This Privacy Policy explains how Attic, Inc. (“Attic,” “we,” “our,” or “us”) collects, uses, retains, discloses, and protects personal data in connection with our personal storage services, mobile applications, websites, waitlists, operational tools, and related services (collectively, the “Services”). Personal data means information that identifies, relates to, describes, or can reasonably be linked to an identified or identifiable individual.
This policy applies to personal data we collect through or in connection with:
- the Attic customer mobile application, website, waitlist, and online services that link to this policy;
- our driver, warehouse, and operations applications, tools, and workflows;
- pickup, storage, delivery, return, cancellation, billing, claims, abandoned-property, customer support, and related service communications; and
- other interactions with us where this policy is provided or linked.
This policy does not apply to information collected by third parties through websites, applications, platforms, or services that we do not control, even if those third-party services link to or are accessible from our Services. We may provide additional notices for certain features, activities, jurisdictions, or categories of users, including employees, contractors, drivers, or other workforce users.
1. Personal Data We Collect or Process
Depending on how you interact with Attic, we may collect or process the following categories of personal data:
- Account and contact information: your name, email address, telephone number, account credentials or identifiers, billing address, service address, mailing address, alternate contact information if provided, and other contact information you provide.
- Waitlist and website information: email address, ZIP or postal code, service-area interest, waitlist status, referral or source information, confirmation token, user agent, hashed IP address, page, form, and campaign information, and related communications if you join a waitlist, request updates, or interact with our marketing website.
- Service, subscription, and transaction information: pickup and delivery requests, crate reservations, subscription status, billing history, refunds, discounts, credits, cancellation and retrieval requests, retrieval-fee status, replacement-fee status, service notes, customer preferences, and information about your use of our Services.
- Payment information: payment method details, card token or payment credential identifiers, last four digits and expiration date where made available by our processor, payment authorization records, saved payment method status, payment transaction information, charge attempts, refunds, disputes, and account-updater information. Payment card information is processed by our payment processor. Stripe processes payment card information on our behalf. We store payment tokens, the last four digits of a card number, card expiration date, and related payment records where made available by Stripe, but we do not intentionally store full payment card numbers or card verification codes on Attic-controlled systems.
- Crate, storage, and contents-related information: crate identifiers, QR codes, QR scans of crate tags and seals, crate labels, customer-provided descriptions, required contents photographs, optional crate cover photographs or other customer-uploaded media, chain-of-custody scan records, pickup, arrival, facility access records, shelf placement, storage location, return, removal, loss, damage, claim, nonpayment, lien, abandoned-property, disposal, donation, sale, and dispute records.
- Communications information: messages you send to customer support, support tickets, chat, email, phone, SMS, in-app, push, survey, feedback, complaint, claim, and dispute communications, and records of our responses.
- Device, usage, and technical information: IP address, device identifiers, browser type, operating system, app version, log data, diagnostics, crash or error information, cookie and SDK information, approximate location inferred from IP address, and information about your interactions with our Services.
- Location and address information: service addresses you enter, address verification information, serviceability checks, pickup and delivery instructions, route and delivery information, approximate location inferred from IP address, and, for driver or operations app users, foreground device location during active shifts if enabled and used to support pickups, deliveries, routing, customer delivery-status views, chain-of-custody, safety, fraud prevention, or operational coordination. The customer-facing features of the app do not collect precise device location, although the app may request or declare location permissions because customer and driver roles may operate through the same application.
- Driver, warehouse, and operations app information: user role, route assignments, pickup and delivery status, scan times, operational notes, warehouse location records, app activity, and related performance or operational information relating to performance of the Services.
- Marketing and preference information: communication preferences, opt-in and opt-out records, waitlist interests, referral information, promotion or offer interactions, and records of whether you have opted in to or opted out of certain communications.
- Claims, safety, and legal information: information relating to prohibited items, suspected unsafe or unlawful items, damage or loss claims, insurance or claim-adjustment matters, chargebacks, collections, law enforcement requests, legal notices, lien rights, abandoned property, and disputes.
- Aggregated, deidentified, or statistical information: information derived from the categories above that does not identify and cannot reasonably be linked to an individual. We do not treat this information as personal data if it is maintained in deidentified form and used in accordance with applicable law.
2. Sensitive Data and Contents-Related Information
We do not intentionally collect government identification numbers, biometric identifiers, health information, precise geolocation from customer devices, information about children, or other sensitive personal data unless we specifically disclose that collection and obtain any consent required by applicable law. The Services are designed for ordinary household goods, not high-value, regulated, hazardous, illegal, perishable, or specially handled property.
