Privacy Policy
This Privacy Policy explains how [Company Name] collects, uses, and shares information when individuals use our website and Services, including checkout via Stripe, optional account features, marketing emails, and limited, privacy‑respecting analytics.
Information We Collect
Information provided directly: email address, name, shipping/billing addresses, order details, optional account data, and support messages.
Payment information: payment method details are processed by Stripe; we receive limited information such as the last four digits of a card, brand, status, and transaction identifiers. We do not store full card numbers.
Analytics and device data: IP address (truncated or hashed where feasible), user agent, pages visited, timestamps, and referrer, collected in a privacy‑respecting manner without cross‑site tracking or third‑party advertising cookies. We minimize identifiers and avoid building cross‑site profiles.
Cookies and similar technologies: we use strictly necessary cookies for core functions (e.g., cart, session) and limited first‑party analytics that do not track users across sites. Where required, we present notices and obtain consent.
How We Use Information
Provide Services: process orders, fulfill shipments, enable checkout, and operate accounts.
Communicate: send transactional messages (e.g., receipts, account notices) and marketing emails if permitted by law, with an unsubscribe link in each marketing email.
Safety, security, and compliance: prevent fraud, enforce policies, and comply with legal obligations and industry standards.
Improve Services: measure performance and user experience using aggregated or de‑identified analytics wherever possible.
Legal Bases (where applicable)
Performance of a contract (e.g., to process an order).
Legitimate interests (e.g., to secure our Services and perform limited first‑party analytics with strong privacy safeguards).
Consent (e.g., when required for certain cookies or marketing communications in specific jurisdictions).
How We Share Information
Service providers: with vendors who help operate our Services (e.g., Stripe for payments, email service providers, hosting), subject to contractual confidentiality and security requirements.
Legal process and protection: to comply with law, respond to lawful requests, or protect our rights and users.
Business transfers: in connection with a merger, acquisition, or asset sale, consistent with this Policy and applicable law.
We do not sell email addresses of those who have unsubscribed from marketing, and we honor unsubscribe requests.
Marketing Emails and Unsubscribe
If an email is provided, we may send marketing messages about products, promotions, and updates as permitted by law; each marketing email includes a clear unsubscribe link. Unsubscribe requests are processed within 10 business days; transactional emails (e.g., receipts, order updates) may still be sent. A valid physical mailing address is included in marketing emails.
Cookies and Analytics
Necessary cookies: enable core functionality (e.g., cart, session, security) and cannot be disabled in our systems.
First‑party analytics: privacy‑first measurement with minimal data, no third‑party advertising cookies, and no cross‑site tracking; where required, consent banners or mechanisms are provided. Opt‑out options are available where feasible.
Transparency: we document analytics practices and review them for compliance with evolving laws and browser policies.
Data Retention
We retain order and account records as necessary for business needs, legal obligations (e.g., tax), dispute resolution, and security; marketing email data is retained until unsubscribed or no longer necessary. Retention periods are reviewed periodically.
Security
We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of the data, and rely on secure payment processing by Stripe for payment transactions. No method of transmission or storage is 100% secure.
User Choices and Rights
Marketing: unsubscribe at any time using the link in any marketing email.
Cookies/analytics: use browser controls or provided settings to manage cookies; where required, consent tools are offered for non‑essential cookies.
Access, correction, deletion: requests may be submitted to [Contact Email]; identity verification may be required, and legal exceptions may apply.
Children's Privacy
Our Services are not directed to children under 13, and we do not knowingly collect personal information from them; if discovered, we will delete it.
International Transfers
If data is transferred internationally, we use appropriate safeguards consistent with applicable law (e.g., contractual protections) and assess vendor practices.
Third‑Party Links and Features
Our Services may link to third‑party sites or include third‑party features; their privacy practices govern data collected by those parties.
Changes to This Policy
We may update this Policy; changes are effective when posted with an updated date. Material changes will be communicated as required by law.
Effective Date: Tuesday, October 7, 2025