Skip to content
ToolCargo

Legal

Privacy notice

Last updated 11 September 2026 (Statcounter visitor statistics on public pages added). This describes the service as it is built today, during early access.

ToolCargo is an early-access service run by its founder, Mustafa Halawa. Contact: mustafa.halawa9@gmail.com. There is no registered company behind it yet; this notice will be updated when there is.

What we collect

DataWhyKept
Email, optional name, password hash (scrypt)Your account and sign-inUntil you delete the account
Session records (hashed token, browser user agent)Keeping you signed in30 days, or until you sign out
API keys and OAuth tokens — stored only as SHA-256 hashes — with name, scopes and last-used timeAuthenticating your AI clientsUntil the account is deleted; access tokens expire after an hour
OAuth app details (name, redirect URLs) for apps you approveShowing and revoking connected appsUntil the account is deleted
Usage records: tool name, result, duration, time, which key was usedQuotas, your usage history, abuse preventionUntil the account is deleted
Subscription status and PayPal subscription IDKnowing which plan you are onAs long as needed for accounting
PayPal notifications, with subscriber name, email and address removed before storageProcessing billing changes exactly onceAs long as needed for accounting
Connector requests you submit, and your email if you give itDeciding what to build and asking follow-upsUntil you ask us to delete them
Saved audits (signed-in users): the audited URL, the check results and short evidence such as the page title or canonicalYour audit history, re-runs, comparisons and client reports — visible only to your account180 days, or until you delete them; you can switch history off
Product events: sign-up, first successful tool call, days with activity, report exports, “I’d pay for Pro” clicks, demo audit outcomes — no URLs or page contentUnderstanding whether the product is useful during early accessAbout 13 months; deleted with the account
Recovery codes and password-reset links — stored only as hashesLetting you back into your accountUntil used, replaced or expired; deleted with the account
Support messages you send (your email, topic and message)Answering youUntil resolved, then up to 12 months; ask us to delete sooner
Pilot access records (dates, call limit, reason) and a log of staff actions on accountsRunning the pilot fairly and keeping an audit trailPilot records are deleted with the account; the staff action log keeps only a hash of your email
Daily counts of anonymous demo runs (no URLs, no IPs)Capacity and abuse monitoringAbout 13 months
Hashed IP address or email in rate-limit countersStopping abuse of sign-in, sign-up and the demoAbout one day
Error events (no request bodies, tokens or page contents)Keeping the service working90 days

What we do not collect

Visitor statistics

Public pages (home, connectors, pricing, docs, about, status, legal pages) load Statcounter to count visits. Statcounter receives the page address, the referring page, your IP address (used for approximate location), browser and screen details, and the time of the visit. We configure it not to store anything in your browser. It never runs on sign-in, password reset, OAuth, dashboard, audit, admin or billing pages, and not when the page address carries anything other than campaign tags.

Cookies

tp_session (HTTP-only, 30 days) keeps you signed in. tp_signed_in (30 days, value “1”) only lets pages show “Dashboard” instead of “Sign in”. Both are strictly necessary.

Who processes data for us

Your data may therefore be processed outside your country. We do not sell personal data or share it for advertising.

Your choices and rights

Changes

If we change what we collect, we will update this page and the date above. Material changes will be announced to account holders before they apply.