If you choose to include sensitive information in crate labels, descriptions, photos, messages, support requests, claims, or other content you submit, we will process that information as described in this policy. We encourage you not to include sensitive personal data or detailed information about sensitive, valuable, or irreplaceable items in optional fields unless necessary for your use of the Services.
3. How We Collect Personal Data
We collect personal data in the following ways:
- Directly from you: when you create or update an account, join a waitlist, request updates, schedule a pickup or delivery, enter a service address, label or describe a crate, upload photos, make a payment, authorize a saved payment method, submit a claim, communicate with support, or otherwise provide information through the Services.
- Automatically through the Services: when our systems collect device, usage, log, diagnostic, app activity, cookie, SDK, QR scan, chain-of-custody, serviceability, and operational information.
- From service providers and business tools: such as payment processors, account sign-in and identity providers, email and messaging providers, mapping and address verification providers, website and waitlist providers, hosting and database providers, analytics tools, customer support tools, accounting tools, security tools, and similar providers.
- From drivers, warehouse personnel, operations personnel, contractors, or other authorized users: such as when they scan crates, update pickup or delivery status, record shelf placement, document a service issue, or otherwise perform the Services.
- From third-party storage facility operators, landlords, property managers, security providers, or similar parties: such as facility access records, incident reports, security or safety information, and information needed to access, store, protect, move, or retrieve crates.
- From third parties involved in transactions, claims, or legal matters: such as payment networks, banks, insurers, claim administrators, collection service providers, law enforcement, regulators, or other parties where necessary to process payments, investigate claims, respond to safety or prohibited-item issues, collect amounts owed, or comply with law.
4. Cookies, SDKs, and Similar Technologies
We and our service providers may use cookies, software development kits, local storage, mobile identifiers, web beacons, logs, and similar technologies to operate the Services, maintain account sessions, remember preferences, protect account security, understand usage, diagnose problems, measure waitlist or marketing website activity, and improve the Services. You may be able to control certain technologies through your browser or device settings, but disabling them may affect the availability or functionality of the Services.
We do not currently use analytics packages, advertising pixels, retargeting technologies, lookalike audience tools, targeted advertising, or cross-context behavioral advertising. If our advertising, analytics, or tracking practices change, we will update this policy and provide any notices, consents, or opt-out choices required by applicable law before those practices begin.
When you interact with our Services, third parties such as app stores, mobile operating system providers, device manufacturers, internet or mobile service providers, payment networks, and integrated service providers may collect information about you or your device under their own privacy policies. We do not control those third-party privacy practices.
6. How We Use Personal Data
We use personal data for the following purposes:
- Provide and operate the Services: including account creation and authentication, serviceability checks, scheduling, pickup, storage, delivery, returns, cancellation, crate identification, crate tracking, chain-of-custody, customer support, and related operations.
- Operate the website and waitlist: including waitlist management, service-area planning, launch updates, priority or referral tracking, and communications about availability of the Services.
- Process payments and subscriptions: including recurring monthly storage fees, retrieval fees, replacement fees, taxes, refunds, credits, chargebacks, failed-payment retries, invoices, accounting, and related financial records.
- Support saved payment methods and off-session charges: including storing payment method tokens through our payment processor, maintaining payment authorization records, using account updater or tokenization tools where available, and processing merchant-initiated transactions or other charges you authorize under our Terms of Service.
- Coordinate drivers, warehouse, and operations: including routing, delivery logistics, warehouse operations, shelf placement, scan verification, service issue resolution, operational quality, and safety-related activities.
- Communicate with you: including sending service, transactional, security, account, billing, support, legal, lien, abandoned-property, claims, and administrative messages by email, in-app message, push notification, phone, SMS, or mail.
- Send marketing or promotional communications: if we do so and you have not opted out where applicable.
- Maintain, analyze, develop, and improve the Services: including debugging, troubleshooting, testing, analytics, quality assurance, product development, capacity planning, service-area planning, and creating aggregated or deidentified information.
- Protect the Services and people: including detecting, investigating, and preventing fraud, misuse, security incidents, prohibited item issues, unsafe conditions, loss, damage, claims, disputes, contamination, pests, odors, or other risks to customers, personnel, service providers, facilities, stored property, or Attic.
