GLAND WORKS

Legal

Privacy Policy

What we collect, why, who processes it, how long we keep it, and your rights under California, other US state, and EU/UK law.

All versions of this document

Last updated: [EFFECTIVE DATE]. This policy explains what personal information we collect, why, who we share it with, how long we keep it, and what you can ask us to do about it.

We apply one privacy posture to every visitor, wherever you are. We do not use your location to decide which rights you get.

1. Who we are and how to reach us

[LEGAL ENTITY NAME], a [STATE OF INCORPORATION] [ENTITY TYPE], of [POSTAL ADDRESS], is the controller of the personal information described here.

Privacy contact: [PRIVACY EMAIL]. Post: [POSTAL ADDRESS], marked "Privacy". Phone: [SUPPORT PHONE].

2. What we collect and why

Account identity — your email address, a hashed password, your name, your phone number, whether you verified your email. Used to sign you in and to contact you about your orders.

Business account information — organization name, your role in it, who invited you, seat status. Used to run business accounts, route approvals and apply payment terms.

Addresses — name, company, street, city, state, ZIP, country, phone, and whether it is a shipping or billing address. Used to ship your order, to calculate the tax for your jurisdiction, and to hand your parcel to the carrier.

Order records — line items, kit configurations, amounts, tax, purchase order number, and the history of the order's status. Used to fulfil, invoice, support and warrant your purchase, and kept as a tax and accounting record.

Payment method references — a Stripe customer and payment method token, plus the card brand, last four digits and expiry month and year for display. We never receive, hold or store a full card number or a security code. Your card details go directly to Stripe.

Tax exemption certificates — your EIN, entity name, state, exemption type, dates, and the certificate document. Used to justify an untaxed sale in an audit. Stored encrypted, readable only by administrators, and every read is logged.

Support tickets and attachments — subject, message text, and any files you attach. Used for customer service and to handle warranty and fitment disputes.

Photographs you upload — pictures of your cylinder or your old seals, used to identify the right kit. We strip location and camera metadata from images on upload.

IP address, session and device data — your session, login IP address and browser user agent, and our server request and error logs. Used for security, fraud prevention and debugging.

Consent records — which cookie categories you allowed or refused, when, by what method, the policy version you were shown, and the IP address and user agent at that moment. Kept as proof that we had your consent.

Policy acceptances — which version of which document you accepted, when and how. Kept to prove which terms governed which order.

Analytics identifiers — a first-party anonymous identifier, and any identifier set by an analytics provider. Set only if you consent.

Marketing subscription — your email address, the time, IP address, source form and exact wording of the opt-in you were shown, and any unsubscribe. Used only if you opt in.

Administrative and audit records — who did what to a record, when. Kept for accountability and breach investigation.

We do not collect health data, biometric data, precise geolocation, or data about race, religion, sexual orientation, union membership or political opinion. We do not knowingly collect information from anyone under 16.

3. Legal bases (EU/UK visitors)

  • Performance of a contract (Art. 6(1)(b)) — account identity, business account information, addresses, order records, payment method references, quotes.
  • Legal obligation (Art. 6(1)(c)) — order, invoice and payment records kept for tax and accounting; tax exemption certificates; consent records; policy acceptances.
  • Legitimate interests (Art. 6(1)(f)) — security, fraud prevention, debugging, request and error logs, and administering a business account. Our interest is running a secure shop that can prove what it sold; we balance it against your interests, and you may object at any time.
  • Consent (Art. 6(1)(a)) — non-essential cookies, analytics, marketing email, and photographs you upload before an order exists. You can withdraw consent at any time, and withdrawing does not affect processing that already happened.

We do not make automated decisions that produce legal or similarly significant effects about you. There is no profiling that decides whether you may buy.

4. Who we share it with

We do not sell your personal information for money. See section 8 on "sale" and "sharing" as California defines them.

We use the following processors. Each acts on our instructions and each has its own privacy notice.

  • Stripe — payment processing and sales tax calculation. Receives your card details directly, plus the amounts, the line items and the addresses needed to calculate and remit tax. https://stripe.com/privacy
  • UPS — parcel carriage. Receives the recipient's name, address, phone number and the parcel details. https://www.ups.com/us/en/support/shipping-support/legal-terms-conditions/privacy-notice.page
  • USPS — parcel carriage. Receives the recipient's name, address and the parcel details. https://about.usps.com/who/legal/privacy-policy/
  • [SMTP PROVIDER] — sends our transactional and marketing email. Receives your email address and the content of the message. [SMTP PROVIDER PRIVACY URL]
  • [ANALYTICS VENDOR, IF ANY] — website measurement. Set only with your consent. [CONFIRM] §7.13 item 14 — the vendor has not been selected; when it is, this entry and the Cookie Policy table must be completed before the tag ships.
  • [HOSTING / COLOCATION PROVIDER] — runs the servers this site and its database sit on.
  • [OFFSITE BACKUP TARGET] — holds our encrypted database replica. A backup target is a processor, and it belongs on this list.

