Privacy Policy
Last updated: June 2026
This Privacy Policy describes how Throughline Global handles personal information across our website forms, configurator, and early client communication. Our launch model is deliberately limited: we collect only what we need to respond to inquiries, generate configurator recommendations, and arrange consultations.
1. Introduction
ThroughLine Global, trading as Throughline Global, is an Abu Dhabi, UAE-based digital agency providing strategy, brand positioning, launch support, social media systems, paid advertising management, website or landing-page strategy, and AI-assisted digital systems.
This Privacy Policy explains how we collect, use, store, share, and protect personal information when you visit our website, submit an inquiry, complete our configurator, book a consultation, or communicate with us.
- Website: throughlineglobal.com
- Location: Abu Dhabi, UAE
- Privacy contact: throughlineglobal@gmail.com
This policy applies to information collected through our website and early client communication workflows. It does not yet apply to a live client portal because our client portal, account registration, login, file uploads, and dashboard features are not active for real client use at launch.
2. Current Website Position
At launch, our website is intended to function as a lead-generation and consultation website.
The following may be active
- Contact form
- Configurator submission form
- Calendly booking link
- Privacy Policy page
- Cookie Notice or cookie disclosure
- Terms of Use page
- Privacy-first analytics, where used
- Email notifications to ThroughLine Global
Future features only, not for real client information until security and legal review are complete
- Account registration
- Login
- Client portal
- Client dashboard
- File uploads
- Campaign reports inside the website
- Client strategy notes inside the website
- Client credentials stored through the website
- Payment collection through the website
3. Information We Collect
3.1 Contact Form Information
When you submit a contact form, we may collect:
- Name
- Email address
- Company name
- Phone or WhatsApp number, if provided
- Service interest
- Message or inquiry details
3.2 Configurator Information
When you complete and submit our configurator, we may collect:
- Answers to business questions
- Business stage
- Main business problem
- Current marketing or digital setup
- Preferred support level
- Written pain point
- Recommended service
- Recommended package tier
- Name
- Email address
- Company name
- Phone or WhatsApp number, if provided
3.3 Booking Information
If you book a consultation through Calendly or another booking tool, the booking provider may collect:
- Name
- Email address
- Phone number, if requested
- Meeting notes
- Selected meeting date and time
- Timezone
- Booking metadata handled by the booking provider
3.4 Communication Information
If you communicate with us by email, phone, WhatsApp, meeting call, or other channels, we may collect information you choose to provide during that communication.
3.5 Technical Information
Depending on the tools used on the website, we may collect limited technical information such as:
- Browser type
- Device type
- Approximate location
- Pages visited
- Referring website
- Time and date of visit
- Basic website performance or analytics data
Where possible, we aim to use privacy-first, cookieless analytics for the initial launch.
4. Information We Do Not Intentionally Collect Through the Website
At launch, we do not intentionally collect the following through our public website forms:
- Client passwords
- Ad account login credentials
- Payment card details
- Bank information
- Government IDs
- Passports
- Health information
- Children's data
- Customer databases
- Sensitive personal data
- Confidential client files
- Legal or financial documents
- Employee records
- Audience lists for ad targeting
If any of this information becomes necessary for a future client engagement, it should be handled through a reviewed process, not through public website forms.
5. How We Use Personal Information
We may use personal information to:
- Respond to inquiries
- Understand your business needs
- Recommend suitable services
- Prepare consultation calls
- Generate configurator recommendations
- Prepare proposals or scopes of work
- Schedule meetings
- Manage early client communication
- Improve our website and service experience
- Maintain basic business records
- Protect our website, systems, and users
- Meet legal, accounting, or regulatory obligations where applicable
6. Legal Basis and Processing Justification
The appropriate legal basis or processing justification may depend on the type of data, user location, and purpose of processing.
For internal planning, our intended processing purposes include:
- Responding to inquiries submitted by users
- Taking steps before entering into a client relationship
- Managing business communications
- Maintaining records where required
- Improving website performance and user experience
- Protecting systems from abuse
- Supporting agreed client services
The correct legal basis for each processing activity should be confirmed with a UAE data-protection lawyer before launch, especially for marketing communications, cookies, tracking pixels, analytics, client CRM data, and cross-border vendor processing.
7. Where Information Is Stored
For production launch, personal data should be held in a managed production database rather than a temporary local development database.
Our planned production approach is:
- A managed Postgres database, with the production region currently planned in the European Union (Frankfurt, Germany), because a UAE or Middle East region was not available in the provider's visible region options at setup time
- Secure environment variables
- Restricted database access
- Email notifications to ThroughLine Global
- Notion or a spreadsheet as a lightweight lead/project tracker for early clients
- Google Drive, PDFs, or Notion workspaces for client project information where appropriate
Because the planned database region is in the European Union rather than the UAE, website form submission data may be processed or stored outside the UAE. This should be treated as cross-border processing and reviewed with a UAE data-protection lawyer or the relevant authority before public launch. Other third-party tools may also process information outside the UAE.
8. Third-Party Tools and Service Providers
We may use third-party tools to operate the website, communicate with users, manage bookings, store files, send email, and track basic website performance.
