LastFolk — Privacy Policy
Last updated: August 4, 2026
This Privacy Policy explains how Pictorica Devs LLC, a Wyoming limited liability company doing business as LastFolk ("LastFolk", "we", "us", or "our"), collects, uses, discloses, and protects personal information in connection with the LastFolk delivery-operations platform and related applications, websites, and services (collectively, the "Service").
1. Who we are and how to contact us
LastFolk is operated by Pictorica Devs LLC. LastFolk connects online stores ("Merchants") with third-party courier networks to enable local delivery, and provides rating, dispatch, tracking, and reconciliation functionality.
For any privacy question or to exercise your rights, contact our designated Data Protection Officer / privacy contact:
- Email: contact@lastfolk.com
- Entity: Pictorica Devs LLC, 30 North Gould Street, Sheridan, Wyoming, United States
The Data Protection Officer function is handled internally by Pictorica Devs LLC and is responsible for data-protection matters across LastFolk and its affiliated entities. You can reach it at the email above.
EU / UK representatives. LastFolk is operated by Pictorica Devs LLC, established in the United States. As required under Article 27 of the EU GDPR and the UK GDPR, we have appointed DataRep (Data Protection Representative Limited, trading as DataRep) as our Data Protection Representative in the EU/EEA and the United Kingdom. You may contact our Representative:
- EU/EEA representative — DataRep: by email at datarequest@datarep.com (please quote "LastFolk; pictorica.dev" in the subject line), via the webform at www.datarep.com/data-request, or by post to "DataRep", The Cube, Monahan Road, Cork, T12 H1XY, Ireland. DataRep maintains contact locations in every EU/EEA member state.
- UK representative — DataRep: by email at datarequest@datarep.com (quote "LastFolk; pictorica.dev"), via www.datarep.com/data-request, or by post to "DataRep", 107-111 Fleet Street, London, EC4A 2AB, United Kingdom.
Please address postal correspondence to "DataRep" (not to LastFolk or Pictorica Devs LLC directly), or it may not reach the Representative.
2. Scope
This Policy applies to:
- Merchants — store owners and their authorized users who install or use LastFolk.
- End Customers — individuals who place orders with a Merchant that are fulfilled through LastFolk.
- Website visitors — people who visit our public websites.
Where LastFolk processes End Customer data on behalf of a Merchant to fulfill deliveries, LastFolk generally acts as a processor/service provider and the Merchant is the controller/business. Where LastFolk determines the purposes of processing (for example, for its own security, billing, and product operation), LastFolk acts as a controller/business.
3. Information we collect
3.1 Information Merchants provide. Account and contact details (name, business name, email, phone), store URL and platform, billing identifiers, plan selection, and — where applicable — credentials or connection tokens for third-party services the Merchant chooses to connect (including a Merchant's own courier account under "bring your own" configurations).
3.2 End Customer delivery information. To rate and fulfill a delivery, we process order and delivery details such as recipient name, delivery and pickup addresses, contact phone, package attributes (size/weight), order identifiers, delivery status, and tracking events. We process this on the Merchant's behalf.
3.3 Payment-related identifiers. We do not store full card numbers. Payment is processed by a third-party payment processor. We may store non-sensitive identifiers (such as a customer or payment-method reference ID) needed for billing and reconciliation.
3.4 Technical and usage data. IP address, device and browser data, log data, timestamps, and product usage events, used to operate, secure, and improve the Service.
3.5 CCPA/CPRA categories. For California residents, the personal information above falls within these statutory categories: identifiers (name, email, phone, IP address); commercial information (plan and billing identifiers); internet or network activity (usage and log data); geolocation data (delivery and pickup addresses); and professional or business information (store details). We do not collect sensitive personal information beyond what is described, and we do not sell personal information. We do not currently "share" personal information as that term is defined under the CPRA — that is, we do not disclose personal information for cross-context behavioral advertising, and we do not build or export advertising audience lists. We do measure the effectiveness of our own advertising: when a visitor arrives from an ad, we may process advertising click identifiers to attribute a resulting sign-up to the campaign that produced it. Sources are the Merchant, the End Customer's order, and automatic collection; purposes are described in Section 4.
4. How we use information
We use personal information to: provide and operate the Service (rating, dispatch, tracking, reconciliation); create and manage accounts; process billing and reconcile charges; communicate service, transactional, and support messages; provide customer support; maintain security, prevent fraud and abuse; measure the effectiveness of our advertising and attribute sign-ups and other conversions to the campaigns that produced them; comply with legal obligations; and improve and develop the Service.
