GOB — Good Ol' Boys
Back to home

PRIVACY POLICY

Effective August 14, 2026

No dark patterns, no data brokers, no fine print written to confuse you. Here is every piece of information this store touches, why it touches it, who else sees it, and how you take it back.

1. Who we are

This site is operated by Good Ol' Boys ("GOB", "we", "us", "our"), a clothing brand based in Escondido, California, United States. We sell apparel directly to customers in the United States through this website.

This Privacy Policy explains what we collect, why we collect it, who we share it with, how long we keep it, and exactly how you can get it changed or deleted. It applies to this website, our order and shipping emails, our newsletter, and our customer support channels. It does not apply to third-party sites we link to.

Plain English up front: we do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not run ad-tech trackers on this site. The data we hold exists to take your order, ship it, support you afterward, and keep the lights on legally.

2. What we collect

Information you give us directly

  • Account data — email address, password (stored only as a salted hash we cannot read), and optional name.
  • Order data — items, sizes, quantities, order totals, discounts, order status and history.
  • Shipping data — recipient name, street address, city, state, ZIP, phone number (when supplied for carrier notifications).
  • Billing data — billing name, billing address, and email. See section 3: we never receive your full card number.
  • Support data — the contents of contact form messages, return requests, cancellation requests, and general feedback, plus the email address you send them from.
  • Marketing data — your newsletter email address, subscription status, and the page or form you signed up from.

Information collected automatically

  • Technical data — IP address, browser and device type, and timestamps in server logs, retained for security and abuse prevention.
  • Anti-fraud signals — Google reCAPTCHA v3 evaluates page interaction signals on sign-up, sign-in, checkout, and form submissions to block bots.
  • Local browser storage — your cart contents and your signed-in session token are stored in your own browser. See section 7.

What we deliberately do not collect

  • No full payment card numbers, CVV codes, or bank credentials — ever.
  • No Social Security numbers, government ID numbers, biometrics, precise GPS location, or health data.
  • No advertising cookies, no data broker enrichment, no cross-site tracking pixels.
  • No knowingly collected data from anyone under 13 (see section 11).

3. Payments and card data

All payments are processed by Stripe, a PCI DSS Level 1 certified payment processor. Card details are entered inside Stripe's own hosted checkout fields and travel directly to Stripe. They never touch, transit, or persist on our servers, and we never have the ability to view or export them.

What we receive back from Stripe and store is limited to: a payment status, an order and session identifier, the amount and currency, tax calculated, the last four digits and brand of the card, and the billing name, email, and address you entered. Stripe processes your information as an independent controller under its own privacy policy, including for its own fraud-prevention obligations.

Sales tax on applicable orders is calculated through Stripe Tax based on your shipping destination and California's sourcing rules. Tax records tied to orders are retained as described in section 8.

4. How we use your information

  • To accept, process, and fulfill your order, and to collect payment and applicable tax.
  • To create shipping labels, hand your address to the carrier, and send you tracking updates.
  • To send transactional email — order confirmation, shipping confirmation, delivery notice, cancellation and refund notices. These are not marketing and you cannot unsubscribe from them while an order is active.
  • To answer support, return, and cancellation requests, and to process refunds.
  • To manage your account, saved details, and order history.
  • To validate one-time promotional codes and enforce single-use limits (which requires checking your account, email, and shipping address against prior redemptions).
  • To detect and prevent fraud, bot abuse, chargeback abuse, and unauthorized access.
  • To send our newsletter, only if you opted in, and only until you opt out.
  • To keep the accounting, tax, and consumer-protection records the law requires us to keep.

We do not use your personal information to train machine-learning models, and we do not profile you in ways that produce legal or similarly significant effects.

6. Who we share it with

We share the minimum necessary with vendors who act as our service providers under contract. They may use your data only to perform their service for us — never to sell it or market to you on their own behalf.

  • Stripe — payment processing, tax calculation, refunds, chargebacks. Receives billing details and order amounts.
  • Shippo and the carriers it books (e.g. USPS) — label creation, rates, tracking, returns. Receives recipient name, address, phone, and parcel details.
  • Resend — delivery of transactional and newsletter email. Receives your email address and message content.
  • Supabase infrastructure provisioned through Lovable Cloud — our managed database, authentication, and file storage. Hosts the data described in section 2.
  • Google reCAPTCHA — bot detection on forms and logins, subject to Google's privacy policy.

We may also disclose information when legally compelled — valid subpoena, warrant, court order, or lawful government request — or where disclosure is necessary to investigate fraud, enforce our terms, or protect the rights, property, or safety of GOB, our customers, or the public. If GOB is ever involved in a merger, acquisition, financing, or sale of assets, customer data may transfer as part of that transaction, and this policy will continue to govern it until you are notified of any change.

We do not sell your personal information, and we have not sold or shared it for cross-context behavioral advertising in the preceding twelve months.

7. Cookies and local storage

We keep this deliberately boring. We use only what the store needs to function:

  • Authentication session — stored in your browser so you stay signed in. Cleared on sign-out and after 30 minutes of inactivity in admin sessions.
  • Cart storage — your cart lives in your browser's local storage so it survives a page refresh.
  • Checkout and fraud — Stripe and Google reCAPTCHA set their own cookies/tokens strictly for payment security and bot detection.