We also disclose information where we must: to comply with law, to respond to lawful requests, to establish or defend legal claims, and to a buyer of our business, in which case we will tell you.

5. Cookies

We use strictly necessary cookies without asking, because the site cannot work without them. We set nothing else unless you consent. The Cookie Policy lists every cookie, and you can change your choice at any time from "Cookie preferences" in the footer of every page.

6. How long we keep it

  • Account identity and business account records: for the life of the account, then 90 days after it closes.
  • Addresses in your address book: for the life of the account.
  • Order, invoice and payment records: 7 years from the order date. These survive a deletion request because tax and accounting law requires them; see section 9.
  • Tax exemption certificates: 7 years from the last transaction they covered.
  • Support tickets and attachments: 3 years from closure. [CONFIRM] §7.13 item 7 — the statute of limitations in [STATE] that sets this period.
  • Uploaded photographs: 2 years from upload, or the parent ticket's or order's clock if attached to one.
  • Sessions: expiry plus 30 days. Request and error logs: 90 days.
  • Consent records: 3 years after they are superseded or withdrawn. The IP address and user agent in a consent record are truncated after 90 days.
  • Marketing subscription: until you unsubscribe. A one-way hash of your address is then kept indefinitely on a suppression list, so that we can keep honoring your opt-out without keeping your address.
  • Administrative and audit records: 2 years, or 7 years where they touch a financial record.

Backups. Deleted data is removed from our live systems immediately and from our encrypted backups within 35 days, as backup snapshots rotate. If we ever restore an old snapshot, we re-apply every deletion completed since it was taken.

7. Security

We encrypt traffic in transit, hash passwords, encrypt tax identification numbers at rest, restrict staff access by role, log administrative access to customer records, and keep an append-only audit trail. We deliberately do not publish details that would help someone attack us.

No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulators as the law requires.

8. California privacy rights (CCPA/CPRA)

[CONFIRM] §7.13 item 1 — whether [LEGAL ENTITY NAME] meets a CCPA/CPRA threshold. We have built and operate this site as though it does.

Categories of personal information we have collected in the last 12 months, in the statute's own vocabulary:

  • Identifiers: name, postal address, email address, phone number, IP address, account identifiers.
  • Customer records (Cal. Civ. Code 1798.80): name, address, telephone number, and financial information limited to a payment token, card brand and last four digits.
  • Commercial information: products purchased or considered, order history.
  • Internet or network activity: pages viewed, searches run in the parts finder, interaction with the site.
  • Geolocation: none. We do not collect precise geolocation, and we strip location metadata from uploaded photographs.
  • Professional or employment information: your employer and your role, for business accounts.
  • Inferences: none drawn for profiling.
  • Sensitive personal information: an EIN supplied on a tax exemption certificate. We use it only for the purpose it was given — justifying an untaxed sale — and we do not use or disclose it to infer characteristics, so the right to limit its use does not arise. We do not collect any other category of sensitive personal information.

Sources: you, directly; your browser; our payment processor and carriers, in relation to your order.

Business and commercial purposes: fulfilling your order, invoicing and collection, customer service, warranty and returns, fraud prevention and security, tax compliance, record-keeping, and, with your consent, measurement and marketing.

Sold or shared. We do not sell personal information for money. [CONFIRM] Whether any future advertising or analytics tag constitutes "sharing for cross-context behavioural advertising" must be reviewed before that tag ships; today we set no such tag. We have not sold or shared the personal information of anyone we know to be under 16.

Your rights: to know what we collect and what we do with it; to access a copy; to correct inaccurate information; to delete, subject to the exceptions in section 9; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of them. We do not offer a different price or a worse service to anyone who exercises a privacy right.

Do Not Sell or Share. Use the "Do not sell or share my personal information" link in the footer of every page, or go to /privacy/do-not-sell. No account and no verification is needed.

Global Privacy Control. We honor the Sec-GPC browser signal as a valid opt-out of sale and sharing, for every visitor, in every state. When your browser sends it, marketing categories are switched off for that session and recorded, and "Accept all" on our cookie banner will not switch them back on.

