Last updated: July 7, 2026
This Privacy Policy explains how Tartabit, LLC ("Tartabit", "we", "us", or "our") collects, uses, discloses, and protects personal information through our public website, marketing activities, checkout flows, and Tartabit services.
This policy is intended to describe Tartabit's practices as a controller for our own website, marketing, account, billing, and business operations. When Tartabit processes customer data on behalf of a customer through Tartabit IoT Bridge or related services, the customer is generally the controller and Tartabit acts as a processor or service provider under the applicable agreement and Data Protection Addendum.
Tartabit, LLC is the controller for the personal information described in this policy, except where we process personal information on behalf of a customer under a separate agreement.
For privacy questions, rights requests, or marketing opt-out requests, contact us at:
We collect personal information in the following categories, depending on how you interact with us:
We do not intentionally collect special category personal data through our public website. Customers control the data they submit to Tartabit services and should not submit sensitive personal information unless it is necessary for their use case and permitted by their agreement with Tartabit.
We collect personal information from:
We use personal information for these purposes:
| Purpose | Examples | Legal basis where GDPR or UK GDPR applies |
|---|---|---|
| Provide and operate services | Account access, service delivery, support, security, maintenance, webhooks, device data routing, and customer-requested integrations | Contract performance, legitimate interests, and customer instructions where Tartabit acts as processor |
| Respond to inquiries | Contact forms, demo requests, sales questions, support requests, and follow-up communications | Legitimate interests, contract steps, and consent where required |
| B2B marketing | Sending product updates, event invitations, service information, and business outreach to professional contacts | Legitimate interests or consent where required by local electronic marketing law |
| Manage subscriptions and opt-outs | Newsletter preferences, unsubscribe requests, suppression lists, and consent records | Consent, legal obligation, and legitimate interests |
| Analyze and improve the website | Google Analytics after opt-in consent, page performance, content engagement, and site improvement | Consent for analytics cookies/storage where required; legitimate interests for aggregate site improvement where permitted |
| Process checkout and billing | Paddle checkout, subscription setup, transaction handling, tax, invoicing, and payment records | Contract performance and legal obligation |
| Security and fraud prevention | Authentication, monitoring, logging, abuse prevention, vulnerability response, and incident investigation | Legitimate interests and legal obligation |
| Legal and business administration | Contract management, compliance, dispute handling, audits, corporate records, and enforcement of agreements | Legal obligation, legitimate interests, and contract performance |
Where we rely on legitimate interests, we consider the nature of the personal information, the purpose of processing, and your rights and expectations. You may object to processing based on legitimate interests as described in Section 11.
Tartabit may receive business contact information from third-party B2B list providers, public business sources, event organizers, referrals, partners, or marketplaces. We use this information only for business-to-business outreach about Tartabit products, services, events, and related updates.
We do not sell contact lists or personal data. We do not sell unsubscribe or suppression lists. If you opt out of marketing, we may retain limited information, such as your email address, to ensure we honor your request.
Marketing communications include an opt-out or unsubscribe method where required. You may also opt out by contacting info@tartabit.com. We honor opt-out requests as required by applicable law.
Electronic marketing rules vary by country. For EU and UK business contacts, our privacy-law basis may be legitimate interests, but electronic marketing laws may require consent or other conditions depending on the recipient type and location.
Our website uses strictly necessary technologies to operate the site, remember security and consent choices, route pages, and support core functionality. These technologies are used without optional analytics consent where permitted because they are necessary for the service you request.
We use Klaro to manage cookie and analytics preferences. Klaro stores your consent choice in a consent cookie or browser storage so the website can remember your preference. The current consent preference is remembered for up to 365 days unless you clear cookies or change your preference earlier.
We use Google Analytics to understand how visitors find and use our website. Google Analytics is optional. Analytics storage defaults to denied and is enabled only after you opt in through the cookie consent tool. You may decline analytics or later withdraw consent through the cookie preferences control where available, or by clearing your browser cookies and revisiting the site.
Google Analytics may set cookies such as identifiers beginning with _ga, _gid, or _gat after consent. Google may process analytics information as an independent provider under its own terms and privacy documentation.
Our website may also use server logs, routing logs, and 404 or broken-link reports to maintain the site, diagnose errors, and improve navigation. Broken-link reports may include the requested URL and query parameters.
We disclose personal information to vendors and recipients that support our business and services, including:
We require service providers and processors to protect personal information and use it only for permitted purposes, subject to applicable agreements.
Tartabit does not sell personal data. We do not sell customer data, website visitor data, contact lists, marketing contacts, service data, or unsubscribe and suppression lists.
Tartabit is not currently subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act, because Tartabit is below the applicability thresholds. If that status changes, or if Tartabit chooses to provide a voluntary California notice, we will update this policy.
Tartabit is based in the United States, and our vendors, customers, partners, and service infrastructure may be located in the United States and other countries. Personal information may be transferred to, stored in, or accessed from countries that may not provide the same level of data protection as your location.
When GDPR, UK GDPR, or similar transfer rules apply, Tartabit uses appropriate safeguards where required. These may include adequacy decisions, the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, vendor data processing terms, transfer risk assessments, and supplemental technical and organizational measures.
We do not rely on your agreement alone as the basis for cross-border transfers.
We retain personal information only as long as needed for the purposes described in this policy, unless a longer period is required or permitted by law. Retention periods depend on the data type, relationship, legal requirements, security needs, and operational context.
Examples of retention criteria include:
When personal information is no longer needed, we delete, anonymize, or securely retain it only as required for legal, security, or backup purposes.
Depending on your location and the nature of our relationship, you may have rights to:
To exercise rights, contact info@tartabit.com. We may need to verify your identity and request enough information to locate the relevant records. If we process personal information on behalf of a customer, we may direct your request to that customer or assist the customer in responding.
EU and UK individuals may contact their local data protection authority or the UK Information Commissioner's Office, as applicable.
We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. These measures include access controls, authentication, monitoring, logging, encryption where appropriate, operational controls, and vendor management.
No security measure is perfect. If we become aware of a personal data breach requiring notice, we will provide notices as required by applicable law and customer agreements.
Our website may link to third-party websites, marketplaces, social networks, documentation, partner pages, or checkout services. These third parties control their own privacy and security practices. Review their privacy policies before providing personal information to them.
Tartabit's website and services are intended for business and professional use. We do not knowingly collect personal information from children through the public website.
We may update this Privacy Policy from time to time. The "Last updated" date shows when this policy was last revised. Material updates will be posted on this page or communicated by other appropriate means.