- Administer claims, insurance, collections, lien, and abandoned-property processes: including investigating damage or loss claims, handling insurance or claim-adjustment matters, collecting amounts owed, enforcing our Terms of Service, exercising or preserving lien rights, returning stored crates, and handling unclaimed or abandoned property in accordance with applicable law.
- Comply with legal, regulatory, tax, accounting, and contractual obligations: including responding to lawful requests, cooperating with law enforcement or regulators where required or appropriate, and establishing, exercising, or defending legal claims.
- Fulfill any other purpose for which you provide the information or to which you consent.
We do not use personal data to make decisions that produce legal or similarly significant effects based solely on automated processing. We also do not currently use personal data for targeted advertising or sell personal data as those terms are defined under applicable state privacy laws.
7. How We Disclose Personal Data
We may disclose personal data as described below:
- Service providers and vendors: we disclose personal data to vendors and service providers that help us operate the Services and our business, such as payment processing, account sign-in and identity management, transactional email, text or messaging, website and waitlist tools, mapping and address verification, database, hosting, storage, security, analytics, customer support, accounting, legal, insurance, claims, and similar business functions. Based on our current information, our service providers include Stripe for payments; Clerk for account sign-in and identity; Resend for transactional email; Klaviyo for waitlist and marketing email; Customer.io for customer engagement and lifecycle messaging; Twilio for text messaging; Google Maps Platform for address autocomplete, address verification, mapping, and serviceability; HarperDB for database services; Google Firebase Cloud Messaging for push notifications; Expo/EAS for mobile app updates and push infrastructure; Vercel for marketing site hosting and waitlist functionality; Google Workspace for business productivity and communications; and other website, hosting, security, support, accounting, legal, insurance, claims, or messaging providers used to operate the Services.
- Drivers, warehouse personnel, operations personnel, and contractors: we disclose personal data to drivers, warehouse personnel, operations personnel, contractors, and other authorized users as needed to perform pickups, storage, deliveries, returns, customer support, claims handling, warehouse operations, safety functions, and related services. These users should access only the information reasonably necessary to perform their assigned functions.
- Payment processors, banks, card networks, and payment tools: we disclose payment-related and transaction information as needed to process payments, store payment tokens, process recurring and off-session charges, address chargebacks or disputes, prevent fraud, and use account updater, tokenization, or similar payment tools.
- Storage facilities and logistics providers: if we use third-party facilities, warehouse operators, carriers, logistics providers, or similar providers, we may disclose information needed to store, track, preserve, transport, return, or otherwise handle crates and stored items.
- Storage facility operators and property-related service providers: We may disclose limited personal data to third-party storage facility operators, landlords, property managers, security providers, access-control providers, insurers, or similar parties as reasonably necessary to store crates, access storage locations, comply with facility requirements, investigate incidents, protect people or property, address claims or disputes, or comply with law.
- Insurers, claim administrators, adjusters, and professional advisors: we may disclose personal data as needed to obtain or administer insurance, evaluate loss or damage claims, respond to incidents, obtain legal or accounting advice, or manage disputes.
- Collection agencies, attorneys, and enforcement providers: we may disclose personal data as needed to collect amounts owed, enforce our Terms of Service, preserve or exercise lien rights, or handle unclaimed or abandoned property.
- Legal, safety, and enforcement purposes: we may disclose personal data to comply with applicable law, legal process, court order, subpoena, or governmental or regulatory request; to enforce our agreements or policies; to investigate or respond to claims, losses, damage, fraud, security, prohibited items, or safety issues; or to protect the rights, property, or safety of Attic, our customers, users, personnel, service providers, or others.
- Business transfers: we may disclose or transfer personal data to a buyer, investor, lender, financing source, successor, or other relevant party in connection with a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, due diligence process, or similar transaction involving all or part of our business.
- With your direction or consent: we may disclose personal data when you direct us to do so or otherwise consent.
We may disclose aggregated or deidentified information that does not identify an individual without restriction, subject to applicable law.
8. No Sale or Targeted Advertising
Based on our current practices, we do not sell personal data and do not share or process personal data for targeted advertising or cross-context behavioral advertising as those terms are defined under applicable state privacy laws. We also do not disclose personal data to third parties for their own direct marketing purposes without your consent. If our practices change, we will update this policy and provide any opt-out rights required by applicable law.
