Legal

Website & Commerce Privacy Policy

Effective September 5, 2026

Website visits, hardware orders, advertising, email and customer support.

1. Overview

The Tokenry, Inc. (“The Tokenry,” “we,” “us”) operates myotto.ai and sells Otto hardware. This policy explains how we handle information when you visit our marketing and checkout website, join a mailing list, place a hardware order, or contact us about an order or privacy request.

The Otto App & Device Privacy Policy covers the Otto apps, Otto OS, accounts, AI requests, AI-credit billing and connected services. Website and order analytics operate separately: the account-wide analytics switch in the Otto app does not control this website or its order analytics.

2. Information We Collect and Use

Information you provide

  • Contact and order details — name, email, billing and shipping addresses, and any phone number, business details, delivery instructions or other notes you provide. We use these to manage reservations, purchases, wholesale orders, delivery and customer communications.
  • Payment information — payment card details are collected by Stripe. Section 3 explains the payment references and limited card information we receive.
  • Support and privacy requests — your contact details, messages, attachments you choose to provide, the scope of a data request and records of how we handle it. These are used to respond and document the request.

Information generated when you use the website

We process order and payment history, product quantities, prices, discounts, taxes, shipment references and technical records needed to operate the website. Our analytics and advertising tools collect page visits, interactions, campaign information and performance measurements as described in Section 4. Our servers and service providers receive ordinary connection information, including IP addresses, request times and browser or device information.

How we use information

We use information to fulfill orders, process payments and refunds, arrange delivery, secure and troubleshoot the website, provide support, measure website use and advertising, run feature experiments, send communications, handle privacy requests, and meet accounting and legal obligations.

3. Payment Processing

We use Stripe to process hardware payments. A reservation may collect a refundable deposit, save a payment method or collect full payment, depending on the checkout option. Applicable amounts, later balance charges, shipping fees and other payment terms are shown at checkout and in your order terms.

  • Your full card number and security code are transmitted directly to Stripe and are never sent to or stored on our servers.
  • We store Stripe-issued identifiers, payment status and amounts, and limited payment-method details such as card brand, last four digits and expiry date.
  • Stripe processes the contact, billing and shipping information supplied during checkout or payment updates. We share delivery details with our fulfillment providers and carriers when arranging shipment.

Stripe’s handling of information is described in its privacy policy.

4. Website Analytics, Advertising and Cookies

PostHog website and order analytics

We use PostHog to understand website visits, interactions, checkout progress, feature experiments and the order lifecycle. Website analytics can include visited URLs and referrers, campaign parameters, browser and device details, timestamps, clicks and other interactions, and persistent visitor and session identifiers stored in cookies or local storage. Recordings of website page content and interactions may also be collected when enabled in our PostHog project.

Website PostHog requests pass through our website domain before being forwarded to PostHog. Using our domain for delivery does not make those events anonymous or prevent PostHog from receiving their contents.

When you provide an email through our waitlist or checkout flow, we can associate website activity with that email. Order analytics sent from our servers can include your email, shipping name and full shipping address, order and payment references, purchased products and quantities, order status, exact payment and refund amounts, timestamps and information about the actions taken on an order. These records can be linked to you and are separate from the restricted app and runtime analytics described in the Otto App & Device Privacy Policy.

Advertising tags and conversion measurement

We use advertising tags from Google Ads, Meta (Facebook and Instagram), TikTok and Lapis (for ChatGPT advertising) to measure visits and advertising conversions. Depending on the tag and action, events include page visits, checkout starts, leads or orders, along with purchase value and currency. Google Ads and Lapis conversion events can also include an order or transaction identifier. The tags receive browser and network information, and may use cookies or similar identifiers to associate visits with advertising.

The Lapis script is requested when a page loads; its advertising attribution is activated by supported campaign information in the landing URL. Lapis reports advertising results onward to OpenAI. The relevant providers describe their practices at Google, Meta, TikTok and OpenAI.

Vercel traffic and performance measurements

Our website uses Vercel for hosting, Web Analytics and Speed Insights. These services process web requests, traffic and page information, browser and device characteristics, and performance measurements such as loading and interaction times. See Vercel’s analytics privacy information.

Cookies, local storage and campaign parameters

We use cookies and browser storage for website access, remembering checkout information, analytics identifiers and feature experiments. Checkout may save an email locally and partially completed delivery details in our order records so you can continue later. Advertising links may contain campaign parameters such as utm_source, utm_medium and utm_campaign; analytics and advertising tools can associate these with visits, interactions and conversions.

