Privacy Policy for TokeConnect
Last updated: July 21, 2026
TokeConnect is a private workplace communication, scheduling, agreement-management, Toke-tracking, and committee-management application intended for approved workplace users.
This Privacy Policy explains:
what information TokeConnect collects;
how that information is collected and used;
when information may be shared with service providers or workplace management;
how long information may be retained;
how users may access, correct, or request deletion of their information; and
the privacy choices available to users.
By creating an account, submitting an application for approval, participating in a Toke Committee nomination process, or using TokeConnect, you acknowledge the practices described in this Privacy Policy.
1. Who May Use TokeConnect
TokeConnect is intended only for authorized and approved workplace users.
Creating an account does not automatically provide access. Account applications may be reviewed by authorized workplace management before access is approved.
Users may be assigned roles such as Slot Attendant, Toke Officer, Co-President, President, Owner, Tester, Toke Committee member, or another authorized workplace role. A user’s role determines which app features and records the user may access.
2. Information We Collect
TokeConnect may collect the following categories of information.
A. Account and identity information
TokeConnect may collect:
full name or display name;
email address;
Firebase user identifier;
account creation date;
approval status;
account status;
assigned workplace role;
Owner, administrator, officer, committee-member, or testing status; and
dates and identifiers related to account approval, denial, role changes, or removal.
Passwords are handled through Firebase Authentication. TokeConnect does not display or store users’ readable account passwords in its application database.
B. Profile and Toke Committee nomination information
TokeConnect may collect:
profile photo or avatar;
display name;
committee biography;
committee profile image;
phone number submitted or used for the Toke Committee nomination process;
nominee name and identifying information;
nomination submissions;
the identity of the person making a nomination, where recorded;
nomination dates and timestamps;
nomination status;
committee candidacy, acceptance, withdrawal, selection, or election information;
records associated with reviewing or administering nominations;
notification preferences;
theme and appearance preferences; and
other settings selected by the user.
Phone numbers collected for the Toke Committee nomination process may be used to identify or contact nominees, confirm participation, communicate nomination-related information, coordinate committee activities, or administer the nomination process.
TokeConnect does not use nomination phone numbers for third-party advertising or unrelated marketing.
Users should only submit a phone number that they are authorized to provide. Users should avoid submitting another person’s phone number without that person’s knowledge or permission.
C. Feed and user-generated content
TokeConnect may collect:
feed posts;
post dates and timestamps;
comments;
likes and reactions;
post-authorship information;
Toke-related posts;
announcement acknowledgements;
content visibility and audience information; and
reports or moderation-related records, where available.
TokeConnect may collect or process:
direct messages between approved users;
sender and recipient identifiers;
message text;
message timestamps;
conversation-participant information; and
read, delivery, or conversation-status information where supported.
Although messages are limited to approved users through app permissions, users should not submit highly sensitive personal, financial, medical, or legally privileged information through TokeConnect.
E. Calendar, shift, and scheduling information
TokeConnect may collect:
calendar dates and events;
shift dates and times;
shift-swap requests;
shift-giveaway requests;
requesting and receiving users;
participants;
notes and descriptions;
claim, approval, signature, completion, cancellation, or archive status; and
related timestamps and workflow records.
F. Agreement and signature information
TokeConnect may collect:
agreement type and status;
agreement participants;
shift or scheduling details;
PDF or document references;
signature records;
signature dates and timestamps;
claim, approval, completion, cancellation, or archive information; and
records needed to verify that an agreement was reviewed or signed.
G. Toke and pooled tip information
TokeConnect may collect, calculate, combine, store, review, and display Toke information.
In this Privacy Policy, “Tokes” and “Toke totals” may refer to workplace tip amounts and pooled tip totals.
