Privacy Policy

Last Update: July 12, 2026

Introduction

Welcome to Thirty Key. We understand that privacy is important to users, customers, resellers, agencies, partners, businesses, and visitors who access or use our website, dashboards, applications, software tools, integrations, and related services.

This Privacy Policy explains how Thirty Key LLC (“Thirty Key,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you access or use our websites, applications, dashboards, subscriptions, reseller services, white-label services, integrations, support services, and related digital services.

By using our Services, you agree to this Privacy Policy, our Terms and Conditions, and our Refund & Cancellation Policy.

If you do not agree with this Privacy Policy, you must stop using Thirty Key immediately.

Our Services

What does Thirty Key provide?
Thirty Key provides digital software access, SaaS tools, business automation systems, social media management tools, chatbot tools, CRM features, content scheduling tools, reseller software access, white-label setup, integrations, and related digital services.

Our Services may allow users to connect and manage social media accounts, messaging accounts, customer communication channels, marketing campaigns, content publishing, automation workflows, chatbot flows, CRM records, analytics, and third-party integrations through one or more online dashboards.

When we provide these Services, we may act as a software provider, service provider, infrastructure provider, data processor, or data controller depending on the type of information and how the Service is used.

Personally Identifiable Information

Definition

Personally Identifiable Information means information that identifies, relates to, describes, contacts, or can reasonably be linked to a specific person, business user, account owner, customer, visitor, authorized representative, or end user.

This may include name, email address, phone number, billing information, business name, IP address, device information, browser information, account data, usage data, support messages, communication data, and information submitted through forms, checkout pages, onboarding, support, or connected integrations.

It does not include anonymized, aggregated, or de-identified information that cannot reasonably identify a specific person.

Information Collection

What information is collected?

We may collect basic information from visitors who browse our website and additional information from users, customers, resellers, agencies, partners, businesses, or organizations that create an account, purchase a service, connect integrations, request support, or use our dashboards.

This may include:

  • Name
  • Email address
  • Phone number
  • Business name
  • Organization name
  • Billing details
  • Account login information
  • Company details
  • Domain information
  • Branding information
  • Plan type
  • Team member information
  • Subscription and transaction information
  • Language and time zone preferences
  • Profile image, if provided
  • Support requests
  • Technical data
  • Usage data
  • Device and browser data
  • IP address
  • Cookies and similar tracking data
  • Information submitted through forms, checkout pages, onboarding, support, or account setup

We only collect information reasonably necessary to provide, secure, improve, support, or operate our Services.

Account and Billing Information

What account and payment data may be processed?

When you create an account, purchase a service, subscribe to a plan, renew a subscription, request an invoice, or use a payment method, we may collect account and billing-related information.

This may include full name, email address, phone number, username, authentication data, business name, billing name, billing email, billing address where required, payment status, invoice details, order ID, subscription details, plan type, renewal status, transaction history, payment method type, account activity, login history, and security logs.

Payments may be processed by third-party payment providers, checkout systems, manual invoices, payment links, billing portals, merchant-of-record providers, card processors, PayPal, bank transfer providers, or other payment methods made available by Thirty Key.

We do not intentionally store full card numbers or sensitive card authentication data on our own systems unless handled by a compliant payment provider.

Payment information is generally processed by third-party payment providers according to their own privacy and security practices.

Customer Content

What uploaded data may be processed?

When you use our Services, you may upload, create, connect, import, send, store, or process content and data.

This may include:

  • Text
  • Images
  • Videos
  • Files
  • Campaigns
  • Social media posts
  • Chatbot flows
  • Automations
  • Contact lists
  • Customer records
  • Phone numbers
  • Email addresses
  • Messages
  • Templates
  • CRM records
  • Tags
  • Notes
  • Branding assets
  • Business data
  • Integration settings
  • API-related data

We process Customer Content only as necessary to provide, maintain, secure, support, troubleshoot, and improve the Services, or as required by law.

You are responsible for ensuring that you have the legal right, permission, consent, and authority to upload, process, store, send, publish, or use any Customer Content through our Services.

Contacts, Messaging, and Communication Data

What communication data may be processed?

If you use Thirty Key for WhatsApp, chatbot, CRM, broadcast, messaging, automation, inbox management, or customer engagement features, you may process contact and communication data through our Services.

This may include contact names, phone numbers, email addresses, tags, message history, chatbot interactions, broadcast campaigns, template messages, opt-in or opt-out status, customer replies, CRM notes, campaign performance data, and related communication records.

