Privacy policy
Last updated: 3 July 2026
Mortar Automation (“Mortar”, “we”, “us”) is a done-for-you automation service operated by Daniel Bennett, based in the Netherlands. This policy explains what personal data we collect, why, and what your rights are. It covers the website mortarautomation.com and, once launched, the Mortar service itself. Contact for anything in this policy: hello@mortarautomation.com.
1. Who is responsible for your data
The data controller is Daniel Bennett, trading as Mortar Automation, Netherlands. Business registration details will be added to this page upon registration with the Dutch Chamber of Commerce (KvK).
2. What we collect today (waitlist)
- Waitlist signups: your email address, the business type you select, any tools you tell us you use, and the signup time.
- Basic technical logs: our web server records IP addresses and request data in standard access logs, kept for a short period for security purposes.
We use this to contact you about Mortar’s launch, to size interest, and to decide which tools to support next. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by unsubscribing or emailing us. We do not sell or share the waitlist with anyone.
3. What we collect when you become a customer
- Account details: name, email, business name, billing information (payment card details are processed by our payment provider, not stored by us).
- Connected-account credentials: when you connect a tool (for example Google Sheets, Google Calendar, Stripe or Calendly), we receive access tokens through that provider’s own sign-in flow. We never see or store your passwords. Tokens are stored encrypted at rest in an isolated, per-customer vault, are used only to run the automations you asked for, and are deleted when you disconnect the tool or close your account.
- Automation run data: the data your automations process (for example a form submission, a booking, a payment record) passes through our systems to do the work you hired us for. We keep execution logs — with sensitive values masked — so we can monitor reliability and fix failures.
- Support conversations: messages you exchange with our onboarding assistant or with us directly.
Legal bases: performance of our contract with you (Art. 6(1)(b) GDPR) for running the service; our legitimate interest (Art. 6(1)(f)) in monitoring, securing and improving it; and legal obligations (Art. 6(1)(c)) for invoicing and tax records.
4. Google user data — Limited Use disclosure
Where you connect a Google service, Mortar’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:
- We only use Google user data to provide and improve the automations you have explicitly set up — never for advertising, profiling, or resale.
- We do not transfer Google user data to anyone except as needed to provide those automations, to comply with law, or as part of a merger/acquisition with notice to you.
- Humans do not read your Google data except with your permission for support, where required for security or legal reasons, or where it is aggregated and anonymised.
- We do not use Google user data to train machine-learning models.
5. Who helps us run the service (processors)
We use a small number of infrastructure providers under data-processing agreements. Currently: Hetzner Online GmbH (server hosting, Germany/Finland, EU) and a transactional email provider for sending service emails. A current list of sub-processors is available on request. We do not transfer your personal data outside the EU/EEA except where a provider offers appropriate safeguards under GDPR (such as Standard Contractual Clauses), and we prefer EU-hosted providers.
6. How long we keep data
- Waitlist data: until you unsubscribe, or 24 months of inactivity, whichever comes first.
- Account and billing data: for the life of your account, then as required by Dutch tax law (7 years for invoice records).
- Connected-account tokens: deleted on disconnection or account closure.
- Execution logs: rolling retention of 90 days unless needed longer to investigate a specific problem you have asked us to fix.
7. Security
Credentials are stored encrypted at rest with per-customer isolation; all traffic is encrypted in transit (TLS); access to production systems is limited and logged; sensitive values are masked in logs; and databases are backed up on EU infrastructure. No internet service can promise perfection — if we ever discover a breach affecting your data, we will notify you and the Dutch supervisory authority as GDPR requires.
8. Your rights
Under the GDPR you can ask us at any time to: access the personal data we hold about you; correct it; delete it; restrict or object to processing; receive it in a portable format; or withdraw consent. Email hello@mortarautomation.com and we will respond within one month. You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
9. Cookies
This website does not use advertising or cross-site tracking cookies. If we add analytics, we will use a privacy-respecting, cookieless option or ask for your consent first, and update this policy.
10. Children
Mortar is a business service and not directed at anyone under 16. We do not knowingly collect data from children.
11. Changes to this policy
If we change this policy in a way that matters, we will note it here with a new “last updated” date and, for significant changes affecting customers, tell you by email before they take effect.