Privacy Policy

Effective date and last updated: September 1, 2026

Torres & Co. Technology LLC (“Torres & Co. Technology,” “we,” “us,” or “our”) is a Portland, Oregon technology company serving businesses and homeowners. This Privacy Policy explains how we handle personal information through our public website at torrescotechnology.com. We seek to collect only information reasonably useful for operating the public site, responding to requests, and protecting our services.

This Privacy Policy is designed to explain our public-website data practices and provide disclosures required by applicable United States federal and state privacy laws, where those laws apply to Torres & Co. Technology. Privacy laws differ by jurisdiction and may apply based on factors such as the nature and volume of personal information processed. Nothing in this Privacy Policy is intended to represent that every privacy statute applies to Torres & Co. Technology.

This policy describes collection, use, disclosure, retention, security, and privacy choices. No security program can guarantee absolute protection.

1. Scope of this Privacy Policy

This policy applies to:

  • The public torrescotechnology.com website and public pages that link directly to this policy;
  • Public contact and consultation forms;
  • The automated public website assistant and messages submitted through it;
  • Public-site analytics, cookies, hosting, content delivery, security, and anti-spam technologies; and
  • Email, telephone, text, or social-media communications initiated through the public website.

This policy does notgovern the authenticated Torres & Co. Technology Client Command Center at admin.torrescotechnology.com or information processed as part of an active client engagement. That excluded information may include client usernames and passwords, project files, contracts, connected Google, Cloudflare, social-media, CRM, scheduling, or business accounts, client dashboards and reports, invoices and authenticated payment records, support information, and data we process on behalf of a client after onboarding. Additional client-facing disclosures and contractual terms may apply when a customer signs up for services or receives access to authenticated tools.

This policy also does not govern third-party websites and services that we do not control.

2. Personal information we collect

Information you provide directly

When you submit a public contact or consultation request, we may collect:

  • Name and business name;
  • Email address and telephone number;
  • Requested service and preferred contact method;
  • Project description, current challenge, and other free-text information; and
  • The date, source page, and submission identifier associated with the request.

When you use the public website assistant, we may collect your chat messages, conversation and session identifiers, message times and status, and—if you request follow-up—your name, email, phone number, company, service needs, and response consent. Communications you later send by email, telephone, text, or social media may also be associated with your request. The current public website does not offer public file uploads, surveys, or a newsletter subscription form.

Information collected automatically

Our hosting, security, and analytics technologies may automatically process:

  • IP address and approximate location derived from IP address;
  • Browser, device, and operating-system information;
  • Pages viewed, links or features used, referral source, and visit date and time;
  • Cookie or similar analytics identifiers; and
  • Server, performance, error, spam-prevention, and security-event logs.

We use this information for public-site operation, analytics, performance, fraud prevention, and security—not to make decisions that produce legal or similarly significant effects about visitors.

Information from other sources

We may receive limited information from analytics providers, referral pages, social-media services when you contact us there, and form-delivery providers that help transmit your request. We do not use this section to describe Client Command Center integrations or information handled during active client work.

Sensitive personal information

The public website is not intended to collect Social Security numbers, government identification numbers, complete payment-card information, financial-account passwords, medical or health records, biometric identifiers, precise geolocation, account passwords, private API keys, or other confidential credentials. Please do not submit this information through a public form or chat. Because free-text fields exist, we cannot guarantee that a visitor will never submit sensitive information voluntarily.

3. How we use personal information

We may use public-site personal information to:

  • Respond to inquiries and determine service needs;
  • Prepare proposals or estimates and schedule consultations;
  • Communicate about a request and provide pre-onboarding support;
  • Operate, maintain, measure, troubleshoot, and improve the public website;
  • Operate the automated website assistant and arrange a requested human follow-up;
  • Detect and prevent spam, fraud, abuse, and security threats;
  • Maintain appropriate business, legal, and security records;
  • Enforce website terms, comply with legal obligations, and protect our company, customers, visitors, and others; and
  • Send marketing communications only when legally permitted and after obtaining any consent required for the communication.

Submitting a contact form does not by itself enroll you in unrelated promotional emails or automated marketing texts. Telephone numbers submitted through the current public form or assistant are used to respond to the request or arrange requested follow-up. We do not currently operate an automated promotional SMS program through the public website. Consent to marketing is not a condition of purchasing services.