You are responsible for obtaining proper consent before contacting people, sending messages, importing contact lists, or using communication features.

Thirty Key does not verify the legality of your contact lists, customer data, messaging activity, or communication practices.

You are responsible for complying with all applicable laws, consent requirements, anti-spam rules, platform policies, privacy laws, marketing laws, and third-party service terms.

If we receive a privacy question, complaint, data request, or legal concern related to your use of customer data through the Services, we may direct the request to you where appropriate.

Social Media and Integration Data

What data is collected from connected platforms?

If you connect social media accounts, messaging accounts, business accounts, APIs, or third-party integrations to Thirty Key, we may receive or process data from those connected services.

This may include connected account names, account IDs, page IDs, profile information, access tokens, authorization tokens, permissions granted, posts, media, comments, messages, scheduling data, analytics, campaign data, API responses, error logs, and integration status.

We use this data only to provide the features you request, such as posting, scheduling, automation, inbox management, analytics, messaging, CRM workflows, data import, data export, reporting, or integration support.

You can disconnect third-party integrations where supported by the platform or by contacting us.

Some features may stop working if an integration is disconnected, authorization expires, permissions are removed, or a third-party platform changes its API, policies, access rules, or technical requirements.

Social Networks and Third-Party Services

Who controls third-party platform data?

Our Services may integrate with or depend on third-party platforms such as Meta, WhatsApp, Facebook, Instagram, X, LinkedIn, Google, YouTube, Telegram, Pinterest, Reddit, Tumblr, payment providers, hosting providers, email providers, AI providers, analytics providers, or other external services.

When you connect or use these services through Thirty Key, we may process the data required to operate the integration, including account details, authorization tokens, permissions, settings, messages, templates, posts, campaign data, logs, technical responses, and API-related information.

Third-party platforms may collect, use, store, restrict, suspend, delete, or process information according to their own privacy policies, terms, API rules, and enforcement decisions.

Thirty Key is not responsible for the privacy practices, policies, security, decisions, restrictions, bans, data handling, or enforcement actions of third-party platforms.

You are responsible for reviewing and complying with the privacy policies, developer terms, platform policies, API rules, and data requirements of any third-party service you connect.

Google User Data Handling

How do we handle Google user data?

If you connect a Google account, YouTube account, Google Sheets account, Google Drive account, Google Business Profile, or any other Google service to Thirty Key, we may access, process, store, or use Google user data only as needed to provide the features you choose to use.

Depending on the Google service or integration you connect, Google user data may include account identifiers, email address, profile information, authorization tokens, permissions granted by you, Google Sheets files or rows, YouTube channel information, YouTube videos, titles, descriptions, thumbnails, comments, analytics, Google Drive files or file metadata, Google Business Profile data, publishing data, scheduling data, automation data, API responses, error logs, and technical metadata.

We use Google user data only to provide, maintain, secure, troubleshoot, and improve user-facing features requested by you.

Thirty Key does not sell Google user data.

Thirty Key does not use Google user data for advertising purposes.

Thirty Key does not use Google user data to train generalized artificial intelligence or machine learning models.

Thirty Key does not transfer Google user data to third parties except as necessary to:

  • Provide or improve user-facing features requested by you
  • Operate, secure, or troubleshoot the Services
  • Comply with applicable law
  • Protect against spam, abuse, fraud, security threats, or unauthorized access
  • Work with service providers who help us operate the Services under appropriate confidentiality or data protection obligations
  • Comply with Google API Services User Data Policy, including Limited Use requirements

We request access only to the Google permissions needed for the features you choose to use, where technically possible.

You may disconnect Google integrations through your Thirty Key account settings where available, through your Google account permissions page, or by contacting us.

If you disconnect a Google integration, some features may stop working, including publishing, scheduling, analytics, import, export, automation, reporting, or synchronization features related to that Google service.

AI and Third-Party AI Services

How is AI-related data used?

Some Thirty Key Services may include AI-powered features such as text generation, content suggestions, chatbot assistance, automated replies, summaries, translations, campaign ideas, or other AI-assisted functionality.

When you use AI features, the information you provide may be processed by Thirty Key and/or third-party AI service providers as necessary to generate or deliver the requested feature.

This may include prompts, instructions, messages, text, business information, campaign content, customer context, or other data submitted by you.

You should not submit sensitive personal information, confidential information, payment card data, passwords, government identification numbers, health information, or highly sensitive data into AI features unless the feature is clearly designed and authorized for that purpose.

