Thing.am Privacy Policy — PMD Solutions LLC
Privacy Policy
thing.am • startthing.com
PMD Solutions LLC
1. Introduction
Welcome to thing.am, a financial management platform for small and service businesses operated by PMD Solutions LLC (“we”, “us”, “our”).
This Privacy Policy explains what personal data we collect when you use thing.am (available at startthing.com and related applications), why we collect it, how we use it, who we share it with, and what rights you have. Please read it carefully.
By creating an account or using our services, you confirm you have read this policy. If you do not agree, please do not use thing.am.
2. Who We Are (Data Controller)
The data controller for your personal data is:
PMD Solutions LLC
Website: startthing.com
Privacy enquiries: [email protected]
Where this policy refers to “GDPR”, it means Regulation (EU) 2016/679. Where it refers to “UK GDPR”, it means the UK General Data Protection Regulation as retained in UK law.
3. Data We Collect
We collect the following categories of personal data:
3.1 Account and Profile Data
* Full name and email address (collected at registration)
* Password (stored in hashed form — we never store your password in plain text)
* Subscription plan, plan history, and account preferences
3.2 Financial Data
* Bank account connections established via Open Banking, including account numbers, sort codes, transaction history, and balances
* Income, expense, and recurring transaction data that you enter or import
* Receipt images that you upload, and extracted data from those receipts
* Excel or CSV files that you import (Advanced plan and above)
* Cash flow reports, budgets, and scenario plans you create in the platform
⚠ TO CONFIRM: Confirm the name(s) of your Open Banking provider(s) (e.g. Plaid, TrueLayer, Yapily) so they can be listed as sub-processors.
3.3 AI Usage Data
* Queries and prompts you submit to the AI CFO Chat (Standard add-on, Advanced add-on, Enterprise included)
* AI credit consumption per query type (basic query, financial analysis, report generation, scenario planning)
* Financial analysis outputs generated by the AI
3.4 Billing and Payment Data
Payments are processed by Paddle, our Merchant of Record. PMD Solutions LLC does not directly collect or store your payment card data. Paddle handles all payment processing in compliance with PCI-DSS. We receive from Paddle: subscription tier, billing date, payment status, and transaction reference.
3.5 Integration Data
* HubSpot integration: contact and deal data synchronised between thing.am and your HubSpot account (Standard: one-way sync; Enterprise/add-on: bidirectional). You authorise this sync.
* MCP integrations: data exchanged with external tools you connect via MCP slots (Advanced: 1 slot; Enterprise: 3 slots). You authorise each integration individually.
* API and webhook data: for Enterprise users who access our API or configure webhooks.
3.6 Technical and Usage Data
* IP address, browser type and version, operating system, and device type
* Usage analytics collected via Google Analytics (pages visited, features used, session duration)
* Behaviour analytics and session recordings collected via Hotjar (see note below)
* Error and diagnostic logs
⚠ LEGAL REVIEW REQUIRED: Hotjar session recording inside authenticated areas of the platform may capture sensitive financial data (transactions, balances, business P&L). Before publishing this policy, confirm that Hotjar is either restricted to public/marketing pages or configured with input masking and suppression in authenticated areas of the app.
3.7 Communications Data
* Support requests and correspondence (email, in-app messages)
* Renewal and billing notification emails (transactional)
* Marketing and promotional emails (you can opt out at any time — see Section 9)
4. How and Why We Use Your Data
We only use your data for specific, lawful purposes. The table below sets out each purpose, the data involved, and our legal basis under GDPR and UK GDPR.
