Privacy Policy
Last Updated: March 24, 2026 Version: 1.1.0
Tote Llama™ LLC ("Tote Llama," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and services (collectively, the "Service").
Please read this Privacy Policy carefully. By using the Service, you consent to the data practices described in this policy.
1. Information We Collect
1.1 Information You Provide
We collect information you voluntarily provide when you:
- Create an account: Phone number
- Set up your profile: Name, email address, delivery address, delivery instructions (some profile fields are optional)
- Use our services: Tote contents (photos, descriptions, labels), pickup/delivery preferences
- Contact us: Support requests, feedback, correspondence
1.2 Information Collected Automatically
When you use our Service, we automatically collect:
- Device information: Device type, operating system, unique device identifiers
- Log data: IP address, browser type, pages viewed, access times
- Location data: Approximate location based on IP address (we do not track precise GPS location)
- Usage data: Features used, interactions with the app, session duration
1.3 Information from Third Parties
We may receive information from:
- Payment processors: Transaction confirmations, payment status (we do not store full credit card numbers)
- SMS verification providers: We use a third-party service to deliver one-time verification codes via SMS to your phone number for account authentication
- Analytics services: Aggregated usage statistics
1.4 Photo and Image Data
When you use our photo inventory feature, we collect and store images of your stored items. We use these images solely to help you organize and search your belongings.
We do not:
- Extract biometric identifiers (including facial geometry) from your photos
- Use facial recognition technology on your images
- Sell or share your images with third parties for training AI/ML models
- Use automated processing to identify individuals depicted in your photos
Images are stored securely in encrypted cloud storage and are retained for the duration of your account plus 90 days following account closure, after which they are permanently deleted.
1.5 Sensitive Personal Information
We may collect certain categories of information classified as "sensitive" under applicable law, including:
- Account credentials: Your phone number and one-time verification codes used for authentication
- Precise geolocation: Your delivery address for completing pickup and delivery services
- Contents of communications: The contents of messages you send to our support team
We use sensitive personal information only as necessary to provide our services and do not use or disclose it for purposes other than those disclosed at collection. Because we limit our use of sensitive personal information to service delivery, we do not offer a separate "Limit the Use of My Sensitive Personal Information" option.
1.6 Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information:
| Category | Examples | Collected | Source |
|---|---|---|---|
| Identifiers | Phone, name, email, address | Yes | You |
| Customer Records | Billing address, payment info | Yes | You |
| Commercial Information | Purchase history, tote inventory | Yes | You, service usage |
| Internet Activity | Device info, IP, usage data | Yes | Automatic |
| Geolocation | Delivery address, IP-based location | Yes | You, automatic |
| Sensory Data | Photos of stored items | Yes | You |
| Inferences | Preferences drawn from above | No | N/A |
2. How We Use Your Information
We use the information we collect to:
2.1 Provide Our Services
- Create and manage your account
- Process pickup and delivery requests
- Store and organize your tote inventory
- Enable search functionality across your stored items
- Process payments and billing
2.2 Communicate With You
- Send one-time verification codes via SMS for account authentication
- Send delivery and pickup status notifications via SMS (you are opted in by default and may opt out at any time—see Section 6.3)
- Send service-related notifications via in-app push notifications (delivery updates, billing)
- Respond to your inquiries and support requests
- Send promotional communications (with your express consent; we do not send marketing messages by default)
2.3 Improve Our Services
- Analyze usage patterns to improve the app
- Develop new features and services
- Troubleshoot technical issues
- Ensure quality and security of our Service
2.4 Legal and Safety
- Comply with legal obligations
- Enforce our terms of service
- Protect against fraud and abuse
- Ensure the safety of our employees and your property
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
3.1 Service Providers
We share information with third-party vendors who perform services on our behalf:
| Category of Provider | Categories of Data Shared |
|---|---|
| Payment processing | Payment card information, billing address |
| Cloud hosting and storage | All data categories |
| SMS and telephony (Twilio) | Phone number |
| Analytics services | Device info, usage data (not personally identifiable) |
| Customer support tools | Phone number, support correspondence |
These providers are contractually obligated to protect your information, use it only for specified purposes, and delete or return it upon termination of services.
3.2 Delivery Operations and Internal Access
We share necessary information with our employees and contractors to complete pickup and delivery services:
- Delivery personnel: Delivery address, delivery instructions, contact phone number
- Operations staff: Access to scheduling, tote tracking, and inventory data
- Customer support: Access to account information and correspondence as needed
All employees and contractors with access to personal data are bound by confidentiality obligations and receive privacy training. Access is limited to the minimum necessary for job functions.
3.3 Legal Requirements
We may disclose your information if required by law or if we believe such action is necessary to:
- Comply with a legal obligation
- Protect and defend our rights or property
- Prevent or investigate possible wrongdoing
- Protect the personal safety of users or the public
3.4 Business Transfers
If Tote Llama is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership.
3.5 No Sale or Sharing of Personal Information
We do not sell your personal information. We do not share your personal information with third parties for cross-context behavioral advertising. Because we do not sell or share personal information as defined under California law, we are not required to offer a "Do Not Sell or Share My Personal Information" link. If this practice changes, we will update this policy and provide the required opt-out mechanism.
4. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit and at rest
- Secure authentication mechanisms
- Access controls and employee training
- Regular security assessments
- Secure cloud infrastructure
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
4.1 Data Breach Notification
In the event of a security breach involving your personal information, we will notify you and applicable regulatory authorities in accordance with state law requirements. Oregon law requires notification in the most expedient time possible. Depending on your state of residence, you may receive notification within 30-60 days of our discovery of a qualifying breach.