9. Categories of Personal Data Disclosed
The categories of personal data we may disclose include account and contact information; waitlist and website information; service, subscription, and transaction information; payment-related information; crate, storage, and contents-related information; communications information; device, usage, and technical information; location and address information; driver, warehouse, and operations app information; marketing and preference information; claims, safety, and legal information; and aggregated or deidentified information.
10. Website and Waitlist
Our marketing website may allow you to join a waitlist, request updates, or tell us where you would like Attic to operate. For waitlist submissions, we may collect your email address, ZIP or postal code, source or referral string, user agent, hashed IP address, confirmation token, form-submission metadata, and related communications. We use a double opt-in process, and a submission is not added to the waitlist unless confirmed. We may use anti-spam tools, such as hidden honeypot fields, and may discard submissions identified as spam without storing them. We use this information to manage the waitlist, estimate demand by geography, prioritize launch areas, communicate with you about availability of the Services, measure the effectiveness of outreach, and improve the website and Services.
The website and waitlist may use different providers than the mobile app. We may disclose waitlist and website information to website hosting providers, form providers, email providers, analytics providers, and other service providers that help us operate the website, manage the waitlist, and send updates. If we add advertising pixels, cross-context behavioral advertising, or other tracking that changes our current practices, we will update this policy and provide any required notices, consents, or opt-out choices.
11. Your Choices
- Account information: you may update certain account information through the Services or by contacting us.
- Marketing communications: you may opt out of marketing emails by using the unsubscribe instructions in those emails or by contacting us. Even if you opt out of marketing communications, we may still send service, transactional, account, billing, security, legal, lien, abandoned-property, claims, or administrative messages.
- Push notifications and text messages: you may be able to control push notifications through your device settings and text message preferences through the instructions provided in the message or through the Services. Disabling certain notices may affect your ability to receive service updates.
- Location information: customer-facing app features do not require precise device location. Driver and operations users may be able to disable location permissions through device settings, but doing so may affect routing, shift, delivery-status, chain-of-custody, and operational features.
- Cookies and similar technologies: you may be able to manage cookies and similar technologies through your browser or device settings. Some features of our Services may not function properly if you disable certain technologies.
- Optional crate labels, descriptions, and photos: you may choose what information to include in optional crate labels, descriptions, photos, or other media, subject to our Terms of Service. We encourage you to avoid including sensitive personal data or detailed information about sensitive or high-value items in optional fields unless necessary.
12. Your State Privacy Rights
Depending on your state of residence and subject to applicable law, you may have some or all of the following rights regarding your personal data:
- Access and portability: you may request that we confirm whether we process your personal data and provide access to or a copy of certain personal data we maintain about you, including in a portable format where required.
- Correction: you may request that we correct inaccuracies in personal data we maintain about you.
- Deletion: you may request that we delete personal data we maintain about you, subject to exceptions under applicable law.
- Opt out: you may request to opt out of the sale of personal data, targeted advertising, or certain profiling, if applicable. As noted above, we do not currently sell personal data or process personal data for targeted advertising or for profiling in furtherance of decisions that produce legal or similarly significant effects.
- Limit or withdraw consent for sensitive data: where applicable, you may have the right to limit certain uses of sensitive personal data or withdraw consent where processing is based on consent.
- Appeal: you may have the right to appeal our decision regarding a privacy rights request.
- Non-discrimination: you have the right not to be discriminated against for exercising privacy rights, subject to applicable law.
To exercise a privacy right, contact us at privacy@heyattic.com. We may need to verify your identity or authority to act on behalf of another person before fulfilling a request. We will respond to requests as required by applicable law. To appeal a decision regarding your request, reply to our response or email privacy@heyattic.com with the subject line “Privacy Request Appeal.”
13. Authorized Agents
Where applicable law allows you to use an authorized agent to submit a request, we may require proof that you authorized the agent to act on your behalf and may require you to verify your identity directly with us, unless applicable law provides otherwise.
14. Global Privacy Control and Universal Opt-Out Signals
Some browsers and browser extensions support signals, such as the Global Privacy Control, that can communicate privacy preferences. Where required by applicable law and technically feasible, we will honor recognized opt-out preference signals for processing activities subject to those signals. Because we do not currently sell personal data or process personal data for targeted advertising, those signals may not change your experience with the Services under our current practices.
15. Nevada Residents
Nevada law provides residents with a limited right to opt out of certain sales of covered information. We do not currently sell covered information as defined under Nevada law. Nevada residents may submit opt-out requests to privacy@heyattic.com.
