KTT Birmingham LLC respects the privacy of every site partner, visitor and customer who interacts with the unattended retail systems it designs, places and operates. This policy explains what information we collect, why we collect it, how we protect it and what choices you have. It applies to our website, our client portals, our vending and kiosk devices and any related service we provide.
This Privacy Policy is issued by the developer known as KTT Birmingham, operating through the company KTT Birmingham LLC, located at 1758 S 1900 W Ste B1, West Haven, UT 84401-0371, United States. Where this policy refers to the Company, we mean KTT Birmingham LLC.
1. Information We Collect
The Company collects information in several ways depending on how you interact with us. When you fill in a form on our website, we receive the details you choose to provide, such as your name, email address, telephone number, company name and the content of your message. When a site partner signs a service agreement, we collect the business contact details needed to deliver and support the program, including site addresses, billing contacts and on site contact names.
When you use one of our vending machines or self service kiosks, the device records transaction level information. This may include the item selected, the price paid, the time and date of the transaction, the payment method type and a device identifier. We do not store full payment card numbers in our own systems, because card processing is handled by specialist payment providers. We also collect technical information from devices and from visitors to our website, such as internet protocol address, browser type, operating system, referring pages and general location derived from an address.
We aim to collect only what we need. If information is not required to deliver a service, support a machine, meet a legal duty or improve our operation, we do not ask for it and we do not keep it.
We also collect information when a visitor interacts with a support channel. If you call the desk, we may keep a record of the call so the ticket can be resolved and referenced later. If you email us, we retain the message thread and any attachments you send. Site contacts may also be recorded in our client portal so that technicians, drivers and planners know who to reach at each building. We keep these records accurate and we update them when a contact changes.
Some information is generated automatically when a machine completes a vend, including the selection code, the shelf and spiral involved, the vend result and the time of sale. This record lets us confirm a purchase, investigate a failed vend and understand demand by hour and by day. It is associated with the machine and the transaction, and only in limited circumstances is it linked to an identified person, such as when a refund claim requires it.
2. How We Use Information
We use the information we collect to plan, install, operate and maintain unattended retail systems. This includes responding to enquiries, preparing placement plans, configuring telemetry and payment systems, scheduling restock routes, designing planograms and dispatching maintenance visits. We use contact details to communicate about service windows, program reviews, invoices and support tickets.
We use transaction and telemetry data to understand how each machine performs, to forecast demand, to reduce waste and to detect faults early. Aggregate and de identified information may be used to improve our services, to benchmark machine performance and to develop new offerings. We use website technical data to keep the site secure, to understand which pages are useful and to fix problems.
We may use your information to meet legal, accounting and tax obligations, to enforce our agreements and to protect the rights, property and safety of the Company, our site partners and the public. We do not sell personal information, and we do not use personal information for unrelated purposes without a lawful basis.
We also use information to keep our systems safe and to prevent misuse. Security monitoring helps us detect unusual access, blocked connectivity, tampering and attempted fraud, and it supports the integrity of the telemetry and payment streams. Where we use information for security, we keep it only as long as needed to investigate and to maintain an appropriate record.
We may contact a site partner about a program review, a planned planogram change or a route adjustment. These communications are part of the service and are based on the working relationship rather than on marketing consent. Where we send optional updates about new offerings, you can opt out at any time without affecting the core service you receive.
3. Legal Bases for Processing
Where applicable law requires a legal basis, we rely on one or more of the following. We process information to perform a contract when we deliver services to a site partner or respond to a request you have made. We rely on legitimate interests when we operate and improve our systems, secure our network, prevent fraud and manage our business, provided those interests are not outweighed by your rights.
We rely on consent where you have given it, for example when you opt in to a newsletter or a non essential cookie. You may withdraw consent at any time. We process information to comply with legal obligations, such as tax, accounting and lawful requests from authorities. Where we process sensitive information, we do so only when the law allows and with appropriate safeguards.
4. Cookies and Similar Technologies
Our website may use cookies and similar technologies to keep the site working, to remember your preferences and to understand how visitors use our pages. Essential cookies support core functions such as navigation and security. Analytics cookies help us measure which content is read and where visitors encounter difficulty, so we can improve the site.
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies, and you can usually set your browser to warn you before a cookie is stored. If you disable essential cookies, some parts of the website may not function correctly. We do not use cookies to build advertising profiles of individual visitors, and we do not permit third parties to use cookies on our site for cross site behavioural advertising.
We keep our cookie use modest by design. The website does not need a large tracking footprint to function, and we prefer a small, transparent set of technologies over an elaborate profile of every visitor. Where we use analytics, we configure it to limit the information collected and to avoid tying activity to a named individual where that is possible.
If we introduce a new category of cookie in the future, we will describe it on this page and, where required, ask for your consent before it is set. You can also use browser privacy controls, including do not track signals and third party cookie blocking, to limit the technologies that operate on your device.
