General Data Protection Regulation
How we protect your data under GDPR.
GDPR Policy
The purpose of the General Data Protection Regulation ("GDPR") is to protect all European Union ("EU") citizens from privacy and data breaches by allowing citizens to maintain control of the personal data kept and processed by organizations, which includes Too Lost LLC ("Too Lost", "us", "we", or "our"). The GDPR also protects the personal data of individuals, regardless of citizenry, in the EU.
Too Lost is committed to safeguarding the privacy of personal data. Furthermore, Too Lost is committed to protecting your privacy online. We are also committed to providing you with the very best experience we can on our website at toolost.com and our other web-based services and other web pages provided by Too Lost (collectively, the "Services"). This Policy also describes how we use personal data, the purpose for sharing and recipients of personal data and your rights and choices associated with that data. By using Too Lost, you are consenting to the practices described in this Privacy Notice.
Use of Information
Our primary goal in collecting personal information is to provide you, the user, with a customized experience on our website. We use the collected data for various purposes including:
- To provide and maintain our Sites and Services, including to take steps to enter into a contract for sale or services, bill you for services and process payments and fulfill transactions
- To enable and allow you to participate in interactive features of our Sites and Services and provide you with a personalized service, content and ads
- To create custom audiences on social media sites
- To provide you with better products and services and improve and grow our business, including to perform research and development, understand our customer base and purchasing trends and understand the effectiveness of our marketing
- To operate and maintain safe, secure and reliable Sites and Services
- To provide customer support, including to contact you in response to an inquiry that you sent, and send administrative messages, technical notices, updates, alerts and other information
- To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information
- To perform accounting, audits and other internal functions
- To comply with a request or order from courts, law enforcement or other government authorities
Too Lost may also use personal information for other business purposes, including the following: (i) perform accounting, audits and other internal functions; (ii) compliance with our legal obligations or to assert or defend a legal claim; (iii) general business administration; (iv) processing employment applications; and (v) systems and data security.
In addition, if we feel that a user abuses the toolost.com site in any way, we reserve the right to use and share certain information with third parties. Abuses include (but are not limited to) possible copyright infringement, possible libel and slander, and possible fraudulent or illegal activity, and other fraudulent behavior outlined in our Anti-Fraud Policy.
Third Party Use of Sensitive Information
We may disclose your Sensitive Information and other Information as follows:
- Consent: We may disclose Information if we have your consent to do so.
- Business Partners: We may share some or all of the information collected in connection with such service, promotion or contest with the co-sponsor(s).
- Service Providers: We may employ third party companies and individuals to facilitate our Services ("Service Providers"), to provide the Services on our behalf, to perform Service-related services or to assist us in analyzing how our Services are used.
- Social Media: We may share your Information if you share our content through social media, for example by liking us on Facebook, following or tweeting about us on Twitter, or giving us a '+1' via Google Plus, those social networks will record that you have done so and may set a cookie for this purpose.
- Third Party Platform Advertising: We may share your information with third party platform providers who assist us in serving advertising regarding the Services to others who may be interested in the Services.
- Facebook Conversion Tracking Pixel: Our website utilizes the Conversion Tracking Pixel service of Facebook. This tool allows us to follow the actions of users after they are redirected to a provider's website by clicking on a Facebook advertisement. We are thus able to record the efficiency of Facebook advertisements for statistical and market research purposes. The collected data remain anonymous and we cannot see the personal data of any individual user, however the collected data is saved and processed by Facebook. Facebook is able to connect this data with your Facebook account and the data is used for their own advertising purposes in accordance with their policy.
- Combined and Aggregated Data: We may analyze aggregated, de-identified data and share these analytics, including to marketing agencies, media agencies and analytics providers. We may also combine information from the Services with other information we obtain. Additionally, information collected about you from a particular browser or device may be linked to information collected from another computer or device that may relate to you.
- Google Analytics: We may use third-party Service Providers to monitor and analyze the use of our Services: Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Services. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network. For more information on the privacy practices of Google, please visit the Google Privacy Terms web page.
- Business Transactions: Under certain circumstances, Too Lost LLC may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
- Disclosure for Law Enforcement: Under certain circumstances, Too Lost LLC may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
- Legal Requirements: Too Lost LLC may disclose your Personal Data in the good faith belief that such action is necessary to: To comply with a legal obligation; To protect and defend the rights or property of Too Lost; To prevent or investigate possible wrongdoing in connection with the Services; To protect the personal safety of users of the Services or the public; To protect against legal liability.
