Reckless Bricks

Privacy Policy

Version 0.1-draft · Effective September 13, 2026

DRAFT. Placeholder structure describing what the site actually does with data, so the page exists during the build. Final policy text is supplied by the operator and must replace this before launch. Bump POLICY_VERSION in lib/policy.ts when it does.

What we collect

  • Account: email address, name, and a password hash held by our authentication provider (Supabase).
  • Orders: the shipping address and phone you enter at checkout, what you bought, the amount paid, and the sales tax rate applied (Arizona addresses only).
  • Payment: handled entirely by Stripe. We never receive or store card numbers.
  • Email list: the address you submit to the drop-notification form, and which page it came from.
  • Campaign attribution: if you arrive through a link carrying utm_ parameters, those labels are kept in a first-party cookie and recorded on any order you place. They contain no personal information.

Analytics and advertising

When enabled, the site loads the Meta Pixel and Google Analytics 4. Events sent are page views, product views, add-to-cart, checkout start, and purchase, with product ids and amounts only. No name, email, phone, or address is sent to either service from the browser.

How we use it

To fulfil orders, ship them, answer support requests, send drop notifications you asked for, and understand which campaigns bring visitors.

Placeholder: remaining sections

Retention, your rights and how to exercise them, third-party processors list (Supabase, Stripe, Vercel, Meta, Google), and contact details to be supplied by the operator.