Privacy Policy

1. Who we are

ToastRunner is a platform that helps Toastmasters clubs run their meetings: role allocation, agendas, evaluations, membership records and more. It is operated by Puneet Gavri, an individual based in India (“we”, “us”).

For the purposes of India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 and its rules, we are the Data Fiduciary responsible for the personal data described in this policy.

ToastRunner is independent and is not affiliated with or endorsed by Toastmasters International.

2. What we collect

Information your club adds about you

Club officers (such as the Vice President Education or club owner) create your account and may add:

  • your name and email address;
  • your Toastmasters member ID;
  • your birthday (day and month only, no year), if the club chooses to record it;
  • the date you joined and whether you are an active member;
  • your role as a member, officer or club owner.

Information you add

  • a profile photo and a short introduction about yourself;
  • your role nominations and preferences;
  • speech details: pathway, project, title, duration and the areas you want to work on;
  • evaluations you write for other members, including ratings, written feedback and photos of evaluation forms;
  • notes on your own performances, and your preparation notes for roles;
  • text in your private scratchpad;
  • role gifts, swaps and backouts you request;
  • anonymous feedback to your club's leadership, which is stored without anything identifying you.

Information created as you use the club

  • roles assigned to you, and the scoring behind each allocation;
  • attendance-related records such as backouts and late arrivals;
  • awards you win;
  • coaching summaries generated from the feedback on your speeches (see section 5).

Guests

When you visit a club meeting as a guest, club officers may record your name, email address, phone number, how many times you have visited and a short remark, so they can welcome you and follow up. Guests do not have accounts.

Demo requests

If you request a demo on our website, we receive your name, email address, club name, and, if you give them, your WhatsApp number and district. This arrives as an email to us and is not stored in the app.

Technical information

  • Sign-in cookie. One cookie keeps you signed in for up to 30 days. It is strictly necessary for the service to work. We use no analytics, advertising or tracking cookies.
  • Sign-in protection. To stop password guessing, we count failed sign-in attempts against your network (IP) address for a short window. The count is cleared when you sign in successfully and expires on its own.
  • Server logs. Our hosting provider records standard request logs, including IP addresses, for security and troubleshooting.
  • Passwords are stored only as a one-way hash. We cannot see them.

3. Why we use it

We use personal data only to:

  • run your club's meetings: allocate roles fairly, publish agendas and handle gifts, swaps and backouts;
  • show you your roles, speeches, evaluations and progress over time;
  • deliver feedback to the speaker it was written for, and generate coaching summaries from it;
  • help officers keep membership, guest, dues and award records;
  • keep accounts secure and prevent misuse;
  • answer demo requests and questions you send us;
  • meet our legal obligations.

We process your data on the basis of your consent, given when you accept this policy, and for legitimate uses permitted by the DPDP Act. We do not sell personal data, use it for advertising, or build profiles for anyone outside your club.

4. Who can see your data

5. Service providers we use

We use a small number of trusted providers to run ToastRunner. They process data only on our instructions and only to provide their service to us.

About AI features. To generate summaries and coaching, we send Google the text of the feedback along with role names and speech projects. We never send a member's name or email address. AI output is a helpful summary, not a judgement, and it may contain mistakes.

6. Where your data is stored

Your data is stored in the United States. The DPDP Act allows personal data to be transferred outside India, except to countries the Government of India restricts. If the rules change, we will change where we store data to follow them.

7. How long we keep it

  • Club records (roles, speeches, evaluations, awards) are kept while your club uses ToastRunner, because they form the club's meeting history and your own progress record.
  • When you leave a club, officers mark you inactive. Your history stays with the club unless you ask us to delete it (see section 8).
  • If a club stops using ToastRunner, we delete its data within 90 days of the club asking us to, or of the club's account being closed.
  • Demo request emails are deleted within 12 months.
  • Sign-in protection records expire within hours.
  • Backups roll off automatically within 30 days, so deleted data leaves our backups within that time.

We may keep data longer only where the law requires us to.

8. Your rights

Under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you and how we use it;
  • Correct or update data that is wrong or incomplete;
  • Erase your data, where we no longer need it for the purpose it was collected or the law does not require us to keep it;
  • Withdraw consent at any time. This does not affect what we did before, but we may no longer be able to provide the service to you;
  • Nominate someone to exercise these rights for you if you die or become unable to;
  • Raise a grievance with us, and then with the Data Protection Board of India if you are not satisfied.

To use any of these rights, email puneet.gavri@gmail.com from the address on your account. We may need to confirm it is you before acting. We aim to respond within 30 days. You can also update much of your profile yourself in the app, or ask your club officers.

9. How we protect it

  • All traffic is encrypted in transit (HTTPS).
  • Passwords are stored only as salted one-way hashes.
  • Repeated failed sign-ins are throttled and accounts lock after too many attempts.
  • Photos are stored in a private bucket and shown only through short-lived links, after the app checks who is asking.
  • Every club's data is kept separate, and each page checks the viewer's permissions.

No system is perfectly secure. If a personal data breach happens, we will inform the affected users and the Data Protection Board of India as the law requires, and tell you what we are doing about it.

10. Children

ToastRunner is meant for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has been added, contact us and we will delete it.

11. Changes to this policy

If we change this policy, we will update the date at the top. If a change is significant, we will tell you in the app or by email before it takes effect.

12. Contact and grievance officer

For any question, request or complaint about your personal data, contact our grievance officer:

If you are not satisfied with our response, you can complain to the Data Protection Board of India. See also our Terms of Use.