Toke-related information may include:
individual Toke amounts used to calculate a pool;
daily pooled Toke or tip totals;
weekly pooled Toke or tip totals;
monthly pooled Toke or tip totals;
yearly pooled Toke or tip totals;
year-to-date pooled Toke or tip totals;
work-week totals;
Toke dates and amounts;
records used to calculate, verify, allocate, or reconcile pooled totals;
imported Toke records;
the user who imported, entered, updated, or reviewed the information;
corrections and adjustments;
discrepancy reports;
review and correction records;
deletion markers; and
related audit information.
Pooled Toke totals may be organized, calculated, and displayed by day, week, month, year, work week, or another applicable reporting period.
TokeConnect may preserve historical pooled totals to support workplace reporting, accounting, verification, discrepancy review, audit history, and operational recordkeeping.
H. Notifications and device information
When notifications are enabled, TokeConnect may collect or process:
Firebase Cloud Messaging registration tokens;
notification-permission status;
notification-preference status;
device or app-instance identifiers needed to deliver notifications;
notification-delivery or token status; and
the date notification settings were updated.
TokeConnect does not use notification identifiers for advertising.
I. Administrative, security, and audit information
TokeConnect may collect:
role changes;
account approval or denial activity;
administrative actions;
announcement activity;
Toke Committee nomination administration;
account-deletion requests;
security-related events;
error and troubleshooting information;
timestamps and user identifiers associated with protected actions; and
records needed to investigate misuse, unauthorized access, discrepancies, or operational problems.
J. Information submitted to management
Some TokeConnect features allow a user to select Send to Management or a similarly labeled action.
When a user selects this action, TokeConnect may process and transmit information necessary to deliver the request to designated workplace-management recipients.
Depending on the feature, this information may include:
the user’s name;
the user’s account email address;
the type of request;
the message entered by the user;
relevant dates;
shift details;
agreement details;
nomination details;
Toke or discrepancy information;
account information;
identifiers needed to associate the request with the correct user or record; and
timestamps and delivery-status information.
The user initiates this transmission by selecting the applicable send button.
3. How Information Is Collected
Information may be collected:
directly from users when they register, complete profile fields, create content, send messages, submit forms, provide nomination information, provide phone numbers, upload images, sign agreements, or change settings;
automatically when app features create timestamps, identifiers, status records, notification tokens, calculated totals, or audit records;
from authorized Owners, administrators, officers, committee members, or other workplace personnel when they approve users, assign roles, enter Toke records, manage nominations, publish announcements, or manage workplace information;
from users who submit information about another person during a Toke Committee nomination process; and
through service providers used to authenticate users, store records, deliver notifications, host the app, and send transactional emails.
4. How We Use Information
TokeConnect may use collected information to:
create and authenticate user accounts;
review and approve account applications;
restrict access to approved workplace users;
assign and enforce role-based permissions;
provide Feed, Comments, Reactions, Messages, Calendar, Agreements, Committee, Tokes, Announcements, and Notification features;
administer the Toke Committee nomination process;
identify or contact Toke Committee nominees;
confirm whether a nominee wishes to participate;
communicate nomination, candidacy, committee, or selection-related information;
facilitate shift swaps and giveaways;
generate, display, and maintain agreement records;
calculate, combine, pool, verify, display, and maintain Toke or tip totals;
organize pooled Toke totals by day, week, month, year, work week, or other reporting period;
allow authorized users to review or correct Toke records;
investigate and correct Toke discrepancies;
maintain historical Toke records for workplace, accounting, audit, dispute-resolution, verification, or operational purposes;
deliver messages and notifications;
send user-initiated requests to workplace management;
maintain account, nomination, administrative, security, and audit history;
respond to support, privacy, correction, or deletion requests;
prevent fraud, misuse, unauthorized access, and security incidents;
troubleshoot technical problems;
maintain and improve app reliability;
comply with legal, workplace, security, audit, accounting, or operational obligations; and
enforce app rules and authorized-access requirements.
5. Emails Sent Through Brevo
TokeConnect uses Brevo as a transactional email-delivery service.
When a user selects Send to Management, TokeConnect may send the request through Brevo so that the message reaches the designated management email address or addresses.