4. Cookies, similar technologies, and analytics

The public website currently uses or may use the following categories:

  • Necessary and security technologies: hosting, content delivery, request routing, spam prevention, fraud detection, and security logs used to deliver and protect the site.
  • Functional technologies: temporary in-memory information used to operate the public website assistant. The current widget removes a legacy chat-session value from local and session storage rather than using it as current persistent storage.
  • Analytics: Google Analytics 4 is active and may receive usage information, device and browser data, referral information, IP-derived location, and analytics identifiers or cookies so we can understand traffic and public-site performance.

We did not identify advertising pixels, retargeting tags, session-replay technology, audience-matching code, or public-site advertising campaigns in the current production code. We do not use public-site information for targeted advertising or qualifying profiling. Google may offer browser controls and an analytics opt-out add-on; browser settings can also be used to limit or delete cookies. Blocking some technologies may affect site operation or measurement.

The site does not currently display a broad advertising-cookie banner because no advertising or targeted-advertising technology was identified. If our practices change or consent becomes legally required for a nonessential technology, we will update our controls and this policy.

5. Automated website assistant

The public site includes an automated assistant that can answer questions using approved Torres & Co. information and connect a visitor with a person. Messages, conversation identifiers, contact details voluntarily supplied for follow-up, and related timestamps or status information are transmitted to and processed by the public receptionist service. Conversations may be stored and reviewed as reasonably needed to respond, arrange follow-up, maintain quality, prevent abuse, protect security, and improve the service.

Do not submit passwords, payment information, private client data, medical information, Social Security numbers, private API credentials, or other sensitive information through chat. Automated responses may be incomplete or incorrect and do not create a professional-services agreement. A service relationship begins only through appropriate written agreement or confirmation.

6. How we disclose personal information

We may disclose relevant public-site information to:

  • Hosting, content-delivery, and security providers, including Cloudflare and the site-hosting platform, to deliver and protect the website;
  • Form and communications providers, including Formspree, to transmit consultation requests and notifications;
  • Analytics providers, including Google Analytics, to measure public-site usage and performance;
  • Public receptionist and business-intake systems used by Torres & Co. Technology to receive chat messages and consultation requests;
  • Professional advisers such as attorneys, accountants, insurers, and security professionals when reasonably necessary;
  • Government agencies, courts, or legal authorities when disclosure is required or permitted by law;
  • Parties to a business transaction involving a proposed or completed merger, financing, acquisition, reorganization, or transfer of assets, subject to appropriate safeguards; and
  • Other parties at your direction or with your permission.

Vendors processing information for us are different from external websites you choose to visit. External services—including social media, client websites, Google services, Square, and Cash App Afterpay—operate under their own privacy policies when you interact with them directly.

7. Square, Cash App Afterpay, and payment information

Torres & Co. Technology does not collect or store complete payment-card information through its public website.

Eligible clients may later receive an invoice or payment link from an independent payment provider such as Square and may be offered Cash App Afterpay, subject to provider eligibility and approval. Information entered on a provider’s website is governed by that provider’s privacy policy. Describing payment options on torrescotechnology.com does not mean that the public website collects card details or controls Afterpay’s approval process. Payment and invoice records associated with an active client relationship fall outside this public-site policy and may be addressed by client documentation.

8. Sale, sharing, targeted advertising, and financial incentives

We do not currently sell personal information for money. Based on the public-site technologies identified in our current code, we do not share personal information for cross-context behavioral advertising, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects. We use Google Analytics for general site measurement, not an advertising pixel or retargeting campaign. We do not offer a privacy-related financial incentive or loyalty program through the public website.

If these practices change, we will update this policy and provide legally required notices and choices before applying a materially different practice.

Global Privacy Control and Do Not Track

Because the current public site does not engage in a sale, cross-context behavioral advertising, or targeted advertising, there is presently no applicable sale or targeted-advertising processing for a Global Privacy Control signal to opt out of, and the site does not alter its behavior in response to that signal. If we adopt applicable processing, we will implement legally required opt-out preference-signal recognition. Browsers may also send “Do Not Track” signals, but there is no uniform industry standard for responding to them. The current site does not change behavior in response to Do Not Track. Third parties that provide hosting, security, or analytics may collect information through the site as described above.

9. Data retention

Retention depends on the category and context. We generally consider the time needed to respond to an inquiry; whether the visitor becomes a client; the duration of related communications; legal, tax, accounting, insurance, and contractual requirements; applicable limitation periods; dispute prevention; security and fraud-prevention needs; provider and backup cycles; and the need to document privacy requests. We do not use an invented single retention period for every category.

We delete or de-identify information when it is no longer reasonably needed, subject to legal, contractual, security, backup, dispute, and recordkeeping exceptions. A deletion request may therefore not result in immediate removal from every backup or legally required record.