Authorized agents may submit a request at /privacy/request. We will ask for the agent's written authority from you, and we will confirm with you directly.

Timing. We confirm receipt within 10 business days and respond within 45 days. If we need more time we will tell you why within that first 45 days and take up to 45 days more. Our own internal target is 30 days for every request, of any kind.

Complaints and appeals. If we deny a request you may ask us to reconsider by replying to our response or writing to [PRIVACY EMAIL]; we will answer within 45 days. You may also complain to the California Privacy Protection Agency or the California Attorney General.

[CONFIRM] §7.13 item 10 — whether our request volume triggers the obligation to publish annual request metrics.

9. Deletion and the records we must keep

Every privacy law we operate under allows a business to keep records it is legally required to keep. Tax and accounting law requires us to keep the record of what we sold you.

So a deletion request does not delete your orders. It removes you from them.

We erase your name, email address, phone number and street address from the order record, and we delete your address book, your saved payment methods, your uploaded photographs and your support attachments.

We keep the order number, the items, the quantities, the amounts, the tax, the city, state and ZIP code the order shipped to, and the dates. The city, state and ZIP are what justify the tax we charged and remitted; dropping them would destroy the record's whole purpose. The street address and your name are not needed for that, so they go.

Your login stops working. We put you on our do-not-email list and keep a one-way scrambled copy of your email address for that purpose only, so that we can keep honoring your opt-out without keeping your address.

We keep these anonymised records for 7 years from the order date and then delete them. [CONFIRM] §7.13 item 6 — the tax and accounting retention period for [STATE] and federal purposes; 7 years is our design value and needs the business's accountant to confirm it.

10. Other US state privacy rights

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island, Arkansas or another state with a comprehensive privacy law, you have materially the same rights as described in section 8: to confirm whether we process your information and access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale and profiling with legal effects.

We apply these rights to every visitor without asking where you live.

Appeal. Several of these states give you the right to appeal a refusal. If we decline your request, our response will tell you how to appeal; you may also write to [PRIVACY EMAIL] with "Appeal" in the subject line. We will respond to an appeal within 45 days with a written explanation. If we deny the appeal, you may complain to your state Attorney General, and our response will include a link for doing so.

11. EU and UK privacy rights (GDPR / UK GDPR)

Controller: [LEGAL ENTITY NAME], [POSTAL ADDRESS], [PRIVACY EMAIL].

Representative: [ART. 27 EU/UK REPRESENTATIVE, IF REQUIRED]. [CONFIRM] §7.13 item 2 — whether an Art. 27 representative is required, or whether our processing is occasional and low-risk enough to fall within the Art. 27(2) exemption.

Your rights: access, rectification, erasure, restriction of processing, objection to processing based on legitimate interests, data portability, and withdrawal of consent at any time. Exercise any of them at /privacy/request or by writing to [PRIVACY EMAIL].

Automated decision-making: none.

Transfers. We store and process personal information in the United States. [CONFIRM] §7.13 item 2 — the transfer mechanism for EU and UK visitor data, whether Standard Contractual Clauses, the UK International Data Transfer Addendum, or another safeguard, together with the transfer impact assessment.

Complaints. You have the right to complain to a supervisory authority, in particular the one in the EU or EEA country where you live or work, or, in the United Kingdom, the Information Commissioner's Office at ico.org.uk. We would rather you came to us first at [PRIVACY EMAIL], but you do not have to.

12. How to exercise your rights

  • Anyone, with or without an account: /privacy/request.
  • Signed in: Account, then Privacy, for a one-click export or account deletion.
  • Opt out of sale or sharing: /privacy/do-not-sell. No verification, no account.
  • Cookies: "Cookie preferences" in the footer, or /privacy/preferences.
  • Marketing email: the unsubscribe link in any marketing message, which works without signing in and never expires.

We verify identity in proportion to what is being asked. An opt-out is never gated on verification. For an access or deletion request from someone without an account, we match an order number, the email address on that order, and the billing ZIP code. We will not ask you for a government-issued ID to answer a privacy request — collecting one would create a worse data problem than the one you asked us to solve.

13. Changes to this policy

We publish a new version with a plain-language summary of what changed, and we keep every prior version at /legal/privacy-policy/versions with its effective date. A material change is emailed to account holders at least [N, typically 30] days before it takes effect, and you will be asked to accept it at your next sign-in.

Version 0.1 — effective 2026-09-15.

Content hash 82fed60d54f5fb1b2e4e60ecd0885c084661a4779f26fb9c9735449af17c7a14