Skip to content
Back to siteLegal

Privacy Policy

Last updated: June 2026

This Privacy Policy describes how Throughline Global handles personal information across our website forms, configurator, and early client communication. Our launch model is deliberately limited: we collect only what we need to respond to inquiries, generate configurator recommendations, and arrange consultations.

1. Introduction

ThroughLine Global, trading as Throughline Global, is an Abu Dhabi, UAE-based digital agency providing strategy, brand positioning, launch support, social media systems, paid advertising management, website or landing-page strategy, and AI-assisted digital systems.

This Privacy Policy explains how we collect, use, store, share, and protect personal information when you visit our website, submit an inquiry, complete our configurator, book a consultation, or communicate with us.

  • Website: throughlineglobal.com
  • Location: Abu Dhabi, UAE
  • Privacy contact: throughlineglobal@gmail.com

This policy applies to information collected through our website and early client communication workflows. It does not yet apply to a live client portal because our client portal, account registration, login, file uploads, and dashboard features are not active for real client use at launch.

2. Current Website Position

At launch, our website is intended to function as a lead-generation and consultation website.

The following may be active

  • Contact form
  • Configurator submission form
  • Calendly booking link
  • Privacy Policy page
  • Cookie Notice or cookie disclosure
  • Terms of Use page
  • Privacy-first analytics, where used
  • Email notifications to ThroughLine Global

Future features only, not for real client information until security and legal review are complete

  • Account registration
  • Login
  • Client portal
  • Client dashboard
  • File uploads
  • Campaign reports inside the website
  • Client strategy notes inside the website
  • Client credentials stored through the website
  • Payment collection through the website

3. Information We Collect

3.1 Contact Form Information

When you submit a contact form, we may collect:

  • Name
  • Email address
  • Company name
  • Phone or WhatsApp number, if provided
  • Service interest
  • Message or inquiry details

3.2 Configurator Information

When you complete and submit our configurator, we may collect:

  • Answers to business questions
  • Business stage
  • Main business problem
  • Current marketing or digital setup
  • Preferred support level
  • Written pain point
  • Recommended service
  • Recommended package tier
  • Name
  • Email address
  • Company name
  • Phone or WhatsApp number, if provided

3.3 Booking Information

If you book a consultation through Calendly or another booking tool, the booking provider may collect:

  • Name
  • Email address
  • Phone number, if requested
  • Meeting notes
  • Selected meeting date and time
  • Timezone
  • Booking metadata handled by the booking provider

3.4 Communication Information

If you communicate with us by email, phone, WhatsApp, meeting call, or other channels, we may collect information you choose to provide during that communication.

3.5 Technical Information

Depending on the tools used on the website, we may collect limited technical information such as:

  • Browser type
  • Device type
  • Approximate location
  • Pages visited
  • Referring website
  • Time and date of visit
  • Basic website performance or analytics data

Where possible, we aim to use privacy-first, cookieless analytics for the initial launch.

4. Information We Do Not Intentionally Collect Through the Website

At launch, we do not intentionally collect the following through our public website forms:

  • Client passwords
  • Ad account login credentials
  • Payment card details
  • Bank information
  • Government IDs
  • Passports
  • Health information
  • Children's data
  • Customer databases
  • Sensitive personal data
  • Confidential client files
  • Legal or financial documents
  • Employee records
  • Audience lists for ad targeting

If any of this information becomes necessary for a future client engagement, it should be handled through a reviewed process, not through public website forms.

5. How We Use Personal Information

We may use personal information to:

  • Respond to inquiries
  • Understand your business needs
  • Recommend suitable services
  • Prepare consultation calls
  • Generate configurator recommendations
  • Prepare proposals or scopes of work
  • Schedule meetings
  • Manage early client communication
  • Improve our website and service experience
  • Maintain basic business records
  • Protect our website, systems, and users
  • Meet legal, accounting, or regulatory obligations where applicable

6. Legal Basis and Processing Justification

The appropriate legal basis or processing justification may depend on the type of data, user location, and purpose of processing.

For internal planning, our intended processing purposes include:

  • Responding to inquiries submitted by users
  • Taking steps before entering into a client relationship
  • Managing business communications
  • Maintaining records where required
  • Improving website performance and user experience
  • Protecting systems from abuse
  • Supporting agreed client services

The correct legal basis for each processing activity should be confirmed with a UAE data-protection lawyer before launch, especially for marketing communications, cookies, tracking pixels, analytics, client CRM data, and cross-border vendor processing.

7. Where Information Is Stored

For production launch, personal data should be held in a managed production database rather than a temporary local development database.

Our planned production approach is:

  • A managed Postgres database, with the production region currently planned in the European Union (Frankfurt, Germany), because a UAE or Middle East region was not available in the provider's visible region options at setup time
  • Secure environment variables
  • Restricted database access
  • Email notifications to ThroughLine Global
  • Notion or a spreadsheet as a lightweight lead/project tracker for early clients
  • Google Drive, PDFs, or Notion workspaces for client project information where appropriate

Because the planned database region is in the European Union rather than the UAE, website form submission data may be processed or stored outside the UAE. This should be treated as cross-border processing and reviewed with a UAE data-protection lawyer or the relevant authority before public launch. Other third-party tools may also process information outside the UAE.

8. Third-Party Tools and Service Providers

We may use third-party tools to operate the website, communicate with users, manage bookings, store files, send email, and track basic website performance.

