PRIVACY POLICY
Kuykendall Industries LLC ("we") operates hardgap.com. This policy describes what we collect, why, who processes it, and how to make us delete it.
What we collect
| Data | Why we hold it | When it is collected |
|---|---|---|
| Email address | Account identity, order receipts, balance-due notice | When you create an account |
| Password | Authentication. Stored only as a hash by our authentication provider; we never see it. | If you choose a password rather than email links |
| Order records | Fulfilment, support, and financial record-keeping | When a deposit is paid |
| Shipping address | Delivering a physical object to you | When you add one |
| Engraving text | Machining your Founders card | When you add a Founders card to your cart |
| Stripe customer and payment identifiers | Linking your order to its payment and issuing refunds | At checkout |
| IP address | Rate limiting, to keep the checkout and sign-in endpoints usable. Also forwarded to our analytics processor, which uses it to separate one visitor from another and stores neither it nor the result. | On each request; retained briefly |
We do not collect card numbers. Payment details are entered on Stripe's hosted checkout page and never touch our servers.
We do not run advertising or third-party tracking. There is no Google Analytics, no pixel, no session recorder, no advertising identifier, and no profile of you anywhere. The Content-Security-Policy served with every page forbids loading script from any origin but our own, so this is enforced rather than promised.
We do count page views. That is a real thing we do and the section below describes exactly what it means, what leaves your browser, what our analytics processor receives, and how to switch it off.
Analytics
The measurement is Plausible. It sets no cookie, stores no identifier in your browser, builds no profile, and follows nobody to another site.
What it records. Which page was viewed, roughly how far down the page you scrolled and how long the tab was in front of you, and a small set of named events — a card reserved, a checkout started, an order confirmed, a sign-in that failed. Each event carries only aggregate facts: which edition, whether an engraving was present, how many items were in the cart, the deposit amount, and a coarse reason when something failed. It does not record who you are, what you engraved, which order you were looking at, what you typed into any form, or the text of any error you were shown.
Your browser still talks only to us. The measurement script is served from hardgap.com rather than a vendor's network, and the events it produces are posted to hardgap.com and forwarded from our server. That is why the Content-Security-Policy on every page can still name no third-party origin at all. It is also the honest limit of what that buys you: the request is relayed, not avoided.
What Plausible receives. When our server forwards an event it passes on your IP address and your browser's User-Agent string, because without them every visitor would look like our server and the count would be meaningless. Plausible uses the pair to compute a hash salted with a key it rotates every day, and stores neither the address nor the User-Agent. Once the salt rotates, yesterday's visitor cannot be matched to today's. Nothing else is forwarded — no cookies, no session, no account, and no query string: page addresses are reduced to their path before they leave, so a link carrying a sign-in token or a payment identifier cannot reach anyone.
You can switch it off. This sets a flag in this browser's local storage that the measurement script checks before sending anything further. It applies to this browser only and lasts until you clear site data. One measurement already open for the page you are on — how long it was in front of you — may still complete; nothing after that is sent.
Analytics is on for this browser.
Local storage is unavailable in this browser, so the flag cannot be saved here.
Cookies
This site sets three cookies. None of them are for tracking.
| Cookie | Purpose | Lifetime |
|---|---|---|
| __Host-csrf | Cross-site request forgery protection on every state-changing request | Session |
| __Host-hg_session | Your signed-in session. HttpOnly, so page scripts cannot read it. | 14 days |
| __session_id | Lets you fill a cart before creating an account. Discarded when you sign in. | 30 days |
Analytics sets no cookie. Two things do get written to this browser's own storage, and neither is sent anywhere: the analytics opt-out flag described above, and — on the order confirmation page only — a note of which checkouts you have already been shown, so that revisiting that page does not count your order twice. The second holds nothing but the checkout reference already in this page's address and in your own browser history, and it keeps at most the last few.
Who processes your data
| Processor | Role | What they receive |
|---|---|---|
| Supabase | Database and authentication | Email, password hash, orders, addresses, engraving text |
| Stripe | Payment processing | Email, payment details you enter with them, order amounts |
| Resend | Transactional email delivery | Email address and message contents |
| Vercel | Hosting and content delivery | Request metadata including IP address |
| Plausible | Page-view analytics | IP address and User-Agent, used to derive a daily-rotating hash and stored by neither. Page paths and aggregate event properties. |
Each is a processor acting on our instructions under a data processing agreement. Each may use its own sub-processors for infrastructure; their current lists are published in their respective trust centres.
We do not sell personal information, and we do not share it for advertising.
How long we keep it
- Account data — until you delete your account.
- Order and transaction records — retained as required by financial record-keeping obligations, seven years, even after account deletion.
- Rate-limiting records — pruned after 24 hours.
- Analytics — aggregate counts, with no identifier attached to erase. The daily salt rotation means a visitor cannot be linked from one day to the next.
- Email delivery logs — held by Resend under their retention schedule.
Your rights
Depending on where you live, you may have the right to access, correct, export, or erase your personal data, and to object to or restrict its processing.
You can delete your account yourself. Go to account settings and use Delete Account. This erases your orders, cart, saved addresses, and authentication record from our database, and deletes your customer profile at Stripe. Records of completed transactions are retained by Stripe where financial regulation requires it; after deletion we no longer hold anything linking them to you. This action cannot be undone.
For any other request, contact us at privacy@hardgap.com. We respond within 30 days.
Security
Sessions are held in HttpOnly cookies rather than browser storage, so a script injected into a page cannot read them. Every state-changing request requires a CSRF token and a matching Origin header. All pages are served with a Content-Security-Policy that permits no third-party script, no inline script, and no connection to any host but our own — analytics included, which is served and relayed from this origin rather than sent to a vendor by your browser. Payment card data never reaches our infrastructure.
No system is perfectly secure. If you believe you have found a vulnerability, contact security@hardgap.com.
Children
This site is not directed to children under 16 and we do not knowingly collect their personal information.
Changes
If we change this policy materially, we will post the revised version here and email account holders before it takes effect.
Kuykendall Industries LLC
Boise, Idaho, United States
privacy@hardgap.com