AI-generated output should be reviewed before use.

You are responsible for how you use, publish, send, rely on, or distribute AI-generated content.

Cookies

Are cookies used?

Yes. We may use cookies, pixels, local storage, analytics tools, tracking technologies, and similar technologies to operate, secure, and improve our websites and Services.

Cookies may help us keep users logged in, remember preferences, analyze traffic, improve performance, detect abuse, prevent fraud, measure marketing performance, personalize content, and provide relevant content or offers.

You may control or disable cookies through your browser settings.

Some features may not work properly if cookies are disabled.

Use of Login Information

How is login information used?

We may use login information, IP addresses, browser data, device data, session data, usage logs, and security logs to analyze trends, administer the website, secure accounts, monitor platform usage, troubleshoot technical issues, detect suspicious activity, prevent abuse, and improve the Services.

Login and technical information may also be used to investigate violations of our Terms, security incidents, payment abuse, fraud, spam, unauthorized access, or misuse of the platform.

Analytics and Website Data

What technical information is collected?

When you browse our websites or use our Services, we may collect technical and usage information automatically.

This may include IP address, browser type, device type, operating system, referring URL, pages visited, time spent on pages, clicks, session data, feature usage, error logs, server logs, approximate location based on IP address, security events, performance data, form analytics, email interaction data, and engagement analytics.

We use this information to operate, secure, troubleshoot, improve, personalize, and monitor our websites and Services.

Use of Information

How is information used?

We may use information to:

  • Provide the Services
  • Create and manage accounts
  • Identify and authenticate users
  • Process orders and subscriptions
  • Handle payments, billing, invoices, and renewals
  • Provide support
  • Configure white-label or reseller services
  • Set up domains, branding, dashboards, or integrations
  • Operate social media, chatbot, CRM, messaging, and automation features
  • Send service notifications
  • Respond to inquiries
  • Improve features and performance
  • Monitor usage and prevent abuse
  • Detect fraud, spam, security risks, or policy violations
  • Enforce our Terms and Conditions
  • Comply with legal obligations
  • Maintain records
  • Communicate updates, offers, and important notices
  • Analyze product usage and improve user experience
  • Protect Thirty Key, users, third parties, platforms, and payment systems

We do not sell personal information in the traditional sense.

Marketing Communications

Can users opt out?

We may send service updates, account notices, onboarding messages, product updates, promotional offers, partner offers, event updates, or marketing communications.

You may opt out of promotional emails by using the unsubscribe link where available or by contacting us.

Even if you opt out of marketing messages, we may still send transactional or service-related communications, such as account notices, billing notices, renewal notices, security alerts, policy updates, support replies, legal notices, or important service information.

Information Sharing

With whom may information be shared?

We may share information only when necessary for business, legal, operational, security, payment, support, integration, or service-related purposes.

Information may be shared with:

  • Payment processors
  • Billing providers
  • Hosting providers
  • Cloud infrastructure providers
  • Email providers
  • Support tools
  • Analytics providers
  • AI service providers
  • Security and fraud prevention providers
  • Automation and integration providers
  • Contractors, developers, or service providers working on our behalf
  • Authorized resellers, agencies, or partners where necessary to support the service
  • Customer organizations that purchased services on behalf of users
  • Legal, tax, compliance, or professional advisors
  • Government authorities, regulators, courts, or law enforcement when legally required
  • Third-party platforms you choose to connect
  • Successors in the event of merger, acquisition, restructuring, sale of assets, or business transfer

We require service providers to access information only as needed to provide services to us, subject to appropriate confidentiality, security, or data protection obligations where applicable.

We may share aggregated or anonymized information for analytics, performance improvement, product improvement, service monitoring, or business reporting.

We do not share personal information with unrelated third parties for purposes outside providing, operating, improving, securing, or legally protecting our Services.

Access by Partners and Providers

Who may access information?

Authorized employees, contractors, developers, support providers, payment providers, hosting providers, security providers, analytics providers, AI providers, integration providers, professional advisors, resellers, agencies, or partners may access certain information strictly on a need-to-know basis.

This access may be needed to provide support, validate accounts, process billing, secure the platform, troubleshoot issues, configure services, manage integrations, prevent fraud, investigate abuse, improve features, or comply with legal obligations.

Where we share information with service providers, resellers, agencies, or partners, we expect them to handle information under appropriate confidentiality, security, or data protection obligations where applicable.

