Login

Legal

Privacy Policy

Last updated August 13, 2026

This Privacy Policy describes how Thor ("Thor," "we," "us," or "our") collects, uses, stores, and shares information in connection with the Thor credit management platform, our websites at jointhor.com and app.jointhor.com, and related services (the "Service").

It also covers information processed when you connect Microsoft 365 or Outlook to Thor. Our Terms of Service govern use of the Service.

1. Who this policy covers

This policy applies to:

  • Visitors to our marketing website
  • Customers and their authorized users of the Thor application
  • Individuals whose information is processed in the Service on behalf of a customer (for example, credit applicants or accounts receivable contacts)

When we process Customer Data on behalf of a business customer, that customer is typically the controller of the data and Thor is a processor. That customer's own privacy notices and instructions also apply.

2. Information we collect

Account and contact information

Name, work email address, company name, role, phone number, billing details, and similar information you provide when you request a demo, create an account, or contact us.

Customer Data you upload or sync

Information you or your systems provide to operate credit applications, risk monitoring, and collections, which may include customer names, addresses, contact details, credit application responses, payment and invoice history, credit limits, notes, and files.

Microsoft 365 and Outlook information

If you connect a Microsoft account, we receive the information needed to complete that connection and provide the requested features. Depending on the permissions you grant, this may include:

  • Basic profile information, such as name, email address, and tenant or mailbox identifier
  • Permission to send email from your mailbox so Thor can deliver collection notices, credit application messages, and other communications you configure
  • Limited mailbox or message metadata required to send, track, or display the status of those communications (for example, whether a message was sent)

We request only the Microsoft Graph permissions required to provide the Outlook integration. We do not use your Microsoft mailbox as a general-purpose email reader, and we do not access unrelated mail, contacts, or files except as needed to operate the features you enable.

Usage and device information

Log data, browser type, IP address, pages viewed, referring URLs, and similar diagnostic or analytics information. We may use cookies or similar technologies on our website as described below.

Information from other integrations

If you connect an ERP, accounting system, credit bureau, or other third-party tool, we receive the data those services provide under the permissions you authorize.

3. How we use information

We use information to:

  • Provide, operate, maintain, and improve the Service
  • Send email and other communications on your behalf through connected accounts, including Outlook
  • Authenticate users and secure accounts
  • Process transactions and provide customer support
  • Monitor, prevent, and address fraud, abuse, and security incidents
  • Comply with law and enforce our Terms
  • Communicate with you about the Service, including product and administrative messages

We do not sell personal information. We do not use Microsoft Graph data to train generalized advertising models or to serve third-party ads.

4. How we share information

We may share information with:

  • Service providers who host infrastructure, provide email delivery, analytics, payments, or support services, under contractual confidentiality and security obligations
  • Integrations you enable, such as Microsoft, your ERP, or a credit bureau, so those features can function
  • Your organization, including administrators and other authorized users on the same customer account
  • Professional advisors and authorities when required by law, legal process, or to protect rights, safety, and security
  • A successor in connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality

We do not sell, rent, or trade Microsoft user data obtained through Microsoft APIs. We do not share that data with third parties except as needed to provide the Service you requested, to comply with law, or with your direction.

5. Microsoft Outlook connection

Thor's Outlook integration is designed so your team can send credit and collections email from a connected Microsoft 365 mailbox without leaving Thor.

  • Access is granted through Microsoft's standard OAuth consent flow. You can review and revoke Thor's access at any time in your Microsoft account permissions
  • Data obtained from Microsoft is used only to authenticate the connection and to send or manage the communications you configure in Thor
  • We apply administrative, technical, and organizational measures intended to protect this data in transit and at rest
  • If you disconnect Outlook or close your Thor account, we will stop using the Microsoft connection and delete or de-identify related tokens and stored Microsoft data except where retention is required by law or for legitimate security or billing records

Microsoft is an independent controller of data it holds in your Microsoft 365 tenant. Your use of Microsoft services is governed by Microsoft's terms and privacy statement.

6. Cookies and analytics

Our marketing site may use cookies, pixels, or similar technologies to understand site usage, remember preferences, and measure campaign performance. You can control cookies through your browser settings. Some site features may not function fully if cookies are disabled.

7. Data retention

We retain information for as long as needed to provide the Service, fulfill the purposes described in this policy, and meet legal, accounting, or security requirements. Customer Data is generally retained for the life of the customer account and deleted or returned within a reasonable period after account closure, unless a longer period is required.

8. Security

We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and least-privilege access to production systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your choices and rights

Depending on your location and role, you may have the right to:

  • Access, correct, or delete personal information
  • Export a copy of your information
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
  • Revoke Microsoft / Outlook access from your Microsoft account

Authorized users can often update account details in the Service. To make a privacy request, email privacy@jointhor.com. If we process your information on behalf of a Thor customer, we may direct your request to that customer.

You may also have the right to lodge a complaint with a data protection authority in your jurisdiction.

10. International transfers

We may process and store information in the United States and other countries where we or our service providers operate. Those locations may have data-protection laws that differ from the laws where you live. Where required, we use appropriate safeguards for cross-border transfers.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take steps to delete it.

12. Changes

We may update this Privacy Policy from time to time. The updated version will be posted at this URL with a revised date. If changes are material, we will provide additional notice where reasonably practicable.

13. Contact

For privacy questions, Microsoft data requests, or to ask us to delete personal information, contact:

Thor
Email: privacy@jointhor.com
Web: https://www.jointhor.com