PRIVACY POLICY

Kuykendall Industries LLC ("we") operates hardgap.com. This policy describes what we collect, why, who processes it, and how to make us delete it.

What we collect

We do not collect card numbers. Payment details are entered on Stripe's hosted checkout page and never touch our servers.

We do not run advertising or third-party tracking. There is no Google Analytics, no pixel, no session recorder, no advertising identifier, and no profile of you anywhere. The Content-Security-Policy served with every page forbids loading script from any origin but our own, so this is enforced rather than promised.

We do count page views. That is a real thing we do and the section below describes exactly what it means, what leaves your browser, what our analytics processor receives, and how to switch it off.

Analytics

The measurement is Plausible. It sets no cookie, stores no identifier in your browser, builds no profile, and follows nobody to another site.

What it records. Which page was viewed, roughly how far down the page you scrolled and how long the tab was in front of you, and a small set of named events — a card reserved, a checkout started, an order confirmed, a sign-in that failed. Each event carries only aggregate facts: which edition, whether an engraving was present, how many items were in the cart, the deposit amount, and a coarse reason when something failed. It does not record who you are, what you engraved, which order you were looking at, what you typed into any form, or the text of any error you were shown.

Your browser still talks only to us. The measurement script is served from hardgap.com rather than a vendor's network, and the events it produces are posted to hardgap.com and forwarded from our server. That is why the Content-Security-Policy on every page can still name no third-party origin at all. It is also the honest limit of what that buys you: the request is relayed, not avoided.

What Plausible receives. When our server forwards an event it passes on your IP address and your browser's User-Agent string, because without them every visitor would look like our server and the count would be meaningless. Plausible uses the pair to compute a hash salted with a key it rotates every day, and stores neither the address nor the User-Agent. Once the salt rotates, yesterday's visitor cannot be matched to today's. Nothing else is forwarded — no cookies, no session, no account, and no query string: page addresses are reduced to their path before they leave, so a link carrying a sign-in token or a payment identifier cannot reach anyone.

You can switch it off. This sets a flag in this browser's local storage that the measurement script checks before sending anything further. It applies to this browser only and lasts until you clear site data. One measurement already open for the page you are on — how long it was in front of you — may still complete; nothing after that is sent.

Cookies

This site sets three cookies. None of them are for tracking.

Analytics sets no cookie. Two things do get written to this browser's own storage, and neither is sent anywhere: the analytics opt-out flag described above, and — on the order confirmation page only — a note of which checkouts you have already been shown, so that revisiting that page does not count your order twice. The second holds nothing but the checkout reference already in this page's address and in your own browser history, and it keeps at most the last few.

Who processes your data

Each is a processor acting on our instructions under a data processing agreement. Each may use its own sub-processors for infrastructure; their current lists are published in their respective trust centres.

We do not sell personal information, and we do not share it for advertising.

How long we keep it

Your rights

Depending on where you live, you may have the right to access, correct, export, or erase your personal data, and to object to or restrict its processing.

You can delete your account yourself. Go to account settings and use Delete Account. This erases your orders, cart, saved addresses, and authentication record from our database, and deletes your customer profile at Stripe. Records of completed transactions are retained by Stripe where financial regulation requires it; after deletion we no longer hold anything linking them to you. This action cannot be undone.

For any other request, contact us at privacy@hardgap.com. We respond within 30 days.

Security

Sessions are held in HttpOnly cookies rather than browser storage, so a script injected into a page cannot read them. Every state-changing request requires a CSRF token and a matching Origin header. All pages are served with a Content-Security-Policy that permits no third-party script, no inline script, and no connection to any host but our own — analytics included, which is served and relayed from this origin rather than sent to a vendor by your browser. Payment card data never reaches our infrastructure.

No system is perfectly secure. If you believe you have found a vulnerability, contact security@hardgap.com.

Children

This site is not directed to children under 16 and we do not knowingly collect their personal information.

Changes

If we change this policy materially, we will post the revised version here and email account holders before it takes effect.