Cookies and Other Technology
Too Lost LLC use of cookies and other data can be found in the Too Lost Privacy Policy and Cookie Policy.
Data Protection
This Data Protection section applies to all users of any services owned or controlled by Too Lost LLC. Furthermore, this section extends to Service Providers, Contractors, Affiliates, Vendors, Agents, and Entities; their parent company and subsidiaries, or their respective employees, officers, directors, members, managers, shareholders, agents, vendors, licensors, licensees, contractors, customers, successors, and assigns (each referred to as "Parties" in the following paragraph).
By executing any Agreement with Too Lost LLC, which uses any personal information, Parties agree to abide by the following paragraph. Violation of this section is cause for termination of Service or rights granted by Too Lost LLC. Moreover, if an agreement has been executed between Too Lost LLC and a Party, violation of this section is considered a material breach.
Each party shall, at its own expense, ensure that it complies with and assists Too Lost LLC to comply with the requirements of all legislation and regulatory requirements in force from time to time relating to the use of personal data, including (without limitation) (i) any data protection legislation from time to time in force in the UK including the Data Protection Act 1998 or 2018 and any successor legislation (ii) for so long as and to the extent that the law of the EU has legal effect in the UK, the General Data Protection Regulation ((EU) 2016/679) ("GDPR") and any other directly applicable EU regulation relating to privacy; and (iii) and any applicable U.S Data Protection Laws, not limited to the California Consumer Privacy Act (CCPA). This clause is in addition to, and does not reduce, remove or replace, a party's obligations arising from such requirements. Parties confirm that they will not rent or sell customer lists, contact details or other data without the customers' express prior approval. Either party may treat a breach of this clause 15 as a reason for termination of this Agreement in accordance clause 11 of this Agreement. Furthermore, under Article 5 of GDPR both parties will comply with the following principles to ensure any personal data will be: a) Processed for limited purposes and not in any way incompatible with those purposes, b) Adequate, relevant and will not be excessive, c) Accurate Not kept for longer than necessary, d) Processed in accordance with the individual rights of any data subject, and e) Secure Not transferred to countries or other parties without adequate data protection.
Retention and Destruction of Your Information
Your information will be retained by Too Lost in accordance with applicable state and federal laws, and the applicable retention periods in the Privacy Policy. Your information will be destroyed upon your request unless applicable law requires destruction after the expiration of an applicable retention period. The manner of destruction shall be appropriate to preserve and ensure the confidentiality of your information given the level of sensitivity, value and criticality to Too Lost.
Your Rights
You have the right to request access to, a copy of, rectification, restriction in the use of, or erasure of your information in accordance with all applicable laws. The erasure of your information shall be subject to applicable state and federal laws, and the applicable retention periods in the Too Lost Privacy Policy. If you have provided consent to the use of your information, you have the right to withdraw consent without affecting the lawfulness of Too Lost LLC use of the information prior to receipt of your request. Information created in the European Union will be transferred out of the European Union to Too Lost. If you feel Too Lost has not complied with applicable foreign laws regulating such information, you have the right to file a complaint with the appropriate supervisory authority in the European Union.
Updates to This Policy
We may update or change this policy at any time. Your continued use of the Too Lost website and third party applications after any such change indicates your acceptance of these changes.
Contact Us
If you have any questions about this GDPR Policy or wish to exercise one of your Data Subject rights, please contact us:
By emailing us: [email protected]
Or by mailing us a written notice to:
Too Lost LLC
2 East 28th St, #459
New York, New York 10016
USA
GDPR Privacy Notice
Effective Date: August 10, 2026
This GDPR Privacy Notice (the "Addendum") supplements the Too Lost LLC Privacy Policy and applies to individuals located in the European Economic Area, Switzerland, and the United Kingdom ("EU/UK Data Subjects"). This Addendum is intended to provide the information required under Articles 12 through 14 of the General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR (hereinafter together the "GDPR"). This Addendum should be read together with the Privacy Policy and any other privacy notice or disclosure that we may provide in connection with a particular product, service, feature, or processing activity. In the event of any conflict between this Addendum and the Privacy Policy or another posted privacy notice, this Addendum will control solely with respect to the processing of personal data subject to the GDPR, unless the more specific notice states otherwise. Any capitalized terms not defined in this notice have the meanings given in the Terms of Use.
