Privacy Policy
Last updated: 18 August 2026
1. Data Controller
The entity responsible for the processing of your personal data is TOTE, UNIPESSOAL LDA, NIF 519259254, with registered office at Avenida da Liberdade 435, 1685-778 Famões (Odivelas), Portugal, operating under the brand TOTE.
Privacy contact: [email protected]
TOTE has not appointed a formal Data Protection Officer (DPO), as the processing carried out does not require it under Article 37 GDPR. Privacy enquiries are handled directly by the controller through the email address above.
2. Data We Collect
We collect the following categories of personal data:
- Identity data: full name, email address, phone number.
- External account data: if you choose to sign in with a Google or Microsoft account, that provider sends us your display name, email address, profile photo URL and the identifier it uses to identify you. Signing in this way is optional: you can always create a TOTE account with an email address and a password instead.
- Address data: postal code, street address, floor/door.
- Billing data: tax identification number (NIF), payment method (processed by Stripe — we do not store card details).
- Service data: pickup history, schedule preferences, recycling statistics.
- Technical data: IP address, browser type, access logs (collected automatically).
- Courier location data: GPS coordinates collected through the courier app during the service relationship (couriers only).
- Courier onboarding documents: the activity start certificate issued by the Portuguese Tax Authority and the proof of ownership of the bank account, uploaded by the courier so we can confirm the activity is open and pay to the right IBAN (couriers only). We do not ask for identity documents.
3. Purposes and Legal Basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide the recycling pickup service | Performance of contract (Art. 6(1)(b)) |
| Process payments and issue invoices | Legal obligation (Art. 6(1)(c)) |
| Send service notifications (pickup alerts, billing) | Performance of contract (Art. 6(1)(b)) |
| Improve the service and analyse usage patterns | Legitimate interest (Art. 6(1)(f)) |
| Send marketing communications | Consent (Art. 6(1)(a)) |
4. Third-Party Sharing
We share personal data with the following processors and recipients, strictly for the purposes described:
- Stripe (payment processing) — name, email, payment data.
- InvoiceXpress (invoicing) — name, NIF, address, amounts.
- Microsoft Azure (hosting and platform infrastructure) — application and database hosting in EU data centres.
- Cloudflare (DNS, edge proxy and DDoS protection) — IP address, browser headers and request metadata.
- Google Firebase Cloud Messaging (push notifications) — push token and device identifier.
- Zoho Mail (transactional email and correspondence with customers and couriers, EU data centre) — recipient email address and message body.
- Google (Places API) (address search in expansion zones) — the address text you type when looking up your address in a newly opened zone.
- CloudAMQP / LavinMQ (message queue that carries events between parts of the platform, hosted in the European Union) — account identifiers travelling inside those events.
- CTT — Correios de Portugal (postal delivery of TOTE bags) — name and postal address.
- Couriers (service delivery) — address and pickup schedule only.
We do not sell personal data to third parties.
Signing in with an external account. If you choose to sign in with a Google or Microsoft account, those companies are not acting as our processors: they are the source of the data described in section 2, which they send us when you authorise it. What they do with your data on their side is governed by their own privacy policies, not by this one. You can avoid this entirely by creating a TOTE account with an email address and a password.
International transfers. TOTE does not transfer funds outside the SEPA area — couriers are paid exclusively to Portuguese bank accounts (IBAN PT50…), and customers are billed through Stripe within the EEA. Our hosting, our email and our message queue stay inside the European Union: Microsoft Azure hosts the application and the database in EU data centres, Zoho Mail runs in its EU data centre, and the CloudAMQP queue is hosted in West Europe. Some of the other processors above (Stripe, Cloudflare, Google) do operate infrastructure outside the European Economic Area. Where this happens, transfers occur under the European Commission's Standard Contractual Clauses or, where applicable, the EU-US Data Privacy Framework.
5. Data Retention
Different categories of personal data are retained for different periods:
- Invoicing and accounting records — 10 years, as required by Portuguese tax law.
- Account data, address and pickup history — kept while the subscription is active and for up to 12 months after cancellation, unless legal obligations require longer retention.
- Technical and application logs (IP, access logs, application logs) — up to 30 days, for security and audit purposes, after which they are automatically deleted.
- Courier location data (GPS) — collected through the courier app to coordinate and evidence pickups; retained for up to 30 days, after which it is automatically deleted.
- Marketing consent and communication records — until consent is withdrawn or the underlying account is deleted.
After the applicable retention period, data is either anonymised (for aggregate impact statistics) or permanently deleted. You may request earlier deletion of non-essential data at any time through the contact below, subject to overriding legal obligations.
6. Your Rights
Under the GDPR, you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your data (subject to legal obligations).
- Portability — receive your data in a structured, machine-readable format.
- Restriction — limit processing in certain circumstances.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise these rights, send an email to [email protected] from the email address registered in your TOTE account, indicating the right you wish to exercise and any relevant details. TOTE may request additional information to confirm your identity before processing the request — specifically when the request originates from an email address not associated with an active account. We will respond within 30 days, with a possible extension of up to 60 additional days for complex requests (Article 12(3) GDPR).
You also have the right to file a complaint with the Portuguese data protection authority (CNPD — www.cnpd.pt).
7. Cookies
TOTE uses necessary cookies to make the platform work and, only with your consent, analytics cookies (Microsoft Application Insights) to understand how the platform is used. We do not use advertising, social-media or profiling cookies.
For the full list of cookies, their purpose and duration, see our Cookie Policy. You can change or withdraw your consent at any time through the "Cookie settings" link in the footer of any page.
8. Security
We implement appropriate technical and organisational measures to protect personal data, including encrypted connections (TLS), access controls, and regular security reviews. Payment data is processed exclusively by Stripe, a PCI DSS Level 1 certified provider.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated by email at least 15 days before they take effect.
10. Contact
For any questions about data protection or to exercise your rights:
Email: [email protected]
Postal address: Apartado 1, Loja Odivelas, 2676-901 Odivelas
11. Open Data Sources
The TOTE address catalog used during sign-up incorporates data from the following open-data sources:
- Instituto Nacional de Estatística (INE) — Base Nacional de Moradas (BNM), published on dados.gov.pt, licensed under CC BY 4.0.
- OpenStreetMap contributors via the Overpass API, licensed under the Open Database License (ODbL).