Information processed by Brevo for this purpose may include:
the recipient email address;
the sender or requesting user’s name and email address;
the email subject;
the message or request content;
related workplace, scheduling, agreement, nomination, Toke, or account details included in the request;
technical delivery information; and
email-delivery status, such as whether the message was accepted, delivered, delayed, or rejected.
Brevo is used to deliver service-related or transactional messages initiated through TokeConnect. TokeConnect does not use these management-request emails for third-party advertising or the sale of user data.
Once an email is delivered to management, the message may also remain in the recipient’s workplace email system and may be retained according to workplace, legal, security, accounting, audit, or operational requirements.
6. Firebase and Google Cloud Services
TokeConnect uses Firebase and related Google Cloud services, which may include:
Firebase Authentication;
Cloud Firestore;
Cloud Storage for Firebase;
Firebase Hosting;
Firebase Cloud Messaging;
Firebase App Check; and
Firebase Extensions or secure backend processing where configured.
These services may process:
account information;
profile and nomination information;
phone numbers;
app records;
pooled Toke or tip records;
uploaded files;
notification tokens;
device or app-instance information; and
technical information necessary to operate the app.
TokeConnect does not use Firebase data for third-party advertising.
7. When Information May Be Shared
TokeConnect does not sell personal information.
TokeConnect does not share personal information with advertising networks or data brokers.
Information may be disclosed only as reasonably necessary for the purposes described below.
Information may be visible to other approved users when required by a feature.
Examples include:
a user’s display name and role;
committee profiles;
nominee or candidate information intended to be visible during a nomination process;
feed posts, comments, and reactions;
agreement-participant information;
available shift giveaways;
direct messages sent to another user; and
information intentionally submitted to workplace management.
A nominee’s phone number should not be displayed broadly to approved users unless that visibility is reasonably necessary for the nomination process and permitted by TokeConnect’s access controls.
B. Authorized management, administrators, and committee personnel
Authorized Owners, Presidents, Co-Presidents, Toke Officers, Toke Committee members, or other permitted roles may access information required to:
approve or deny applications;
manage roles;
manage announcements;
review agreements;
manage or review Toke information;
calculate or verify pooled Toke totals;
investigate discrepancies;
administer the Toke Committee nomination process;
contact nominees;
confirm nomination participation;
respond to account, privacy, correction, or support requests; and
operate and secure the app.
Access depends on each user’s assigned role and the permissions configured within TokeConnect.
Phone numbers collected for Toke Committee nominations should only be accessed and used by authorized persons for nomination-related communication, verification, coordination, committee administration, or another legitimate workplace purpose.
Information may be processed by service providers that help operate TokeConnect, including:
Google Firebase and Google Cloud for authentication, database storage, file storage, hosting, notifications, and related infrastructure; and
Brevo for transactional email delivery when a user sends information to management.
These providers process information to perform services on behalf of TokeConnect and are expected to protect it according to their contractual and legal obligations.
D. Legal, safety, and security disclosures
Information may be disclosed where reasonably necessary to:
comply with law, regulation, subpoena, court order, or valid legal process;
protect users, workplace personnel, or the public;
investigate suspected fraud, abuse, harassment, or unauthorized access;
investigate Toke discrepancies or manipulation;
enforce app rules or workplace policies;
protect TokeConnect systems, rights, or property; or
respond to an emergency involving safety or security.
8. Data Storage and International Processing
TokeConnect information may be stored or processed through Firebase, Google Cloud, Brevo, and workplace email systems.
This may include:
These systems may process information in the United States or other countries where the applicable service providers maintain infrastructure or subprocessors.
Privacy and data-protection laws may differ between countries. TokeConnect relies on its service providers’ contractual and security safeguards when they process information on its behalf.
TokeConnect uses administrative, technical, and access-control measures intended to protect user information.
These measures may include:
encrypted network connections;
Firebase Authentication;
Firestore security rules;
role-based access controls;
restricted Owner, administrator, officer, and committee tools;
approved-user access requirements;
account-status controls;
protected storage permissions;
audit and operational records; and
notification and device-token controls.