Data Controller
For purposes of the GDPR, Too Lost LLC is the controller for the personal data it collects and processes in connection with providing the Services, unless otherwise expressly stated. In limited circumstances, Too Lost may process personal data on behalf of a customer, partner, or other third party and act as a processor or service provider, in which case the relevant third party will be responsible for determining the purposes and means of that processing and for providing any required privacy notices.
Too Lost LLC
2 East 28th St, #459
New York, NY 10016
Email: [email protected]
Personal Data Processed
Too Lost processes the categories of personal data described in the Privacy Policy and any other applicable privacy notice we provide. This personal data is obtained directly from you via your interactions with the Services (including through the use of automated technologies e.g. on our website) and through third party providers and sources. The specific categories of personal data processed depend on how you interact with the Services, but include: (i) identifiers and contact information; (ii) account and login credentials; (iii) payment, transaction, and billing information; (iv) device, internet, and usage data; (v) communications and support records; (vi) marketing and analytics information; (vii) geolocation data where enabled or inferred from your device or IP address; and (viii) any other personal data you submit to us or that is generated through your use of the Services.
In connection with identity verification, fraud prevention, compliance, or account security, Too Lost may also use third-party identity verification providers that collect and process verification-related information from you on Too Lost's behalf or in connection with services they provide to Too Lost, which may include government identification information, facial images, liveness or selfie-verification data, device and network information, and, where applicable, other sensitive data or special-category data as permitted by and in accordance with applicable law.
Purposes of Processing and Legal Bases
The personal data described above is processed for the following purposes and pursuant to the following lawful bases under Article 6 GDPR:
- Providing, operating, maintaining, and administering the Services, including account creation and account management (lawful basis: performance of a contract)
- Processing billing, payments, subscriptions, and transactions (lawful basis: performance of a contract and compliance with legal obligations)
- Responding to inquiries, providing customer support, and communicating with you about the Services (lawful basis: performance of a contract and legitimate interests)
- Verifying identity, confirming account ownership or authority, conducting fraud prevention and security checks, and supporting legal, regulatory, and compliance obligations, including through third-party identity verification providers where appropriate (lawful basis: legitimate interests, compliance with legal obligations, and, where applicable, consent)
- Monitoring, preventing, investigating, and addressing security incidents, fraud, abuse, and other misuse of the Services (lawful basis: legitimate interests and, where applicable, compliance with legal obligations)
- Conducting analytics, measuring performance, improving the Services, and carrying out internal research and development (lawful basis: legitimate interests)
- Sending marketing or promotional communications and using cookies, pixels, SDKs, and similar technologies where permitted by law (lawful basis: consent or legitimate interests, as applicable)
- Complying with applicable law, lawful requests, and legal process, and establishing, exercising, or defending legal claims (lawful basis: compliance with legal obligations and legitimate interests)
Consent
Where processing is based on consent, you may withdraw your consent at any time, and where required by applicable law we will apply your withdrawal going forward. Such withdrawal will not affect the lawfulness of processing carried out before the withdrawal.
Legitimate Interests
Where processing is based on legitimate interests, those interests generally include operating and improving the Services, maintaining the security and integrity of the Services, preventing fraud and misuse, responding to users and providing support, understanding how the Services are used, and marketing or promoting the business where permitted by applicable law. Where required, or in circumstances where Too Lost determines, in its reasonable business judgment, that such action is warranted, Too Lost conducts a balancing assessment weighing its legitimate interests against the rights and freedoms of affected individuals before processing personal data on the basis of legitimate interests. Too Lost does not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
Whether Provision of Data Is Required
Certain personal data is required for Too Lost to enter into or perform a contract with you, create and maintain your account, process payments, provide requested Services, and comply with legal obligations. If you do not provide personal data that is required for these purposes, Too Lost may be unable to provide some or all of the Services or respond to your request.