There are no advertising, retargeting, or third-party analytics cookies on this site. Because we set no non-essential cookies, there is no consent banner to click through. You can clear or block storage in your browser settings, but signing in and checking out will stop working if you do.

We do not currently respond to browser "Do Not Track" signals because there is no common standard for them. We do honor Global Privacy Control signals to the extent they apply — though we do not sell or share data in the first place.

8. How long we keep it

  • Order and tax records — retained for a minimum of four years to satisfy California and federal tax, accounting, and audit requirements. Even after account deletion, we keep the transaction record with your name, email, and address scrubbed.
  • Account and profile data — kept until you delete your account, then removed.
  • Support, return, and cancellation messages — kept while the matter is open and for a reasonable period afterward to handle disputes and chargebacks, then deleted on request.
  • Newsletter data — kept until you unsubscribe; we retain a suppression record of your email so we do not accidentally mail you again.
  • Server and security logs — retained on a short rolling window for abuse investigation.

9. How we protect it

  • All traffic is encrypted in transit over HTTPS/TLS; database storage is encrypted at rest.
  • Row-level security policies in our database mean your records are readable only by you and authorized staff — not by other customers.
  • Passwords are salted and hashed; nobody at GOB can read yours.
  • Administrative access requires a separate staff role, two-factor authentication, reCAPTCHA scoring, and automatic sign-out after inactivity.
  • Card data is out of scope entirely because it never reaches us (section 3).

No system is unbreakable, and we will not pretend otherwise. If a breach affects your personal information we will notify you and the appropriate regulators within the timeframes required by California Civil Code §1798.82 and any other applicable law.

10. Your rights and how to actually use them

Everyone. In your account's Privacy tab you can, without emailing anyone: toggle your newsletter subscription on or off, and permanently delete your account. Deletion removes your login, profile, saved addresses, support messages, and mailing-list entries; past orders are retained for tax purposes with your name, email, and address scrubbed. Deletion is blocked while an order is still in transit — contact support and we will handle it.

California residents (CCPA/CPRA). You have the right to know what we collect and why, to access a copy, to correct inaccuracies, to delete, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we do not collect any), and to be free from retaliation for exercising any of these rights. We do not offer financial incentives for your data.

EEA/UK residents. You additionally have rights of portability, restriction, objection, and to lodge a complaint with your supervisory authority.

Other states. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states with comprehensive privacy laws have substantially similar rights, and we extend them to every customer regardless of where you live.

Appeals. If we deny a privacy request, we will tell you why and how to appeal. Reply to our decision email within 30 days and a different person will review it; we respond to appeals within 45 days. If the appeal is denied, you may contact your state attorney general.

California "Shine the Light" (Civil Code §1798.83). We do not disclose personal information to third parties for their own direct-marketing purposes, so there is nothing to request under this law — but you may ask us to confirm that in writing at any time.

Categories disclosed for a business purpose. In the past twelve months we disclosed identifiers, contact and shipping details, commercial/order information, and internet activity limited to fraud signals, to the service providers listed in section 6, solely to run the store. We disclosed no personal information for money or other valuable consideration.

To make any request not covered by the self-serve tools, email customerservice@goodoleboys.clothing from the address on your account. We verify identity by confirming control of that email and matching order details, we respond within 45 days (extendable once by another 45 where permitted), and it costs you nothing. An authorized agent may submit on your behalf with written permission we can verify.

11. Children

This site is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has given us data, email customerservice@goodoleboys.clothing and we will delete it promptly. Customers under 18 should use the site only with a parent or guardian's involvement, and orders must be placed by someone legally able to enter a contract.

12. Email preferences

Transactional email (order confirmation, shipping, delivery, cancellation, refund) is part of the sale and is sent regardless of marketing preferences.

Newsletter email is opt-in only. Every message carries a one-click unsubscribe link and RFC-8058 list-unsubscribe headers, so the "Unsubscribe" button in Gmail or Apple Mail works instantly. You can also toggle it in your account's Privacy tab. Unsubscribes are honored immediately, not "within 10 business days."

13. Where your data lives

We operate in the United States and our infrastructure and vendors process data in the United States. If you access the site from outside the US, you understand your information will be transferred to and processed in the US, where privacy laws may differ from those in your country. Where required, we rely on Standard Contractual Clauses or equivalent safeguards with our processors.

14. Changes to this policy

We will update this policy when our practices change. The effective date at the top always reflects the current version. If a change is material — a new category of data, a new purpose, a new class of recipient — we will notify account holders by email or with a prominent notice on the site before it takes effect. Continued use after the effective date means you accept the updated policy.

15. Contact us

Questions, requests, or complaints — a human reads every one of these. We respond within 2–3 business days.

Good Ol' Boys (GOB)
1325 Gary Lane, Escondido, CA 92026, United States
customerservice@goodoleboys.clothing

Prefer a form? Use the Contact page and pick "General" as the subject.

This policy describes our practices in good faith and is provided for transparency. It is not legal advice, and it does not replace the terms that govern your purchase.