tovin.io
LedgersFor FinanceGuidesField notesCompare
PricingSign in Start free
CloudsAWS · GCP · DigitalOceanMappingTags, accounts, regexCadenceWeekly reviewOpen
Privacy Policy

What we collect, where it lives, and how to make us delete it.

Last updated 2026-06-17

Tovin.io is a cloud cost monitor operated by VectraSEO LLC, a Pennsylvania limited liability company (“VectraSEO”, “Tovin.io”, “we”, “us”). VectraSEO is the data controller for the personal data described here. This policy describes what we collect when you use tovin.io and app.tovin.io, why we collect it, the legal bases we rely on, where it is stored, and the choices you have. It is written to be read, not skimmed past — if anything here is unclear, email hello@tovin.io and a human will answer.

Who we are

The service is provided by VectraSEO LLC, a limited liability company organized under the laws of the Commonwealth of Pennsylvania, USA. For any privacy question, request, or complaint, contact us at hello@tovin.io; a postal address for legal notices is available on request.

What we collect

  • Account data: your email address (we are passwordless — sign-in links are sent to it), organization names, and team membership.
  • Cloud billing metadata: cost rows, service names, resource identifiers, and tags pulled from AWS Cost Explorer, your GCP BigQuery billing export, and the DigitalOcean billing API — via the read-only credentials you connect. We never see your workloads, file contents, databases, or application data; only billing metadata.
  • Cloud credentials: the AWS role ARN/external ID or access keys, GCP service-account key, or DigitalOcean token you provide. Each credential blob is envelope-encrypted with a per-blob AES-256-GCM data key wrapped by AWS KMS and bound to your organization — it is never logged, never returned by the API, and cannot be decrypted for a different organization.
  • Billing data: if you upgrade to a paid plan, payment is processed by Stripe. We store your Stripe customer and subscription identifiers; your card number never touches our servers.
  • Newsletter email: if you subscribe to the Friday note, your email is processed by EMCognito, our newsletter delivery provider.
  • Usage analytics: we use Google Analytics (gtag.js) on the marketing site to understand which pages are read. Standard server logs (IP address, user agent, request path) are kept for security and debugging.

What we do not collect

  • No passwords — authentication is magic-link only; sign-in tokens are single-use, HMAC-hashed at rest, and expire after 15 minutes.
  • No workload or application data — every cloud integration uses read-only billing scopes, validated with a no-op call on connect.
  • No data sold for money — we do not sell, rent, or trade your personal data for money. We use Google Analytics for marketing-site measurement, which some U.S. state laws (including California) treat as “sharing” of personal information; you can opt out via the cookie banner or your browser’s Global Privacy Control signal — see “Cookies and analytics” and “California privacy rights” below.

How we use your data

  • To run the product: ingest and aggregate your billing data into project ledgers, budgets, forecasts, and anomaly alerts.
  • To send email you control: sign-in links and team invites (transactional), plus alert emails and the weekly digest — both toggleable in Settings.
  • To bill paid plans through Stripe.
  • To improve the product, using aggregate usage patterns.
  • We may publish aggregated, anonymized statistics (for example, the share of untagged spend by cloud) only from organizations that explicitly opt in, and never in a form that could identify a customer.

Legal bases (EU/EEA & UK)

Where the GDPR or UK GDPR applies, we process personal data on these legal bases:

  • Performance of a contract (Art. 6(1)(b)) — to create your account, ingest and present your billing data, and provide the service you signed up for.
  • Legitimate interests (Art. 6(1)(f)) — to secure the service, prevent abuse, keep server logs, and improve the product using aggregate usage patterns, balanced against your rights.
  • Consent (Art. 6(1)(a)) — for the marketing newsletter and for non-essential analytics cookies; you can withdraw consent at any time without affecting prior processing.
  • Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, and other laws that apply to us.

Where your data lives & international transfers

All customer data at rest is stored in Amazon Web Services, US East (N. Virginia, us-east-1): DynamoDB for application data, KMS for credential encryption keys, and S3 for static assets. The API runs on DigitalOcean Kubernetes and holds no data at rest. Transactional email is sent through Amazon SES.

If you are in the EU/EEA or UK, your personal data is transferred to and processed in the United States. We rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) as the transfer mechanism, together with the technical safeguards described on our Security page. A copy of the relevant clauses is available on request at hello@tovin.io. If you need a different residency arrangement, talk to us before connecting production accounts.

Subprocessors

  • Amazon Web Services — hosting, storage, encryption, email delivery (US).
  • DigitalOcean — API compute (US).
  • Stripe — payment processing.
  • EMCognito — newsletter delivery (only if you subscribe).
  • Google Analytics — marketing-site usage analytics.

