Legal

Privacy Policy

Teamline is a workplace messaging service. This policy explains what we collect, why, who it is shared with, and the choices you and your employer have over it.

Last updated: 24 August 2026

1. Who this policy covers

Teamline (theteamline.com) is operated by ODD TECHNOLOGIES LLC, registered at 1309 Coffeen Ave, Ste 1200, Sheridan, WY 82801, United States (“Teamline”, “we”, “us”).

Teamline is sold to organisations, not to individuals. When your employer creates a workspace, they are the controller of the content in it and we process it on their instructions. We are the controller for the account and technical data we need to run the service itself. If your employer administers your workspace, their own internal policies apply alongside this one, and requests about workspace content are usually best directed to them first.

2. What we collect

Account information

  • Your name, username and profile picture, if you set one.
  • Your work email address. Teamline requires a company domain — free consumer mail domains are refused — and a new workspace must confirm its address within 24 hours of being created.
  • A password hash. We store an argon2 hash, never the password itself, and we cannot recover or read your password.
  • Your role in the workspace (owner, admin or member) and the channels you belong to.

Workspace content

  • Messages you send in channels, threads and direct messages, including edits.
  • Files and images you upload, and their filenames and metadata.
  • Voice messages you record.
  • Meeting links and any other links you post, plus link preview data we fetch for them.
  • Reactions, @mentions and read state (which conversations you have caught up on).

Technical data

  • Your IP address. This one deserves a specific mention: Teamline supports per-channel IP allowlists, so your IP address is matched against the rules a workspace administrator has configured every time you list or open a channel. It is also used for ordinary security purposes such as abuse prevention.
  • A session token stored in a cookie (or sent as a bearer token by the mobile app), so you stay signed in.
  • A push notification token, if you use the mobile app and enable notifications. Dead tokens are pruned automatically.
  • Server logs, which may include request paths, timestamps and error details.
  • Aggregate, non-identifying page analytics for our public pages, provided by Vercel Analytics.

What we do not collect

We do not sell personal data, we do not use your messages or files to train machine learning models, and we do not serve advertising or share data with advertising networks.

3. Why we use it

  • To deliver messages, files and notifications to the right people.
  • To enforce access control — channel membership, per-channel IP allowlists and Active Hours schedules — on every read and write, including direct API calls.
  • To keep each company’s data separated from every other company’s.
  • To verify a workspace’s email domain and send invitations.
  • To detect, investigate and prevent abuse, fraud and security incidents.
  • To support you when you contact us, and to comply with legal obligations.

Where the GDPR or a comparable law applies, we rely on the performance of a contract (running the service you or your employer signed up for), our legitimate interests (security, abuse prevention, service improvement), consent where you have given it (for example, push notifications), and legal obligation where one applies.

4. Who can see your content

  • People in your channels. Public channels are visible to your company; private channels are members-only, and membership is checked before any message, file or attachment is served.
  • Your workspace owners and admins. They can manage users, channels and settings, and they can be granted access to conversations in the course of administering the workspace. Treat a work chat as work property.
  • Nobody in another company. Every record carries the company that owns it and every query is scoped to it. This is verified by an automated cross-company isolation test suite.
  • Us, only when necessary — to operate the service, resolve a support request you raise, or respond to a valid legal demand. Access is limited and logged.

Note that access control cuts both ways: a channel restricted by IP allowlist is hidden from everyone off the allowed networks, owners and admins included, and a channel with Active Hours is closed to members outside its window.

5. Service providers

We use a small number of processors, each bound to handle data only on our instructions:

  • Amazon Web Services (AWS), US East — hosting and storage, where the application and database run and uploaded files are kept.
  • Resend — transactional email (invitations and address confirmation).
  • Expo Push Service, Apple (APNs) and Google (FCM)— mobile push delivery. A push notification may include the sender’s name and a message preview.
  • Vercel Analytics — aggregate traffic measurement on our public pages.

6. Where your data is stored

Teamline runs in the United States (AWS US East), so using the service means your workspace content and account data are stored and processed there, whichever country you are in. Where personal data leaves the EEA or the UK to reach us, we rely on Standard Contractual Clauses or another lawful transfer mechanism.

7. How long we keep it

  • Workspace content is kept until it is deleted by you or by an administrator, or until the workspace is closed.
  • Account data is kept for as long as your account exists.
  • Closed workspaces are deleted, along with their content and uploaded files, within 30 days of closure, except where we must retain something to meet a legal obligation.
  • Logs and backups roll off on their own schedule, and backups are retained for no longer than 15 days. Content deleted from a live workspace can therefore persist in a backup for up to that long.

8. How we protect it

  • Passwords are stored as argon2 hashes and are never recoverable.
  • Sessions use opaque tokens and can be revoked by signing out.
  • Uploaded files are served only through an endpoint that authorizes the request first — there is no public file URL that can be forwarded to someone without access.
  • Message content is sanitized before it is stored, to prevent script injection.
  • Traffic is encrypted in transit with TLS.
  • Access rules — channel membership, IP allowlists and Active Hours — are enforced on every API path, not only in the interface.

No system is perfectly secure. If we become aware of a breach affecting your data we will notify the affected workspace and any regulator, as required by law.

9. Cookies

Teamline uses a session cookie to keep you signed in, and it is strictly necessary for the service to function — blocking it means you cannot use the app. We do not use advertising or cross-site tracking cookies.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, restrict or object to the processing of your personal data, and to withdraw consent at any time. You can update your name, username, picture and password yourself from your profile.

For anything else, contact your workspace owner or administrator first — for workspace content they are the controller and we act on their instruction. You can also reach us at info@theteamline.com, and you have the right to complain to your local data protection authority.

To have your account deleted — or a whole workspace, with its users, settings and chat history — use the account deletion form. It needs no sign-in, so it works even if you have lost access, and it is handled by a person: we confirm the account is yours before removing anything.

11. Children

Teamline is a workplace tool and is not directed at anyone under 16. We do not knowingly collect data from children; if we learn that we have, we delete it.

12. Changes to this policy

We may update this policy as the service changes. The “last updated” date above always reflects the current version, and we will give notice inside the app before a material change takes effect.

13. Contact

Write to info@theteamline.com, or by post to ODD TECHNOLOGIES LLC, 1309 Coffeen Ave, Ste 1200, Sheridan, WY 82801, United States.

Questions about this document? Write to info@theteamline.com — or read the Privacy Policy and Terms & Conditions side by side.