose: an address that shows the structure, works nowhere, and deceives nobody. A real policy would list a monitored inbox and a postal address here.
[8]Changes to this policy
Material changes would be announced 30 days before taking effect, by email to account administrators: the same mechanism, and the same notice period, as the subprocessor list. The date at the top of this page is the record of the current version.