Sunrunner Labs LLC is the company responsible for Toora. In this policy, “Toora,” “we,” “us,” and “our” mean Sunrunner Labs LLC. Toora provides scheduling, attendance, communication, and billing software for independent service professionals, initially in figure-skating instruction. This policy applies to the Toora mobile apps, websites, and related services (collectively, the “Service”).
Who we mean
- A “Professional” is an adult who provides services and uses Toora to operate their practice.
- A “Client” is an adult who receives services from a Professional or arranges or manages services for a Youth Participant.
- A “Youth Participant” is a person under 18 who receives services arranged or managed by a Client.
- A “User” is an adult who directly uses Toora: a Professional or a Client.
- “Technology Vendors” are third-party companies whose hosting, authentication, database, artificial-intelligence, email, or similar technology helps us operate the Service.
Information we handle
Account and contact information
When a User signs in, we receive account identifiers and contact information such as a name and verified email address from Google, Apple, or Firebase Authentication. Users may also provide names, email addresses, and phone numbers for Clients or Youth Participants so the Service can organize records and deliver information.
Practice and business records
The Service stores information needed to operate a professional practice, including schedules, session titles and notes, attendance, group membership, rates, charges, invoices, sharing permissions, and records of messages sent through the Service. These records may concern Clients and Youth Participants.
Service and diagnostic information
Technology Vendors that supply hosting, authentication, and security may process technical information such as IP address, user agent, request time, account identifier, requested operation, error details, and, when an operation fails, the content of the request that failed. We use this information to deliver the Service, authenticate requests, prevent abuse, troubleshoot failures, and protect Users and data. Google Sign-In may use an IP address to estimate a device’s general area for fraud prevention; Toora does not request device location. Toora does not use an advertising identifier, advertising SDK, or cross-app tracking.
Website waitlist information
If someone requests an invite on toora.ai, we collect their email address so we can confirm the request and contact them about the pilot.
How we use information
- Provide, maintain, secure, and troubleshoot the Service.
- Authenticate Users and enforce access to records they are authorized to access.
- Show schedules, record attendance, calculate and deliver invoices, and send Professional-directed communications.
- Fulfill requests made through AI-assisted features, including actions the Professional reviews and confirms.
- Respond to support, privacy, safety, and legal requests and prevent misuse.
- Contact waitlist members or Users about the Service. We do not use practice records or information about Clients or Youth Participants for advertising.
AI-assisted features
Some Toora features use artificial intelligence to help Professionals summarize information and propose or perform administrative actions. When a Professional uses these features, we process the text they enter, the responses generated for them, and any photos, PDFs, spreadsheets, or other files they choose to attach. This content may include Client or Youth Participant names, schedule details, rates, or other information the Professional provides. These features also receive relevant practice context and, after the Professional confirms an action, may use Toora tools to update the Professional’s records.
To provide these features, Toora sends the Professional’s request, relevant practice context, and attachments the Professional selects to a Technology Vendor that operates a commercial language model. Toora currently supports Anthropic and OpenAI and may select the active vendor as our infrastructure changes. These companies process the content on our behalf to generate a response and support safety and abuse monitoring under their commercial service terms. Their commercial API services do not use customer inputs and outputs to train models by default unless the customer affirmatively opts in. We do not opt in.
Text messages
Toora can deliver notifications by text message to a mobile number a User provides. A Professional may provide a Client’s mobile number after the Client agrees to receive these messages about their services. The messages are transactional: account access invitations, invoice notices, and schedule updates. We do not send marketing or promotional text messages.
Message frequency varies with practice activity and is typically a few messages per month. Message and data rates may apply. A recipient can stop messages at any time by replying STOP, can reply HELP for assistance, or can contact support@toora.ai.
We provide mobile numbers to Twilio, the Technology Vendor that delivers text messages on our behalf, solely to deliver these messages. We do not sell mobile numbers. No mobile information is shared with third parties or affiliates for their own marketing or promotional purposes, and text-messaging consent is not shared with any third party.
When we disclose information
We disclose information only as described here:
- Technology Vendors. Google Firebase provides authentication and database infrastructure; Vercel hosts the web and API service; the language-model Technology Vendor described above processes requests made through AI-assisted features; Resend delivers email; Twilio delivers text messages; and Sentry receives error reports we use to diagnose failures. These companies handle information to supply technology we use to operate the Service under their applicable agreements.
- At the User’s direction. A Professional may share a schedule, invoice, note, or message with a Client or collaborator they select. Access-sharing features show records only to Users who hold the required permission.
- Safety and law. We may disclose information when we reasonably believe it is necessary to comply with law, protect a person, investigate abuse or fraud, or secure the Service.
- Business changes. If Toora is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction subject to appropriate safeguards.
Youth Participants
The Service is for adult Users. Youth Participants do not create accounts, sign in, or provide information directly. Information about a Youth Participant reaches Toora indirectly when a Professional or Client provides it to operate the practice or access records.
If you are a parent or legal guardian and believe information about a child was provided without appropriate authority, contact privacy@toora.ai. We will review the request with the relevant account holder and take appropriate action.
Retention, deletion, and privacy rights
We keep information while an account is active and as reasonably needed to provide the Service. We may retain records longer when necessary for security, fraud prevention, dispute resolution, legal obligations, or legitimate business recordkeeping—for example, an invoice or audit history involving more than one party. Backup copies may persist for a limited period after deletion before they are overwritten.
Depending on where you live, you may have rights to know about, access, correct, delete, restrict, or obtain a copy of personal information, or to object to certain processing. You may also withdraw consent where consent is the basis for processing. To make a request, email privacy@toora.ai. We may verify the requester’s identity and authority before acting, and we will not discriminate against someone for exercising a privacy right. Deleting a login does not necessarily delete practice or transaction records involving other people; we will explain any information we must retain and why. A Professional can also correct day-to-day Client, Youth Participant, and schedule information within the Service.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use information about Clients or Youth Participants for advertising. Therefore, Toora does not offer a separate “Do Not Sell or Share” mechanism.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted network connections, managed cloud storage, authenticated access, and permission checks. No system is completely secure, so we cannot guarantee that information will never be accessed, used, or disclosed improperly.
International processing
Toora and its Technology Vendors may process information in the United States and other countries. Those countries may have different data protection laws from the place where the information originated.
Changes to this policy
We may update this policy as the Service or law changes. We will post the updated policy here, revise the effective date, and provide additional notice when a change materially affects how we handle information.
Contact us
Privacy questions and requests can be sent to privacy@toora.ai. General product support and all other questions should be sent to support@toora.ai.
Sunrunner Labs LLCCalifornia, United States
