Privacy Policy

Privacy Policy

Effective Date: May 1, 2020
Last Updated: February 11, 2025

Introduction

This Privacy Policy explains how Todspot LLC (“Todspot,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you visit or use our website (www.todspot.com, the “Site”) and related services​. By using our Site, you agree to the practices described in this Privacy Policy. We are based in the United States, and our services are intended for users worldwide, including in the EU and UK, with compliance to applicable privacy laws.

Information We Collect

Personal Identifiable Information (PII): We collect PII that you voluntarily provide to us, including:

  • Contact Details: Your name, email address, phone number, and billing/shipping address​
    Account Credentials: If you create an account, a username and password​
    Payment Information: Payment details (e.g. credit card number or PayPal account) for purchases. Payments are processed securely via third-party processors like Stripe or PayPal; we do not store full payment card details ourselves​

  • Communications: Information you provide in correspondence with us, such as when you contact customer support or submit inquiries (which may include email content or chat messages)​

  • Survey and Contest Data: If you participate in our surveys, promotions, or contests, we collect any data you submit related to those activities​

Non-Personal Identifiable Information (Non-PII): When you interact with our Site, we automatically collect certain technical and usage data through cookies and similar technologies​. 

This includes:

  • Device and Browser Information: IP address, browser type, operating system, device identifiers, and device type​

  • Usage Data: Information about how you use our Site, such as the pages or screens you view, the dates/times of visits, the time spent on each page, clickstream data, and the website or advertisement that referred you to our Site​

  • Cookies and Tracking: We use cookies and similar tracking technologies to collect and store information when you use our Site. See the Cookies & Tracking Technologies section below for details.

We may also obtain information from third-party sources (such as social media platforms if you engage with our pages) in accordance with their terms and your settings on those services. Any data we collect from third-party sources will be handled according to this Privacy Policy and applicable laws.

How We Use Your Information

We use your personal information only for legitimate and lawful purposes​. The ways we use information include:

  • Providing and Improving Services: To create and manage your account, process your orders or bookings, deliver services or digital content you’ve purchased, and improve our offerings​. For example, we may use your information to personalize your experience or to develop new features based on how you use our Site.

  • Customer Support: To respond to your inquiries, provide technical support, and address any issues or complaints you raise​

  • Communications and Updates: To send you administrative information (such as confirmations, invoices, technical notices, updates, security alerts) and, with your consent, to send you marketing or promotional communications. This may include newsletters or special offers; you can opt out of marketing at any time

  • Security and Fraud Prevention: To protect our business, services, and users by monitoring for suspicious or fraudulent activity and enforcing our Terms & Conditions​

  • Legal Compliance: To comply with legal obligations, such as tax and accounting requirements, and to respond to lawful requests by public authorities (including to meet national security or law enforcement requirements)​

We do not sell your personal information to third parties​. We also do not use your personal data for third-party advertising purposes. Any usage of your data is limited to the purposes described above or as otherwise disclosed to you with your consent.

Lawful Bases for Processing (GDPR): If you are located in the European Economic Area (EEA) or United Kingdom, we only process your personal data when we have a valid legal basis. Under the EU/UK General Data Protection Regulation (GDPR), the lawful bases we rely on include: (a) your consent (for example, when you sign up for marketing emails or provide us with health-related information, we will ask for your explicit consent as required for sensitive data​.); (b) performance of a contract (to provide you with the services and products you requested, such as fulfilling a purchase or providing a consultation); (c) legal obligation (to comply with applicable laws and regulations); (d) legitimate interests (to improve our services, secure our platform, and communicate with you as necessary for our business — we will always consider your rights and interests before doing so). In rare cases, we may process data to protect vital interests (e.g., in an emergency) or for tasks in the public interest, but our typical bases are the ones listed above​. Where processing is based on consent, you have the right to withdraw your consent at any time (see “Your Rights” below).

Sharing Your Information

We respect your privacy and handle your personal data carefully. We do not sell, trade, or rent your PII to third parties​. We only share your information in the following circumstances:

  • Service Providers: We may share necessary information with trusted third-party service providers who perform functions on our behalf, such as payment processing (e.g., Stripe, PayPal), e-commerce platform and website hosting (e.g., Kajabi or similar platforms), email newsletter distribution, scheduling services, or analytics providers​. These parties are given access only to the information needed to perform their specific services, and they are contractually obligated to protect your data and use it only for our instructed purposes​

  • Affiliates and Subsidiaries: We may share information with our affiliated businesses or subsidiaries (if any) for internal business operations. Any such affiliate will also uphold this Privacy Policy or similarly protective practices​

  • Legal Requirements and Protection: We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to (i) comply with a legal obligation, regulatory requirement, or judicial process, (ii) protect and defend our rights or property, (iii) prevent fraud or investigate suspected illegal activity on our Site, (iv) protect the personal safety of users or the public, or (v) enforce our Terms & Conditions or other agreements​

We do not share your personal information with third parties for their own marketing or advertising purposes. In the event we ever need to share data for any new purpose not covered above, we will update this Privacy Policy and, if required by law, seek your consent.

