Toast Ninja Inc.
Last reviewed: June 2026
Contact: support@toast.ninja
Toast is a GitHub and Slack integration that delivers pull request notifications and team activity summaries to Slack. It listens to GitHub webhook events, processes metadata about pull request activity, and sends formatted messages to Slack channels and users.
Toast does not provide code hosting, code execution, file storage, or any service that requires access to the contents of your repositories.
When you install Toast, you authorize it through GitHub's and Slack's standard OAuth flows. Through those authorizations, Toast accesses:
This access model is intentional and architectural. Because Toast operates on metadata rather than content, a compromise of Toast's systems would not expose your source code, your intellectual property, or sensitive information that might be present in code or issue descriptions.
Toast's production infrastructure runs entirely on cloud services operated by established, compliance-certified providers. Toast does not operate any physical servers, data centers, or networking equipment.
| Component | Provider | Location | Provider Compliance |
|---|---|---|---|
| Application hosting | Heroku (Salesforce) | US (AWS us-east-1) | SOC 2 Type II, ISO 27001 |
| PostgreSQL database | Heroku Postgres | US (AWS us-east-1) | Covered by Heroku SOC 2 |
| Message queue | CloudAMQP | US | SOC 2 Type II |
| Cache (Redis) | Redis Cloud | US | SOC 2 Type II |
| Error monitoring | Sentry | US | SOC 2 Type II |
| Payment processing | Stripe | US | PCI DSS Level 1 |
All production data is stored and processed in the United States.
User authentication is handled entirely through OAuth 2.0 via GitHub and Slack. Toast does not implement its own username and password system and does not store user passwords.
GitHub App installation grants scoped, revocable API access. Customers can revoke Toast's access at any time from GitHub's organization settings, which immediately terminates all API access. Slack App installation uses OAuth 2.0 workspace authorization and can similarly be revoked at any time.
All inbound webhooks from GitHub and Slack are verified using HMAC signature validation before processing. Stripe webhook payloads are verified using Stripe's webhook signature scheme.
Toast uses the following third-party subprocessors that may process customer personal data as part of delivering the service:
| Subprocessor | Service | Location |
|---|---|---|
| Heroku (Salesforce, Inc.) | Application hosting and managed PostgreSQL | US |
| CloudAMQP (84codes AB) | Managed message queue | US |
| Redis Cloud (Redis Ltd.) | Managed cache | US |
| Sentry (Functional Software, Inc.) | Error monitoring and performance tracking | US |
| Stripe, Inc. | Payment processing (billing data only) | US |
We will notify customers of material changes to this subprocessor list with reasonable advance notice. A Data Processing Addendum (DPA) is available on request at support@toast.ninja.
Toast commits to notifying affected customers within 72 hours of becoming aware of a confirmed incident involving unauthorized access to personal data, consistent with GDPR Article 33 obligations. Notification will include the nature of the incident, the categories and approximate volume of data affected, and the measures taken to address it.
To report a suspected security vulnerability or incident, contact: support@toast.ninja
Toast's service continuity relies on the redundancy and backup capabilities of its infrastructure providers. Heroku Postgres provides continuous WAL archiving and point-in-time recovery, with daily backups retained automatically. The application can be redeployed from source within approximately 30 minutes.
Recovery Time Objective (RTO): 4 hours (best effort).
Recovery Point Objective (RPO): 24 hours, or shorter with point-in-time recovery.
No. The GitHub App permissions Toast requests explicitly exclude repository contents. We receive pull request metadata (titles, states, reviewer assignments) but not diffs, file contents, or any repository content. This is enforced at the GitHub API permission level, not just by policy.
| Permission | Why |
|---|---|
| Pull requests (read) | To receive PR events and read PR metadata |
| Members (read) | To map GitHub users to Slack users within your org |
| Metadata (read) | Required by GitHub for all App installations |
| Statuses / Checks (read) | To report CI check states on PRs |
| Emails (read) | To match GitHub accounts to Slack accounts |
Toast does not request: contents (code), administration, secrets, or any write permission to your repositories.
| Permission | Why |
|---|---|
| chat:write | To send PR notification messages |
| users:read | To look up Slack users by email for notification routing |
| channels:read | To let you select which channel receives notifications |
| commands | To support /toast slash commands |
Toast does not request access to read message history, access private conversations, or any administrative Slack permissions.
A small number of Toast personnel with authorized access to the production environment can access account data for support and operational purposes. We do not access customer data unless required to resolve a support issue, and we do not sell or share data with third parties for advertising or analytics purposes.
When you uninstall the Toast GitHub App or Slack App, we stop receiving new data immediately. On request, we will delete your organization's data from our database. Contact support@toast.ninja to request deletion.
No. Toast does not sell, rent, or share customer data with third parties for advertising, marketing, or any commercial purpose unrelated to delivering the Toast service.
Toast processes personal data (names, usernames, email addresses) on behalf of customers who may be subject to GDPR. We offer a Data Processing Addendum (DPA) that governs our obligations as a data processor. Contact support@toast.ninja to request a DPA.
No security incidents involving unauthorized access to customer data have occurred.
Yes. Contact support@toast.ninja for a signed PDF version or to request our Data Processing Addendum.