Purpose
Data used
Legal basis (GDPR/UK GDPR)
Providing the thing.am service (account, features, financial tracking)
Account, financial, AI usage, integration data
Performance of contract (Art. 6(1)(b))
Processing payments and managing subscriptions
Billing data (via Paddle)
Performance of contract (Art. 6(1)(b))
Sending transactional emails (receipts, renewal reminders, credit alerts)
Account and billing data
Performance of contract (Art. 6(1)(b))
Keeping tax and financial records
Billing records
Legal obligation (Art. 6(1)(c))
Preventing fraud, security monitoring, and abuse detection
Account, usage, and technical data
Legitimate interests (Art. 6(1)(f))
Improving the platform and analysing product usage
Usage and technical data (anonymised or pseudonymised)
Legitimate interests (Art. 6(1)(f))
Providing customer support
Account and communications data
Legitimate interests (Art. 6(1)(f))
Sending marketing and promotional emails
Account and communications data
Consent (Art. 6(1)(a)) for EU/UK users [CONFIRM opt-in mechanism]; Legitimate interests for others
Cookies and analytics tracking
Technical and usage data
Consent (Art. 6(1)(a)) where required by ePrivacy / PECR
⚠ LEGAL REVIEW REQUIRED: Marketing email legal basis: The current product plan uses a pre-ticked opt-out box. This does not meet GDPR Article 7 requirements for EU/UK users (consent requires a clear affirmative action). Before publishing, either: (a) add an explicit opt-in checkbox for EU/UK users at signup, or (b) rely on the ‘soft opt-in’ exception if all conditions are met. Resolve with legal counsel.
5. Who We Share Your Data With
We do not sell your personal data. We share it only with the service providers (“sub-processors”) needed to operate thing.am, and only to the extent necessary. Each sub-processor is subject to a Data Processing Agreement.
Sub-processor
Purpose
Location
Safeguards
Paddle
Payment processing (Merchant of Record)
UK / EU
PCI-DSS; Paddle Privacy Policy
AWS (Amazon Web Services)
Cloud hosting and data storage
EU (Frankfurt)
SCCs; AWS DPA
HubSpot
CRM integration (user-authorised)
USA
SCCs; HubSpot DPA
Google Analytics
Usage analytics
USA
SCCs; IP anonymisation enabled
Hotjar
Behaviour analytics and session recording
EU
Hotjar DPA; input masking [CONFIRM]
Open Banking provider(s) [CONFIRM NAME]
Bank account data connections
[CONFIRM]
FCA-regulated / PSD2-compliant
MCP integration services (user-chosen)
External tool connections you authorise
Varies
User authorises each; terms of the integrated service apply
We may also disclose your data where required by law (e.g. court order, regulatory request), to protect the rights or safety of our users, or in connection with a business transfer (see Section 12).
6. Cookies and Tracking Technologies
We use cookies and similar technologies on our website and platform. Some are strictly necessary for the service to function; others help us understand how people use thing.am.
Category
Examples
Purpose
Consent required?
Strictly necessary
Session cookie, CSRF token
Login, security, core function
No
Analytics
Google Analytics (_ga)
Measuring usage and feature adoption
Yes (EU/UK)
Behaviour / recording
Hotjar (_hjSession)
Session recording, heatmaps (marketing pages only)
Yes (EU/UK)
EU and UK users will be shown a cookie consent banner. You can withdraw consent at any time through the cookie settings link in our footer.
⚠ LEGAL REVIEW REQUIRED: A cookie consent management platform (CMP) must be implemented before launch for EU/UK users. This is required by the ePrivacy Directive and UK PECR. Analytics and Hotjar cookies must not load until consent is given.
7. International Data Transfers
Your data is primarily stored in the EU (AWS Frankfurt). Some of our sub-processors are based outside the EU/EEA, including the United States (HubSpot, Google Analytics). We ensure these transfers comply with GDPR Chapter V by relying on:
* Standard Contractual Clauses (SCCs) approved by the European Commission, and
* Adequacy decisions where applicable.
For UK users: we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs for transfers from the UK to non-adequate countries.
A copy of the relevant transfer mechanism is available on request by emailing [email protected].
8. Data Retention
We keep your personal data only for as long as necessary for the purposes set out in this policy, or as required by law.
⚠ TO CONFIRM: Retention periods below are recommended defaults. Confirm with your engineering/product team before publishing.