You can use browser settings or blocking tools to restrict cookies, local storage and requests, and use the advertising providers’ settings to manage their advertising preferences. Blocking third-party domains alone may not block analytics delivered through our website domain, and browser blocking does not stop order events sent by our servers. The Otto app analytics switch does not control website or order analytics. For access, objection or deletion requests concerning these records, use Section 9.

5. Email Communications

We use Loops for marketing and subscriber communications. It receives email addresses and related subscription, source, purchase-status and purchase-date information. We use Resend for transactional messages, including order confirmations, payment notices, order-access links and privacy-request verification. It receives recipients and the contents of those messages, which can include order details, amounts and access or confirmation links.

Marketing emails include an unsubscribe link. Unsubscribing stops marketing delivery; it does not prevent necessary transactional messages or itself delete order records. You can request deletion of your information through Section 9.

6. Data Storage

Website order and privacy-request records are stored in PostgreSQL hosted by Neon. Hosting, databases, operational logs and backups process the contact, order and service information described in this policy. Our providers may process information in the United States and other countries where they operate.

Public connections to our services use HTTPS/TLS. We use access controls to restrict administrative access and do not store full payment card numbers or security codes. No storage or transmission method can provide an absolute guarantee of security.

7. Service Providers and Recipients

These providers and recipients process information for the purposes below. Which recipients receive information depends on the website features and purchase options you use. Their own terms and privacy notices also describe how they handle information.

Stripe

Purpose: Payments and billing

Data shared: Payment details supplied to Stripe; contact, billing and shipping details; transaction and limited payment-method information.

PostHog

Purpose: Website analytics, experiments and order analysis

Data shared: Visitor/session identifiers, interactions and technical metadata; email, shipping name/address, order and payment references, products, status and amounts. Page recordings when enabled (Section 4).

Google Ads, Meta and TikTok

Purpose: Website advertising measurement

Data shared: Visits and conversion events, campaign/browser/network identifiers, value and currency; Google Ads also receives transaction identifiers.

Lapis / OpenAI

Purpose: ChatGPT advertising measurement

Data shared: Visits, campaigns, order/conversion identifiers, value and currency, and browser/network metadata.

Vercel

Purpose: Website hosting, traffic and performance measurement

Data shared: Web requests, page/traffic information, browser/device characteristics and performance measurements.

Loops

Purpose: Marketing communications

Data shared: Email address, subscription/source, purchase-status and purchase-date information.

Resend

Purpose: Transactional email

Data shared: Recipient addresses and message contents, including order details and access or confirmation links.

Neon

Purpose: Website database hosting

Data shared: Order, contact, delivery, payment-reference and privacy-request records.

Shopify, fulfillment partners and carriers

Purpose: Order fulfillment and delivery

Data shared: Recipient name and address, order/product/quantity/value details, shipment information and a supplied shipping phone number where applicable.

17TRACK

Purpose: Shipment tracking

Data shared: Tracking number, order/shipment references, ship date, destination postal code and carrier information.

Support service providers

Purpose: Customer support and privacy requests

Data shared: Support messages and submitted material, contact and order references, and records used to respond to and document requests.

8. Data Retention and Deletion

We retain order data to fulfill orders, process refunds, resolve disputes and comply with accounting and legal obligations. Our order and mailing-list retention commitments are:

  • Cancelled reservations — data is deleted within 90 days of cancellation.
  • Completed orders — data is retained for up to 7 years for accounting and legal compliance, then deleted.
  • Email subscribers — you can unsubscribe at any time. Upon request, we will delete your email from our marketing lists within 30 days.

We retain records needed to document support, privacy requests and their handling. Removing records from active systems does not immediately remove copies from backups or operational logs. Analytics and other provider records can have different retention periods. Blocking future browser collection or unsubscribing from email does not erase information already collected.

Deleting an Otto app account does not automatically erase separate website orders, website analytics or Stripe payment records. You can request access to or deletion of those records through Section 9. Account and device deletion is described in the Otto App & Device Privacy Policy.

9. Your Rights and Choices

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Data portability
  • Withdraw consent where processing relies on consent
  • Complain to the data protection authority where you live or work

The fastest way to exercise these rights is our data request form. Tell us what you want handled; we email that address a confirmation link, and a person replies. You can also contact us at the address below. Either way, we will respond within 30 days.

You can unsubscribe from marketing emails and use the browser and advertising controls in Section 4. We may need to verify your identity before handling a data request. Some records must be retained for legal or security reasons; we will explain applicable limitations when responding to your request.

10. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our website. The effective date at the top of this page indicates when the policy was last revised.

11. Contact

If you have questions about this policy or wish to exercise your data rights, contact us at:

The Tokenry, Inc.
1115 West Bay Drive Northwest, Ste 302
Olympia, WA 98502
support@myotto.ai

© 2026 | The Tokenry, Inc.