Notification will be provided by postal mail to your address on file. We may also send an SMS notification to your phone number and/or an in-app notification as a supplement, but these do not replace the legally required written notice. If we do not have a postal address on file, notice will be provided by SMS to your registered phone number and any other contact method available, in accordance with substitute notice provisions under applicable law.
5. Data Retention
We retain personal information based on the following criteria:
| Category | Retention Period |
|---|---|
| Account information | Duration of account plus 90 days |
| Tote photos/inventory | Duration of account plus 90 days |
| Payment transaction records | 7 years (tax/legal compliance) |
| Support correspondence | 3 years from last interaction |
| Usage/analytics data | 2 years (aggregated/anonymized thereafter) |
| Security logs | 1 year |
When you close your account, we will delete or anonymize your personal information within 90 days, except where we are required to retain it for legal, tax, or regulatory purposes as specified above.
6. Your Rights and Choices
6.1 Access and Update
You can access and update your account information at any time through the Tote Llama app.
6.2 Delete Your Account
You may request deletion of your account by contacting us at support@totellama.com. Note that we may retain certain information as required by law or for legitimate business purposes.
6.3 Communication Preferences
SMS Delivery Notifications: When you create an account, you are opted in by default to receive delivery and pickup status notifications via SMS. You can opt out of these SMS notifications at any time by:
- Replying STOP to any notification message
- Toggling off SMS notifications in the app settings
- Contacting us at support@totellama.com
SMS Verification Codes: You cannot opt out of receiving one-time verification codes via SMS, as they are required to sign in to your account.
In-App Notifications: You may adjust in-app notification preferences through your device settings.
Promotional Communications: We do not send marketing or promotional messages by default. If you have opted in to promotional communications, you can opt out at any time by adjusting your notification settings in the app or contacting us at support@totellama.com.
6.4 State-Specific Privacy Rights
Depending on your state of residence, you may have additional privacy rights as described below.
Oregon Residents (OCPA): If you are an Oregon resident, you have the right to: (a) confirm whether we process your personal data; (b) access your personal data; (c) correct inaccuracies; (d) delete your personal data; (e) obtain a copy in a portable format; (f) opt out of targeted advertising, sales of personal data, and profiling; and (g) obtain a list of specific third parties to whom we have disclosed your personal data. Effective January 1, 2026, you may also use a browser-based opt-out preference signal.
California Residents (CCPA/CPRA): If you are a California resident, you have the right to: (a) know what personal information we collect, use, disclose, and sell; (b) request deletion of your personal information; (c) correct inaccurate personal information; (d) opt out of the sale or sharing of personal information (we do not sell or share your data); (e) limit the use of sensitive personal information (we only use it for service delivery); and (f) non-discrimination for exercising your privacy rights.
Virginia Residents (VCDPA): You have the right to access, correct, delete, obtain a copy of your data in a portable format, and opt out of targeted advertising, sales of personal data, and profiling.
Colorado Residents (CPA): You have the right to access, correct, delete, obtain portable data, and opt out of targeted advertising, sales of personal data, and profiling.
Texas Residents (TDPSA): You have the right to access, correct, delete, obtain portable data, and opt out of targeted advertising, sales of personal data, and profiling. We honor universal opt-out preference signals as required by Texas law.
Connecticut, Delaware, Iowa, Montana, Tennessee, New Hampshire, New Jersey, Maryland, Nebraska, Indiana, and Kentucky Residents: Similar rights to access, correct, delete, port data, and opt out of sales and targeted advertising apply under your state's privacy law.
To exercise any of these rights, contact us at privacy@totellama.com or support@totellama.com. We will respond within the timeframe required by applicable law (typically 30-45 days). You may designate an authorized agent to make a request on your behalf.
6.5 Opt-Out Preference Signals
We honor browser-based opt-out preference signals, including Global Privacy Control (GPC), as required by applicable state law. If you have enabled GPC or a similar mechanism in your browser, we will treat this as a valid opt-out request for the sale or sharing of personal information and targeted advertising.
7. Children's Privacy
Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn we have collected information from a child under 18, we will delete that information promptly.
8. Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.
9. International Users
Our Service is operated in the United States. If you access our Service from outside the United States, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the new Privacy Policy on our website
- Sending you an SMS notification, in-app notification, or email (if on file)
- Displaying a notice in the app
Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
Tote Llama LLC Eugene, Oregon
General inquiries: support@totellama.com Privacy-specific requests: privacy@totellama.com
For data-related requests, please allow up to 30 days for us to respond (or longer if permitted by applicable state law). We may need to verify your identity before processing certain requests.
12. Cookies and Tracking Technologies
12.1 Cookies We Use
We use cookies solely for authentication purposes. When you sign in to your account, we set the following cookies:
- Authentication tokens: Secure, HTTP-only cookies that maintain your authenticated session
- Login status indicator: A non-sensitive marker cookie that enables proper routing within our application infrastructure
These cookies are strictly necessary for the Service to function and cannot be disabled while using the Service. We do not use cookies for analytics, advertising, or to store user preferences.
12.2 Analytics
We use privacy-focused, cookie-less analytics to understand how our Service is used and to improve it. Our analytics technology does not place cookies on your device. Instead, it uses privacy-preserving techniques that:
- Do not store personally identifiable information
- Do not track you across other websites
- Comply with GDPR and CCPA requirements without requiring a cookie consent banner
For visitors in the EU/UK, IP addresses are further anonymized.
12.3 Your Choices
Because we use only strictly necessary authentication cookies and cookie-less analytics, we do not display a cookie consent banner. You may clear your authentication cookies through your browser settings or by signing out of the Service; however, doing so will require you to sign in again to access your account.
By using Tote Llama, you acknowledge that you have read and understood this Privacy Policy.