Your Rights and Choices

You have rights regarding your personal information and choices about how we use it:

  • Access and Correction: You may request access to the personal information we hold about you and ask that we correct or update any inaccuracies​.Most of your basic account information can be reviewed and edited by you directly by logging into your account. For other data, please contact us (see “Contact Information” below) to request access or correction.

  • Deletion (Right to Erasure): You can request that we delete your personal data. If you have an account, you may request account deletion by contacting us at our support email​. We will honor deletion requests to the extent we are legally permitted to do so; note that we may retain certain information as required by law or for legitimate business purposes (e.g., record-keeping).

  • Opt-Out of Marketing: If you no longer wish to receive marketing or promotional communications, you may opt out at any time. You can unsubscribe by clicking the “unsubscribe” link in any promotional email, or by contacting us to be removed from our mailing list​. Even if you opt out of marketing, we may still send you transactional or administrative emails related to services you have requested (such as purchase confirmations or important account notices).

  • Withdraw Consent: If we are processing your information based on your consent, you have the right to withdraw that consent at any time. For example, if you consented to receive newsletters or to share health-related information, you can withdraw your consent and we will stop that specific processing as required by law. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

  • Object to Processing: In certain situations, you have the right to object to our processing of your personal data, particularly regarding processing for direct marketing or when we process data based on legitimate interests. If you object, we will evaluate the request and stop or limit processing unless we have compelling legitimate grounds to continue or as otherwise permitted by law.

  • Restrict Processing: You have the right to request that we restrict the processing of your personal information (for instance, while we verify or investigate your concerns about data accuracy or our reasons for processing your data).

  • Data Portability: To the extent applicable, you have the right to request a copy of the personal data you have provided to us in a structured, commonly used, machine-readable format, and you can request that we transmit that data to another data controller where technically feasible.

  • Lodge a Complaint: If you are in the EU/UK and believe we have infringed your privacy rights, you have the right to lodge a complaint with your national Data Protection Authority or supervisory authority. For example, UK residents can contact the Information Commissioner’s Office (ICO), and EU residents can contact the supervisory authority in the country where you live or work. We would, however, appreciate the chance to address your concerns directly before you do this – please see our Contact Information below to reach out with any questions or issues.

To exercise any of your rights, please contact us using the information in the Contact section. For your security and to prevent fraud, we may take steps to verify your identity before fulfilling your request. We will respond to your request within the time frame required by applicable law (generally within one month for GDPR-related requests, with the possibility of extension if the request is complex). There is no fee for making a request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse the request.

Cookies & Tracking Technologies

Cookies are small text files placed on your device to store data that can be recalled by a web server in the domain that placed the cookie. We use cookies and similar tracking technologies to collect Non-PII information as described above​.Specifically, our use of cookies and tracking tech helps us to:

  • Ensure Site Functionality: Some cookies are essential for our Site to operate properly (for example, to keep you logged in or to remember items in your shopping cart). These are often called “strictly necessary” cookies.

  • Improve User Experience: We use cookies to remember your preferences and settings, so you don’t have to re-enter them each time, and to provide enhanced features when you return to our Site​. For instance, cookies may remember your language preference or region.

  • Analytics: We use analytics providers (such as Google Analytics) that set cookies to collect information about Site usage and performance. This helps us understand how visitors navigate our Site, which pages are popular, or if there are error messages on certain pages​. We use this data to improve the content and overall experience of our Site.

  • Personalized Content: We may use cookies to tailor certain Site content based on your interactions, such as showing you content that is more relevant to topics you’ve shown interest in​. (Note: We do not use cookies for third-party advertising or tracking across different websites for ad targeting purposes.)

Your Choices: By using our Site, you consent to our use of cookies as described. However, you have options to control or limit how cookies are used on your device. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. You may also delete cookies that have already been set. Please be aware that if you disable or delete cookies, some parts of our Site might not function properly for you (for example, you might not be able to log in or use certain interactive features).

Cookie Consent (EU/UK Users): If you are visiting our Site from the EU or UK, you may see a cookie consent banner or notice when you first visit. Even if our full cookie consent management tool is not yet implemented, we strive to follow best practices by only using non-essential cookies (like analytics) with your consent. You can withdraw consent for analytics cookies at any time by adjusting your browser settings or using opt-out mechanisms provided by the analytics provider. We will continue to monitor regulatory guidance and implement a comprehensive cookie consent solution to ensure compliance with EU/UK laws.

For more information on cookies and how to manage them, you can visit resources like aboutcookies.org.

Data Security

We employ a variety of technical and organizational measures to protect your personal information and keep it secure​. These measures include:

  • Encryption: We use Secure Sockets Layer (SSL) / Transport Layer Security (TLS) technology to encrypt data transmitted between your device and our Site. This is designed to prevent unauthorized parties from viewing any personal information you provide us during transmission (such as login credentials or payment information)​.

  • Restricted Access: Access to personal data is limited to authorized Todspot personnel and service providers who have a legitimate need to know in order to perform their job duties. All such persons are subject to confidentiality obligations​.

