We collect the minimum information needed to run the Service. We don’t run third-party analytics, don’t serve ads, and don’t sell or share your data with advertisers. Here is exactly what we collect, why, and how to remove it.
1. What we collect
- Email address, when you create an account. Used to send you sign-in magic-links, billing receipts from our payment processor, and material service notices.
- Payment information, processed by our payment processor (LemonSqueezy, Paddle, Stripe, or equivalent — see Third Parties below). We do not store or transmit card numbers ourselves; the processor handles card data on PCI-compliant infrastructure.
- Server logs, automatically: your IP address, browser user-agent, requested URL, and timestamp. Retained for up to 30 days. Used to operate the Service, debug, and identify abuse.
-
Cookies:
bb_age_21— confirms you’ve indicated you are 21 or older. Expires after 30 days.- Session cookie — keeps you signed in. Expires at the end of your session.
2. What we don’t collect
- No third-party analytics (no Google Analytics, Facebook Pixel, Mixpanel, or equivalent).
- No advertising trackers.
- No card numbers stored on our infrastructure.
- No precise location data. We see only the city-level approximation that any web server gets from your IP.
3. How we use what we collect
- To operate the Service (sign you in, charge subscriptions, send receipts and service notices).
- To debug, improve, and identify abuse (server logs).
- To respond when you contact support.
4. Third parties
The third-party services we use and the data they receive:
- Cloudflare — serves the Service via its CDN and receives request metadata in the course of doing so.
- Payment processor (LemonSqueezy, Paddle, Stripe, or equivalent) — receives your billing email, card details, and transaction history.
- Transactional email provider (Resend, Postmark, or equivalent) — receives your email address and the contents of messages we send you (magic-links, receipts, service notices).
The optional “worth the drive?” trip-cost calculator on the /carts/15pack page uses Nominatim (OpenStreetMap) for geocoding and OSRM (project-osrm.org) for routing. These requests run in your browser, not on our server — your start address never reaches us.
5. Data retention
- Account data: retained for the lifetime of your account. If you delete your account, we delete the associated email and subscription record within 30 days, except where we are required to retain transaction records for tax purposes.
- Server logs: 30 days.
6. Your rights
- Access: email [email protected] to request a copy of the data we hold on you.
- Delete: email us to delete your account. We’ll process the request within 30 days.
- Correct: update your account email from your account settings, or email us.
- California residents (CCPA): you have rights under the CCPA including the right to know, delete, and not be discriminated against for exercising your rights. We do not sell your data. To exercise these rights, email [email protected].
7. Children’s privacy
The Service is intended for users 21 years of age and older. We do not knowingly collect personal information from individuals under 21.
8. Changes to this Policy
We may update this Privacy Policy. We’ll post a new “Last updated” date and, for material changes, notify subscribers by email.
9. Contact
Privacy questions: [email protected].