Privacy Policy – Thimblehub
Effective Date: November 1, 2026
Last Updated: November 1, 2026
At Thimblehub, we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how Thimblehub, Inc. (“Thimblehub,” “we,” or “us”) collects, uses, discloses, and safeguards information when you use our website and Services or otherwise interact with us. It also describes your rights and choices regarding your personal information. This policy applies to all users and customers of our Services and website, and it is incorporated into our Terms of Service above. By using Thimblehub's website or Services, you agree to the collection and use of information in accordance with this Privacy Policy.
If you have any questions about this policy or our data practices, please contact us using the information provided at the end of this policy.
Information We Collect
We may collect several types of information from or about you, including:
- Information You Provide Directly: When you create an account, purchase our Services, or communicate with us, you may provide personal information such as your name, business name, email address, phone number, billing address, and payment details. For example, during checkout or registration we'll ask for contact details and billing information to process your order. If you contact customer support or fill out a form, we will collect whatever information you choose to provide in that correspondence.
- Account and Transaction Information: In the course of using our Services, you might provide additional information. For instance, if you use our Portal service to store data, you may upload content or data that could include personal information about you or third parties. If you use the Sites service (website development), you might send us content (text, images, etc.) to include on your website, which could contain personal information. We also keep records of your purchases, subscription plan, and payment history with Thimblehub.
- Automatically Collected Information: Like many websites, we (or our third-party partners) use cookies and similar tracking technologies to collect certain information automatically when you visit our site or use the Services. This may include your IP address, browser type, device identifiers, the pages or features you access, the dates/times of access, and referral information (how you arrived at our site). We may also track usage data such as clicks, scrolls, and errors to help improve our Services. This automatically collected data helps us understand how users interact with our site and Services. (See Cookies and Tracking below for more details.)
- Analytics Data: We use third-party analytics services (such as Google Analytics or similar tools) that use cookies and internet technologies to collect data about use of our website and Services. This includes information on which pages you visit, how long you stay, how you navigate the site, and other usage metrics. This information is generally aggregated and does not identify you individually; it helps us analyze trends and user needs so we can enhance user experience.
- Information from Third Parties: We may receive information about you from third-party sources. For example, if you login or register via a third-party identity provider (like Google or LinkedIn), we might receive your name and email from them (with your consent). Or, if a business partner or referral gave us your information, we will only use it for the purposes for which it was provided (such as contacting you to offer our Services, if permitted). We also might receive confirmation of payment from our payment processors or updated address information from shipping providers, etc.
- Sensitive Information: Generally, we do not seek to collect sensitive personal information (such as Social Security numbers, health information, or biometric data) through our site, unless necessary for providing a specific Service. If you are using our Services to store sensitive data (including health information/PHI in the Portal), please note that such processing is governed by our MSA (which includes a Business Associate Agreement, if applicable) rather than just by this general Privacy Policy. We handle sensitive data in compliance with relevant laws and our contractual obligations to you, but we expect you to only upload such data if it's necessary and permitted.
We do not knowingly collect personal information from children under 13, and our Services are not directed to minors. If you are under 13 (or under 16 in certain jurisdictions), please do not submit any personal information to us. We do not knowingly collect, sell, or share personal information about consumers under the age of 16. If we learn that we have inadvertently collected personal data from a child under 13, we will take steps to delete it. Parents or guardians who believe their child may have provided us personal information should contact us so we can remove it.
How We Use Your Information
We use the information we collect for various purposes consistent with providing and improving our Services, as well as for legitimate business and legal reasons. The uses include:
- Providing and Maintaining Services: We use your information to deliver the Services you have requested, to process transactions (e.g., billing and fulfillment), to authenticate you when you log in, and to operate and maintain our platform. For example, we use your payment information to charge for subscriptions, and we use data you upload to provide the functionality of the Cart, Sites, or Portal service to you.
- Improving and Developing Services: We analyze usage data and feedback to understand how our Services are used and to make improvements. This helps us fix bugs, optimize user experience, and develop new features or services that better meet user needs.
- Personalization: We may use information like your preferences, past interactions, or organization profile to personalize your experience. This could include customizing content or recommendations on our dashboard, or adjusting our communications to be more relevant to your interests.
- Communication: We use contact information (email, phone) to send you important notices about your account or transactions, such as confirmations, invoices, technical alerts, security notifications, or support messages. We may also send you informational or marketing communications about product updates, new features, newsletters, or promotions, but you can opt out of marketing emails at any time.
- Customer Support: If you contact us with questions or for assistance, we will use your information to respond and resolve issues. This may require accessing your account information, trouble tickets, or the data you have stored with us (with your permission) to troubleshoot problems.