  • Secure Storage: We store personal data on secure servers. We maintain appropriate physical, technical, and administrative safeguards to protect data against loss, misuse, unauthorized access or disclosure, alteration, and destruction.

  • Breach Notification: While we strive to protect your information, no method of transmission over the internet or method of electronic storage is 100% secure​. In the event of a data breach that affects your personal information, we will notify you and the relevant authorities as required by law​. We have a data breach response plan in place to quickly address and mitigate any incidents.

Please understand that you share information at your own risk; we cannot guarantee absolute security of information, especially information transmitted via the internet. You are responsible for maintaining the secrecy of your account credentials and for any activities conducted through your account. We encourage you to use a strong, unique password for our Site and to log out of your account when you have finished using it.

Data Retention

We will retain your personal information only for as long as necessary to fulfill the purposes we collected it for, including for the purposes of providing services to you, satisfying any legal, accounting, or reporting requirements, and enforcing our agreements. For example, we may retain your profile information and purchase history for as long as your account is active and a reasonable period thereafter in case you decide to return to our services. We may also retain certain data for longer periods if necessary to comply with laws (such as maintaining transaction records for tax/regulatory compliance) or to resolve disputes.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it. If deletion or anonymization is not immediately feasible (for example, because the data is stored in backup archives), we will securely store the data and isolate it from further processing until deletion is possible.

Children’s Privacy

We do not knowingly collect or solicit personal information from children under the age of 13. Our Site and services are directed to parents and caregivers, not to children. In compliance with the U.S. Children’s Online Privacy Protection Act (COPPA), if we learn that we have inadvertently collected personal data from a child under 13, we will promptly delete that information from our records​. If you believe that we might have any information from or about a child under 13, please contact us so that we can take appropriate action.

For teens between 13 and 18, our services are intended to be used with the involvement of a parent or guardian. If you are under 18, you should obtain your parent or guardian’s permission before providing any personal information on our Site.

If you are a parent or guardian in the EU/UK, please note that the age of consent for data processing may be higher (for example, 16 in some countries). We do not knowingly offer services to children under the age of consent in applicable jurisdictions without appropriate parental consent. Parents have the right to request the removal of personal data collected from their children – to do so, contact us at our support email​.

International Data Transfers

Todspot LLC is based in the United States. If you are located outside of the U.S. (for example, in the European Union, United Kingdom, or elsewhere), any information you provide to us will be transferred to and processed in the United States and possibly other jurisdictions. The data privacy laws in these countries may be different from, and less protective than, the laws in your country of residence.

However, we take steps to ensure that your privacy is protected in line with this Policy wherever your data is processed. In particular, for personal data collected from individuals in the EEA/UK, any transfer of such data to third parties or servers in countries not deemed “adequate” by the European Commission will be governed by appropriate safeguards. These may include entering into the European Commission’s Standard Contractual Clauses (SCCs) with the data importer, which are designed to ensure that your personal data receives a consistent level of protection​. We will also implement any additional measures required by applicable law for international data transfers.

By using our Site or providing us with information, you acknowledge the transfer of your personal data to the United States and other jurisdictions as described in this Policy. Where required by law, we will obtain your explicit consent for such transfers. If you have questions about our international data transfers or need more information about the safeguards in place, please contact us.

Automated Decision-Making

We may use automated decision-making or profiling in limited ways to enhance your user experience. For instance, we might use algorithms to recommend content or courses that could be of interest to you based on your browsing or purchase history. Any such processing will not have legal or similarly significant effects on you; it is solely aimed at providing a more personalized experience.

If you are an EU/UK resident and we ever engage in automated decision-making that produces legal effects or similarly significantly affects you (as defined by GDPR Article 22), we will ensure we have your consent or that it is necessary for the performance of a contract, and we will provide you with an opportunity to request human intervention, express your point of view, and contest the decision​. Currently, our use of any AI or automated tools is only to support and improve our services (for example, analyzing common user questions to better direct you to resources) and not to make impactful decisions about individuals without human review. If this policy changes, we will update you and this Privacy Policy accordingly.

Changes to This Policy

We may update or revise this Privacy Policy from time to time. If we make material changes, we will post the updated Policy on this page with a new effective date, and we may notify you by email or by means of a prominent notice on our Site prior to the change becoming effective, if required by law​. We encourage you to review this Policy periodically for any updates. Your continued use of the Site after any changes to this Privacy Policy signifies your acceptance of those changes.

Contact Information

Todspot LLC is the controller responsible for your personal information. If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us:

  • Company Name: Todspot LLC

  • Email: arianne@todspot.com (for general privacy inquiries or to exercise your rights)​

  • Data Protection Officer (for EU/UK inquiries): You may contact our data protection contact at the same email above, Attn: Data Protection – we will address GDPR-related queries or concerns.

  • Mailing Address: 2000 Island Boulevard, Apt 2210, Aventura, FL 33160, USA (Todspot LLC’s registered address)

We will respond to your inquiries as soon as reasonably possible, and within any timeframes required by law. If contacting us by mail, please include attention to “Privacy Officer” or “Legal Department” so we can direct your correspondence appropriately.