We do not sell personal information, and we do not use End Customer delivery data for advertising.
5. Legal bases for processing (EEA/UK)
Where GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Service); legitimate interests (to secure, operate, and improve the Service, balanced against your rights); legal obligation (to comply with law); and consent where required (which you may withdraw at any time).
6. How we share information
We share personal information only as needed to run the Service, with the following categories of recipients (we work with vetted subprocessors and do not sell your data):
- Third-party courier networks — to dispatch and fulfill deliveries. Recipient and pickup details are shared with the courier assigned to a delivery.
- Payment processor — to charge fees and reconcile payments.
- Cloud hosting and infrastructure providers — to host and operate the Service.
- Address and mapping services — to validate and geocode addresses for accurate rating and routing.
- Analytics, communications, and error-monitoring providers — to operate, support, and secure the Service.
- Advertising and measurement providers — to deliver our advertising and measure its effectiveness, including attributing sign-ups to the campaign that produced them.
- Professional advisors, and authorities — where required by law, to protect our rights, or in connection with a corporate transaction.
The categories of recipients listed above reflect our current subprocessors. We maintain a current list of specific subprocessors, available to Merchants on request via contact@lastfolk.com. Where LastFolk acts as a processor, we will give Merchants advance notice of any intended addition or replacement of a subprocessor and an opportunity to object, as set out in our Data Processing Agreement (available at /dpa).
7. International data transfers
The Service is operated from, and data may be processed in, the United States and other countries. Where we transfer personal data across borders, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses (2021) for transfers from the EEA, the UK International Data Transfer Addendum (IDTA) for transfers from the United Kingdom, and, for other jurisdictions, adequacy decisions or other lawful transfer mechanisms. Where required, we conduct a transfer impact assessment and apply supplementary measures. A copy of the relevant transfer mechanism is available to Merchants on request.
8. Data retention
We retain personal information for as long as needed to provide the Service, comply with legal, tax, accounting, and reconciliation obligations, resolve disputes, and enforce our agreements. When no longer needed, we delete or anonymize it. Merchants may request deletion of End Customer data they control, subject to our legal retention needs.
9. Security
We use technical and organizational measures to protect personal information, including encryption in transit (TLS/HTTPS) and at rest, access controls and role-based access, and least-privilege practices. No system is perfectly secure; we cannot guarantee absolute security, but we work to protect your information and to notify affected parties of incidents as required by law.
10. Your rights
EEA/UK (GDPR): you may request access, correction, deletion, restriction, portability, and objection, and may lodge a complaint with a supervisory authority.
California (CCPA/CPRA): you may request to know, access, correct, and delete personal information, and to opt out of "sale" or "sharing" (we do not sell or share personal information as defined by law). You may use an authorized agent to submit a request on your behalf. We will not discriminate against you for exercising your rights.
Other U.S. states: residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and others) have similar rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. If we deny a request, you may appeal that decision by contacting us at contact@lastfolk.com; if your appeal is denied, you may contact your state attorney general.
Brazil (LGPD): individuals in Brazil have rights of confirmation, access, correction, anonymization, portability, deletion, and information about data sharing, and may contact the Brazilian National Data Protection Authority (ANPD).
To exercise any right, contact contact@lastfolk.com. Where LastFolk processes data on behalf of a Merchant, we will direct End Customer requests to the relevant Merchant or assist the Merchant in responding.
11. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
12. Cookies and similar technologies
Our websites and application use cookies and similar technologies. Strictly necessary cookies (for authentication, security, and core functionality) are always active because the Service cannot work without them. Non-essential cookies (such as analytics, preference, and marketing/advertising cookies) are used only where permitted: for visitors in the EEA and UK, we set non-essential cookies only after you give consent through our cookie banner, and you may withdraw consent at any time. Marketing cookies and advertising identifiers — including advertising click identifiers used to attribute a sign-up to the campaign that produced it — are set only with your marketing consent. Two copies of such an identifier may exist, and they are governed separately: the copy stored in your browser is deleted immediately when you withdraw marketing consent, and in any case expires no later than 90 days after it was captured; where the identifier has already been attached to an enquiry or record you submitted, it is kept alongside that record for no more than 90 days from capture and is then erased automatically. You can also control cookies through your browser settings; disabling some cookies may affect functionality. Our cookie banner lets you review and change your choices at any time.
13. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, provide additional notice. Continued use of the Service after changes take effect constitutes acceptance.
14. Contact
Pictorica Devs LLC (LastFolk) — Privacy contact: contact@lastfolk.com — 30 North Gould Street, Sheridan, Wyoming, United States.
