Privacy

Privacy Policy

Effective date: May 31, 2026  ·  Last updated: May 31, 2026

This Privacy Policy explains how ToyBox Consulting & Management, LLC ("ToyBox," "we," "us," or "our") collects, uses, and shares information when you visit or interact with our websites:

and any related subdomains, event landing pages, email lists, or services we operate (collectively, the "Services").

Questions? Contact us at katoya@toyboxconsulting.net or by mail at ToyBox Consulting & Management, LLC, 1428 140th Ct SE, Bellevue, WA 98007.

Quick links: Washington residents — see Section 10 (My Health My Data Act). California residents — see Section 11 (CCPA/CPRA). Other US states — see Section 12.

1. Information we collect

We collect three categories of information:

(a) Information you give us directly. When you subscribe to a newsletter, fill out a contact form, RSVP through Eventbrite, schedule through Calendly, email us, or submit a sponsorship/performer/vendor inquiry, you may give us your name, email address, phone number, organization, role, geographic region, and the substance of your message.

(b) Information collected automatically. When you visit our Services, we and our analytics providers collect technical and usage data including IP address, browser type, device type, operating system, referrer URL, pages viewed, time spent, clicks, scroll depth, and approximate location derived from IP address. We use:

See our Cookie Notice for details on each tool and how to opt out.

(c) Information from integrated services. When you book through Calendly, RSVP through Eventbrite, subscribe through Substack, watch an embedded Vimeo video, or follow a link to our social profiles (LinkedIn, TikTok, Instagram), those third parties collect data under their own privacy policies. We receive limited reporting data from them.

2. How we use information

We do not sell your personal information for money. We may "share" personal information for cross-context behavioral advertising (as defined under CCPA) through Bing UET, Google Analytics 4, and similar tools. You can opt out — see Section 11.

3. Legal bases (for users in Europe / UK)

Where European or UK data protection law applies, we rely on: consent for non-essential cookies and marketing emails; contract for delivering services you request; legitimate interests for security, fraud prevention, and improvement; legal obligation where required. You may withdraw consent at any time.

4. How we share information

We do not share consumer health data (as defined under WA MHMDA) without your express written consent. See Section 10.

5. Cookies and similar technologies

See our Cookie Notice for the full inventory. You can manage your choices through our cookie consent banner. We honor the Global Privacy Control (GPC) signal as an opt-out of "sharing" for cross-context behavioral advertising.

6. Your choices

7. Data retention

We keep information only as long as needed to fulfill the purposes described in this policy or to meet legal, tax, accounting, or contract obligations. Marketing list subscribers are retained until they unsubscribe. Inquiries are retained for up to 7 years for accounting and recordkeeping. Analytics data is retained per the platform's setting (typically 14–26 months for GA4).

8. Security

We use industry-standard administrative, technical, and physical safeguards. No system is perfectly secure. If we learn of a data breach affecting your information, we will notify you and regulators as required by Washington law (RCW 19.255) and other applicable laws.

9. Children

The Services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us and we will delete it.

For family-friendly events (e.g., Golden Hour Unboxed), photography may capture children attending in a public setting. We do not knowingly use children's images in marketing without a parent's consent. To request removal of an image, email us.

10. Washington My Health My Data Act notice

This section applies to Washington residents and to consumers whose consumer health data we collect or process in Washington.

(a) Categories of consumer health data we collect. We do not knowingly collect biometric data or precise location data. We may collect inferences from form fields, email content, or visited content that suggest interest in mindfulness, mental wellness, caregiving, or related personal practices — for example, when you subscribe to mindfulness-themed content or contact us about Mindfulness in the Middle programming. This may constitute "consumer health data" under RCW 19.373.

(b) Sources. Directly from you (forms, emails) and automatically from your interactions with content tagged as wellness or mindfulness.

(c) Categories of consumer health data we share. None for advertising. We share with service providers (email platform, analytics) under contract, only as needed to deliver the service.

(d) How to exercise your rights. Washington consumers may: (i) confirm whether we are processing their consumer health data; (ii) access that data; (iii) request deletion; (iv) withdraw consent. Email katoya@toyboxconsulting.net with the subject line "WA MHMDA Request." We will verify and respond within 45 days.

(e) Right to appeal. If we decline a request, you may appeal by replying to our response. You may also file a complaint with the Washington State Attorney General at atg.wa.gov.

(f) No sale. We do not sell consumer health data and will not without separate written authorization meeting RCW 19.373.030's standard.

(g) Geofence. We do not use a geofence around any in-person health-care location.

11. California (CCPA / CPRA) notice

California residents have the right to: know what personal information we collect, use, share, or sell; delete personal information; correct inaccurate personal information; opt out of "sale" or "sharing" for cross-context behavioral advertising; limit use of sensitive personal information; and non-discrimination for exercising rights.

Categories of personal information collected in the last 12 months: identifiers (name, email, IP, device IDs), commercial information (subscriptions, RSVPs), internet activity (pages viewed, clicks), geolocation (approximate, from IP), professional information (organization, role), inferences.

Categories sold/shared: none sold for money; internet activity and identifiers may be "shared" for cross-context behavioral advertising via Google and Microsoft tools.

To exercise rights: Use the "Do Not Sell or Share My Personal Information" link in the footer, or email katoya@toyboxconsulting.net with subject "California Privacy Request." We will verify identity and respond within 45 days. Authorized agents may submit requests on your behalf with written authorization.

12. Other US states

Residents of Colorado, Connecticut, Oregon, Utah, Virginia, and other states with comprehensive consumer privacy laws have rights similar to the California rights above. To exercise, email katoya@toyboxconsulting.net with subject "State Privacy Request." We honor the GPC universal opt-out signal where required by state law.

13. International transfers

We are based in Washington State, USA. If you access the Services from outside the US, your information will be transferred to and processed in the US under US law, which may differ from the law of your country.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new effective date at the top. Material changes will be highlighted on the website for at least 30 days.

15. Contact

ToyBox Consulting & Management, LLC
1428 140th Ct SE
Bellevue, WA 98007
katoya@toyboxconsulting.net