Book a demo Open the ROI calculator

[soc 2 type ii · 14-day trial · no card]

[legal / privacy]

Privacy policy

[last updated ] [version 1.0] [illustrative]

[portfolio concept]

Throughline is fictional. This site is a design studio's portfolio piece, and this page shows the structure of a real privacy policy so a reviewer can judge the craft. Its specifics are illustrative, it is not legal advice, and it creates no rights or obligations. One part is literally true of this website: clause [2].

[1]The short version

This website collects nothing about you. No analytics script, no measurement endpoint, no cookies, no tracking pixels, no fingerprinting. That is unusual enough that clause [2] spends its whole length on it.

Throughline itself is fictional, so it has no users and no user data. But a policy that stopped there would show you nothing, so clauses [3] through [8] lay out what a real product of this shape would have to disclose: what it collects, on what legal basis, for how long, and what you could do about it.

[2]This website ships no analytics at all

Most privacy policies describe what is collected and hope you stop reading before the list ends. This one gets to be shorter. This site sends nothing, to anyone:

  • No third-party scripts. No tag manager, no analytics vendor, no session recording, no A/B testing, no social pixels. View the page source: the only scripts are the site's own.
  • No first-party measurement either. There is no analytics endpoint of our own. Page views are not counted. We cannot see that you were here.
  • No cookies. None, first-party or third-party, session or persistent. There is no consent banner because there is nothing to consent to.
  • One local preference. If you use the theme toggle, your choice of light or dark is kept in your browser's localStorage. It never leaves your device and identifies nothing.

[2.1]Enforced, not promised

The site's Content-Security-Policy header sets connect-src 'self'. Your browser enforces that rule: it refuses any network request from this page to any other origin. Nothing can beacon out, even by accident, even from a bug. You can check this yourself: open your browser's developer tools, watch the network panel, and browse. Every request goes to this site.

The reasoning, including what the choice costs (no visitor counts, no field performance data), is recorded in the project's decision log. It stands until this site needs to prove conversion behaviour rather than demonstrate craft.

[2.2]Hosting

The site is static files served by a hosting platform (Vercel). Like any host, it keeps standard, short-lived access logs (IP address, URL requested, user agent) to operate and secure its network. That is a property of being on the web, not a choice this site adds to, and those logs are governed by the host's own privacy policy.

[3]What a real product would collect

A real Throughline would be a business tool processing business data. The categories below are the honest shape of that disclosure; every specific is [illustrative]. Its policy would separate two roles, because the law does:

  • Data we would control. Account and billing data: your name, work email, role, and authentication identifiers; support conversations; invoices. Collected directly from you and used to run your account.
  • Data we would process for the customer. Shipment records: carrier references, order numbers, addresses on shipping documents, and the names and business contact details of the people on those documents. For this data the customer is the controller and Throughline the processor, acting only on documented instructions under the data processing addendum.

[4]Lawful basis

For the data a real Throughline would control:

  • Contract. Account data, billing, and support: needed to provide the service the customer signed up for.
  • Legitimate interest. Service security, abuse prevention, and product improvement, balanced against your rights and documented in an assessment you could request.
  • Consent. Marketing email only: opt-in, withdrawable at any time, and never a condition of using the service.

Shipment data processed for a customer runs on the customer's own lawful basis and instructions; the processor does not need, and does not claim, a separate one.

[5]Retention

Data is kept only as long as the reason for keeping it, then deleted:

[retention schedule · illustrative]
Data Kept for Why
Account data Life of the contract, plus 30 days The export window promised in the terms
Shipment data Life of the contract, plus 30 days Deleted after the export window, with written confirmation
Support conversations 24 months after the ticket closes Context for recurring issues
Invoices and billing records 7 years Statutory bookkeeping obligations
Marketing consent records Until withdrawn, plus 12 months Proof the consent existed

[6]Your rights

A real Throughline would honour the full set of data-subject rights and apply them to everyone, rather than run two grades of privacy by jurisdiction:

  • Access. A copy of what is held about you.
  • Rectification. Correction of anything wrong.
  • Erasure. Deletion, where the law does not require keeping it.
  • Portability. A machine-readable export. The product itself exports CSV and Parquet; the policy should not be shier than the product.
  • Restriction and objection. Including to any legitimate-interest processing, which then stops unless the interest demonstrably overrides.
  • Complaint. To your supervisory authority, and the policy would tell you which one applies rather than make you find out.

Requests would be verified, answered within 30 days, and free.

[7]Contact

Questions about this policy, or about the demonstration itself:

privacy@throughline.example [illustrative]

The .example domain is reserved for exactly this purpose: an address that shows the structure, works nowhere, and deceives nobody. A real policy would list a monitored inbox and a postal address here.

[8]Changes to this policy

Material changes would be announced 30 days before taking effect, by email to account administrators: the same mechanism, and the same notice period, as the subprocessor list. The date at the top of this page is the record of the current version.