Access to nomination phone numbers and detailed Toke records should be limited to authorized roles that require the information for a legitimate app or workplace purpose.
No electronic system is completely secure. TokeConnect cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.
Users are responsible for:
protecting their password;
securing access to their device;
signing out of shared devices;
avoiding the sharing of account credentials;
avoiding the submission of unnecessary sensitive information; and
promptly reporting suspected unauthorized access.
10. Notifications and Device Permissions
Users may allow or deny notification permission through their device settings.
Notification permission is used to deliver workplace-related app notifications. Users may disable notifications at any time through TokeConnect settings or the device’s operating-system settings.
Disabling notifications does not delete the user’s account or other records, but it may prevent the user from receiving timely app updates.
Where TokeConnect requests access to photos, files, documents, or other device features, that access is used only for the feature the user selected, such as choosing a profile image, uploading a document, or selecting an agreement file.
TokeConnect does not require access to a user’s device contacts merely because a phone number may be entered during the Toke Committee nomination process, unless a separate app feature clearly requests and explains that permission.
11. User Choices and Access
Depending on available app features, assigned permissions, and applicable law, users may:
update their display name;
change their profile image;
update notification preferences;
change theme preferences;
change their email address;
request a password reset;
review information displayed in the app;
disable device notifications;
request correction of inaccurate information;
submit a Toke discrepancy request where permitted;
request correction or removal of an inaccurate nomination phone number;
withdraw from a nomination process where permitted; and
request account and data deletion.
Certain information may only be changed by authorized management.
This may include:
12. Account and Data Deletion
TokeConnect users may delete their account directly within the app by opening:
Settings → Delete Account
Users who cannot complete deletion within the app may submit an account and data deletion request using the following form:
https://forms.gle/2MLk6pbvgMN9doex7
Users may also request assistance by contacting:
rcpslots@gmail.com
The request should include the email address associated with the TokeConnect account.
Users should not include their password, payment information, government-issued identification numbers, or other unnecessary sensitive information.
TokeConnect may require the user to confirm their identity and ownership of the account before processing a deletion request.
After the user confirms deletion, TokeConnect may delete, remove, or anonymize the user’s account profile and associated personal data stored in Firebase Authentication, Cloud Firestore, Firebase Storage, and other TokeConnect systems used for that account.
Depending on the information connected to the account, deletion may include:
the user’s authentication account;
profile information and profile images;
notification tokens and notification preferences;
feed posts, comments, reactions, and other user-generated content;
direct messages associated with the account;
calendar, shift-swap, shift-giveaway, and agreement records associated with the user;
personal identifiers associated with Toke records;
announcement acknowledgements;
account settings;
account-status information;
other associated Firestore records;
phone numbers collected for the Toke Committee nomination process when they are no longer required;
nomination records where deletion or anonymization is appropriate; and
files or documents stored for the account.
Account deletion may not be immediate when identity verification or manual review is required. The user may receive confirmation when processing is complete.
Deleting an account is permanent. After deletion, the user will lose access to TokeConnect, and the deleted account and data generally cannot be restored.
Deleting an account does not necessarily require deletion of aggregated, pooled, or historical Toke totals when those totals:
are no longer directly associated with the deleted user;
are required for workplace reporting;
are required for accounting or reconciliation;
are needed for audit or discrepancy review;
are required to preserve operational history; or
must be retained for a legal or workplace obligation.
13. Information That May Be Retained After Deletion
Some information may be retained when reasonably necessary to:
comply with legal or regulatory obligations;
maintain workplace operational records;
preserve signed agreements or records of workplace transactions;
maintain financial, Toke, pooled tip, audit, or correction history;
verify daily, weekly, monthly, yearly, or year-to-date pooled Toke totals;
prevent fraud or abuse;
investigate security incidents;
resolve disputes;
investigate discrepancies;
enforce app or workplace rules;
maintain records of prior administrative actions;
document a completed nomination process;
protect the rights, safety, or security of users or others; or
maintain backup integrity until backups are overwritten through normal processes.
