Crumb & Copper Bakery · POLICIES
Privacy Policy
What information is used for your order, why it is needed, and how it is handled.
Scope and current preview
This policy describes the guest ordering service planned for Crumb & Copper Bakery and the limited browser storage used by the current storefront preview. Customer accounts and the Phase 2 reporting and forecasting features are not part of the current guest checkout.
Online payments, order records, customer emails, and the production database are not connected in this preview. The planned processing described below must be checked against the deployed services before this policy is published.
Information used for ordering
When ordering is enabled, checkout requests your business name, contact name, phone number, email address and confirmation, delivery address, selected delivery date, quantities, item notes, and order instructions. The service also keeps the accepted terms version, acceptance time, prices, tax, and payment references needed to record the order.
Please include only information needed to prepare and deliver your order in free-text notes. The payment page is hosted by Stripe; card details are entered there, rather than in a bakery-hosted card form.
Why information is used
Order information is used to validate your order, reserve available stock and delivery capacity, arrange delivery, process payment and eligible refunds, and send order confirmations, changes, cancellations, and shortage notices.
Customer records are matched using email so paid orders can be associated with the correct wholesale business. The planned Phase 2 customer directory and statements use paid-order history. The PDFs do not specify a marketing subscription, so this draft does not describe checkout as consent to marketing.
Saved carts and secure links
The storefront saves your cart in your browser’s local storage, including item quantities and notes and whole-order instructions. This lets the cart remain after closing the tab. Removing items or clearing the site’s browser storage removes that local copy. Current checkout form details are held in the open page; the preview does not save a paid order.
When ordering is enabled, confirmation and shortage emails contain secure links. Treat those emails as private because someone with a valid link may be able to view or act on the related order. Links have a limited lifetime and may be invalidated after use or replacement.
Service providers
The build plan uses Hostinger for hosting, database services and transactional email; Stripe for payments and refunds; Cloudflare Turnstile for bot checks; Sentry for error monitoring; and Backblaze B2 or an S3-compatible service for off-site backups.
These are planned services, not a claim that every provider is active in this preview. Before launch, the bakery must confirm the actual providers, processing locations, access arrangements, and the information each service receives. No analytics or advertising service is specified in the PDFs.
Retention and deletion
The documented production cleanup schedule deletes unpaid checkout details after 30 days and used secure-link records after 90 days. Manage Order viewing ends 14 days after delivery. Raw link tokens are not kept in the email queue; token records are stored in hashed form.
The plan retains nightly database and image backups for 30 days. These cleanup and backup jobs still need to be connected and verified in the deployed system. The PDFs do not specify a complete retention period for paid orders, customer records, payment records, or monitoring logs; that schedule must be finalized before this policy is published.
Access and protection
The production plan limits team access through permissions, uses secure expiring links, verifies payment notifications, and includes bot checks and request limits. Staff roles have different access to order and payment information; kitchen views omit prices.
These controls describe the planned production service. They are not a statement that the unfinished preview already implements every control. Submitted order information should be handled only through the verified production flow when it is available.
Questions and information requests
Contact the bakery using its confirmed business contact details for a question about your information or a request to review, correct, or delete it. The bakery will explain whether any records need to remain for payment, business, or applicable legal requirements.
Confirmed contact details and the final retention and service-provider information must be added before publication. Changes to the published policy will carry a new version label and update date.