Skip to content
Home

Privacy Policy

This policy explains what data we collect when you use TodoMore, what we use it for, and the responsibilities we take on to keep it safe.

Last updated: 27 August 2026

1.Data We Collect

We process a limited set of personal data in order to provide the service. It falls into these categories:

  • Account details: name, e-mail address and profile photo if provided.
  • Workspace content: the projects, tasks, files and messages you create, and their metadata.
  • Usage and security records: IP address, browser and device information, session and activity logs.
  • Billing details: plan, subscription status, invoice title and address. Your card number, expiry date and CVV never reach us.
  • Analytics (only with your consent): page views and product usage measurements.

2.How We Use It

  • To create, verify and manage your account
  • To provide, maintain and improve the platform's features
  • To detect and prevent activity that could threaten security
  • To deliver service notifications and support responses
  • To operate subscription and billing processes
  • To meet our legal obligations

3.Data Sharing

Your personal data is never sold, rented or transferred to third parties for advertising or marketing purposes, unless there is a legal obligation (court order, lawful request) or you have given explicit consent.

To the extent necessary to provide the service, we work with the following providers as data processors:

  • Cloud infrastructure (Supabase — Frankfurt, Germany, EU region): database, file storage and authentication.
  • CDN, security and hosting (Cloudflare, Inc.): carrying site and app traffic, bot protection and attack filtering. In this context your IP address and browser information are processed for security purposes.
  • Merchant of record (Paddle.com Market Ltd): subscription charges, invoicing, tax handling and refunds.
  • E-mail provider: transactional e-mail (invitations, password resets, notifications).
  • Consent record: when you accept cookies, we store the date of the decision, the approved categories, the policy version, your browser type and an irreversible hash of your IP address, so that consent can be demonstrated. Nothing is stored when you reject.
  • Public authorities: only where legally required, limited to the scope requested.

4.Payment Data

Payments are processed by Paddle.com Market Ltd, our merchant of record. Your card number, expiry date and security code are never transmitted to TodoMore servers, are not visible to us and are not stored by us.

That data is processed directly in Paddle's PCI-DSS compliant environment. We retain only the outcome of the charge (success or failure), the amount, the date and the transaction reference generated by Paddle. Customers billed in Türkiye are processed by iyzico instead; see the Turkish version of this policy.

5.Data Security

Your data is encrypted in transit with TLS and at rest on the server side; sensitive fields such as identity numbers are additionally encrypted at column level.

Access between workspaces is separated by row-level security policies in the database — one workspace's data cannot be read by another.

Even so, no method of transmission over the internet can be guaranteed 100% secure. Account-side measures such as using a strong password and enabling two-step verification remain your responsibility.

Our security architecture is described in detail on the Security page.

6.Retention

We keep your personal data for as long as your account is active and for as long as it is needed to provide the service.

When you delete your account, your content data is permanently deleted within a reasonable period. Billing and accounting records must be retained for the minimum period required by tax legislation (as a rule, ten years).

7.Cookies and Tracking

We use strictly necessary cookies for core functions such as session management and remembering preferences; the site does not work without them.

Analytics cookies run only with your explicit consent. Until you consent, not a single request is sent to analytics providers and their scripts are never downloaded to your browser. You can withdraw that consent at any time via the “Manage my cookie preferences” link at the bottom of the page; your decision is asked again after 12 months.

Every cookie we use — its name, who sets it, how long it is kept and what it does — is listed in a table on the Cookie Policy page.

No cookie is used for advertising, profiling or selling data to third parties.

8.Your Rights

Under KVKK and the GDPR you may contact us to exercise the following rights:

  • To learn whether your personal data is being processed and request information about it
  • To request correction of incomplete or inaccurate data
  • To request erasure or destruction where the grounds for processing no longer apply
  • To export a copy of your data in a structured format
  • To object to processing and to withdraw consent you have given

9.Changes to This Policy

We may update this policy from time to time. For material changes we notify the e-mail address registered on your account. The current version applies from the date it is published.

10.Contact

Write to us with any questions or requests about our privacy practices. All enquiries go through a single address; naming the type of request in the subject line (for example KVKK Request or Security Report) helps us route it faster.

For KVKK applications and the detail of your rights under Turkish law, see the KVKK Disclosure Notice.