Last updated 27 July 2026
We collect the minimum needed to sell you a hoodie and tell you when the next drop lands. We don't sell your data, we don't run ad pixels, and we never see your card number. That's the whole posture — the detail below just spells it out.
| Data | When |
|---|---|
| Name, email, shipping address, phone (optional) | Collected by Stripe at checkout and passed to us to fulfil the order |
| What you ordered, the amount, and the order status | When you place an order (stored in our database) |
| Email address | When you join the Drop List |
| Name, email, order number, message | When you use the contact form |
| The contents of your bag | While you shop — held in a session cookie, not in our database |
| Standard server log data — IP address, browser, pages requested | Automatically, by our host |
We do not collect or store card numbers. Checkout happens on Stripe's own hosted page; your card details go straight to Stripe and never touch our site. We receive only the outcome (paid or not) and the shipping details you gave Stripe.
Only the companies we need to run the shop, and only what each one needs:
We may also disclose data where the law requires it, or to protect our rights. We never sell your personal information, and we don't share it for cross-context behavioural advertising.
This site sets one cookie: a session cookie that remembers what's in your bag (and, if you're us, that you're logged into the admin area). It carries no advertising identifier and expires when your session ends. There is no analytics and no advertising tracker on this site.
Stripe sets its own cookies on its checkout page, which are necessary for payment and fraud prevention — see Stripe's privacy policy for those.
If we add analytics later, we'll update this section and, where required, ask for your consent first.
Order and tax records: seven years, as US accounting rules require. Drop List email addresses: until you unsubscribe. Contact form messages: two years. Server logs: typically 30–90 days depending on our host. Abandoned checkouts are kept briefly and then cleared.
Wherever you live, you can ask us to:
If you're in California (CCPA/CPRA), the EU or UK (GDPR), or a US state with a comprehensive privacy law, you may have further rights including data portability and the right to object. Email hello@goldstandardunruly.com and we'll action any request within 30 days, free of charge. We won't discriminate against you for exercising these rights.
Payment is handled by a PCI-DSS Level 1 processor, so card data never reaches our systems. Access to order data is limited to the people who need it. No system is perfectly secure, though — if a breach ever affects your data, we'll notify you and the relevant regulator as the law requires.
This site isn't directed at children under 13 and we don't knowingly collect their data. If you believe a child has given us personal information, email us and we'll delete it.
Questions, requests, or complaints: hello@goldstandardunruly.com, or use the contact form. Unruly™ is based in Atlanta, Georgia, USA, and is the data controller for the information described here.
If we change this policy, the "last updated" date above changes with it. Material changes will be announced to the Drop List.