Privacy Policy

Effective: May 25, 2018


Is Toymail Secure?

Toymail Co takes security seriously and cares about the integrity of your personal information.

Talkies by Toymail are certified by the iKeepSafe Seal Program. To learn more, visit

Talkies are built on top of a platform certified to UL-2900-2-2 standard for Cybersecurity.

We use commercially reasonable physical, administrative, and technological methods to transmit your data securely including HTTPS, SSL, and 128bit encryption. The data is stored using Amazon’s S3 cloud service (AWS infrastructure). While Amazon provides security around that infrastructure which prevents unauthorized access to it, just being on AWS does not guarantee security. Our engineers have implemented AWS in a fashion that enables us to avail of proper security processes.

Toymail follows all the best practices when it comes to security. We secure our infrastructure accounts, servers and databases with complex protocol and passwords. We preform automated deployments and security upgrades in order to minimize any possible "user error" when performing maintenance or upgrades.

We would like to stress again that we take the security of your data very seriously. In addition to taking all of the precautions and following best practices on our end, we have had independent third-party entities audit our system for security vulnerabilities, as well as follow COPPA compliance procedures.

If you have any questions, please let us know. We're here to help!

What personal information is collected from children under 13?

Users under 13 are expected to use the Toymail app under their parent/guardian's account. As a result, we do not knowingly collect emails or other contact information directly from children under 13. When children use Toymail app, audio recordings are captured as part of its use.

What controls do parents have over account information and content?

Children under 13 are not authorized to create their own accounts, but instead must use their parent's account. Therefore, parents have full control over all account information and content for children under 13. Parents may review and delete audio files in their account and may also permanently delete their accounts by emailing us at

When you set up your app user account, your password is encrypted. If you need to reset your password, you will need to confirm it via e-mail.


We're serious about keeping things private.

This page explains what kind of information Toymail, Inc. and its subsidiaries and affiliates (collectively, "Toymail") collects and stores, including Personally Identifiable Information (i.e., data that can be reasonably linked to a specific individual or household) in connection with the operation of the the Toymail app and our toys, the Mailmen™ and Talkies™ (collectively, "Toymail Products").

We want you to know that we will always:

  • Be transparent about the different types of information we collect and how we use them.
  • Ask your permission before sharing your Personally Identifiable Information with third parties for purposes other than to provide Toymail's services, and to do so only when we think they will provide you with a welcome additional service.
  • Use best-in-class data security tools to keep your data safe and protect the Toymail Products from unauthorized access.
  • By using this service, you agree to allow us to collect and process information as described below.

What information does Toymail ask for?

  • Information input during toy setup using the Toymail app including name and image associated with the toy in use.
  • Information input during toy setup in conjunction with the Toycloud in the Toymail app including your child's birthday, timezone, and soundbite of the child's name.
  • To access your Toymail Product over the Internet from a smartphone or a tablet, you will need to connect it to your Wi-Fi network. During setup, we will ask for your Wi-Fi network name (SSID) and password to connect to the Internet. It will save this information on the device, along with your IP address, so that you can access it and control it from your smartphone or tablet, and so that it can communicate with Toymail servers and download software updates.
  • Additionally, when you create a Toymail Account, we collect and store your email address. From that point forward, your email address is used for communications from Toymail  You are responsible for maintaining the confidentiality of your login ID and password. Like most Internet sites, we routinely record log entries (including information such as your IP address) and technical information (such as your browser type and version) when your browser, mobile device or Toymail Product contacts our servers. These log files are used for troubleshooting and are stored on our cloud servers.
  • Payment processing information is collected when you purchase through our site, though not stored beyond processing.

What information does Toymail collect?

  • We record your Toymail device ID and software version as necessary.
  • Once connected to your Wi-Fi network, your Toymail Product regularly uploads to Toymail cloud servers the data mentioned above (excluding your Wi-Fi password) to provide you with the service. Incoming and outgoing messages are stored in the Toymail app for your retrieval and playback.
  • Cookie and Usage Data for us with Google Analytics.
  • Email addresses when you sign up to the Toymail Email list.

How does Toymail use the information it collects?

