ThingsBoard License Portal - Privacy Policy
Revision Date: September 15, 2026
1. Introduction and Scope
This Privacy Policy (“Policy”) governs the collection, processing, use, disclosure, and protection of personal data by ThingsBoard, Inc. (“ThingsBoard,” “we,” “us,” or “our”) across all our operational touchpoints, including our corporate website (thingsboard.io), the ThingsBoard License Portal (https://license.thingsboard.io, hereinafter the “Portal”), our cloud services, IoT software ecosystem, customer support channels, and administrative infrastructure.
Our role depends on the data. ThingsBoard, Inc. acts as the data controller for the personal data described in this Policy — Portal accounts, licensing, billing and customer records, website and support interactions, and the system and license data described in Section 2.3 — under applicable global data protection laws, including the EU General Data Protection Regulation (GDPR) and applicable US state privacy legislation.
Where we process personal data contained in a customer’s own ThingsBoard deployment on that customer’s instructions — including data held in our cloud services and data sent to our hosted AI service as described in Section 2.5 — we act as a data processor on behalf of that customer, who is the controller of it. That processing is governed by our agreement with the customer, including any data processing agreement, rather than by this Policy.
This Policy applies to visitors, account holders, customers, developers, and representatives of Organizations utilizing ThingsBoard products, services, or web platforms. Our products, website, and Portal are intended for business and professional use and are not directed to children under 16; we do not knowingly collect personal data from children.
2. Information We Collect
We collect information directly from you, automatically through your interactions with our platforms, and from third-party services.
2.1 Information Provided Directly by You
- Account and Registration Information: When you register for a ThingsBoard account, sign up for the Portal, request a software license key, or participate in the Community Grant Program, we collect personal identity and professional details, including your full name, business email address, corporate entity/Organization name, country, phone number, and account authentication credentials (passwords or security tokens).
- Commercial and Licensing Data: Records of licenses requested, generated, assigned, or deleted; commercial declarations submitted (including non-commercial operational status, device allocations, and organizational identity); and records of communications with our sales, compliance, or support teams.
- Support and Inquiry Data: Information provided during customer support interactions, technical inquiries, sales inquiries, or community forum participation.
2.2 Payment and Billing Data
What Stripe handles. We do not collect, process or store payment instruments — card numbers, bank credentials or equivalent. All card transactions made through the Portal or our website are collected, processed and secured by our payment processor, Stripe, Inc. (“Stripe”), under its own privacy policy. Stripe returns to us only transaction confirmations, billing addresses, Tax/VAT IDs and payment status.
What we hold ourselves. We maintain our own billing and customer records, in our accounting system (Intuit Inc., QuickBooks) and our customer relationship management system (Pipedrive). These records include your legal entity name and billing address, Tax/VAT ID, the name, business email address and telephone number of your billing and account contacts, purchase order numbers, invoices and credit notes, amounts, currency, dates, payment status and payment history, and correspondence relating to your purchases and account.
We keep these records to perform our contract with you, to meet our accounting and tax obligations, and to manage our relationship with your organization. Retention is described in Section 6.
2.3 System, License Check, and Instance Check Data
When you utilize our Software, license keys, or the Portal, we collect technical operational data:
- Standard License Validation Data: Under a standard online license, the Software periodically contacts our license server. Each request carries your license secret, instance ID, and cluster ID, and our servers record the connecting source IP address for license-compliance and abuse-protection purposes. Some requests also include a usage snapshot: aggregate, platform-wide metrics such as packaging type and database backend, software version, entity counts (e.g., tenants, devices, assets, users), feature-mix breakdowns (e.g., rule node types, integration types, solution templates), database size, and previous-day hourly API/message volumes (e.g., messages, emails, SMS, data points). The snapshot is pseudonymous and attributable to your licensed account, but never contains message payloads, telemetry values, user names, credentials, or customer-authored scripts. You may disable the snapshot by setting the environment variable
TB_ANONYMOUS_USAGE_REPORTING=falsein the Software’s configuration, without affecting platform functionality, license validity, or support entitlements; license validation requests and IP recording continue. The specific counters may evolve; the collecting code is available in the source-available distribution. Offline (air-gapped) licenses are validated entirely within your deployment against the signed license data issued to you; such instances send no validation requests or usage snapshots to our license server. - Instance Check Reports: If your Organization registers for or maintains a license under the Community Grant Program, you generate and submit an Instance Check Report. To size and verify your Community Grant, you run the verification tool against your own deployment. The tool operates locally under your control and opens the database read-only, and produces a single encrypted report. When you proceed with a license grant, the tool uploads the report automatically. Where your deployment has no outbound connectivity, the tool cannot upload it, and you transfer and submit the report through the Portal yourself. Submitted reports are retained as described below in this Privacy Policy.