Retention and deletion

  • Deleting a cloud connection permanently deletes its encrypted credential blob.
  • Deleting a project removes its mapped cost aggregates.
  • Deleting your organization cascades: connections, credentials, rules, projects, cost rows, alerts, and memberships are removed.
  • Magic-link tokens self-expire after 15 minutes; refresh sessions expire after 7 days.
  • Operational logs and backups age out on a rolling window (point-in-time recovery retains 35 days).
  • To delete your account entirely or to export your data, email hello@tovin.io — we will confirm completion.

Cookies and analytics

  • Strictly necessary: the app sets one httpOnly refresh cookie to keep you signed in (7-day lifetime, scoped to authentication). This is essential to the service and is not subject to consent.
  • Analytics (non-essential): the marketing site uses Google Analytics (gtag.js, measurement ID G-8K3SSGPW4Q) to understand which pages are read. These cookies load only after you accept them in the cookie banner. We run Google Consent Mode v2 with all consent signals defaulted to “denied,” so no analytics cookies are set until you opt in.
  • Global Privacy Control: if your browser sends a GPC signal, we treat it as a valid opt-out of analytics/“sharing” and do not load Google Analytics — you do not need to interact with the banner.
  • You can change or withdraw your choice at any time from the “Cookie settings” link in the site footer. We do not run advertising or cross-site retargeting cookies.

Your rights

You can access, correct, export, or delete your personal data at any time — most of it directly in the product, and anything else by emailing hello@tovin.io. We respond within 30 days. We will not discriminate against you for exercising any of these rights.

EU/EEA & UK data rights

If you are in the EU/EEA or UK, you have the rights to access, rectification, erasure, restriction, data portability, and objection, and the right to withdraw consent at any time. To exercise them, email hello@tovin.io; we respond within one month.

You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office; in the EU, the data-protection authority of your country). We would appreciate the chance to address your concern first. If we are required to appoint an EU/UK representative under Article 27, their contact details will be published here.

California privacy rights

Under the California Consumer Privacy Act as amended (CCPA/CPRA), California residents have the right to know, access, correct, delete, and to opt out of the “sale” or “sharing” of personal information, and to limit use of sensitive personal information. We do not sell personal information for money and do not use sensitive personal information for any purpose requiring a limitation right.

  • Categories we collect: identifiers (email), commercial/usage information (cloud billing metadata you connect, product usage), internet activity (analytics, server logs), and the cloud credentials you provide (held encrypted).
  • Purposes: to provide, secure, and improve the service, to bill paid plans, and to send email you control. See “How we use your data” above.
  • “Sharing”: our only disclosure that may count as “sharing” under the CPRA is Google Analytics on the marketing site. You can opt out using the cookie banner, the “Cookie settings” footer link, or a Global Privacy Control browser signal, all of which we honor.
  • To exercise any California right, email hello@tovin.io. We will verify your request against your account email and respond within 45 days. You may use an authorized agent.

Children

Tovin.io is a business tool not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, email hello@tovin.io and we will delete it.

Security

Read-only credential scopes, KMS envelope encryption with tenant-bound context, rate-limited authentication, sanitized provider errors, and a public vulnerability-disclosure channel — the full posture is documented on our Security page and kept current.

Changes and contact

If this policy changes materially, we will note it in the changelog and update the date at the top of this page before the change takes effect; where the law requires, we will seek your consent. Questions, requests, or complaints: hello@tovin.io (a postal address is available on request).

Companion documents: Terms of Service · Security

✉︎ The Friday note

Get the weekly cloud cost note,
delivered Fridays.

What shipped, what broke, and what engineering teams are learning about AWS, GCP, and DigitalOcean spend. Unsubscribe with one click.

By subscribing you agree to receive one short email per week. No paid plugs.

Tovin.io

  • About
  • Changelog
  • Security
  • Open source
  • Privacy
  • Terms

Reading

  • Guides
  • Comparisons
  • Glossary
  • Field notes

For engineers

  • Docs
  • Pricing
  • Contact
  • Sign in

For finance

  • For finance teams
  • Cloud financial management
  • Month-end cloud close
  • SaaS gross margin

Stay in the loop

  • The Friday note
  • DigitalOcean wedge
  • FinOps for small teams

© 2026 Tovin.io · A multi-cloud cost ledger for engineering-led teams

Read-only credentials·KMS-encrypted at rest·No paid media· Last reviewed 2026-06-12