This Privacy Policy explains how Totesi Inc., a Kansas corporation (“Totesi,” “we,” “us,” or “our”), collects, uses, discloses, and retains information through totesi.com, Totesi applications, store “picker” devices, customer support, and related marketplace, pickup, delivery, catalogue, and hosting services (the “Services”).
Contact: privacy@totesi.com · 4601 E. Douglas Ave. STE 150 WICHITA, KS 67218
Totesi operates a technology marketplace. Participating grocery stores sell and fulfill products. For an order, the Store receives the information needed to accept, pick, pack, support, and hand off the order. Each Store is an independent business responsible for its own collection and use of information outside Totesi and for any use beyond Totesi’s instructions or the customer’s request.
We do not disclose your information to a Store merely because you browsed it. A Store receives order-related information when you order from that Store or deliberately communicate with it.
We may collect:
We may collect:
During Store onboarding and catalogue maintenance, we generally capture photographs of each product’s front, back, nutrition panel, and ingredients panel. We may also collect product codes, brand, name, size, package information, category, price, availability, and Store-provided corrections.
We create a cropped copy of an ingredients photograph to improve readability. Our operating rule is to crop to the detected panel, not into it. We validate the crop against detected text boundaries and retain the uncropped original. Although product images are intended to show packaging rather than people, an image may incidentally capture a person, badge, document, or other personal information; personnel should avoid that, and we may remove or redact incidental content.
We use information to:
We may maintain identified operational records about complaints, suspected fraud, repeated fulfillment failures, unsafe products, poor-quality vendors, and policy violations. Those records are used for operations and safety, not placed into an AI-training dataset with direct identifiers.
Each Store is the merchant of record and uses a Stripe connected account. Card details are entered into a Stripe-hosted or Stripe-controlled payment component and transmitted to Stripe. Stripe returns limited payment and transaction information to Totesi and the Store.
Totesi may create or manage a charge, authorization, capture, refund, application fee, or dispute workflow on the Store’s connected account as permitted by the Store agreement and Stripe configuration. Stripe’s own privacy notice and connected-account terms also apply to its handling of information.
We disclose information only as reasonably needed for the purposes described here:
We may replace a provider without obtaining each user’s approval. We will update this Policy or our sub processor page and provide notice of a material change where appropriate.
We do not sell personal information, rent customer lists, or share personal information for cross-context behavioral advertising. We do not allow a provider to train its own model on Totesi, Store, customer, or order information without a separate written authorization from Totesi.
We use vision models to extract structured product information from catalogue photographs. Extracted information may include brand, product name, package size, barcode, nutrition information, ingredients, allergen statements, and visible label text. We store the structured output internally for catalogue matching, duplicate detection, search, and substitution ranking. We display photographs to customers; we do not display extracted ingredient or allergen text as a separate Totesi claim.
Automated extraction can be wrong or become outdated when packaging changes. It is not used as a verified allergen certification. Our current product policy prohibits using extracted ingredient or allergen data to make an allergy-safe or dietary-safe recommendation unless Totesi launches a separately validated feature with appropriate review, controls, and disclosures.
Messages may be processed by an automated translation provider so a customer and Store can communicate. Where the feature is available, the interface identifies translated text and permits access to the original. Translation can contain errors and should not be used for emergency, medical, or legally significant instructions.
We do not use automated processing to make decisions that produce legal or similarly significant effects about customers or Store personnel. Fraud and quality signals may assist a human or rule-based review of account restrictions, disputes, or Store participation.
When a customer or Store accepts the applicable agreement, the account’s setting authorizes Totesi by default to use eligible de-identified information for Totesi’s own AI model development and improvement. The account holder may opt out at any time in Settings.
Eligible information may include de-identified product popularity, category relationships, catalogue-matching results, average order and fulfillment timing, delivery timing, substitution outcomes, inventory-pattern signals, and non-price product data.
The following are not eligible for AI training under this default authorization: names, email addresses, telephone numbers, physical addresses, private message content, Store/vendor names, staff identities, Store-identified prices, contact lists, credentials, or direct account identifiers. Store-specific prices remain isolated from cross-Store model improvement.
For this purpose, “de-identified” means Totesi has removed direct identifiers, taken reasonable measures intended to prevent association with a person or Store, committed not to reidentify the information except to test those protections, and required recipients to follow equivalent restrictions.