- What it contains: solely operational and structural metadata, installation and enrollment identifiers, software and tool versions, collection timestamps, earliest-activity dates, entity counts and creation-interval statistics, processing-node counts, storage-size and row-count estimates, two PostgreSQL server markers (the age of the database transaction counter and the server start time), statistical checks that the deployment’s recorded history is genuine, and reliability markers.
- What it NEVER contains: telemetry or attribute values, entity names or descriptions, host or node names, credentials, message payloads, dashboard or rule chain contents, or personal data.
- Update Server Communications: Separately from licensing, the Software contacts our update server (updates.thingsboard.io) in two ways; in both cases our servers record the connecting source IP address for license-compliance and abuse-protection purposes.
- Release update checks. Unless disabled in the Software’s configuration, each core node periodically checks for newer ThingsBoard releases and the matching ThingsBoard Edge version, sending only the installed software version, packaging type, and a randomly generated local installation identifier not linked to your account or license. This applies to all installations regardless of license type and can be disabled without affecting platform functionality or license validity.
- Offline license check-in. Instances under an offline license also attempt a short identity check-in at startup and approximately hourly from every node. Without outbound connectivity these attempts fail silently and have no effect on the license or platform. A successful check-in transmits only your customer identifier and subscription identifier as recorded in the offline license, plus the packaging type and licensing component version — no usage counters, telemetry, configuration, or personal data of your users. We use it to confirm the license is in active use and to detect use beyond its scope (e.g., in additional, separate deployments). As an essential anti-abuse and intellectual property protection control, it cannot be disabled within the product.
2.4 Website Usage, Cookies, and Tracking Technologies
When visiting our websites or Portal, we automatically collect log data and technical information, including your IP address, browser type, operating system, referring URLs, access times, pages viewed, and device parameters. We utilize essential cookies for authentication and platform security, as well as analytics cookies (where consented to) to measure platform usage and performance.
2.5 ThingsBoard AI Feature Interactions
When users interact with ThingsBoard AI capabilities:
- We collect messages users type, the AI model’s responses, resulting conversation history, including the platform data retrieved through tool calls (as explained below). We also collect active UI screen context, the user’s time zone, and browser language.
- To answer a query, the AI model may request additional platform context (a “tool call”). The AI service executes such requests on behalf of the requesting user, subject to that user’s platform permissions, and returns the results to the model. Data requested this way may include: telemetry readings and attribute values of any platform entity (devices, assets, customers, and others); entity records and configurations, including customer-defined names and labels, dashboards, alarm data, and entity relations; personal details of platform users and customer organizations (such as first/last names, emails, phone numbers, and postal addresses); and device credentials (such as access tokens).
- AI features in self-hosted (on-premise) installations are served by our hosted AI service (ai.thingsboard.cloud): user requests and the data described above are sent to that service, which forwards them to the AI providers described in Section 4, and stores conversation history and AI audit records. AI features can be completely disabled system-wide, per tenant, or per user role; when disabled, no AI-related data is collected or sent.
2.6 Business Contact and Prospect Data
We also hold business contact records for people who have not purchased from us — for example, someone who requests a demonstration or a quotation, registers for a webinar or event, subscribes to updates, or otherwise contacts our sales team. These records are kept in our customer relationship management system (Pipedrive) and typically comprise name, business email address, telephone number, employer, role, country, the source of the enquiry, and our correspondence about it.
We process this data on the basis of our legitimate interests in developing and managing business relationships. You may object at any time under Section 8, and every marketing email carries an unsubscribe link. Where we rely on consent for electronic marketing, you may withdraw it at any time, without affecting processing carried out before withdrawal.
