Skip to main content

Privacy notice

Collect less. Explain it clearly.

The intended Curbidz privacy model uses personal information for disclosed, limited purposes; does not treat it as a blank-check company asset; and gives customers practical choices. The live systems and final notice are not complete.

Prelaunch draft

This page is a working draft, not a final policy or legal conclusion. Checkout is disabled until the missing business and product facts are finalized and the required review is complete.

Draft updated: August 30, 2026Effective date: not establishedPrivacy contact: pending verification

1. Scope

What the final notice will cover

The final notice will cover the Curbidz website, customizer, checkout and order flow, transactional communication, customer support, consented marketing, and related administrative systems. It will identify the responsible business and explain which practices apply when someone merely browses, builds a preview, places an order, requests support, or chooses marketing.

It will not claim that Curbidz “owns” a customer's personal information. Any limited rights needed to process a customization, fulfill an order, prevent fraud, provide support, or meet legal obligations will be described by purpose and duration.

2. Planned data map

Information tied to a specific job

Only categories needed for a working storefront, a reliable production record, or an explicitly chosen relationship are planned for launch.

Contact and delivery

Name, email address, shipping address, and—only if the final workflow needs it—an optional telephone number. Used for checkout, fulfillment, transactional notices, and customer support.

Customization and order

Address digits, selected design, dimensions, quantity, preview/version references, order number, price components, tax, shipping, status, refund, replacement, and production-quality records.

Payment metadata

A hosted payment provider is planned to process card details. Curbidz intends to retain only limited transaction references and permitted display details, not full card numbers or card security codes.

Device and security events

Limited network, browser, request, error, fraud-prevention, and authentication information when needed to deliver and protect the service. Personal details will be scrubbed from debugging tools wherever practicable.

Support information

Messages, issue categories, order references, and focused photographs or attachments a customer chooses to provide. Unrelated sensitive data will not be requested, and image metadata will be minimized when feasible.

Consent and preferences

Separate records of marketing choice, notice version, timestamp, source, and unsubscribe or opt-out status. Order communication will not depend on an agreement to receive promotional messages.

3. Intended purposes

Why information would be used

  • Render, validate, save, and reproduce a customer-approved customization.
  • Calculate the order total and operate a hosted payment and fraud-prevention flow.
  • Create, produce, quality-check, ship, track, support, refund, or replace an order.
  • Send confirmations, service notices, delay choices, support responses, and other transactional messages.
  • Protect accounts and systems, diagnose errors, prevent abuse, preserve evidence, and recover service.
  • Maintain tax, accounting, dispute, warranty or claim records where applicable.
  • Send marketing only after a separate, voluntary choice and preserve the suppression record after opt-out.
  • Comply with valid legal obligations and establish, exercise, or defend legal claims.

A materially new use that is incompatible with the disclosed purpose will not be smuggled into the system merely because the information already exists.

4. Current and future recipients

Service providers—not a free-for-all

The final notice will name or clearly categorize each active provider and link to additional information where useful. It will describe the system that actually exists—not a vendor wish list.

Current public preview

  • Cloudflare delivers and protects the public website
  • The browser may hold a short-lived customization handoff in session storage
  • No payment, order database, transactional email, marketing, or customer-monitoring integration is active

Before commerce opens

  • A hosted payment provider will process payment details
  • Approved data, storage, email, monitoring, carrier, and support providers will be configured and tested
  • The final notice will identify or categorize each active recipient before customer information is collected

Access will be limited by role and contract where appropriate. Information may also be disclosed when required by valid legal process, to protect rights and safety, or as part of a reviewed business transaction with legally required notice and choices. The final notice will describe the actual practice—not a hypothetical permission to disclose information for any reason.

5. Cookies, analytics & advertising

No behavioral-advertising stack at launch

Required technology

Security, session, checkout, load-balancing, and fraud-prevention technology may be necessary to deliver the requested service. The final cookie notice will identify what is actually deployed.

In the current preview, an address number and selected design may be held in this browser tab's session storage for up to 30 minutes solely to prefill the full customizer. The browser automatically deletes the handoff when that period ends. The value is not placed in the URL or sent to Curbidz by that handoff.

Measured analytics

The intended first-party measurement approach favors Cloudflare's privacy-oriented web analytics and PII-scrubbed operational telemetry. Session replay is not planned for launch.

Marketing controls

Meta, TikTok, Google advertising pixels, and cross-context behavioral advertising are not planned for launch. Adding them would require a new legal, consent, opt-out, and Global Privacy Control review first.

The intended launch position is not to sell personal information or share it for cross-context behavioral advertising. The finished preference system will recognize applicable browser-based opt-out signals, including Global Privacy Control, and will not use a dark pattern to reverse a choice.

6. Retention

Keep the record only as long as the job requires

Different records need different retention periods. An abandoned preview, unpaid checkout, paid order, production artifact, tax record, support case, security log, backup, and marketing suppression record should not all live forever under one generic rule.

Before launch, Curbidz will assign each record a documented trigger, period, deletion or anonymization action, legal-hold exception, backup behavior, and responsible owner. Exact periods will be confirmed with operational, tax, warranty, dispute, and legal requirements and then summarized in the final notice. Information that is no longer needed will be securely deleted or de-identified under that schedule.

7. Customer choices

A usable rights process

Curbidz intends to offer a practical baseline of privacy choices to U.S. customers where feasible, while honoring any broader rights required by applicable law.

Access and know
Request the categories or specific personal information maintained about you, subject to verification and lawful exceptions.
Correct
Ask Curbidz to correct inaccurate personal information, with order-integrity records preserved where alteration would be improper.
Delete
Ask for deletion, subject to exceptions needed for completed transactions, security, tax, disputes, legal duties, and suppression of unwanted marketing.
Portable copy
Receive eligible information in a usable format where applicable and technically feasible.
Opt out
Unsubscribe from marketing and exercise applicable sale, sharing, targeted-advertising, or profiling choices—even though those advertising practices are not planned at launch.
Appeal
Use the final published appeal path if an applicable state law requires one and a request is denied.
No retaliation
Exercise an applicable privacy right without unlawful discrimination.

The final request page will explain identity verification, authorized-agent treatment, search systems, processor propagation, response timing, exceptions, and appeals. Curbidz will not ask for more verification information than the request reasonably requires.

8. Security and children

Guardrails without false guarantees

Reasonable safeguards

The planned controls include multi-factor authentication, least privilege, managed secrets, row-level database rules, signed webhooks, restricted admin access, encrypted transport, logging minimization, backups, monitoring, and an incident-response process. No internet service can promise absolute security.

General-audience service

Curbidz is not intended for children under 13 and does not plan to knowingly collect their personal information. The intended purchasing rule is for adults able to enter a binding agreement. The final policy will provide a verified channel for a parent or guardian to raise a concern.

9. Updates and contact

No silent mismatch between words and code

The published notice will carry an effective date and version. A material change will receive notice appropriate to the change and applicable law. Code, consent surfaces, vendor configuration, retention rules, and customer-rights operations will be reviewed against the text before a new version takes effect.

The responsible seller/controller name, monitored privacy contact, and mailing address have not been finalized and therefore do not appear as placeholders. See the contact status page for the current state.