Data Use Policy
Last updated: 2026-05-22
This policy explains what we collect, what we sell or share, what we never share, how long we keep it, and how you can opt out or request deletion. It supplements our Privacy Policy and is written in plain English on purpose.
What we collect
| Source | Data | Purpose |
|---|---|---|
| Account signup | Email, first/last name, optional institution | Account creation, order history |
| Checkout | Ship-to address, attestation timestamp, browser user-agent, timezone | Order fulfillment, compliance log |
| Cart and browsing | Cart contents (first-party cookie), pages viewed | Session continuity, abandoned-cart recovery |
| Email capture | Email + source tag (exit-intent, newsletter, waitlist) | Restock alerts, single-use coupon, opt-in newsletter |
| Wholesale form | Org, role, institution, volume estimate, payment preference | Quote response, underwriting |
| Affiliate form | Name, audience, URL, pitch | Approval review |
| Support ticket | Email, message body | Reply, audit |
| Server logs | IP, request method, URL, user-agent, timestamp | Security, abuse detection |
| Optional analytics | Page-view counts, referrer (aggregated, no PII) | Site improvement |
What we sell or share
We do not sell or rent personally identifiable buyer data. We share with these categories of partners only when strictly necessary to fulfill the service:
- Payment processor receives the card or bank (ACH) data you enter at checkout. We never see the full card or account number.
- Shipping carrier receives your ship-to address and the package weight.
- Email service provider (when configured) receives your email + the transactional message we send.
- Tax authority receives jurisdiction-required information when state nexus is triggered.
- Compliance counsel and auditors may receive order, attestation, and audit-log data under NDA.
- Aggregated, de-identified data (counts, ranked categories, geographic distribution at state granularity, time-series purchase volumes) may be analyzed internally, used in marketing materials, or shared with research partners. This data cannot be re-identified to you.
If we ever decide to monetize aggregated data through a paid dataset or analytics product, we will:
- Update this page first.
- Send a 30-day email notice to every account holder.
- Provide a clear opt-out toggle in your account settings.
- Honor the toggle retroactively for the next aggregation cycle.
We do not participate in any third-party advertising network, retargeting platform, or data broker. We do not use Google Analytics 4 in its default configuration. If we add analytics in the future, it will be a privacy-friendly product (Plausible, Fathom, or self-hosted PostHog with IP anonymization), disclosed here.
What we never share
- Full payment card numbers (held only by the processor).
- The contents of your cart with anyone outside the order-fulfillment chain.
- Support-ticket bodies with anyone outside the team.
- Account password (hashed at rest, never transmitted in plain text).
- Browsing patterns linked to your identity with any third-party ad network.
Retention
| Data class | Retention |
|---|---|
| Order records + attestations | 7 years (recordkeeping requirement for research-material commerce) |
| Audit log | 7 years (append-only) |
| Account profile | Until you request deletion + a 30-day grace period |
| Support tickets | 3 years |
| Email marketing list | Until you unsubscribe (one-click) |
| Aggregated analytics | Indefinite (no PII) |
| Server access logs | 90 days |
Your rights
Regardless of your state of residence, you can:
- Access what we have on file. Email [email protected].
- Correct any inaccurate field via account settings or by email.
- Delete your account. Order records remain for the 7-year recordkeeping requirement; personal identifiers are purged from those records.
- Export your account data in JSON or CSV by email request, delivered within 30 days.
- Opt out of any marketing email with one click in any email we send.
- Opt out of future aggregated-data programs in account settings (we will add the toggle before the first such program launches).
California residents (CCPA): the rights above satisfy CCPA. We will not discriminate against you for exercising them. We do not sell personal information as defined by CCPA.
Virginia, Colorado, Connecticut, Utah residents: equivalent rights apply. Email requests are honored within statutory windows.
EU/UK residents: at this time we ship to US addresses only. If you are an EU/UK researcher with a US ship-to address, GDPR Article 14 information is available on request.
Cookies
We use only first-party cookies, all functional. No third-party tracking cookies are set. The categories are:
| Cookie name pattern | Purpose | Lifetime |
|---|---|---|
xfp_cart_* | Shopping cart contents | 30 days (rolling) |
xfp_cookies_v1 | Your cookie-banner choice | 12 months |
xfp_last_* | UX state (last attestation, last order) | 30 days |
xfp_logged_in_* | Session continuity for signed-in users | Session + 30 days |
The cookie banner on first visit lets you Accept or Reject. Reject removes all non-functional cookies. The site continues to work either way.
Children
We do not knowingly collect data from anyone under 21. If you believe a minor has used the site, contact [email protected] immediately.
Security
See SECURITY.md in the repository for our security posture, including the threat model, audit-logging, and the password and 2FA story. To report a vulnerability: [email protected] (24-hour acknowledgement target).
Changes to this policy
Material changes appear here with a new "Last updated" date and a 30-day notice on the home-page banner. Non-material wording fixes appear silently.
Contact
Privacy questions: [email protected] Security: [email protected] Legal: [email protected] General: [email protected]