If you purchased a service through a reseller, agency, white-label provider, or partner, we may provide information to them or receive information from them as necessary to support your use of the service you purchased.

Resellers, Agencies, and White-Label Customers

Who is responsible for end-user data?

If you are a reseller, agency, partner, white-label customer, or business using Thirty Key to serve your own customers, you are responsible for your relationship with your customers and end users.

You are responsible for your own privacy policy, terms of service, refund policy, customer notices, consent collection, legal basis for processing, handling customer requests, marketing compliance, messaging compliance, data protection obligations, end-user support, customer data accuracy, and lawful use of contact lists and campaigns.

Thirty Key may act as a software provider, infrastructure provider, service provider, processor, or technical platform depending on the context.

We do not control how resellers, agencies, partners, or white-label customers collect, use, sell, message, market to, support, or communicate with their own customers.

If an end user contacts Thirty Key about data controlled by a reseller, agency, partner, or white-label customer, we may direct the request to the relevant business customer where appropriate.

Data Storage

How is information stored?

Information may be stored on secure systems, servers, databases, cloud platforms, backups, logs, and service provider systems used to operate Thirty Key.

Thirty Key LLC is based in the United States.

If you access our Services from outside the United States, your information may be transferred to, stored in, processed in, or accessed from the United States or other countries where we or our service providers operate.

Because social media, messaging, payment, hosting, AI, and third-party services may operate globally, information connected through those services may also be processed from locations determined by those third parties under their own policies.

Data Retention

How long is information kept?

We retain personal information and Customer Content for as long as reasonably necessary to provide the Services, operate our business, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, maintain security, and support legitimate business purposes.

Retention periods may vary depending on account status, subscription status, legal requirements, tax obligations, accounting obligations, security needs, backup systems, dispute history, support requirements, abuse prevention, technical limitations, connected integrations, and data type.

When information is no longer needed, we may delete, anonymize, archive, restrict, or securely retain it as appropriate.

Deleted data may remain in backups, logs, caches, or archived systems for a limited period before being removed according to our backup and retention practices.

Some Content may continue to exist on Social Networks or Third-Party Platforms even after it is deleted from Thirty Key. You may need to contact the relevant third-party platform directly to request removal from their systems.

Data Security

How is information kept secure?

We use reasonable administrative, technical, and organizational measures to protect information from unauthorized access, misuse, loss, disclosure, alteration, or destruction.

These measures may include access controls, passwords, authentication, encryption where appropriate, monitoring, backups, logging, security reviews, restricted access, and abuse-prevention controls.

No website, software, server, storage system, transmission method, or cloud platform is completely secure.

You are responsible for using strong passwords, protecting your login credentials, limiting access to trusted users, and notifying us of unauthorized access or security concerns.

Security Incident Notice

What happens if there is a security incident?

If Thirty Key becomes aware of a security incident that materially affects personal information, we may investigate the issue and take reasonable steps to reduce risk, secure affected systems, and respond appropriately.

Where required by applicable law, we may notify affected users, customers, business customers, service providers, authorities, or other relevant parties.

Not every security event, technical issue, suspicious activity, failed login, blocked request, or attempted attack will require individual notice.

Users are responsible for promptly notifying Thirty Key if they suspect unauthorized access, credential compromise, account misuse, data exposure, or security concerns related to their account or use of the Services.

Legal Bases for Processing

What legal basis do we rely on?

Where applicable privacy laws require a legal basis for processing, we may process personal information based on:

  • Your consent
  • Performance of a contract
  • Our legitimate business interests
  • Compliance with legal obligations
  • Protection of rights, safety, security, and fraud prevention
  • Your request to take steps before entering into a contract

Our legitimate interests may include operating the Services, improving features, preventing abuse, securing systems, supporting customers, processing payments, communicating with users, maintaining service quality, and protecting our business.

Controller and Processor Roles

What is Thirty Key’s role?

Depending on the situation and the type of data involved, Thirty Key may act as a data controller, data processor, service provider, infrastructure provider, or software provider.

Thirty Key may act as a data controller when we collect and use information to create and administer your account, process billing, provide support, monitor website usage, send service communications, manage our business relationship with you, or comply with legal obligations.

Where you use the Services to process your own customer data, contact lists, messages, campaigns, CRM records, or end-user information, you may act as the data controller and Thirty Key may act as a data processor or service provider.

