Legal
Privacy Policy
Last updated August 13, 2026
This Privacy Policy describes how Thor ("Thor," "we," "us," or "our") collects, uses, stores, and shares information in connection with the Thor credit management platform, our websites at jointhor.com and app.jointhor.com, and related services (the "Service").
It also covers information processed when you connect Microsoft 365 or Outlook to Thor. Our Terms of Service govern use of the Service.
1. Who this policy covers
This policy applies to:
- Visitors to our marketing website
- Customers and their authorized users of the Thor application
- Individuals whose information is processed in the Service on behalf of a customer (for example, credit applicants or accounts receivable contacts)
When we process Customer Data on behalf of a business customer, that customer is typically the controller of the data and Thor is a processor. That customer's own privacy notices and instructions also apply.
2. Information we collect
Account and contact information
Name, work email address, company name, role, phone number, billing details, and similar information you provide when you request a demo, create an account, or contact us.
Customer Data you upload or sync
Information you or your systems provide to operate credit applications, risk monitoring, and collections, which may include customer names, addresses, contact details, credit application responses, payment and invoice history, credit limits, notes, and files.
Microsoft 365 and Outlook information
If you connect a Microsoft account, we receive the information needed to complete that connection and provide the requested features. Depending on the permissions you grant, this may include:
- Basic profile information, such as name, email address, and tenant or mailbox identifier
- Permission to send email from your mailbox so Thor can deliver collection notices, credit application messages, and other communications you configure
- Limited mailbox or message metadata required to send, track, or display the status of those communications (for example, whether a message was sent)
We request only the Microsoft Graph permissions required to provide the Outlook integration. We do not use your Microsoft mailbox as a general-purpose email reader, and we do not access unrelated mail, contacts, or files except as needed to operate the features you enable.
Usage and device information
Log data, browser type, IP address, pages viewed, referring URLs, and similar diagnostic or analytics information. We may use cookies or similar technologies on our website as described below.
Information from other integrations
If you connect an ERP, accounting system, credit bureau, or other third-party tool, we receive the data those services provide under the permissions you authorize.
3. How we use information
We use information to:
- Provide, operate, maintain, and improve the Service
- Send email and other communications on your behalf through connected accounts, including Outlook
- Authenticate users and secure accounts
- Process transactions and provide customer support
- Monitor, prevent, and address fraud, abuse, and security incidents
- Comply with law and enforce our Terms
- Communicate with you about the Service, including product and administrative messages
We do not sell personal information. We do not use Microsoft Graph data to train generalized advertising models or to serve third-party ads.
4. How we share information
We may share information with:
- Service providers who host infrastructure, provide email delivery, analytics, payments, or support services, under contractual confidentiality and security obligations
- Integrations you enable, such as Microsoft, your ERP, or a credit bureau, so those features can function
- Your organization, including administrators and other authorized users on the same customer account
- Professional advisors and authorities when required by law, legal process, or to protect rights, safety, and security
- A successor in connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality
We do not sell, rent, or trade Microsoft user data obtained through Microsoft APIs. We do not share that data with third parties except as needed to provide the Service you requested, to comply with law, or with your direction.
5. Microsoft Outlook connection
Thor's Outlook integration is designed so your team can send credit and collections email from a connected Microsoft 365 mailbox without leaving Thor.
- Access is granted through Microsoft's standard OAuth consent flow. You can review and revoke Thor's access at any time in your Microsoft account permissions
- Data obtained from Microsoft is used only to authenticate the connection and to send or manage the communications you configure in Thor
- We apply administrative, technical, and organizational measures intended to protect this data in transit and at rest
- If you disconnect Outlook or close your Thor account, we will stop using the Microsoft connection and delete or de-identify related tokens and stored Microsoft data except where retention is required by law or for legitimate security or billing records
Microsoft is an independent controller of data it holds in your Microsoft 365 tenant. Your use of Microsoft services is governed by Microsoft's terms and privacy statement.
6. Cookies and analytics
Our marketing site may use cookies, pixels, or similar technologies to understand site usage, remember preferences, and measure campaign performance. You can control cookies through your browser settings. Some site features may not function fully if cookies are disabled.
7. Data retention
We retain information for as long as needed to provide the Service, fulfill the purposes described in this policy, and meet legal, accounting, or security requirements. Customer Data is generally retained for the life of the customer account and deleted or returned within a reasonable period after account closure, unless a longer period is required.
8. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and least-privilege access to production systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your choices and rights
Depending on your location and role, you may have the right to:
- Access, correct, or delete personal information
- Export a copy of your information
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Revoke Microsoft / Outlook access from your Microsoft account
Authorized users can often update account details in the Service. To make a privacy request, email privacy@jointhor.com. If we process your information on behalf of a Thor customer, we may direct your request to that customer.
You may also have the right to lodge a complaint with a data protection authority in your jurisdiction.
10. International transfers
We may process and store information in the United States and other countries where we or our service providers operate. Those locations may have data-protection laws that differ from the laws where you live. Where required, we use appropriate safeguards for cross-border transfers.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take steps to delete it.
12. Changes
We may update this Privacy Policy from time to time. The updated version will be posted at this URL with a revised date. If changes are material, we will provide additional notice where reasonably practicable.
13. Contact
For privacy questions, Microsoft data requests, or to ask us to delete personal information, contact:
Thor
Email: privacy@jointhor.com
Web: https://www.jointhor.com
