Last updated: 2026-05-31
Privacy policy
How TontonPro SASU collects, processes and protects personal data in the operation of tontontools.com and the TontonTools products.
This Privacy Policy explains how TontonPro SASU collects, uses and protects personal data in connection with the website tontontools.com, the TontonTools software products, customer communications and related services.
1. Data controller
The data controller is TontonPro SASU, registered with the Versailles Trade and Companies Register under number 994 272 045 R.C.S. Versailles, with its registered office at 15 Rue des Coquelicots, Maison 15, 78500 Sartrouville, France.
For any privacy-related request, you may contact us at contact@tontontools.com.
2. Scope of this policy
This policy applies to personal data processed by TontonPro SASU when you:
- visit tontontools.com;
- contact us by email or through any contact channel made available on the website;
- request information about TontonTools;
- download, trial, purchase or use TontonTools software;
- interact with product activation, licensing or support processes;
- communicate with us as a customer, prospect, partner or supplier.
Where purchases, subscriptions, invoicing and payment processing are handled by Lemon Squeezy LLC as Merchant of Record, Lemon Squeezy may process personal data under its own privacy policy and contractual terms.
3. Personal data we may collect
Depending on your interactions with us, we may process the following categories of data.
Identification and contact data
- first name and last name;
- professional or personal email address;
- company name;
- job title or role;
- country;
- billing or business contact details, where applicable.
Commercial and contractual data
- products or subscriptions selected;
- license tier;
- activation status;
- customer reference;
- support history;
- refund or cancellation requests;
- subscription status, where made available to us by the Merchant of Record.
Technical data
- IP address;
- browser type, device type and operating system;
- approximate location derived from technical connection data;
- security logs, website access logs and download logs;
- software activation logs;
- diagnostic data voluntarily sent in the context of support.
Software licensing data
- license key or license identifier;
- product activated and activation date;
- workstation or device identifier used for licensing control;
- tenant or organization identifier, where necessary for enterprise licensing;
- number of activations used;
- subscription validity status.
Support data
- support messages;
- screenshots or logs you choose to send us;
- diagnostic files;
- description of your IT environment, only where necessary to understand or resolve your request.
4. Purposes of processing
We process personal data for the following purposes:
- operating and securing the website;
- responding to enquiries and support requests;
- providing software downloads, trials and updates;
- managing licenses, activations and subscription status;
- preventing fraud, misuse, unauthorized sharing of licenses and security abuse;
- improving the website, documentation and software products;
- managing customer relationships;
- handling contractual, accounting and administrative obligations;
- complying with legal obligations;
- establishing, exercising or defending legal claims.
5. Legal bases
Depending on the processing activity, we rely on one or more of the following legal bases under the GDPR.
- Performance of a contract — providing access to purchased or trial software, managing licenses and activations, delivering support, and handling subscription-related requests.
- Legitimate interests — securing the website and software, preventing fraud and license abuse, improving products and documentation, communicating with professional prospects and customers, and keeping evidence of customer interactions and technical incidents.
- Legal obligations — accounting, tax, invoicing and business record obligations, and compliance with applicable legal or regulatory requirements.
- Consent — optional cookies and analytics where required, and marketing communications where consent is required.
6. Merchant of Record and payment data
Payments, subscriptions, invoicing, tax calculation and checkout operations may be handled by Lemon Squeezy LLC as Merchant of Record. TontonPro SASU does not intend to directly collect or store full credit card numbers or payment card security codes through its own website.
When you purchase through Lemon Squeezy, payment and billing data may be collected and processed by Lemon Squeezy for payment processing, fraud prevention, tax compliance, invoice generation, subscription management and customer portal access. We may receive limited customer, order, subscription, license or payment status information from Lemon Squeezy in order to provide the purchased software, manage licenses, provide support and comply with our own administrative obligations.
7. Hosting and technical providers
The website is hosted by Vercel Inc. Vercel may process technical data such as IP addresses, logs and security-related data in order to host, deliver, protect and monitor the website.
Other technical providers may be used for email, analytics, support, source-code management, deployment, monitoring, security or licensing infrastructure. We select providers that offer appropriate technical and organizational safeguards for the nature of the processing.
8. Cookies and consent management
The website may use a cookie consent banner allowing users to accept, refuse or customize optional cookies. Strictly necessary cookies may be used without consent where they are required for website operation, security, checkout, customer portal access or services expressly requested by the user.
Optional cookies, such as audience measurement, marketing or non-essential third-party cookies, are used only where a valid legal basis exists and, where required, after consent. For more information, please read our Cookie Policy.
9. International transfers
Some providers, including hosting, payment, deployment or software infrastructure providers, may be located outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on appropriate safeguards where required, such as:
- adequacy decisions;
- Standard Contractual Clauses approved by the European Commission;
- equivalent contractual, organizational and technical safeguards;
- additional security measures where appropriate.
10. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy. Indicative retention periods are:
- Website security logs — generally up to 12 months, unless a longer period is required for security investigation.
- Contact and support requests — up to 3 years after the last interaction, unless a longer retention is necessary for contractual evidence.
- Customer account, licensing and activation data — for the duration of the contractual relationship, then for a reasonable period required for support, audit, dispute management and legal evidence.
- Accounting, invoicing and transaction records — for the legally required retention period, generally up to 10 years where applicable.
- Marketing data — until you unsubscribe or object, or after a reasonable period of inactivity.
Where data is processed by Lemon Squeezy or another independent provider, their own retention periods may also apply.
11. Data recipients
Personal data may be accessed by:
- authorized personnel or contractors of TontonPro SASU;
- hosting and infrastructure providers;
- payment, invoicing and Merchant of Record providers;
- email and communication providers;
- analytics providers, where enabled;
- legal, accounting or tax advisers;
- public authorities, courts or regulators where legally required.
We do not sell personal data.
12. Security
We implement reasonable technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss or destruction. These measures may include access controls, secure hosting, HTTPS encryption, limited access rights, backups, monitoring, logging, vulnerability management and contractual safeguards with service providers.
No method of electronic transmission or storage is completely secure. Customers are responsible for protecting their own systems, accounts, passwords, license access and administrative credentials.
13. Your rights
Subject to the conditions provided by applicable law, you may exercise the following rights:
- right of access;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to data portability;
- right to object;
- right to withdraw consent where processing is based on consent;
- right to define instructions regarding the fate of your personal data after death, where applicable under French law.
To exercise your rights, contact us at contact@tontontools.com. We may ask you to provide information necessary to verify your identity before responding to your request.
You also have the right to lodge a complaint with the CNIL, the French data protection authority: cnil.fr.
14. Marketing communications
TontonPro SASU may send professional communications to customers or prospects about TontonTools products, updates, security information, documentation or related services. Where consent is required, we will request it before sending marketing communications. You may unsubscribe or object at any time by using the unsubscribe mechanism provided or by contacting us at contact@tontontools.com.
15. Children
TontonTools is intended for professional users and organizations. The website and software are not directed to children, and we do not knowingly collect personal data from children.
16. Changes to this policy
We may update this Privacy Policy from time to time, particularly to reflect legal, technical, commercial or product changes. The “Last updated” date at the top of this page indicates the latest version. Material changes may be highlighted on the website or communicated by appropriate means where required.