Expected or possible tools include:

  • Vercel for website hosting
  • Neon for managed Postgres database hosting, with the production region currently planned in the European Union (Frankfurt, Germany)
  • Google Workspace for business email
  • Calendly for booking
  • Resend for transactional email
  • Plausible or another privacy-first analytics tool
  • Notion for lightweight client/project workspaces
  • Google Drive for file sharing
  • A spreadsheet or CRM tool for lead/project tracking, if needed later

Some of these providers may process or store information outside the UAE. Vendor locations, sub-processors, and cross-border transfer implications should be reviewed before launch and updated as tools change.

9. Cookies, Analytics, and Tracking

For the initial launch, our preferred setup is privacy-first:

  • No Meta Pixel on ThroughLine Global's own website at launch
  • No TikTok Pixel on ThroughLine Global's own website at launch
  • Privacy-first, cookieless analytics where possible
  • Cookie notice or cookie disclosure
  • Consent banner before adding non-essential tracking scripts

If Meta Pixel, TikTok Pixel, Google Analytics, advertising cookies, or similar tools are added later, we should update this Privacy Policy, publish a Cookie Notice, and implement appropriate consent controls where required.

10. Client Pixel Setup

Meta and TikTok pixels may be part of ThroughLine Global's paid advertising management services for clients.

For client websites, our working principle is:

  • The client is generally responsible for their own website privacy notice, cookie notice, and consent setup.
  • ThroughLine Global is responsible for installing and configuring pixels correctly according to the agreed scope and client instructions.
  • ThroughLine Global should not install client pixels without confirming that the client has considered their privacy, cookie, and consent obligations.

The client-pixel consent chain remains an open item requiring UAE legal review.

11. How Long We Keep Information

Working retention rules:

  • Contact inquiries: up to 12 months, then review or delete
  • Configurator submissions: up to 12 months, then review or delete
  • Inactive leads: review or delete after 12 months
  • Campaign reports and client deliverables: suggested 12 to 24 months after engagement ends, subject to legal review
  • Test accounts: no real personal data should be collected until production handling and security review are complete
  • Contracts, invoices, and financial records: retention period to be confirmed with a licensed UAE accountant

These periods are planning defaults and should be reviewed by a UAE lawyer or accountant before being treated as final.

12. Who Can Access Personal Information

Access is based on the least-privilege principle.

This means access is limited to people who need specific information for a specific task.

Possible access roles include:

  • Founder: full access and accountability
  • Assistant/team member: access to leads, inquiries, project files, and campaign data needed for daily work
  • Developer: codebase and database structure only, with dummy or seed data for development
  • Accountant: financial records only, where needed
  • Lawyer: matter-specific access only
  • Contractors: project-specific, time-limited access only after confidentiality or data-processing terms are in place

We do not intend to use shared accounts or shared passwords for client or internal systems.

13. Security Measures

We aim to protect personal information using reasonable technical and organisational measures, including:

  • HTTPS
  • Secure environment variables
  • Server-side validation
  • Password hashing if account functionality is later enabled
  • Spam protection on forms
  • Rate limiting where appropriate
  • Restricted database access
  • MFA on key tools where available
  • Password manager use
  • Least-privilege access
  • No real personal data in development or test environments
  • Backups where applicable
  • Access removal when a person leaves or a project ends
  • Logging that avoids unnecessary personal data
  • Incident-response process

No website or online system can guarantee absolute security. Users should avoid sending sensitive information through public website forms.

14. Client Credentials and Sensitive Access

Client credentials are considered a high-sensitivity category.

ThroughLine Global should not collect client credentials through the website.

Where access is required for a client project, the preferred approach is:

  • Client-owned accounts
  • Named user access
  • Minimum necessary permissions
  • Password manager storage where credentials are unavoidable
  • No credentials in spreadsheets, email threads, WhatsApp, or chat tools
  • Access removed when the project ends

15. Your Rights

Depending on applicable law and your location, you may have rights relating to your personal information, including the right to:

  • Request access to your personal information
  • Request correction of inaccurate information
  • Request deletion of certain information
  • Object to certain uses
  • Withdraw consent where processing is based on consent
  • Request information about how your data is used or shared

To make a request, contact: throughlineglobal@gmail.com

We may need to verify your identity before responding to certain requests.

16. International and GCC Clients

ThroughLine Global is initially focused on the GCC, with possible future expansion to international clients.

If we work with clients or users outside the UAE, additional privacy, data-transfer, contract, or cookie requirements may apply. This is especially relevant for users or clients in jurisdictions with stricter privacy frameworks.

17. Children's Data

Our website and services are intended for businesses and adult users. We do not intentionally collect personal information from children through our website.

18. Links to Third-Party Websites

Our website may link to third-party websites or tools, such as Calendly or external platforms. We are not responsible for the privacy practices of those third parties. Users should review their privacy notices before submitting information.

19. Changes to This Policy

We may update this Privacy Policy from time to time as our website, services, tools, or legal obligations change.

The latest version will be posted on throughlineglobal.com with an updated date.

20. Contact

For privacy questions or requests, contact:

  • ThroughLine Global
  • Abu Dhabi, UAE
  • Email: throughlineglobal@gmail.com
  • Website: throughlineglobal.com

This page is provided for general information and does not constitute legal advice. Legal and regulatory matters should be reviewed with a qualified UAE professional.

Privacy Policy · Throughline Global