Where practical, retained information may be limited, restricted, de-identified, or anonymized.
Toke Committee nomination information, including phone numbers, may be retained for as long as reasonably necessary to:
complete the nomination process;
contact or verify nominees;
resolve questions or disputes;
document the nomination result;
administer committee transitions; or
satisfy applicable workplace or legal requirements.
When a nomination phone number is no longer required, it may be deleted, restricted, or anonymized where appropriate.
Pooled Toke or tip totals for a day, week, month, or year may be retained after an account is deleted when they are required for:
workplace reporting;
accounting;
reconciliation;
audit history;
discrepancy review;
operational records; or
legal compliance.
Where practical, retained pooled totals will not remain directly linked to the deleted user unless that association is necessary for one of these purposes.
Messages or emails already delivered to another approved user, management recipient, or workplace email account may remain in the recipient’s records after the sender’s TokeConnect account is deleted.
Other information may remain outside the deleted account when it has already been delivered, copied, downloaded, or stored by another person or external system.
Examples include:
direct messages or content received, saved, or copied by another user;
emails previously sent to management through Brevo;
information retained in a management recipient’s email system; and
records that TokeConnect is legally required to retain.
Where retention is legally required, the information will be limited to what is necessary and retained only for the required purpose and period.
Different categories of information may be retained for different periods.
TokeConnect generally retains information for as long as needed to:
maintain an active approved account;
provide app functions;
support workplace scheduling and agreements;
administer Toke Committee nominations;
maintain Toke and pooled tip records;
calculate or verify daily, weekly, monthly, and yearly totals;
respond to disputes or support requests;
maintain security and audit history; and
satisfy legal, accounting, audit, operational, or workplace requirements.
TokeConnect may retain:
nomination phone numbers for the duration of the nomination process and a reasonable review or dispute period;
nomination records for workplace, dispute-resolution, committee-history, or administrative purposes;
daily pooled Toke totals;
weekly pooled Toke totals;
monthly pooled Toke totals;
yearly and year-to-date pooled Toke totals;
historical Toke records needed for workplace reporting;
supporting records used to verify calculations or corrections; and
audit records associated with Toke entries, imports, adjustments, and discrepancy reviews.
Information that is no longer needed may be deleted, anonymized, restricted, or allowed to expire through normal system and backup processes.
TokeConnect is not designed or intended for children.
The app is intended for approved workplace users who are legally permitted to work and participate in the relevant workplace environment.
TokeConnect does not knowingly seek to collect personal information from children for consumer, advertising, or entertainment purposes.
Users should not submit a child’s phone number or other personal information through the Toke Committee nomination process.
16. Advertising, Tracking, and Sale of Data
TokeConnect:
does not display third-party advertising;
does not sell personal information;
does not use personal information for cross-app advertising;
does not share personal information with data brokers;
does not use nomination phone numbers for advertising;
does not use Toke or tip information for advertising; and
does not use advertising identifiers to track users across unrelated apps or websites.
17. Changes to This Privacy Policy
This Privacy Policy may be updated when:
TokeConnect adds or changes features;
the Toke Committee nomination process changes;
Toke calculation or reporting practices change;
service providers change;
legal or platform requirements change;
data-handling practices change; or
security and operational procedures are updated.
The revised policy will display a new Last updated date.
Material changes may also be communicated through the app, an announcement, the website, or email where appropriate.
For privacy questions, account requests, correction requests, nomination-information requests, or data-deletion requests, contact:
rcpslots@gmail.com
Users may also submit an account and data deletion request through:
https://forms.gle/2MLk6pbvgMN9doex7
When contacting TokeConnect, include enough information to identify the applicable account and describe the request.
Do not submit passwords, payment details, government-issued identification numbers, or other unnecessary sensitive information.