Privacy Policy

Your privacy matters to us. Here's how we collect, use, and protect your personal information.

Last updated: April 3, 2026

📋 Information We Collect

When you use our website or place an order, we may collect the following information:

  • Name and contact information
  • Email address
  • Shipping and billing address
  • Phone number
  • Payment information — processed securely via Stripe. We never see or store your full credit card number.
  • Browsing behavior — pages visited, products viewed, search queries
  • IP address and general location data

🔧 How We Use Your Information

  • Process and fulfill orders — shipping, payment, order confirmation
  • Communicate about your orders — tracking updates, delivery notifications, order issues
  • Improve our website — understand how customers use our site to make it better
  • Send marketing emails — only with your explicit consent, and you can unsubscribe at any time
  • Prevent fraud — protect our customers and our business from fraudulent transactions

🔒 We Do NOT

  • Sell your personal information. Ever.
  • Share your data with third parties for their marketing purposes.
  • Store credit card numbers on our servers.

🌐 Third-Party Services

We use a limited number of trusted third-party services to operate our business:

  • Stripe — Payment processing. Your payment data is handled securely by Stripe and is subject to Stripe's Privacy Policy.
  • Cloudflare — Website security and CDN (Content Delivery Network). Subject to Cloudflare's Privacy Policy.
  • Email service provider — For order notifications and marketing communications (with consent).

🍪 Cookies

We use cookies to provide essential site functionality:

  • Cart functionality — Remember items in your shopping cart
  • Login sessions — Keep you signed in to your account
  • Site analytics — Understand how visitors use our site to improve the experience

We do not use third-party advertising or tracking cookies.

📅 Data Retention

  • Order data: Kept for 7 years for tax and legal compliance requirements.
  • Account data: Kept until you request deletion of your account.
  • Browsing data: Retained for 90 days, then automatically deleted.

✅ Your Rights

You have the right to:

  • Access — Request to see what personal data we have about you
  • Correct — Request corrections to any inaccurate personal data
  • Delete — Request deletion of your personal data

To exercise any of these rights, email us at toledoindoorgarden@gmail.com. We will respond within 30 days.

👶 Children's Privacy

Our website is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete that information promptly.

🔐 Security

We take the security of your personal information seriously and employ multiple layers of protection:

  • SSL/TLS encryption on all pages and transactions
  • Secure servers with regular security updates
  • Access controls limiting who can access customer data
  • Stripe PCI compliance for all payment processing

While no method of electronic transmission or storage is 100% secure, we take commercially reasonable measures to protect your personal data.

🇪🇸 California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal data we collect about you
  • Right to request deletion of your personal data
  • Right to opt out of the sale of personal data — we do not sell your data, so there is nothing to opt out of
  • Right to non-discrimination for exercising your CCPA rights

📝 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. The "Last updated" date at the top of this page indicates when this policy was last revised. We encourage you to review this page periodically.

📧 Contact Us

If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us: