Effective Date: 2023-07-05
Tailscale, Inc. (“Tailscale”, “we”, “our” or “us”) allows customers and individuals to directly connect servers, computers, mobile devices, and cloud instances in a simple mesh VPN network, in which every connection is encrypted.
In providing our Services, we may process certain information about Users on behalf of organizations that have contracted to use the Tailscale Solution under a Master Services Agreement or Terms of Service (“Customers”). In such circumstances, our Customers are the data controllers and we are the “data processor” or “service provider,” depending on applicable law. This means that our Customers are responsible for processing information in accordance with their own privacy policies and practices, and otherwise complying with applicable data protection laws. When we act as a data processor, we will only process information about Users using our Customers’ accounts according to the Customers’ instructions and the applicable data processing agreement we have in place with our Customers, or as otherwise required by applicable law. In such circumstances, if you have any questions about the processing of your information, or would like to make any requests regarding your information, please contact the Customer for assistance.
2. THE INFORMATION WE COLLECT
We collect, store and use certain information from or about you for the purposes described below.
INFORMATION YOU PROVIDE TO US
We collect a variety of information that you provide directly to us. For example, we collect information from you through:
Your registration to use the Services
Your use of the Services
Your participation in product demos and webinars
Your communications with our support/sales teams
Requests or questions you submit to us via online forms, email, or otherwise
Your participation in surveys, research, sweepstakes, or contests
When you communicate with our customer support teams via email, phone, videoconferencing, or chat (e.g., you email, video chat, open a support ticket, file a feature request, tweet at us, etc. for customer support)
When you attend our conferences or events or interact with us at other conferences or events
When you sign up for our newsletters
When you use a blog or forum made available through the Services (for example, if you comment on a post or submit a question)
The types of data we collect directly from you include:
First and last name
Email address or username
Log-in authentication information
Your company or organization name
Any other information you choose to directly provide to us in connection with your use of the Services
INFORMATION WE COLLECT THROUGH AUTOMATED MEANS
Tailscale Solution Information. When you use the Tailscale Solution, we collect limited metadata regarding your device used to access the Tailscale Solution, such as: the device name; relevant operating system type; host name; IP address; cryptographic public key; user agent (where applicable); language settings; date and time of access to the Tailscale Solution; logs describing connections and containing statistics about data sent to an from other devices (“Inter-Node Traffic Logs”); and version of Tailscale Solution installed. This information is needed to provide the Tailscale Solution to you. However, please note that Tailscale does not process, or have the ability to access, the content of User traffic data transmitted through the Tailscale Solution, which is fully end-to-end encrypted.
As you use the Services, we also collect aggregated usage statistics (such as the amount of data transmitted through the Tailscale Solution over a period of time, and information about how you’re using the Tailscale Solution). Please note that to the extent such aggregated information or the metadata discussed above that we collect through your use of the Tailscale Solution cannot be used to identify you or your device, we can use and disclose such information in our discretion as discussed in the “Aggregate/De-Identified” Information section below.
Site Information. When you use our Site, we automatically collect certain information about your device and how you use the Site, including your IP address, browser type, browser language, operating system, the state or country from which you accessed the Services, software and hardware attributes (including device IDs), referring and exit pages and URLs, platform type, the number of clicks, files you download, domain names, landing pages, pages viewed and the order of those pages, the amount of time spent on particular pages, the date and time you used the Services, error logs, and other similar information. From your IP address, we may be able to infer your general location (e.g., city/state or postal code).
INFORMATION WE COLLECT FROM OTHERS
From time to time, we may collect information about Prospects from other sources, including partners, data enhancement services, conferences, and other industry events or other purposes that we explain to you at the time of collection, to the extent permitted by applicable law. We use this information to supplement the information that we collect directly from Prospects in order to better understand our Prospects’ interests and to provide them with more relevant information, and to improve our analytics and advertising.
When you “like” or “follow” us on Facebook, LinkedIn, Twitter or other social media sites, we may collect some information from you including your name, username, email address, and any comments or content you post relevant to us.