3. Legal Bases and Purposes of Processing
We process personal data only where we have a valid legal basis under applicable law:
| Processing Purpose | Category of Data | Legal Basis (GDPR / Global Equivalent) |
|---|---|---|
| Account Creation & Service Delivery: Administering accounts, issuing license keys, facilitating Portal access, sending system notifications. | Account information, credentials, organization details. | Performance of a Contract (Art. 6(1)(b) GDPR). |
| License Compliance & Grant Evaluation: Verifying key validity, evaluating Community Grant eligibility, and ensuring adherence to device caps and License Agreement terms. | License usage data, Instance Check Reports, commercial declarations. | Legitimate Interests (Art. 6(1)(f) GDPR) in enforcing IP rights; Performance of Contract (Art. 6(1)(b) GDPR). |
| Fraud Prevention & Abuse Mitigation: Detecting manipulated declarations, illegal key sharing, unauthorized access, or breach of software terms. | Deployment and cluster identifiers, account log data, hashed identifiers. | Legitimate Interests (Art. 6(1)(f) GDPR) in mitigating legal and commercial risk. |
| Payment & Billing Administration: Facilitating Stripe billing, issuing invoices, maintaining accounting records, processing tax liabilities. | Transaction logs, Tax/VAT ID, billing address, legal entity name, billing contact details, invoices and payment history. | Performance of Contract (Art. 6(1)(b) GDPR) & Legal Obligation (Art. 6(1)(c) GDPR). |
| Product Analytics & Improvement: Producing statistical and analytical reports on use of the Software to guide product development, prioritisation and improvement. | Usage snapshot statistics only (aggregate, platform-wide counters, pseudonymous and attributable to a licensed account rather than to an individual). | Legitimate Interests (Art. 6(1)(f) GDPR) in understanding and improving our own product. The usage snapshot can be disabled in the Software’s configuration at any time, without affecting platform functionality, license validity or support entitlements. |
| Communications & Consent-Based Activities: Sending direct newsletters, product updates, or voluntary feedback collection. | Contact details, communication preferences. | Consent (Art. 6(1)(a) GDPR), which may be withdrawn at any time. |
| Anti-Abuse & License Enforcement: Validating online licenses, verifying deployment scale, detecting duplicate license usage across isolated instances, and logging connecting network addresses. | Source IP address; for offline licenses: customer and subscription identifiers, software version, packaging type; for online licenses: license secret, instance and cluster identifiers. | Legitimate Interests (Art. 6(1)(f) GDPR) in protecting intellectual property rights, enforcing license terms, and preventing unauthorized duplication. |
| AI Feature Delivery: Processing user messages, maintaining conversation history, retrieving platform data requested by the AI model, and generating requested content (dashboards, IoT solutions, and other configurations). | User messages, conversation history, platform data retrieved via tool calls, UI screen context, time zone, browser language. | Performance of Contract (Art. 6(1)(b) GDPR). |
| AI Quality Assurance & Observability: Debugging AI features, evaluating answer quality and improving AI responses, and maintaining AI audit records; accounting for AI credit usage. | AI audit records containing the full conversation content (user messages, AI responses, model reasoning, tool call arguments and results), user and tenant identifiers, user email; aggregated per-tenant usage counters. | Legitimate Interests (Art. 6(1)(f) GDPR) in operational quality and service security; Performance of a Contract (Art. 6(1)(b) GDPR) for credit accounting. |
| Customer Relationship Management: Maintaining records of your organization, its contacts, purchases and correspondence in order to administer your account, respond to requests and manage renewals. | Company name, contact name, business email address and telephone number, purchase and payment history, correspondence. | Performance of Contract (Art. 6(1)(b) GDPR) & Legitimate Interests (Art. 6(1)(f) GDPR) in administering and developing our customer relationships. |
| Sales and Business Development: Responding to enquiries, preparing quotations, and maintaining prospect records in our CRM. | Name, business email address and telephone number, employer, role, country, enquiry source, correspondence. | Legitimate Interests (Art. 6(1)(f) GDPR) in developing business relationships, and Consent (Art. 6(1)(a) GDPR) where required for electronic marketing. |
4. Third-Party Data Sharing and Processing
ThingsBoard does not sell, rent, or trade your personal data. We share personal and technical data strictly as necessary for administrative and legal purposes:
- Service Providers and Processors: We engage trusted third-party service providers to execute business operations, including Stripe, Inc. (payment processing), Intuit Inc. (accounting and invoicing — QuickBooks), Pipedrive (customer relationship management), cloud infrastructure hosting providers, and customer communication tools. These service providers process data strictly on our instructions and under confidentiality and data protection agreements. To deliver AI features, we share data with specialized AI service providers: Google LLC (Gemini API): User messages, conversation history, and the platform data retrieved via tool calls (see Section 2.5) are processed via Google’s paid Gemini API. Tavily, Inc.: Search queries composed by the AI model are transmitted to Tavily to perform web searches; the search results and retrieved page content are returned to the AI model. No platform identity data or user credentials are sent to Tavily. These service providers process data in accordance with their standard legal terms and privacy practices. To learn more about how our service providers handle, store, and protect your data, please read their respective privacy policies on their official websites.