5. Device and Telemetry Data
Every machine and kiosk we operate may report telemetry to our platform. This data covers sales counts, stock levels, temperature readings, door open and close events, coin and bill levels, card reader status, error codes, uptime and network health. Telemetry is linked to a device identifier and to a site, not to a named individual, unless a specific feature requires otherwise.
We use telemetry to keep machines full and online. It allows us to raise an alert when a spiral jams, when a cooler drifts out of range or when a reader goes offline, often before any customer notices. It also supports route planning and planogram design. We retain telemetry in line with our retention schedule and we take reasonable steps to keep it secure in transit and at rest.
Telemetry supports more than uptime. It helps us plan restock routes by showing which machines are low and which are still full, and it supports planogram design by showing which products sell through and which stall. Because the data is tied to devices and sites rather than people, it lets us run the floor efficiently without building profiles of individual shoppers.
Where telemetry includes a diagnostic image or a sensor reading, we treat it with the same care as other operational data. Access is limited to staff and providers who support the service, and the information is used to fix faults, improve reliability and maintain a service history for each unit.
6. Payment Information
Cashless payments on our machines are processed by regulated payment providers and card networks. When you tap a card or a phone wallet, the payment credentials are captured and transmitted by the payment terminal and the acquiring provider. The Company receives confirmation that a transaction succeeded, along with limited transaction details such as the amount, the time and a masked reference.
We do not store full card numbers, security codes or full track data in our own systems. Settlement reports and reconciliation records are retained for accounting and dispute purposes. If you believe a charge on your statement is incorrect, contact us using the details at the end of this policy and we will work with the payment provider to investigate. Please do not send full card details to us by email.
Because payment processing sits with regulated providers, the Company sees only the information needed to operate and reconcile the program. We may see the amount, the time, the machine and a masked reference that lets us match a transaction to a provider record when a dispute or refund is raised. We use this limited data to keep the ledger accurate and to resolve customer claims fairly.
If a site partner requests a payment report, we provide the settlement and reconciliation detail available to us. We do not attempt to identify a specific shopper from a card transaction, and we do not request or store the sensitive authentication data that belongs with the payment provider and the card networks.
7. Sharing and Disclosure
We share information only as needed to run our business and only with parties who are bound to protect it. We may share information with site partners, because a site partner needs to know how its machines are performing and when a service visit is planned. We may share information with payment providers, telemetry platform operators, logistics partners and maintenance contractors who help us deliver the service.
We may disclose information when the law requires it, such as in response to a valid legal process, a court order or a request from a regulator. We may disclose information to protect the rights, property and safety of the Company, our partners or the public, or to investigate suspected fraud. If the Company is involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that transaction, subject to this policy or a policy that is at least as protective.
8. Service Providers and Vendors
We rely on carefully selected service providers for hosting, telemetry, payment processing, mapping, communications, accounting and support. These providers receive only the information they need to perform their function, and they are expected to handle it in line with their contracts and applicable law.
We review our vendors periodically and require appropriate technical and organisational safeguards. Where a provider processes information on our behalf, we remain responsible for the information we have entrusted to it. We do not authorise any provider to use our information for its own independent marketing purposes.
9. Data Retention
We keep information only as long as it is needed for the purpose for which it was collected, to meet legal and accounting duties, to resolve disputes and to enforce our agreements. Transaction and reconciliation records are generally kept for the period required by tax and accounting rules. Telemetry is kept long enough to support forecasting, service history and quality improvement, then aggregated or deleted.
Website enquiry details are kept while we handle the enquiry and for a reasonable period afterwards so we can follow up. When information is no longer needed, we delete it or render it anonymous. If deletion is not immediately possible, for example because information sits in a backup archive, we isolate it and remove it when the archive cycle completes.
We apply the same discipline to backups and archives. When information is held in a backup, we limit access, keep the backup secure and remove the information when the retention period ends and the backup cycle allows. If a legal hold applies, we preserve the relevant information until the matter is closed, then resume the normal retention schedule.
We review our retention periods periodically and shorten them where we can. The goal is to keep what supports the service, the accounting record and the law, and to remove what no longer serves a purpose. Site partners may ask us about the retention that applies to their program.
10. Data Security Measures
We use technical and organisational measures designed to protect information against loss, misuse, unauthorised access, alteration and disclosure. These measures include encryption of data in transit, access controls that limit information to staff and providers who need it, network segmentation for connected devices, logging of administrative actions and regular review of our practices.
No method of transmission or storage is completely secure. While we work to protect information, we cannot guarantee absolute security. If we become aware of a breach that affects personal information, we will take steps to contain it and will notify affected parties and authorities as required by law. We encourage site partners to keep their own accounts and devices secure and to tell us promptly about any concern.