3. HOW WE USE YOUR INFORMATION
We use your information for various purposes depending on the types of information we have collected from and about you, to:
Provide the Tailscale service: Provide you with access to and to administer our Services
Provide customer support: Respond to your requests for information and provide you with more effective and efficient customer support
Send marketing communications: Contact you by email, postal mail, or phone with news, updates, information, promotions, surveys or contests relating to the Services or other services that may be of interest to you, in accordance with applicable legal requirements related to such communications
Customize the content you see on our Site
Conduct customer research: Engage in analysis and research regarding use of the Services, and improve our Services
Secure our Services and resolve technical issues being reported
Meet legal requirements: Comply with any procedures, laws, and regulations which apply to us where it is necessary for our legitimate interests or the legitimate interests of others
Establish, exercise, or defend our legal rights where it is necessary for our legitimate interests or the legitimate interests of others
Aggregate/De-Identified Information. We may aggregate and/or de-identify any information collected through our Services so that such information can no longer be linked to you or your device (“Aggregate/De-Identified Information”). We may use such information for any purpose, including without limitation for research, and may also disclose such data with any third parties, including our third-party partners.
4. LEGAL BASES FOR USE OF YOUR INFORMATION
Where we need to perform the contract we are about to enter into or have entered into with you for the Services
Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests
Where we need to comply with a legal or regulatory obligation
Where we have your consent to process your information in a certain way
SITE ANALYTICS AND ADVERTISING
ANALYTICS. We may use third-party web analytics services (such as those of Segment Analytics) on our Site to collect and analyze usage information through cookies and similar tools; engage in auditing, research, or reporting; assist with fraud prevention; and provide certain features to you. To prevent Segment Analytics from using your information for analytics, you may use the Segment consent management tool by emailing us using the Contact Us information below. If you receive email from us, we may use certain analytics tools, such as clear GIFs to capture data such as when you open our message or click on any links or banners our email contains. This data allows us to gauge the effectiveness of our communications and marketing campaigns.
ONLINE ADVERTISING. In using the Site, we allow select third party advertising technology partners to place cookies or other tracking technologies on the browser of your device to collect information about you as discussed above. These third parties (e.g., ad networks and ad servers such as Google) may use this information to serve relevant content and advertising to you as you browse the Internet, and access their own cookies or other tracking technologies on your browser to assist in this activity. If you are interested in more information about these online advertising activities, and how you can generally control cookies from being put on your computer to deliver tailored advertising, you may visit the Digital Advertising Alliance of Canada, Network Advertising Initiative’s Consumer Opt-Out link, the Digital Advertising Alliance’s Consumer Opt-Out link, or Your Online Choices to opt-out of receiving tailored advertising from companies that participate in those programs.
We do not control these opt-out links or whether any particular company chooses to participate in these opt-out programs. We are not responsible for any choices you make using these mechanisms or the continued availability or accuracy of these mechanisms. Please note that if you use these mechanisms, you may still see advertising on the Internet, but it will not be tailored to you based on your online behavior over time.
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. We are committed to providing you with meaningful choices about the information collected on our Services for third party purposes, and that is why we provide the variety of opt-out mechanisms listed above. However, we do not currently recognize or respond to browser-initiated DNT signals.
5. HOW WE DISCLOSE YOUR INFORMATION
We will disclose your information in the following ways:
Service Providers. We provide access to or disclose your information to select third parties who help us deliver our Services or perform services on our behalf, including billing and credit card verification, advertising and marketing, content and features, analytics, research, customer support, data storage, security, web hosting, fraud prevention, and legal services.
Affiliates and Subsidiaries. We may disclose the information we collect within the Tailscale family of companies.
Your Organization. If you are a User using the Tailscale Solution under an organization’s account, we may provide your information to the organization you are engaged or employed by in order to fulfill and enforce our services agreement with your organization, and to inform your organization regarding usage, support, or training needs.
Protection of Tailscale and Others. By using the Services, you acknowledge and agree that we may access, retain, and disclose the information we collect and maintain about you if required to do so by applicable law or in a good faith belief that such access, retention or disclosure is reasonably necessary to: (a) enforce any contracts with you; (b) respond to claims that any content violates the rights of third parties; (c) protect the rights, property or personal safety of Tailscale, its agents and affiliates, its users and/or the public; and/or (d) comply with legal process (e.g. a subpoena or court order).
Canadian Law Enforcement Requests. We disclose your information solely in accordance with our Terms of Service and applicable law, including the Canadian Criminal Code, R.S.C. 1985, c. C-46, to the extent it applies. Canadian law generally requires lawful authority by means of a warrant issued by a judge to compel the disclosure of User information.
U.S. Law Enforcement Requests. We disclose your information solely in accordance with our Terms of Service and applicable law, including the federal Stored Communications Act, 18 U.S.C. Sections 2701-2712, to the extent it applies. In accordance with U.S. law:
A jurisdictionally valid subpoena, issued in connection with an official criminal investigation, is required to compel the disclosure of basic User records, which may include name, length of service, credit card information (including billing address), email address(es), and an IP address, if available.