- Corporate Transactions: In the event of a merger, acquisition, corporate reorganization, asset sale, or bankruptcy involving ThingsBoard, Inc., personal and organizational account data may be transferred to the acquiring or surviving entity subject to standard privacy obligations.
- Legal and Regulatory Disclosures: We may disclose personal data where required to do so by applicable law, court order, subpoena, government inquiry, or to protect the safety, legal rights, or property of ThingsBoard, Inc., our users, or the public.
5. International Data Transfers
ThingsBoard, Inc. is a United States corporation. Personal data collected from users located outside the US (including the European Economic Area (EEA), the United Kingdom, and Switzerland) is transferred to, stored, and processed in the United States and other regions where ThingsBoard or its subprocessors operate.
To protect cross-border transfers of personal data originating from the EEA, UK, or Switzerland, ThingsBoard relies on legally recognized transfer mechanisms, including:
- Standard Contractual Clauses (SCCs): Execution of the European Commission’s Standard Contractual Clauses (and UK Addendum) for transfers to data controllers or data processors in third countries lacking an adequacy decision.
- Supplementary Measures: Supplementary technical, organizational, and contractual measures designed to ensure a level of data protection equivalent to European Union standards.
6. Retention, Account Deletion, and Post-Deletion Evidentiary Rules
6.1 Standard Account Retention
We retain personal data associated with active user or Organization accounts for as long as the account remains open, as needed to fulfill contractual obligations, or as required by applicable tax, accounting, and legal recordkeeping regulations.
6.2 Voluntary Account Deletion
You may request or execute the deletion of your user or Organization account at any time within the Portal settings or by contacting privacy operations. Upon execution of an account deletion request, ThingsBoard permanently deletes your personal identity data—including your name, personal email address, login credentials, and direct links connecting your identity to system records.
If your Organization operates the Software under an offline (air-gapped) license, our automated cloud systems cannot detect when a user is deleted locally within your infrastructure. Consequently, local deletions do not automatically trigger a deletion of associated account data held centrally by ThingsBoard. To exercise a deletion of data held by ThingsBoard, the user or Organization representative must manually submit a deletion request to privacy@thingsboard.io, providing information sufficient for us to locate the data, such as an account or subscription ID.
6.3 Technical Data and License Evidence Retained After Account Deletion
Pursuant to Article 17(3)(e) of the GDPR (and equivalent statutory exemptions permitting retention necessary for the establishment, exercise, or defense of legal claims):
- License & Deployment Records: Technical instance identifiers (instance IDs and cluster IDs), generated license keys, commercial declarations, and uploaded Instance Check Reports are retained after account deletion for the period defined below.
- Delinking Mechanics: Prior to retention, all such technical records are irreversibly delinked from your personal account details (name, personal email, direct credentials).
- Evidentiary Purpose: These records constitute objective evidence of the legal licensing status of a specific software deployment and the declarations behind perpetual or granted permissions. ThingsBoard maintains these technical records for as long as the underlying license grant, software deployment, or potential legal claim exists.
- Billing and Accounting Records: Invoices, credit notes, payment records and the company and contact details they carry are retained for the period required by applicable tax and accounting law — generally seven (7) years from the end of the relevant financial year — including after account deletion. These records are not delinked, because tax law requires the customer to remain identifiable on them.
