> Internal notes for Kenny / Dave: Standard digital-store privacy policy adapted for our tech stack (Stripe, PayPal, MailPoet, Google Analytics 4 via Site Kit, Wordfence, CookieYes). Covers GDPR + CCPA at a baseline level. Items in [BRACKETS] need Dave’s confirmation. If Dave actively markets to California or EU residents, a lawyer review for full GDPR/CCPA compliance is recommended. Not legal advice.
—
Last updated: [DATE BEFORE LAUNCH]
This Privacy Policy describes how DaveArmstrongBooks.store (“we,” “us,” “our”) collects, uses, and protects information when you visit the site, create an account, or purchase a book. We take privacy seriously and we collect the minimum we need to run the store responsibly.
If you have questions after reading this, contact [privacy@davearmstrongbooks.store].
1. Information we collect
Information you give us
- Name and email address — when you create an account or place an order
- Billing address — when you place an order (required by our payment processors for fraud protection and tax)
- Payment information — your credit card or PayPal account is processed by Stripe or PayPal directly. We never see or store your full card number. We do receive a transaction confirmation that includes your billing name, address, and the last four digits of your card.
- Communications — if you email us, we keep the message for support and reference
- Optional account info — display name, password (stored hashed, never plain text), and any newsletter preferences you set
Information collected automatically
- Device and browser — type, operating system, screen size (so the site can render correctly)
- IP address — for security, fraud prevention, and approximate geolocation (country-level)
- Usage data — pages visited, time spent, links clicked, referring source
- Cookies and similar technologies — see Section 6
Information from third parties
- Payment confirmations — from Stripe and PayPal, when you complete a purchase
- Affiliate referrals — if you reach the site from an external Amazon Associates link, basic referral information
2. How we use this information
We use the information we collect to:
- Process your orders and deliver your books
- Send transactional emails (order confirmation, download links, password resets)
- Provide customer support
- Send marketing emails — only if you’ve opted in by subscribing to the newsletter or by checking the marketing-opt-in box at checkout
- Prevent fraud, abuse, and security incidents
- Comply with legal and tax obligations
- Improve the site (which pages confuse readers, which books people search for and don’t find)
- Personalize your experience (saved cart, wishlist, “books you’ve already bought”)
We do not use your information to make decisions about you using automated profiling.
3. Who we share information with
We share the minimum necessary with the third parties we depend on to run the store. Each is a contractually-obligated processor — they may not use your data for their own marketing.
- Stripe — payment processing. Their privacy policy.
- PayPal — payment processing. Their privacy policy.
- Bluehost — web hosting. Their privacy practices govern data stored on the server.
- Google (via Site Kit / Google Analytics 4) — analytics. IP addresses are anonymized. Their privacy policy.
- Wordfence — security and firewall. Limited data on blocked threats may be shared with Wordfence’s threat-intelligence network. Their privacy policy.
- MailPoet (or successor email tool) — newsletter delivery for opted-in subscribers
- Amazon Associates — when you click an affiliate “Buy in paperback on Amazon” link, Amazon sees a referral tag identifying this store and tracks the resulting purchase. Amazon’s privacy policy governs anything that happens on amazon.com.
We do not sell your data
We do not sell, rent, or trade your personal information to advertisers, data brokers, or any third party for their own marketing.
Legal compliance
We may disclose information when required by law — for example, in response to a subpoena, court order, or government request — or when we believe in good faith that disclosure is necessary to protect rights, safety, or property.
4. Marketing emails
We send transactional emails (receipts, download links, password resets) regardless of marketing preference — those are required to deliver your order.
We send marketing emails (newsletter, new-book announcements) only if you’ve opted in by:
- Subscribing to the newsletter via a form on the site
- Checking a marketing opt-in box at checkout
- “Purchasing” a free resource (which gives us a soft opt-in for newsletters about new free content)
Every marketing email includes an unsubscribe link in the footer. Clicking it removes you immediately. You can also email us at [privacy@davearmstrongbooks.store] to be removed.
5. Your rights
Depending on where you live, you may have specific rights regarding your data:
All visitors:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to fix anything that’s wrong
- Deletion — ask us to delete your account and personal data (we’ll retain only what’s required for legal/tax compliance)
- Unsubscribe from marketing at any time
European Economic Area, UK, Switzerland (GDPR):
- All of the above, plus:
- Right to portability — receive your data in a structured, machine-readable format
- Right to restrict processing
- Right to object to processing
- Right to withdraw consent for activities based on your consent
- Right to lodge a complaint with your local data protection authority
California residents (CCPA/CPRA):
- All of the above, plus:
- Right to know what categories of personal information have been collected, used, shared, or sold
- Right to opt-out of “sale” or “sharing” — we don’t sell or share your information for advertising; this right is automatically honored
- Right not to be discriminated against for exercising your CCPA rights
To exercise any right, email [privacy@davearmstrongbooks.store] with your request. We’ll respond within 30 days. To protect your account, we may ask you to confirm your identity by replying from the email address on file.
6. Cookies and similar technologies
We use cookies — small text files stored in your browser — for three purposes:
- Essential cookies that make the site work (cart contents, login session, security). These cannot be disabled.
- Analytics cookies (Google Analytics 4) that help us understand which pages are useful and which are confusing. These are anonymized.
- Marketing cookies are not in use at the time of this policy. If we add them in the future, this section will be updated and we’ll ask for consent via the cookie banner.
A cookie banner appears on your first visit asking which categories you accept. You can change your preferences anytime via the “Cookie preferences” link in the site footer. Your browser also lets you block or delete cookies entirely; doing so may break checkout or login.
7. Data retention
- Order records: kept for at least 7 years after the purchase, to meet U.S. tax and accounting requirements.
- Account data (name, email, password hash, preferences): kept until you delete your account, after which it is deleted within 30 days, except for what’s tied to order records.
- Marketing subscriber data: kept until you unsubscribe.
- Email correspondence: kept for 3 years after the last message, for support reference.
- Analytics data: Google Analytics retains user-level data for 14 months by default; we use the default unless we change it.
8. Children
The Store is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If you believe we’ve collected information from a child, contact [privacy@davearmstrongbooks.store] and we’ll delete it.
9. International users
The Store is operated from the United States. If you access the Store from outside the U.S., your information will be transferred to, processed in, and stored in the United States, where data-protection laws may differ from those in your country. By using the Store, you consent to that transfer.
10. Security
We protect your data with industry-standard measures:
- All site traffic is encrypted in transit (HTTPS / TLS)
- Payment processing happens on Stripe’s and PayPal’s servers, which are PCI DSS compliant — your card never touches our database
- Passwords are stored as one-way salted hashes, never plain text
- Server access is restricted to authorized administrators
- Site security is monitored by Wordfence with daily threat scans
No system is completely impervious. If a security incident affecting your information ever occurs, we’ll notify you and the appropriate authorities as required by applicable law.
11. Third-party links
The Store contains links to external sites — most notably Amazon for print editions of some books. Once you click an external link, the destination site’s privacy policy applies, not ours. Review the privacy practices of any external site before sharing personal information.
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the current version. Material changes will be announced via an email to registered customers and a banner at the top of the site for at least 30 days.
13. Contact
Privacy questions, data requests, complaints: [privacy@davearmstrongbooks.store]
Operator name and mailing address: [LEGAL ENTITY NAME, MAILING ADDRESS — to populate before launch]
If you’re in the EU/EEA and not satisfied with our response to a privacy request, you have the right to contact your local data-protection authority.