A court order is required to compel the disclosure of certain records or other information related to a user account (not including contents of communications), which may include message headers and IP addresses, in addition to the basic User records identified above.
A search warrant properly issued under the procedures described in the Federal Rules of Criminal Procedure or equivalent state warrant procedures, based on a showing of probable cause, is required to compel the disclosure of the stored contents of any account, including the contents of communications (e.g., messages and attachments). As noted above, Tailscale does not process, or have the ability to access, the content of User traffic data transmitted through the Tailscale Solution, which is fully end-to-end encrypted.
International Law Enforcement Requests. In the case of requests from law enforcement outside of the Canada and the U.S., a Mutual Legal Assistance Treaty (MLAT) request or letter rogatory may be required to compel the disclosure of User data.
User Notification. Tailscale’s policy is to notify Users of law enforcement requests for their information, which includes a copy of the request, prior to disclosure, so that they may have an opportunity to challenge such request unless: (a) we are prohibited from doing so by law or court order; (b) there are exceptional circumstances, such as an emergency involving the risk of bodily injury or death to a person or group of people or potential harm to minors; or (c) prior notice would be counterproductive (for example, if we believe that the account in question has been hijacked).
Business Transactions. In accordance with applicable legal obligations, your information may be provided to third parties in connection with a merger or acquisition (including transfers made as part of insolvency or bankruptcy proceedings) involving all or part of Tailscale or our assets, or as part of a corporate reorganization or stock sale or other change in corporate control or fundamental business change, including for the purpose of determining whether to proceed or continue with such transaction or business relationship.
Aggregate/De-Identified Information. From time to time, we may disclose Aggregate/De-identified Information about use of the Services or our user base with partners and others, but such information will not identify you personally.
6. RETENTION OF YOUR INFORMATION
We keep your information for no longer than necessary for the purposes for which it is processed. The length of time for which we retain information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws.
7. YOUR RIGHTS AND YOUR CHOICES
You have certain rights with respect to your information as further described in this section.
YOUR LEGAL RIGHTS
If you would like further information in relation to your legal rights under applicable law or would like to exercise any of them, please contact us using the information in the “Contact Us” section below at any time. Your local laws (e.g., if you are a citizen or resident of the European Economic Area or California) may permit you to request that we:
provide access to and/or a copy of certain information we hold about you
update information which is out of date or incorrect
delete certain information that we are holding about you
restrict the way that we process and disclose certain of your information
revoke your consent for the processing of your information
provide you with information about the financial incentives that we offer to you, if any.
We will consider all requests and provide our response within the time period stated by applicable law and as otherwise required by applicable law. Please note, however, that certain information may be exempt from such requests in some circumstances, which may include if we need to keep processing your information for our legitimate interests or to comply with a legal obligation. We may request you provide us with information necessary to confirm your identity before responding to your request. To submit a request, please contact us using the information in the “Contact Us” section below.
8. THIRD PARTY LINKS AND FEATURES
9. INTERNATIONAL USERS
Your information is maintained and processed by us and our third-party service providers in Canada, Germany, and the United States, and may also be maintained, processed, and stored in other jurisdictions that may have different data protection laws than those in your country of residence. In the event that your information is transferred in these ways, please note that we comply with applicable legal requirements governing the transfer of information across borders. By using the Services, you agree to and acknowledge these transfers.
10. HOW WE PROTECT YOUR INFORMATION
Tailscale takes a variety of technical and organizational security measures to protect the information provided to us from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no Internet or email transmission is ever fully secure or error free. Please keep this in mind when disclosing any information to us online. For more information about our data security practices, please see https://tailscale.com/security/.
If you become aware of or suspect any unauthorized use of your Tailscale account, please contact us immediately using the information in the “Contact Us” section below.
11. PRIVACY INFORMATION FOR CERTAIN U.S. STATE RESIDENTS
Do Not Sell Rights. Please note that certain U.S. state laws set forth obligations for businesses that “sell” personal information to third parties, as such term is defined under those laws. We do not engage in such activity.
The California “Shine the Light” law gives residents of California the right under certain circumstances to request information from us regarding the manner in which we disclose certain categories of personal information (as defined in the Shine the Light law) with third parties for their direct marketing purposes. We do not disclose your personal information with third parties for their own direct marketing purposes.
13. CONTACT US
By phone: +1 (415) 886-9844
Tailscale Data Privacy Officer
125-720 King St. West
Toronto, ON M5V 3S5