11. Your Privacy Rights
Depending on where you live, you may have rights to access the personal information we hold about you, to correct it, to delete it, to restrict or object to certain processing, to receive a portable copy and to withdraw consent where consent is the basis for processing. You may also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise a right, contact us using the details at the end of this policy. We will verify your request and respond within the timeframe required by law. We will not discriminate against you for exercising a privacy right. If we cannot fulfil a request, we will explain why, and in some cases you may have a right to appeal or to lodge a complaint with a supervisory authority.
We make it easy to reach the right person. Send your request to the contact details at the end of this policy and describe what you would like us to do. If you are a site partner, you may also raise the request through your usual contact at the desk. We keep a record of privacy requests so we can track them and confirm that they were handled correctly.
If we need more information to verify your identity or to locate the relevant records, we will ask for it and explain why. We aim to fulfil valid requests without unnecessary delay and to keep you informed if a request will take longer than expected because of its complexity or volume.
12. California Privacy Rights
Residents of California may have additional rights under state privacy law. These may include the right to know the categories of personal information collected, the sources of that information, the business purposes for collection and the categories of third parties with whom it is shared. Residents may also have the right to delete personal information, to correct inaccurate information and to opt out of certain sharing.
The Company does not sell personal information as that term is commonly understood, and it does not share personal information for cross context behavioural advertising. To make a request, contact us using the details below. An authorised agent may submit a request on your behalf where the law permits, and we may ask for proof of authorisation and verification of identity before acting.
13. Children and Privacy
Our services are intended for businesses, site operators and adult customers. We do not knowingly collect personal information from children. Vending and kiosk systems are designed for general use and do not require a child to create an account or submit personal details. If you believe a child has provided personal information to us, please contact us so we can review the matter and delete the information where appropriate.
Site partners who operate machines in locations that serve younger visitors should ensure that their own practices, signage and policies are appropriate for their environment. The Company is happy to provide guidance on privacy friendly configuration for such sites.
14. International Data Transfers
The Company is based in the United States, and the information we collect is generally processed and stored in the United States. If information is transferred from another country, we take steps to ensure that the transfer is lawful and that appropriate safeguards are in place. These safeguards may include standard contractual clauses, vendor commitments and technical measures such as encryption.
Where local law requires additional protections, we work with our providers to apply them. If you have questions about where your information is processed, contact us and we will explain the arrangements that apply to your situation.
We choose providers that can support lawful transfers and that apply strong safeguards. Where a provider processes information in another country, we rely on recognised transfer mechanisms and we review the provider arrangements as part of our vendor management. If you would like more detail about the safeguards used for a particular service, we will provide it on request.
Because our operations are concentrated in Utah, most information stays within the United States. When a support tool or platform provider stores data elsewhere, we take steps to ensure the transfer remains protected and that the information is handled to a standard consistent with this policy.
15. Third Party Links
Our website and communications may link to third party sites, portals or applications. We are not responsible for the privacy practices of those third parties, and this policy does not apply to them. We encourage you to read the privacy notices of any third party service you use.
Where we integrate a third party payment or telemetry service into our offering, that provider may process information under its own policy. We select providers with strong privacy and security records, but the terms of their processing are governed by their own agreements with you or with us as applicable.
16. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements or business operations. When we make a material change, we will post the updated policy on this page and revise the date at the top. Where the change significantly affects how we use personal information, we will provide a more prominent notice or contact affected parties directly where appropriate.
We encourage you to review this page periodically. Continued use of our website or services after an update takes effect means you accept the revised policy. If you do not agree with a change, you may stop using the service and contact us to discuss your options.
We keep a dated record of prior versions so that site partners and visitors can see what changed and when. If a change reduces your rights under this policy, we will not apply it retroactively without a lawful basis, and where required we will seek your consent before the change takes effect for you.
If you have questions about a specific update, contact us and we will explain the reason for the change and how it affects the information we hold. We would rather answer a question than leave a site partner uncertain about how their information is handled.
17. How to Contact Us
If you have questions about this policy, wish to exercise a privacy right or want to raise a concern, please contact the Company using the details below. We take privacy enquiries seriously and aim to respond promptly.
KTT Birmingham LLC
1758 S 1900 W Ste B1, West Haven, UT 84401-0371, United States (US)
Email: team@kttbirmingham.surf
Phone: +17433432186
18. Accessibility and Language
The Company wants this policy to be readable and useful. We aim to present it in clear language and in an accessible format. If you need this policy in another format or require assistance understanding it, contact us and we will do our best to help.
This policy is published in English. Where a translation is offered for convenience, the English version governs in the event of any conflict. We review the text regularly to keep it accurate and up to date.
This Privacy Policy forms part of the terms that govern the use of the KTT Birmingham LLC website and services. It should be read together with our Terms of Service. For questions, contact team@kttbirmingham.surf or call +17433432186.