Store

Privacy

Version 5. Effective 2026-10-06

We collect the contact email, name, delivery address, optional order note, purchased items and order/payment/shipment records needed to operate the store. The site also processes an IP address for abuse prevention and hosting security. We do not collect card details, bank credentials or payment-app passwords.

Cloudflare hosts the website, database, photos and encrypted backups. Venmo or Cash App processes payments in its own service. Carriers receive delivery details. For California orders, the delivery street address, city and ZIP code are sent to the California Department of Tax and Fee Administration to identify the applicable tax district. Email sent to our domain is forwarded through Cloudflare to our Gmail inboxes. Automatic customer email delivery is not enabled.

Essential cookies provide guest order access and protect forms. Local browser storage keeps the cart for seven days. Private saved order links normally expire after 30 days and can be revoked. There are no advertising pixels, marketing signup or third-party analytics in the store. We do not sell personal information or share it for advertising; Do Not Track settings do not change essential order functionality.

Order, tax, payment and fulfillment records may be kept for up to seven years for accounting, disputes and legal requirements, and longer if a specific legal obligation requires it. We review unnecessary contact information annually. Encrypted daily backups rotate after 14 days and weekly backups after 56 days; independent recovery copies are protected and reviewed separately.

Contact us to request access, correction or deletion of your information. We verify your identity first and retain records when needed to complete an order, resolve a dispute or meet legal duties. Material policy changes are published here with an updated version and effective date.

Contact: contact@gryphonedm.com