10. Security and data-breach notices

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. No internet transmission or storage system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur. If a data breach requires notice under applicable law, we will provide notice as required by that law.

11. Children’s privacy

The public website is directed to businesses, homeowners, and adults seeking technology services—not children. We do not knowingly collect personal information from children under 13 through the public website, and the site does not perform age verification. A parent or guardian who believes a child submitted information may request deletion using the contact information below.

12. Third-party websites and services

The public website may link to client websites, Instagram or other social-media services, Google, Square, Cash App Afterpay, review providers, and other external websites. We do not control or endorse every privacy practice of those companies. Review their privacy notices before submitting information directly to them.

13. State privacy rights

Depending on your state, the type and volume of information processed, and whether the relevant law applies to Torres & Co. Technology, you may have rights to:

  • Confirm whether we process your personal information and access it;
  • Correct inaccuracies or request deletion;
  • Obtain a portable copy where required;
  • Learn the categories of information collected, sources, purposes, and categories of recipients;
  • Learn specific third parties to which information was disclosed when required by law;
  • Opt out of sales, targeted advertising, or qualifying profiling;
  • Limit certain uses of sensitive personal information;
  • Withdraw consent where processing is based on consent;
  • Use an authorized agent and appeal a denied request where applicable; and
  • Receive equal service without unlawful discrimination for exercising privacy rights.

Legal exceptions may apply. We may voluntarily honor appropriate access, correction, and deletion requests from U.S. residents even when a particular comprehensive state privacy law does not apply. Doing so does not concede that a specific statute applies to us.

14. California privacy disclosures

During the preceding 12 months, the public site may have collected these California categories:

  • Identifiers: name, business name, email, phone number, IP address, submission or chat identifiers;
  • Customer-record information: contact and business information voluntarily provided;
  • Commercial information: requested services, project interests, and inquiry history;
  • Internet or electronic activity: pages viewed, interactions, referral information, device/browser data, and logs;
  • Approximate geolocation: general location inferred from IP address;
  • Professional or employment-related information: company or role information voluntarily included in an inquiry; and
  • Inferences: limited conclusions about likely service needs based on information you submit.

Sources include you, your device/browser, referral pages, analytics services, and form or communications providers. Purposes are described in Section 3. Recipient categories are described in Section 6. Retention is based on the criteria in Section 9. We do not currently sell these categories or share them for cross-context behavioral advertising, and we do not use or disclose sensitive personal information to infer characteristics about visitors.

Where the California Consumer Privacy Act applies, California residents may exercise applicable access, correction, deletion, portability, sale/sharing opt-out, limitation, authorized-agent, and non-discrimination rights using Section 16. Nothing here states that Torres & Co. Technology necessarily meets the statutory thresholds of a CCPA-covered business.

California’s “Shine the Light” law permits certain requests concerning disclosures for third parties’ own direct-marketing purposes. We do not currently disclose public-site personal information to third parties for their own direct marketing. Our Do Not Track and third-party collection disclosures appear in Section 8. We do not offer a privacy-related financial incentive through the public site.

15. Nevada and other state disclosures

Nevada residents may submit a verified request to opt out of a future covered sale under Nevada law. We do not currently engage in a covered sale of public-site personal information. Residents of other states may use the same request process for rights available under applicable law.

16. How to submit a privacy request

Email info@torrescotechnology.com with the subject “Privacy Request,” or call (408) 594-6707. Include your name, the email or telephone number used to contact us, your state of residence, the right you wish to exercise, and enough detail for us to locate the relevant public-site information.

We may request information reasonably necessary to verify your identity and authority, but we will not require a Client Command Center account. An authorized agent should identify the person represented and provide legally sufficient proof of authority; we may verify the request directly with the resident when permitted. We will respond within the period required by applicable law. Where an appeal right applies, reply to our decision with “Privacy Appeal” and explain the reason for the appeal. We may retain a record of the request for compliance, fraud-prevention, and security purposes.

17. International visitors

Torres & Co. Technology is based in the United States. Information submitted through the public website may be processed in the United States and other locations used by our service providers. This policy does not claim compliance with the GDPR, UK GDPR, Canadian privacy laws, or every international privacy regime.

18. Changes to this policy

We may update this policy as our public-site practices, services, providers, or legal requirements change. We will revise the “last updated” date and may provide additional notice for material changes when appropriate. Please review this page periodically. Continued site use is not treated as consent where affirmative consent is legally required.

19. Contact us

Questions and privacy requests may be sent to:

Torres & Co. Technology LLC
Portland, Oregon
info@torrescotechnology.com
(408) 594-6707
Back to home