Expected or possible tools include:
- Vercel for website hosting
- Neon for managed Postgres database hosting, with the production region currently planned in the European Union (Frankfurt, Germany)
- Google Workspace for business email
- Calendly for booking
- Resend for transactional email
- Plausible or another privacy-first analytics tool
- Notion for lightweight client/project workspaces
- Google Drive for file sharing
- A spreadsheet or CRM tool for lead/project tracking, if needed later
Some of these providers may process or store information outside the UAE. Vendor locations, sub-processors, and cross-border transfer implications should be reviewed before launch and updated as tools change.
9. Cookies, Analytics, and Tracking
For the initial launch, our preferred setup is privacy-first:
- No Meta Pixel on ThroughLine Global's own website at launch
- No TikTok Pixel on ThroughLine Global's own website at launch
- Privacy-first, cookieless analytics where possible
- Cookie notice or cookie disclosure
- Consent banner before adding non-essential tracking scripts
If Meta Pixel, TikTok Pixel, Google Analytics, advertising cookies, or similar tools are added later, we should update this Privacy Policy, publish a Cookie Notice, and implement appropriate consent controls where required.
10. Client Pixel Setup
Meta and TikTok pixels may be part of ThroughLine Global's paid advertising management services for clients.
For client websites, our working principle is:
- The client is generally responsible for their own website privacy notice, cookie notice, and consent setup.
- ThroughLine Global is responsible for installing and configuring pixels correctly according to the agreed scope and client instructions.
- ThroughLine Global should not install client pixels without confirming that the client has considered their privacy, cookie, and consent obligations.
The client-pixel consent chain remains an open item requiring UAE legal review.
11. How Long We Keep Information
Working retention rules:
- Contact inquiries: up to 12 months, then review or delete
- Configurator submissions: up to 12 months, then review or delete
- Inactive leads: review or delete after 12 months
- Campaign reports and client deliverables: suggested 12 to 24 months after engagement ends, subject to legal review
- Test accounts: no real personal data should be collected until production handling and security review are complete
- Contracts, invoices, and financial records: retention period to be confirmed with a licensed UAE accountant
These periods are planning defaults and should be reviewed by a UAE lawyer or accountant before being treated as final.
12. Who Can Access Personal Information
Access is based on the least-privilege principle.
This means access is limited to people who need specific information for a specific task.
Possible access roles include:
- Founder: full access and accountability
- Assistant/team member: access to leads, inquiries, project files, and campaign data needed for daily work
- Developer: codebase and database structure only, with dummy or seed data for development
- Accountant: financial records only, where needed
- Lawyer: matter-specific access only
- Contractors: project-specific, time-limited access only after confidentiality or data-processing terms are in place
We do not intend to use shared accounts or shared passwords for client or internal systems.
13. Security Measures
We aim to protect personal information using reasonable technical and organisational measures, including:
- HTTPS
- Secure environment variables
- Server-side validation
- Password hashing if account functionality is later enabled
- Spam protection on forms
- Rate limiting where appropriate
- Restricted database access
- MFA on key tools where available
- Password manager use
- Least-privilege access
- No real personal data in development or test environments
- Backups where applicable
- Access removal when a person leaves or a project ends
- Logging that avoids unnecessary personal data
- Incident-response process
No website or online system can guarantee absolute security. Users should avoid sending sensitive information through public website forms.
14. Client Credentials and Sensitive Access
Client credentials are considered a high-sensitivity category.
ThroughLine Global should not collect client credentials through the website.
Where access is required for a client project, the preferred approach is:
- Client-owned accounts
- Named user access
- Minimum necessary permissions
- Password manager storage where credentials are unavoidable
- No credentials in spreadsheets, email threads, WhatsApp, or chat tools
- Access removed when the project ends
15. Your Rights
Depending on applicable law and your location, you may have rights relating to your personal information, including the right to:
- Request access to your personal information
- Request correction of inaccurate information
- Request deletion of certain information
- Object to certain uses
- Withdraw consent where processing is based on consent
- Request information about how your data is used or shared
To make a request, contact: throughlineglobal@gmail.com
We may need to verify your identity before responding to certain requests.
16. International and GCC Clients
ThroughLine Global is initially focused on the GCC, with possible future expansion to international clients.
If we work with clients or users outside the UAE, additional privacy, data-transfer, contract, or cookie requirements may apply. This is especially relevant for users or clients in jurisdictions with stricter privacy frameworks.
17. Children's Data
Our website and services are intended for businesses and adult users. We do not intentionally collect personal information from children through our website.
18. Links to Third-Party Websites
Our website may link to third-party websites or tools, such as Calendly or external platforms. We are not responsible for the privacy practices of those third parties. Users should review their privacy notices before submitting information.
19. Changes to This Policy
We may update this Privacy Policy from time to time as our website, services, tools, or legal obligations change.
The latest version will be posted on throughlineglobal.com with an updated date.
20. Contact
For privacy questions or requests, contact:
- ThroughLine Global
- Abu Dhabi, UAE
- Email: throughlineglobal@gmail.com
- Website: throughlineglobal.com
This page is provided for general information and does not constitute legal advice. Legal and regulatory matters should be reviewed with a qualified UAE professional.
