Privacy & Security
ThroughLine’s goal is to connect people to meaningful help. To access this support, people need to feel safe and secure. Furthermore, the confidentiality and anonymity of mental health and crisis services are a main reason people contact them.
Our privacy and security measures reflect our commitment to supporting users. We aim for people in distress and our partners to feel confident and comfortable in using our products.
You can review our Privacy Policy here.
Please see below for how users can access ThroughLine's privacy policy across our 3 products.
Web app | Our Privacy Policy is hyperlinked on all pages of ThroughLine's web app product. |
|---|---|
Widget | We recommend you link to our Privacy Policy in a clause in your website or app’s privacy policy |
API | As end users do not directly interact with ThroughLine via the API, a privacy notice is not required. |
The table below details the default user data collected across ThroughLine’s product suite.
Web app & Widget | ✅ Anonymous behavioral analytics of end users collected via cookieless Matomo analytics. 🚫 No end-user personally identifiable information collected |
|---|---|
API | 🚫 No end-user data collected by ThroughLine ✅ Login credentials of the Developer to access the ThroughLine API. |
No. In all of ThroughLine's products provided to customers, no features expressly collect personally identifiable information. This also means you will not receive any personally identifiable information of end users from ThroughLine, as it will not exist.
Outside of our customer integrations, we only collect the personally identifiable information of end users if they are expressly contacting ThroughLine for an inquiry, such as through our website contact form, in which case we collect a user's email address.
ThroughLine uses cookieless analytics through Matomo, which does not require user consent under GDPR and other privacy legislation. Our cookieless tracking approach ensures that no cookies are stored on users' devices for analytics purposes, eliminating the need for cookie consent banners while still providing valuable insights into user behavior.
Matomo's cookieless tracking framework enables compliance with the following key legislation globally: GDPR (EU & UK), LGPD (Brazil), PIPEDA (Canada), Law 25 (Quebec), POPIA (South Africa), nFADP (Switzerland), Privacy Act (Australia), PDPL (Saudi Arabia), PDPL (Argentina), PDPL (Andorra), DPA (Faroe Island).
Customers have the option to disable analytics. However, if they choose to switch off analytics, ThroughLine will not provide them with any analytics data.
In the web app and widget, Matomo tracks anonymous user interactions with the product (such as key click interactions, scroll distances, and basic device information) using Matomo's JavaScript tracking code as the primary method.
No. When a user contacts a helpline they are interacting with a phone number, SMS number, WhatsApp number, or website provided by the helpline. ThroughLine does not have any ability to collect personal information about the user when they take action to contact a helpline, or any ability to collect information about the conversation they have had. ThroughLine anonymously tracks actions to contact a helpline to inform our ranking algorithm, improve our product, and provide anonymous analytical reporting to our partners.
The user impact dashboard is only available for the web app. It includes the number of users, sessions, helpline contacts, country distribution, engagement metrics (rate, time), access patterns, and most-used helplines/topics. No personally identifiable information is collected so no such information will be shared. A demo dashboard is available on request.
We aim to comply with legislative requirements in the jurisdictions where we serve users. With a global user base, ThroughLine has taken a conservative approach to the information it collects from users to comply with legislation globally. This includes leading legislation such as the GDPR, which much of the subsequent legislation is modeled on.
To this end, we serve a cookie banner and privacy policy to users informing them of what data we collect and how we use it, their rights to access that information, and our commitment to data security.
In line with our values and goal to connect people with meaningful help, we only collect anonymous behavioral analytics of end users via third-party vendors. We do not collect any end-user personally identifiable information through any of our customer integrations.
Yes. If required, we can turn off all behavioral analytics to ensure that even anonymous and non-identifiable information is not collected.
While ThroughLine does not collect personally identifiable information of users in our product integrations, we take seriously our information security. This includes:
- All employees and contractors sign a nondisclosure or confidentiality agreement before accessing any ThroughLine information.
- Access by employees and contractors to any ThroughLine information requires unique credentials.
- All ThroughLine employees and contractors are required to use multi-factor authentication for all software systems where it is available and can be enforced.
We are happy to respond to security questionnaires upon request.
Anonymous | Users may willingly, but are not required to, disclose personal information at their discretion, provided that such information is kept confidential. Online chats that require an email address or phone number to access the service qualify, as long as they are confidential. |
|---|---|
Confidential | Information provided by the user may be used:
|
These definitions essentially mean that conversations are held in confidence, except if there’s an immediate safety risk such as suspicion that a child may be at risk of harm, or a user or someone else faces serious harm, either self-inflicted or from others.
Many services keep a record of each conversation and information such as phone number, mobile service provider, IP address, or internet service provider that the user used to contact them.
The service might then share this information with emergency responders (police, ambulance/medical services) who will use it to try and provide support. In many countries, services are obligated by law to advise authorities if there is an acute risk to life, and often services will have these privacy policies on their website. It’s also common for users to be asked to confirm that they understand these policies before getting support.