Data category
Retention period
Account data (name, email, preferences)
Deleted within 30 days of account deletion request [CONFIRM]
Financial data (transactions, receipts, reports)
Retained for [X] years after account deletion [CONFIRM]; may be retained longer to comply with tax obligations
Billing records (invoices, payment history)
7 years from the date of the transaction (tax legal obligation)
AI CFO Chat queries and outputs
Retained while your account is active; deleted [X days/months] after account deletion [CONFIRM]
Support correspondence
2 years from resolution of the support request [CONFIRM]
Usage analytics (Google Analytics)
26 months (Google Analytics default)
Session recordings (Hotjar)
365 days (Hotjar default) [CONFIRM]
When we no longer need your data, we delete or anonymise it securely. You can request deletion of your account at any time (see Section 10).
9. Marketing Communications
We may send you marketing and promotional emails about thing.am features, offers, and updates.
You can opt out at any time by clicking the ‘unsubscribe’ link in any marketing email, or by emailing [email protected]. Opting out of marketing emails will not affect transactional messages such as billing receipts and renewal reminders.
⚠ LEGAL REVIEW REQUIRED: Current plan: pre-ticked opt-out at signup. This is not valid consent under GDPR for EU/UK users. Resolve before publishing: either use an explicit opt-in checkbox for EU/UK users, or document reliance on the soft opt-in exception (existing customers, similar services, clear opt-out). Seek legal advice.
10. Your Privacy Rights
10.1 Rights under GDPR and UK GDPR
If you are in the EU, EEA, or UK, you have the following rights:
* Right of access — you can request a copy of the personal data we hold about you.
* Right to rectification — you can ask us to correct inaccurate or incomplete data.
* Right to erasure (‘right to be forgotten’) — you can ask us to delete your data in certain circumstances.
* Right to restriction — you can ask us to restrict processing in certain circumstances.
* Right to data portability — you can request your data in a structured, machine-readable format.
* Right to object — you can object to processing based on legitimate interests or for direct marketing.
* Right to withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
* Right to lodge a complaint — you have the right to complain to your supervisory authority (e.g. the ICO in the UK, or your EU Member State’s data protection authority).
10.2 Rights under the CCPA / CPRA (California residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (as amended by the CPRA):
* Right to know: you can ask what personal data we collect, use, share, or sell.
* Right to delete: you can ask us to delete your personal data (subject to legal exceptions).
* Right to correct: you can ask us to correct inaccurate personal data.
* Right to opt out of sale or sharing: we do not sell or share your personal data for cross-context behavioural advertising.
* Right to non-discrimination: we will not discriminate against you for exercising your privacy rights.
10.3 Exercising your rights
To exercise any of the rights above, email us at [email protected]. We may ask you to verify your identity before responding. We will respond to GDPR/UK GDPR requests within 1 calendar month (extendable to 3 months for complex requests, with notice). We will respond to CCPA requests within 45 days (extendable to 90 days with notice).
11. Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These include:
* Encryption of data in transit (TLS) and at rest
* Password hashing (we never store passwords in plain text)
* Access controls limiting who within our organisation can access your data
* Regular security monitoring and vulnerability management
No system is completely secure. If you discover a security vulnerability, please email [email protected].
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (where required by GDPR) and will notify affected users without undue delay where required.
12. Business Transfers
If PMD Solutions LLC is involved in a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the acquiring entity as part of that transaction. We will notify you via email and/or a notice on our website and give you an opportunity to make choices about your data before it is subject to a different privacy policy.
13. Children’s Privacy
thing.am is not directed at children under the age of 16 (or such higher age as required by applicable law). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at [email protected] and we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email to your registered address and/or by posting a notice in the thing.am application at least 14 days before the changes take effect.
The date at the top of this policy shows when it was last updated. Your continued use of thing.am after the effective date of changes constitutes your acceptance of the updated policy.
15. Contact Us
For any questions about this Privacy Policy, to exercise your rights, or to submit a data subject access request, contact us at:
PMD Solutions LLC — thing.am / startthing.com
Email: [email protected]