An opt-out applies prospectively after it is processed. It stops new eligible information from being added to future training datasets. It does not require unwinding a completed training run or removing information from a de-identified dataset or trained model where the contribution cannot reasonably be isolated. The opt-out persists through renewals and later Terms or Policy updates unless the account holder changes it.
We will not obtain broader AI-training rights through a unilateral change to this Policy. A material expansion requires a separate, specific written or electronic agreement.
Totesi owns its training datasets, catalogue intelligence, model inputs and outputs, fine-tuned artifacts, evaluation results, and improvements, subject to third-party rights in source materials and pre-existing models. Vaxen Labs Inc. may perform development as Totesi’s contractor but may use the information only for Totesi and must assign Totesi-specific work product to Totesi.
Totesi currently uses Together AI for product-image vision processing under a zero-data-retention (“ZDR”) arrangement. Totesi’s production account and endpoints must remain configured so submitted images, prompts, and outputs are processed only to provide the requested inference and are not retained for model training or secondary use.
Because ZDR is configuration- and account-dependent, Totesi will verify that production credentials and each model endpoint remain covered before use. If Totesi changes to a provider or configuration with materially different retention or training terms, Totesi will assess the change and update this Policy before sending covered information.
We may use essential cookies or local storage for login, cart state, security, preferences, and service operation. We may use limited analytics to understand performance and feature use. We do not use third-party advertising cookies or cross-context behavioral advertising. Where law requires, we will request consent before placing a nonessential cookie.
We retain information for the shortest period reasonably consistent with service, safety, accounting, dispute, and legal needs. Our current targets are:
Deletion may be delayed in backups, but backup information is protected and not restored for ordinary use. A legal hold, fraud investigation, safety event, tax obligation, or dispute may extend a period.
Subject to verification and legal exceptions, you may request access, correction, deletion, or a portable copy of personal information associated with your account. You may also:
Send requests to privacy@totesi.com . We aim to respond within 30 days. We may retain transaction, fraud, safety, consent, dispute, tax, and legal records after account deletion. A request to delete Totesi’s copy does not require an independent Store to delete information it lawfully maintains.
The Store controls employment decisions and determines which personnel may use its account. Totesi owns Platform software, logs, and de-identified or aggregated operational intelligence. The Store may access identifiable fulfillment reports about its own personnel for its legitimate business use. Totesi does not disclose an individual worker’s performance to competing Stores or customers.
The Store is solely responsible for notices to its workers and for lawful use of reports in employment decisions. Totesi may use identified staff records for security, support, quality, fraud, and contract enforcement, but staff identities are not eligible for AI training.
We maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information and Totesi’s size. These include access controls, protected credentials, encryption where appropriate, logging, backups, vendor review, and device-management controls. We do not claim SOC 2 certification unless and until obtained.
No system is perfectly secure. If an incident occurs, we will investigate and provide notices required by applicable law. Kansas and Missouri breach-notification duties generally turn on the affected person’s residence and the information involved, so timing and recipients may differ.
Store personnel must promptly report a lost picker device, suspected account compromise, misdirected customer information, or other security concern to support@totesi.com .
Transactional messages may include order status, substitutions, security codes, pickup, delivery, and support. Marketing messages require a separate marketing choice. Message frequency varies; message and data rates may apply. Reply STOP to stop a text program and HELP for help. Opting out of texts may limit real-time order communication but does not cancel an existing order.
We retain the consent screen, telephone number, time, source, and opt-out record as reasonably needed to prove compliance. The exact enrollment language and messaging campaign must be reviewed before launch.
The Services are intended for adults. We do not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact us for review and deletion. Users under 18 may not place orders.
Information is primarily processed in the United States. A provider may process information in another location subject to its agreement and applicable law. Before Totesi launches in a new state or materially changes its data uses, it will review additional privacy requirements and update notices and controls as needed.
We may update this Policy prospectively. We will post the revision and update the date. We will provide additional notice for a material change where appropriate or required. A Policy update alone will not create broader AI-training rights; those require a separate, specific agreement.
Totesi Inc.
4601 E. Douglas Ave. STE 150
WICHITA, KS 67218
privacy@totesi.com