Privacy Policy for TemplateDocs
Last Updated: July 18, 2026
Thank you for visiting TemplateDocs ("we," "us," or "our"). TemplateDocs is operated by ByteSail, located in Kfar Adummim, Israel.
This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our website, application, APIs, forms, and related services (collectively, the "Service").
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree with the practices described in this policy, please do not use the Service.
This Privacy Policy is intended to provide information required by applicable privacy laws, including the General Data Protection Regulation (GDPR) and the California Privacy Rights Act (CPRA), where applicable.
This Privacy Policy applies to personal information that TemplateDocs processes for its own purposes, such as account and website information. When customers use TemplateDocs to process personal data in templates, forms, workflows, documents, or other Customer Data, TemplateDocs generally acts as a processor or service provider on behalf of the customer. That processing is governed by our Data Processing Addendum at https://templatedocs.io/dpa.
1. Information We Collect
We collect personal information necessary for providing and operating our services. The information we collect depends on how you use the Service.
1.1. Personal Information
We may collect the following personal information when you use our services:
- Name
- Email address
- Organization and account information
- Communications with us
- Subscription and billing-related information
Payments are processed by Paddle, our merchant of record. TemplateDocs does not directly receive or store full payment card details.
Under GDPR, where applicable, we process personal information based on contractual necessity, legitimate interests, consent, and compliance with legal obligations, depending on the purpose of the processing.
1.2. Customer Data
Customers may submit, store, or process content through the Service, including:
- Data submitted through forms, APIs, webhooks, or other integrations
- Workflow inputs, outputs, variables, and related metadata
- Uploaded templates and other files
- Generated documents and other workflow outputs
- Email content and recipient information
- Integration credentials and authorization data
The nature of Customer Data is determined by each customer. TemplateDocs does not control what personal data customers choose to process through the Service.
Where Customer Data contains personal data, the customer is responsible for determining the purposes and lawful basis for that processing and for providing any notices or obtaining any consents required by applicable law.
1.3. Non-Personal Information
We collect limited technical and usage information to analyze trends, operate and improve our services, and identify technical issues. This may include:
- Page views and navigation patterns
- Referrer information, excluding personal tracking IDs where feasible
- Aggregated session counts
- Browser and device type
- Hashed or masked identifiers and IP information
- Product usage and error telemetry
Product analytics and error telemetry are configured with data-minimization, masking, and pseudonymization measures. Where applicable, this data is processed under our legitimate interests (Article 6(1)(f) GDPR) in operating and improving the Service while respecting user privacy.
We do not use Customer Data for advertising or to train AI models.
2. How We Use Your Information
We collect and process personal information to:
- Provide, operate, maintain, and secure the Service
- Process service requests and execute customer workflows
- Manage accounts and organizations
- Facilitate payments
- Communicate with you about the Service
- Provide support and troubleshoot technical issues
- Analyze and improve product performance and usability
- Detect, prevent, and respond to abuse, fraud, and security incidents
- Comply with legal obligations and enforce our agreements
Customer Data is processed only as necessary to provide the Service, follow customer instructions, secure and protect the Service, comply with applicable law, and as otherwise described in our Data Processing Addendum.
3. Legitimate Interest for Analytics
We process limited usage analytics to improve our services while minimizing the personal information involved. This data helps us enhance product performance, usability, and security.
Our analytics approach:
- Does not use cookies or persistent identifiers for analytics
- Masks personal information in analytics and error payloads
- Hashes user and organization identifiers
- Does not use analytics data for advertising
- Respects "Do Not Track" (DNT) browser settings
- Provides an opt-out option in account settings
Where applicable, this processing is based on our legitimate interests in operating and improving the Service while respecting user privacy.
If you prefer to opt out of analytics tracking, you can disable it via your account settings.
4. Customer Data Processing and Retention
Customer Data may be processed and retained as follows:
- Templates are stored until deleted by the customer.
- Form submissions, webhook inputs, workflow step data, run logs, and generated documents associated with workflow runs are retained according to the organization's configured retention period and applicable plan defaults. The standard default run-history retention period is 30 days.
- Webhook test samples are retained as needed to configure the input schema and may be replaced by newer samples.
- Documents generated through the direct document-generation API are processed temporarily and are not stored by TemplateDocs after delivery.
- Temporary files and in-memory generation buffers are deleted after the relevant operation completes.
- Application and operational logs may contain limited Customer Data and are retained for up to 30 days.
- Database backups are managed by our infrastructure provider and are generally retained for up to 7 days.
When a workflow run is deleted, associated step inputs and outputs, logs, and generated files are removed. When a template is deleted, its stored files and related metadata are removed.
When an account is deleted, we delete the account and Customer Data owned by organizations that are deleted with it, subject to limited backup retention, legal obligations, and records that third parties such as Paddle must retain for tax, accounting, or compliance purposes.
5. Data Sharing and Disclosure
We do not sell or rent personal information or Customer Data.