You are responsible for ensuring that your use of the Services complies with applicable data protection laws, including providing required notices, obtaining consent where required, maintaining a lawful basis for processing, and handling end-user privacy requests.

Visitor Choices

Opt-out options

Users may opt out of promotional communications by using the unsubscribe link where available or by contacting us.

Users may also control cookies through browser settings, disconnect integrations where supported, remove connected platform permissions, or contact us to request access, correction, deletion, restriction, or review of personal information.

Some choices may limit or disable certain features of the Services.

Some requests may be limited by legal obligations, security needs, billing records, fraud prevention, dispute resolution, contractual obligations, technical limitations, or legitimate business interests.

Corrections and Deletions

Correcting inaccuracies

Users may contact us to request correction or update of inaccurate personal information associated with their account.

We may need to verify your identity before processing correction requests.

Deleting information

Users may request deletion or deactivation of personal information by contacting us.

Some information may be retained where required for legal compliance, tax records, billing records, dispute resolution, fraud prevention, security, backups, legitimate business purposes, or technical limitations.

Deleted information may remain in backups, logs, caches, or archived records for a limited period before being removed according to our backup and retention practices.

If you are a customer of one of our resellers, agencies, partners, or white-label customers, you may need to contact that reseller, agency, partner, or white-label provider directly regarding your privacy request.

Privacy Rights

What rights may users have?

Depending on your location, you may have privacy rights regarding your personal information.

These rights may include the right to access your personal information, correct inaccurate information, request deletion, request restriction of processing, object to certain processing, request data portability, withdraw consent where processing is based on consent, opt out of certain marketing communications, or request information about how your data is used.

To submit a privacy request, contact us at:

Email: [email protected]
Phone: +1 (307) 400-1302

We may need to verify your identity before responding.

Some requests may be limited by legal obligations, security needs, fraud prevention, contractual obligations, technical limitations, or legitimate business interests.

GDPR, EEA, UK, and International Users

What applies to international privacy rights?

If you are located in the European Economic Area, the United Kingdom, Switzerland, or another region with similar privacy rights, you may have additional rights under applicable data protection laws.

Where applicable, you may have the right to access, correct, delete, restrict, object, request portability, withdraw consent, or lodge a complaint with a local data protection authority.

Where Thirty Key acts as a processor or service provider, certain requests may need to be handled by the business customer, reseller, agency, or white-label provider that controls the relevant data.

California and United States Privacy Rights

What applies to U.S. privacy requests?

Depending on your location and applicable law, United States residents, including California residents, may have rights related to access, deletion, correction, portability, and opting out of certain data uses.

Thirty Key does not sell personal information in the traditional sense.

If analytics, advertising, or tracking technologies are considered “sharing,” “targeted advertising,” or similar regulated activity under certain privacy laws, you may contact us to request more information or available opt-out options.

Children Privacy

Do we collect children data?

Our Services are intended for business and professional use.

We do not knowingly collect personal information from children under 13 years old or the minimum age required by applicable law.

Our Services should only be used by individuals who are at least 18 years old or the age of legal majority required to enter into a contract in their jurisdiction.

If you believe a child has provided personal information to us, contact us and we will take reasonable steps to delete the information where required.

Links

External links

Our website, dashboards, emails, content, integrations, or Services may contain links to third-party websites, tools, platforms, plugins, embedded content, partner services, or external resources.

We are not responsible for the privacy practices, content, security, data collection, transactions, communications, or policies of third-party websites or services.

You should review the privacy policies and terms of any third-party website or service before providing personal information or using their services.

Privacy Policy Changes

Notification of changes

We may update this Privacy Policy from time to time.

When we update it, we may post the updated version on our website and update the “Last modified” date.

Your continued use of the Services after the updated Privacy Policy becomes effective means you accept the updated policy.

If a change materially affects how we handle personal information, we may provide additional notice where required by law.

Contact Information

Support

For questions, privacy requests, corrections, deletions, account data, or concerns about this Privacy Policy, contact us at:

Thirty Key LLC
Email: [email protected]
Phone: +1 (307) 400-1302
Location: 30 N Gould St Ste N Sheridan, WY 82801 

Scroll to Top

Free Trial Available With PayPal

Choose the Unlimited plan & link your PayPal to start your Free Trial. Cancel anytime. You can also Skip adding a payment method.

⚠️ Usage Will Be Limited

You’ll only be able to explore our apps, not use them. Start your Free Trial for unlimited access. Cancel anytime, no charges until the trial ends.