Privacy policy

Last updated 12 August 2026

What follows is an accurate description of what this site actually does with your data — written from the code, not from a template.

What we collect

What we never see

Your card number.Payment happens on Stripe’s hosted checkout page. Card details never reach our servers, our database, or our logs.

Who processes it

ProcessorWhat for
SupabaseDatabase, authentication, and product image storage
StripePayment processing; collects and holds card and billing data
VercelWebsite hosting and request logs
Web3FormsEmails us a copy of contact, quote, and dealer form submissions
ResendOrder confirmation emails

Each holds your data under its own terms. We don’t sell your data, and we don’t share it with anyone beyond the processors above.

Analytics and tracking

We run no analytics, no advertising pixels, and no third-party tracking cookies. The only cookies set are the ones Supabase Auth needs to keep you signed in, and they only exist if you create an account. Your cart is stored in your own browser, not on our servers.

How long we keep it

Orders are kept as business records. Contact, quote, and dealer messages are kept while we’re dealing with them and for a reasonable period after.

TODO(owner)Set actual retention periods — how long order records are kept (tax rules usually drive this), and when form submissions get purged.

Your rights

Email us and we’ll action it: a copy of what we hold, corrections, or deletion. Deletion doesn’t extend to records we’re required to keep, such as completed order and tax records.

TODO(owner)If you sell to California or EU residents, CCPA and GDPR add specific obligations (response deadlines, a "do not sell" mechanism, and a lawful basis for processing). BRIEF §9 calls for cookie consent — currently there is no consent banner, which is defensible only while the site sets no non-essential cookies. Revisit the moment analytics or ads are added. Worth a lawyer’s eye on scope.

Contact

Privacy questions go to our contact form.

TODO(owner)Add a dedicated privacy contact address once the entity is registered.