Order Online Pay Separately Blank Apparel
Menu

Privacy

Privacy (CCPA)

Policies

California Consumer Privacy Act (CCPA)

This page describes California residents' rights under the California Consumer Privacy Act (CCPA/CPRA) and the disclosures required by the California Online Privacy Protection Act (CalOPPA). Effective / last updated: 2026-07-30.

Categories of Data Collected, Sources & Purposes (Notice at Collection)

  • Identifiers (source: you): name, email, phone, account — used for your account, orders, and customer service.
  • Sign-in credentials (source: you): password hash, verification/reset tokens — used for account security.
  • Commercial information (source: you / transactions): orders, shipping addresses, tax-exemption applications, artwork, and group store data — used for fulfillment, tax, and dispute handling.
  • Payment information (source: you / Stripe): card numbers are processed by Stripe; we do not store full card numbers.
  • Internet activity (source: automatic): IP address, browser, cart/customizer records, GPC/opt-out preferences — used for security, fraud prevention, and honoring privacy signals.
  • Communications (source: you): contact forms, quotes, privacy requests — used for responses and compliance records.

Disclosure Recipients & Third-Party Categories

Service providers may include: payment processing (Stripe), email delivery, and hosting providers (such as Bluehost). We instruct them to process data only to provide their services. This site does not load fonts or libraries from public CDNs such as Google Fonts or jsDelivr.

Sale / Sharing & GPC

We currently do not sell personal information, nor do we "share" it for cross-context behavioral advertising. If your browser sends Global Privacy Control (GPC / Sec-GPC), we record it and treat it as an opt-out-of-sale/sharing signal.

California Do Not Track Disclosures (CalOPPA)

Legacy browser Do Not Track (DNT) is different from GPC. This site currently does not engage in behavioral-advertising tracking across time or across third-party websites (no third-party trackers at this time), so we do not respond further to DNT. We do honor GPC. If we add analytics or advertising trackers in the future, we will update this disclosure and disable the relevant vendors where feasible.

Whether other parties currently collect personal information about your cross-site activity on this site: No (to our knowledge and under our current configuration).

Categories Disclosed in the Past 12 Months

In the past 12 months, we may have disclosed for business purposes the following categories to service providers (not sold, and not shared for cross-context behavioral advertising): identifiers, commercial information, information needed for payment processing, internet activity (security/fraud prevention), and communications. Recipients are limited to service providers such as Stripe, email delivery, and hosting providers.

Cookies, localStorage & sessionStorage

  • Cookies: session, CSRF, GPC/opt-out preferences, and guest order authorization (HttpOnly).
  • localStorage / sessionStorage: cart (about 30-day TTL), checkout drafts (about 14 days), and customizer autosave — used only to complete transactions and improve your experience, not for cross-site ad tracking.

Player Names & Children's Data

Group stores may optionally collect player/name notes, used solely for print identification and order fulfillment. This service does not target advertising to children under 16 and does not knowingly collect children's personal information for marketing. If we learn such data was collected in error, we will delete or anonymize it upon request (subject to legal retention exceptions).

Retention

Tax-related records such as orders, invoices, refunds, and exemption certificates are retained for at least about 1460 days (aligned with California sales/use tax records, typically at least four years); retention is longer during ongoing audits, disputes, or legal holds. Contact/marketing data is retained for about 730 days, or handled under legal exceptions after you request deletion or your account is anonymized.

Your Rights & Identity Verification

  • The right to know/access, delete, correct, opt out of sale/sharing, limit the use of sensitive personal information (where applicable), and non-discrimination.
  • Requests may be submitted through an authorized agent; before exporting or deleting data, we require reasonable identity verification (for example, matching recent orders and contact details).
  • Signed-in members can find correction/deletion entry points on the account page, which lead to the verified privacy request flow.
  • We aim to respond within 45 days, and will extend as permitted by law with notice to you when necessary.

To submit a request: use the Privacy Request Form or email [email protected].

Deletion exceptions may include: completing a transaction, tax/accounting requirements, fraud detection, ongoing disputes, or legal retention obligations.

← Back to the general Privacy Policy