Recipients of Personal Data
Personal data processed by Too Lost may be disclosed to vendors, service providers, contractors, and other processors that process personal data on our behalf where necessary for the purposes set out above, including: (i) third-party identity verification providers that collect or process verification-related information in connection with services they provide to Too Lost; (ii) payment processors; (iii) analytics, advertising, and marketing partners that may act as independent controllers or process data under their own privacy notices or terms where permitted by law; (iv) professional advisors, auditors, and insurers; (v) government authorities, regulators, law enforcement, or other third parties where required by law or legal process; and (vi) relevant parties in connection with a corporate transaction such as a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets. Where third parties process personal data on our behalf, they are subject to contractual restrictions and security obligations consistent with applicable law.
International Data Transfers
When sharing personal data within Too Lost and to third parties as set out above, the personal data may be transferred to, stored in, or accessed from countries outside the European Economic Area, Switzerland, or the United Kingdom, including the United States, where data protection laws may not provide the same level of protection as those in your jurisdiction. Where required in accordance with applicable laws, Too Lost ensures reliance on and/or implements appropriate safeguards for such transfers, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or other valid UK transfer mechanism, adequacy decisions, or other lawful transfer tools recognized under applicable law. Too Lost may also implement supplementary technical, organizational, and contractual measures where appropriate. You may request additional information about applicable transfer safeguards by contacting [email protected].
Data Retention
Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected and processed, including to provide the Services, maintain the business relationship, comply with legal, tax, accounting, and regulatory obligations, resolve disputes, enforce agreements, and protect our rights. Retention periods vary depending on the type of personal data and the context in which it was collected. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. When personal data is no longer required, it is deleted, anonymized, or otherwise securely disposed of in accordance with applicable law.
Automated Decision-Making and Profiling
Too Lost does not engage in automated decision-making, including profiling, that produces legal effects or similarly significant effects concerning EU/UK Data Subjects within the meaning of Article 22 GDPR.
Your GDPR Rights
Subject to applicable law, EU/UK Data Subjects have the following rights:
- Right to access: You have the right to confirm whether we are processing your personal data and request access to (and obtain a copy of, if applicable) the personal data that we hold about you, including the type and source of the personal data, the purpose and period of processing, and the persons with whom the data is shared.
- Right to rectification: You have the right to update the personal data we hold about you or to rectify any inaccuracies. Based on the purpose for which we use your personal data, you can instruct us to add supplemental information about you in our database.
- Right to erasure: You have the right to request that we delete your personal data in certain circumstances, such as when it is no longer necessary for the purpose for which it was originally collected.
- Right to restriction of processing: You may also have the right to request to restrict the use of your personal data in certain circumstances, such as when you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
- Right to data portability: You have the right to transfer your personal data to a third party in a structured, commonly used and machine-readable format, in circumstances where the personal data is processed by automated means with your consent or where we used the data to perform a contract with you.
- Right to object: You have the right to object to the use of your personal data in certain circumstances, such as the use of your personal data for direct marketing or in certain circumstances where we rely on legitimate interests.
- Right to lodge a complaint: You have the right to lodge a complaint about the processing of your personal data with the appropriate supervisory authority or other regulator.
- Right to withdraw consent: As set out above, where processing is based on consent, you may withdraw your consent at any time, and where required by applicable law we will apply your withdrawal of consent going forward.
You may request to exercise these rights by contacting [email protected] or through any request mechanisms we make available through the Services where applicable. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to clarify the request or aid our response.
Supervisory Authority
EU/UK Data Subjects also have the right to lodge a complaint with the supervisory authority or data protection regulator in their place of habitual residence, place of work, or the place of the alleged infringement. Data Subjects based in the UK should complain to, or ask for clarification from, Too Lost as the data controller in the first instance before contacting the UK's Information Commissioner's Office.
Children's Data
The Services are not directed to individuals under the age of 16, and Too Lost does not knowingly collect personal data directly from children who are under the age of 16. If you believe that a child has provided personal data to Too Lost in violation of applicable law, please contact [email protected] so that we can take appropriate steps to investigate and, where appropriate, delete the information. If local law requires parental or guardian authorization for certain processing activities involving minors, Too Lost will seek to comply with those requirements.
Updates to This Addendum and Your Information
Too Lost may update this Addendum from time to time to reflect changes in applicable law, regulatory guidance, our data processing practices, or related updates to the Privacy Policy or other posted privacy notices and disclosures. When required by applicable law, we will provide notice of material changes to you, for example through the Services, by updating the effective date, or by other appropriate means.
It is also important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example a new address or email address.
Contact Us
Too Lost LLC
2 East 28th St, #459
New York, NY 10016
Email: [email protected]