16. State-Specific Supplemental Notices
Additional state-specific privacy notices may apply depending on where you live, where you use the Services, or where Attic operates. If we provide state-specific supplemental notices, those notices are incorporated into this policy and control to the extent they conflict with this policy for the applicable person, location, or processing activity.
17. Data Retention
We retain personal data for as long as reasonably necessary to fulfill the purposes described in this policy, provide the Services, operate our business, comply with legal, tax, accounting, and contractual obligations, resolve disputes, protect safety and security, prevent fraud, collect amounts owed, administer claims, enforce our Terms of Service, and establish, exercise, or defend legal claims.
Subject to those purposes and applicable law, our current anticipated retention periods are:
- Account and customer relationship information: for as long as your account remains active and for up to three years after account closure, unless a longer period is reasonably necessary for legal, safety, claims, billing, collection, or dispute purposes.
- Waitlist and marketing website information: until you unsubscribe or request deletion, until it is no longer needed for launch planning or marketing purposes, or for up to three years after your last interaction with the waitlist or website, whichever occurs first unless you become a customer or a longer period is reasonably necessary.
- Transaction, billing, payment authorization, tax, and accounting records: for as long as required or appropriate for tax, accounting, audit, chargeback, payment network, legal, and compliance purposes.
- Chain-of-custody, scan, pickup, delivery, return, storage location, lien, abandoned-property, and crate status records: for up to seven years after the applicable crate is returned, removed from the Services, disposed of, or otherwise resolved.
- Customer-provided contents photographs, optional crate cover photographs, and other customer-uploaded media: for up to 90 days after the applicable crate is returned to you, removed from the Services, or otherwise no longer stored by Attic, unless a longer period is reasonably necessary for claims, disputes, legal compliance, safety, security, billing, lien, abandoned-property, insurance, or operational purposes.
- Support, claim, loss, damage, dispute, prohibited-item, safety, insurance, collection, and incident records: for as long as reasonably necessary to address the issue and maintain appropriate business and legal records, which may be up to seven years or longer if required by law or reasonably necessary for an active dispute or claim.
- Driver, warehouse, and operations app records: for as long as reasonably necessary for operations, safety, quality assurance, security, workforce or contractor administration, payment, legal, and compliance purposes.
- Nonpayment, dunning, lien, abandonment, replacement-fee, collection, donation, disposal, and mercy-return records: for as long as reasonably necessary to administer the account, document notices and actions taken, resolve disputes, comply with law, and establish, exercise, or defend legal claims.
- Logs, diagnostics, analytics, and security records: for a period reasonably necessary for security, debugging, service integrity, analytics, and business operations, unless a longer period is reasonably necessary to investigate security incidents, fraud, prohibited items, claims, or disputes.
When personal data is no longer needed for the purposes described above, we will delete, destroy, deidentify, or anonymize it in accordance with our retention practices and applicable law. Backup copies may persist for a limited period before deletion in the ordinary course of business.
18. How We Protect Personal Data
We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal data from accidental loss, unauthorized access, use, alteration, and disclosure. These safeguards may include encryption, access controls, role-based permissions, logging, vendor management practices, physical security measures, and personnel training, as appropriate for the nature of the information and the Services. In addition, our crate labels and seal codes are designed to use internal identifiers and not to display your name, address, contents description, declared value, or other customer-identifying information on the exterior of the crate.
No website, mobile application, system, transmission, or electronic storage method is completely secure. We cannot guarantee the security of personal data. You are responsible for maintaining the confidentiality of your account credentials and for using appropriate safeguards when accessing the Services.
19. Children and Minors
The Services are not intended for children or minors under 18 years of age. You must be at least 18 to use the Services and we may require users to confirm that they are at least 18 years old when creating an account. We do not knowingly collect personal data from children under 13 or knowingly allow minors under 18 to create customer accounts. If you believe a child or minor has provided personal data to us, please contact us at privacy@heyattic.com so that we can take appropriate action.
20. Changes to This Policy
We may update this policy from time to time. The date this policy was last updated appears at the top of the policy. We will provide notice of changes by posting the updated policy through the Services and updating the date above. If we make material changes, we will provide additional notice as required by applicable law, which may include email, in-app notice, website notice, or other reasonable notice.
To ask questions about this policy or our privacy practices, or to exercise privacy rights, contact us at:
Attic, Inc.
Email: privacy@heyattic.com
Mailing address: 5110 Beech Street, Arvada, CO 80002