- Security and Fraud Prevention: We may use personal and technical information to monitor for and prevent fraudulent, abusive, or unlawful activities.
- Legal Compliance: We will use or disclose your information as necessary to comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
- Aggregated Analytics: We may aggregate or de-identify personal information to remove any identifying elements and use that data for analytical purposes, such as calculating overall platform usage statistics or security trends. Aggregated data cannot reasonably be used to identify any individual and may be used by us for any lawful purpose.
- Other Purposes: We may use your information for any other purpose described to you at the time the information was collected or with your consent.
How We Share and Disclose Information
Thimblehub is not in the business of selling your personal information. We do not sell personal information to third parties for monetary consideration. However, we do share certain information with third parties in the following circumstances:
- Service Providers: We share personal information with trusted third-party service providers and partners who perform services on our behalf.
- Business Transactions: If we are involved in a merger, acquisition, sale of assets, financing, or transfer of all or a portion of our business to another company, your information may be transferred to the acquiring or successor entity as part of that transaction.
- Legal Requirements and Safety: We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary.
- Professional Advisors: We may share information with our lawyers, accountants, and other professional advisors.
- Affiliates: We may share information with our corporate affiliates.
- With Your Consent or At Your Direction: We will share your personal information with third parties when we have your consent to do so.
In all cases, we disclose only the minimum amount of personal information necessary for the specific purpose.
Cookies and Tracking Technologies
Thimblehub uses cookies and similar tracking technologies to provide and improve our Services. We use cookies for:
- Authentication: To recognize you when you log in and keep you logged in.
- Preferences: To remember your settings and preferences.
- Analytics: To help us understand user activity on our website.
- Advertising (if applicable): Currently, we do not serve third-party ads on our site.
You have choices regarding cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies or alert you when a cookie is being placed. However, please note that if you disable or reject cookies, some features of our site or Services may not function properly.
Do-Not-Track Signals: Our website does not currently respond to DNT signals because there is no industry-standard approach to doing so.
Third-Party Analytics and Tracking: We use third-party analytics services like Google Analytics. You can often opt out by installing a browser add-on or by using privacy plug-ins that block trackers.
Data Security
We take reasonable and appropriate measures to protect the security of your personal information from unauthorized access, alteration, disclosure, or destruction. Thimblehub implements administrative, technical, and physical safeguards designed to protect personal data.
However, please note that no method of transmission over the Internet or method of electronic storage is completely secure. In the event of a data breach that affects your personal information, we will act promptly to contain and investigate the breach, and notify you and any applicable regulators as required by law.
Data Retention
We will retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy. We generally follow these guidelines:
- Account Data: Information associated with your account is kept until you delete the account or for a set period of inactivity.
- Content/Data on Services: If you delete specific content from our Services, we will make efforts to remove it from active use, but it may persist in backups or archives for a period.
- Legal Obligations: We might need to retain certain records to comply with our legal obligations.
- Disputes and Enforcement: If there is an ongoing dispute, we will retain the necessary information until it is resolved.
Your Rights and Choices
- Access and Correction: You may access and update certain account information by logging into your Thimblehub account.
- Deletion: You can request that we delete your personal information.
- Opt-Out of Marketing Communications: You can unsubscribe at any time by clicking the “unsubscribe” link in marketing emails.
- Do Not Sell or Share (California/CCPA): We do not sell personal information to third parties for monetary value.
- California Privacy Rights: If you are a California resident, you have specific rights under the CCPA/CPRA.
- GDPR and International Rights: If you are in the EEA, UK, or other region with similar data protection laws, you may have rights under the GDPR or equivalent laws.
- Choices in Services: Where we provide you with administrative controls within the Services, you can use those controls to manage your data directly.
International Data Transfers
Thimblehub is based in the United States, and our website and Services are hosted in the U.S. If you are accessing from outside the U.S., be aware that your information will likely be transferred to, stored, and processed in the United States.
Third-Party Links and Services
Our website or Services may contain links to third-party websites. This Privacy Policy does not apply to information collected on any third-party site or service that is not controlled by Thimblehub.
Changes to this Privacy Policy
We may update or change this Privacy Policy from time to time. If we make material changes, we will provide prominent notice. Your continued use of our Services after the effective date of an updated Privacy Policy will constitute your acceptance of the changes.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or about your personal information, please contact us at:
Email: hello@thimblehub.com (Please include “Privacy Inquiry” in the subject line)
We will respond to your inquiries as soon as reasonably possible, generally within 30 days.