We use trusted third-party service providers to operate the Service. Depending on the features used, these may include:
| Provider | Purpose | Processing Location |
|---|---|---|
| Google Cloud Platform and Google services | Cloud services and infrastructure, logging, secrets management, document processing, and URL-safety scanning | Primarily European Union; some security services may operate globally |
| Supabase | Database, authentication, file storage, and backups | European Union |
| Resend | Default email delivery | United States and European Union |
| Crisp | Customer support and website messaging | European Union |
| Mixpanel | Product analytics and error telemetry using masked or pseudonymized data | European Union |
| Paddle | Payments and billing as merchant of record | United Kingdom and United States |
| Microsoft Azure and Microsoft services | Additional cloud services and document processing | Depends on the service and configuration |
| OpenAI, Anthropic, and Google AI | Customer-invoked AI features and automated outbound-email moderation | United States and other locations depending on provider and service |
These service providers are permitted to process data only as necessary to provide their services to us and are subject to applicable contractual and data protection obligations.
When a customer configures its own SMTP server or another third-party integration, Customer Data may be sent directly to that destination at the customer's instruction.
Document content may temporarily pass through Microsoft or Google services when customers use features that require document editing or conversion.
Outbound workflow emails may be automatically analyzed by AI services for abuse moderation, and embedded URLs may be checked through Google Web Risk or similar security services. This processing is performed to protect the Service and its users. If a customer configures its own SMTP server, workflow email content is not sent to our default email-delivery provider or to these AI providers for outbound-email moderation.
We may also disclose information where required by law, to protect legal rights or security, or in connection with a merger, acquisition, financing, or sale of assets, subject to applicable safeguards.
Our Data Processing Addendum contains the authoritative list of subprocessors that may process Customer Personal Data.
6. International Data Transfers
Our primary application infrastructure, databases, queues, and file storage are located in Europe.
ByteSail is established in Israel, and authorized personnel may access production systems and Customer Data from Israel where necessary for support, debugging, security, or legal compliance.
Some service providers may process data outside the European Economic Area or Israel. Where required by applicable law, we use appropriate safeguards for international transfers, such as adequacy decisions or contractual protections.
7. Children's Privacy
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information directly from children under 13.
Customers are responsible for ensuring that their own use of the Service, including Forms, complies with applicable requirements relating to children and minors.
8. Security
We implement appropriate technical and organizational measures designed to protect personal information and Customer Data from unauthorized access, alteration, disclosure, or destruction.
These measures include, as applicable:
- Encryption in transit using TLS/HTTPS
- Encryption at rest through our infrastructure providers
- Storage of integration credentials in Google Cloud Secret Manager
- Logical isolation of customer data by organization
- Role-based access controls
- Restricted production access for authorized personnel
- Multi-factor authentication for authorized personnel with administrative or production access
- Automated backups
- Logging, monitoring, and alerting
- Incident-response procedures
Additional information about the security measures applied to Customer Personal Data is available in our Data Processing Addendum.
While we use reasonable safeguards, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Information About Other Individuals
Customers may submit or collect information about other individuals through the Service, including through forms, APIs, webhooks, integrations, and other ways of submitting data to the Service. In those cases, the customer determines what information is collected, why it is processed, and how it is used.
The customer is responsible for:
- Establishing a lawful basis for collecting and processing personal data
- Providing any privacy notices required by applicable law
- Obtaining any required consent
- Ensuring that the information collected is appropriate for the customer's intended use
Public forms may display "Powered by TemplateDocs" or similar service branding. TemplateDocs does not provide a customer-specific privacy notice to individuals submitting information through the Service.
If your information was submitted to TemplateDocs by one of our customers and you wish to exercise privacy rights regarding that information, you should generally contact that customer. We will provide reasonable assistance to the customer where required by applicable law.
10. Cookie Policy
Our website does not use cookies for analytics tracking. However, essential cookies and similar technologies may be used to enable necessary website and application functionality, such as authentication, security and support.
You can configure your browser to refuse cookies, but this may affect certain features of the Service.
11. Your Rights
Under applicable privacy laws, including GDPR and CPRA where relevant, you may have rights regarding personal information that TemplateDocs controls, including the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your information
- Object to or restrict certain processing
- Withdraw consent where relevant
- Opt out of analytics tracking
You will not be discriminated against for exercising applicable privacy rights.
To exercise rights regarding account information or other personal information controlled by TemplateDocs, contact us at support@templatedocs.io.
For personal data contained in Customer Data, requests should generally be directed to the relevant TemplateDocs customer. TemplateDocs provides in-product deletion controls and reasonable assistance to customers responding to data-subject requests.
12. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, provide the Service, or meet legal, accounting, security, and compliance obligations.
Specific retention periods for Customer Data are described in Section 4 above and may depend on the customer's plan and organization settings.
Analytics data is retained according to our data retention settings in Mixpanel and is masked or pseudonymized as described above.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by email or through the Service.
14. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy, please contact us at support@templatedocs.io.
ByteSail
23 Eretz Binyamin
Kfar Adummim
Israel