We use this information to provide and improve Toymail Products and services. We may use your email address to send you this information, or to ask you to participate in surveys about your Toymail use. We use service providers to perform some of these functions. Those service providers are restricted from sharing your information for any other purpose.

We use industry-standard methods to keep this information safe and secure while transmitted over your home network and through the Internet to our cloud servers.'

How long does Toymail save my personal information and how can I delete it?

Toymail stores your Personally Identifiable Information on Toymail's cloud servers for as long as you remain a Toymail customer in order to provide you with the service. As described above, some information is stored directly on the Toymail device. All information is encrypted and cannot easily be accessed. You can delete the information on the Toymail device by deleting the associated child from your app.

You have the right to review, have deleted and/or refuse to permit further collection or use of your child’s information. If you refuse collection of data or stop further collection your child will no longer be able to send voice messages via their Talkie. 

To delete your Personally Identifiable Information from Toymail's servers, please request this in writing from the same email used to create your Toymail account.  Because of the way we maintain certain services, after your information is deleted, backup copies may linger for some time before they are deleted.

Please send requests about information collected or deletion requests to our main operator:

Toymail will notify customers of any material change in the collection, use, or disclosure practices to which they have previously consented.

Toymail, Inc
847 Sumpter Road #5032
Belleville, MI 48111

If you have additional questions or have a complaint related to our privacy policy and practices, please contact

Toymail will notify customers of any material change in the collection, use, or disclosure practices to which they have previously consented.

For complete information, please review our TERMS OF USE page.


We're serious about keeping your information safe and secure.

Under no circumstance do we share Personally Identifiable Information for any commercial or marketing purpose unrelated to the delivery of Toymail Products and services. Period. We do not rent or sell our customer lists.

Our service technicians and other Toymail employees have supervised access to your information so they can answer your questions if you contact us for help and so they can monitor our servers for technical problems.

Except as described herein, we will only provide Personally Identifiable Information about our users to a third party if required to do so by law, or in the good-faith belief that such action is necessary to comply with state and federal laws or respond to a court order, subpoena, or search warrant.

We may share your aggregated and anonymous information in a variety of ways, including to publish trends and improve our system. We've taken steps to ensure that the information cannot be linked back to you and we require our partners to keep all information in its anonymous form.

Your personal information may be collected, processed and stored by Toymail or its service providers in the United States and other countries where our servers reside. As a result, your personal information may be subject to legal requirements, including lawful requirements to disclose personal information to government authorities, in those jurisdictions. If you select an outside party for the purchase, installation, or service of your Toymail device and share your personal information, we cannot control the collection, storage or sharing of information collected by that party. For example, if you bought your toy from a retailer, they may collect personal information as part of the transaction. Or the party that installed the device may retain information that you provided to them to assist them in servicing the device if needed. Always check the privacy policies for any company that collects your personal information.

In order to help Toymail provide, maintain, protect and improve our services, Toymail shares information with other partners, vendors and trusted organizations to process it on our behalf in accordance with our instructions, and any other appropriate confidentiality, security or other requirements we deem appropriate.  These companies will only have access to the information they need to provide Toymail service.

You can find information on these partners and service providers we work with below, including what data we share with them or they provide to us, the service the provide for Toymail and links to their respective privacy policies. This list may change over time, and we’ll work hard to keep it up-to-date. If you have any questions, please get in touch here.


AWS for providing servers, databases and network infrastructure for storage, service delivery and other related services.
  • Info Shared: All customer data related to the Toymail application is stored on Amazon Web Services. 

mLab for managing the database services (the data itself is stored on AWS).

  • Info Shared: All customer data related to the Toymail application is stored in databases managed by mLab. All personal data is stored in databases residing in AWS. mLab provides tools to manage the scaling, backup, and maintenance of these databases.


Asana for managing our technical support tickets.
  • Info Shared: Customer information (email, device id) and other details related to customer issue like logs.


     Freshdesk for managing our technical support tickets.

    • Info Shared: Customer information (email, device id) and other details related to customer issue like logs.


    Apple for mobile app downloads and in-app purchases.

    • Info Shared: Customer information (device id), usage data, crash logs.


    Google (Gmail) for email service.

    • Info Shared: Customer information (email, device id) and other details related to customer issue like logs.