6.4 Suspected Violation & Integrity Retention
Where an account or deployment is linked to an ongoing investigation or suspected violation of our LICENSE terms, License Agreement, Community Grant License Agreement, or Portal Terms at the time of account deletion, ThingsBoard reserves the right to retain a minimal, privacy-preserving cryptographic record (a one-way hashed identifier) tied to the historical deployment or identity. This hashed record is retained strictly for the purpose of establishing, exercising, or defending against legal claims, preventing fraudulent re-registration, and enforcing retroactive commercial license compliance under GDPR Article 17(3)(e).
6.5 AI Feature Data
Conversation history and AI audit records created by the AI features (see Section 2.5) are retained while the user account remains active, as part of service delivery, security, and AI credit accounting. Users may delete individual conversations at any time; deleted conversations are immediately and permanently erased. Upon account deletion, all remaining records are permanently deleted or de-identified in the manner described below for Improvement Records within 90 days, alongside the deletion described in Section 6.2.
- Improvement Records: Records selected for analyzing user requests and improving the quality of AI responses are retained for no longer than 24 months from creation, after which they are permanently deleted. If the user account is deleted before then, these records are de-identified: the user’s account identifiers and email address are irreversibly removed, and the records are no longer linked to any user account. If the entire tenant is deleted, these records are permanently deleted along with all other tenant data.
- Evidentiary Carve-Out: Where specific AI records are reasonably necessary for billing disputes, abuse investigation, or the establishment, exercise, or defense of legal claims (Article 17(3)(e) of the GDPR), they are retained under the mechanics of Section 6.3 for no longer than 24 months from creation.
- Usage Counters: Aggregated per-tenant usage counters contain no personal data and are retained as service statistics.
6.6 Business Contact and Prospect Data
Where an enquiry does not lead to a purchase, we keep the contact record described in Section 2.6 for as long as the enquiry remains a realistic business prospect. We judge that by whether there has been meaningful interaction — a reply, a meeting, a quotation, or a renewed enquiry — and we delete or anonymize records that no longer meet it when we review our records. You may ask us to delete your record, or object to the processing, at any time under Section 8, and we will act on that request.
7. Data Security
ThingsBoard maintains appropriate administrative, physical, and technical safeguards designed to protect personal data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access.
- Encryption: Instance Check Reports, authentication tokens, Portal communications, and all AI-related communications are transmitted using industry-standard TLS/SSL encryption.
- Payment Isolation: Direct payment card processing is isolated and handled exclusively by Stripe. We do not receive or store payment card details.
- Access Control: Access to personal data is restricted to authorized ThingsBoard personnel and contractors who require access to execute administrative, compliance, or support tasks under binding confidentiality agreements.
8. Your Data Subject Rights
Depending on your jurisdiction (including the EEA, UK, Canada, and various US states), you may hold statutory rights regarding your personal data:
- Right to Access / Know: Request confirmation of whether we process your personal data and obtain a copy of such data.
- Right to Rectification: Request correction of inaccurate, incomplete, or outdated personal data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data, subject to the retention exemptions outlined in Section 6.
- Right to Restrict or Object to Processing: Object to processing based on legitimate interests or request restrictions on specific processing activities. For online licenses, you may disable the collection and transmission of usage snapshot statistics at any time by setting the relevant parameter in your environment configuration. Disabling usage statistics does not affect platform functionality, license validity, or support entitlements, but it does not disable standard license-validation checks or the recording of connecting source IP addresses for anti-abuse and security purposes.
AI Features: AI data processing occurs only when users actively invoke AI features. Administrators can disable AI features system-wide, per tenant, or per user role; when disabled, no AI-related data is collected or sent.
- Right to Data Portability: Receive a structured, commonly used, and machine-readable copy of personal data provided under contract or consent.
- Right to Withdraw Consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: Lodge a complaint with your local Data Protection Authority (DPA) or regulatory body.
To exercise any applicable right, please submit a written request to privacy@thingsboard.io. We will respond within statutory timeframes upon verifying your identity and legal authority.
9. Amendments to This Privacy Policy
ThingsBoard reserves the right to modify or update this Privacy Policy periodically to reflect technological changes, legal requirements, or adjustments to our business practices. The updated Policy will be published on our website and Portal with a revised “Revision Date”. In the event of material structural or legal changes, registered account holders will be notified via email to the primary address associated with their Organization account prior to the effective date.
10. Contact Information
For inquiries, legal notices, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer at: privacy@thingsboard.io