    Google for mobile app downloads and in-app purchases.

    • Info Shared: Customer information (device id), usage data, crash logs.


    MailChimp for sending email messages.

    • Info Shared: Customer email


    CleverTap for sending email messages, push notifications and analytics and customer support.

    • Info Shared: Device information, OS information, event and crash logs, user id for support.


    Segment for analytics and customer support.
    • Info Shared: Device information, OS information, event and crash logs, user id for support.


    Amplitude for analytics and customer support.
    • Info Shared: Device information, OS information, event and crash logs, user id for support.


    Whiplash for providing shipping services.
    • Info Shared: Customer info (name, address, phone number), order details (weight).


    Shopify for hosting our website and order processing.
    • Info Shared: Customer info (name, email, address, phone number), order details, credit card.


    Loggly for device logs for technical support.
    • Info Shared: Device info, event and crash logs, user id and troubleshooting data for support.


    ElectricImp for device provisioning, pairing and networking services.
    • Info Shared: Device and network configuration information.


    Stripe for processing credit card transactions for age verification.
    • Info Shared: Customer information (name, email, id), credit card.


    AudioBurst for receiving podcasts.
    • Info Received: Audio clips from selected podcasts for fun facts and stories.


    Facebook for user registration and friends.
    • Info Received: Customer information (name, email), list of Facebook friends who are also registered on Toymail.


    Conctr for device logs and technical support.
    • Info Sent: Device info, event and crash logs, user id and troubleshooting data for support.


    This section applies solely if you are an individual located in the European Union or any jurisdiction in which the General Data Protection Regulation ("GDPR") (or a law or regulation implementing the General Data Protection Regulation 2016/679) ("EU Data Subject").

    Data Controller

    Toymail is the data controller for processing of Personal Data (as defined in the GDPR) of our Customers and job applicants. We act as a data processor on behalf of Customers when we process any end users Personal Data for the purpose of providing the Service to Customers in accordance with the applicable Customer contract.

    Your Rights

    For Personal Data that we process as a data controller, you may have the following rights in relation to your Personal Data, depending on applicable law:

    Right of access If you ask us, we will confirm whether we are processing your Personal Data and, if so, provide you with a copy of that Personal Data (along with certain other details).

    Right to rectification If your Personal Data is inaccurate or incomplete, you are entitled to ask that we correct or complete it.

    Right to erasure You may ask us to delete or remove your Personal Data in some circumstances.

    Right to restrict processing You may ask us to restrict or block the processing of your Personal Data in certain circumstances, such as where you contest the accuracy of that Personal Data or object to us processing it (but not continuing to store it). We will tell you before we lift any restriction on processing.

    Right to data portability You may have the right to obtain the Personal Data we process about you in a structured, commonly used and machine-readable format, and to reuse it elsewhere.

    Right to object You may ask us at any time to stop processing your Personal Data, and we will do so, if we are:

    • relying on legitimate interests to process your Personal Data and we cant otherwise demonstrate compelling legal grounds for the processing; or
    • processing your Personal Data for direct marketing.

    Right to withdraw consent If we rely on your consent as our legal basis for processing your Personal Data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on your prior consent.

    Right to lodge a complaint with the data protection authority If you have a concern about any aspect of our privacy practices, including the way we have handled your Personal Data, you can report it to the data protection authority that is authorized to hear those concerns.

    You may exercise your rights by contacting us as follows:

    Legal Bases

    The legal bases for using your information as set out in this Privacy Policy are as follows:

    • Where use of your information is necessary to comply with a legal obligation under EU Member State law (e.g., to provide information to EU tax authorities about revenue and purchases originating in the EU)
    • Where use of your information is necessary to perform our obligations under a contract with you (for example, to comply with: the terms of service of our websites which you accept by browsing the websites/registering; and/or our contract to provide our Service to you); or
    • Where use of your information is necessary for our legitimate interests or the legitimate interests of others (for example, to provide security for our websites, products, software, or applications; operate our business and our Services; make and receive payments; comply with legal requirements and defend our legal rights; prevent fraud and to know the customer to whom we are providing Services).
    • Where we have your consent to engage in a particular processing activity.

      Updated: 05.23.2018