Privacy Policy
Goth-It
521 8th Street, Greeley, Colorado 80631
Last updated: September 2026
What we do
We are a retail shop with special events: we take your order, we ship it, we help you if something goes wrong. We collect what that requires and nothing else.
- No advertising trackers. No Meta pixel, no Google Ads tag, no retargeting of any kind.
- No analytics package.
- No selling, renting, or trading your information. Ever, to anyone.
- No comments, no forums, no user profiles beyond an optional account.
- All newsletters are opt-in first.
- We never see your full credit card number or financial information.
If this seems short for a privacy policy, that is the point.
This policy covers the website. Shopping with us in person is not covered in this document except that an in-store order entered into this system is handled the same way.
1. What we collect
When you place an order: your name, shipping address, billing address, email address, and phone number if you give one. We collect information about what you bought, what you paid, and anything you typed into the order notes.
When you pay: our payment processor collects and handles your card details. We receive only whether the payment succeeded, the card brand, and the last four digits. Full card numbers never touch our servers.
If you create an account: We store your username, email address, a scrambled version of your password that cannot be read back, and any addresses you choose to save.
When you contact us: Whatever you write to us, and your email address or phone number so we can answer.
When you return something or report a lost or damaged package: your order details and any photos you send.
Automatically: our web host keeps standard server logs with your IP address, browser type, the pages requested, and the time. These exist for security and troubleshooting. We do not analyze them for marketing.
We do not collect precise location, we do not ask for a date of birth, and we do not collect anything about you that is not on the list above.
2. Cookies
We only use cookies the store cannot run without:
- Cart and checkout. WooCommerce sets a cart identifier, an item counter, and a session cookie so your cart survives while you shop. Without these, checkout does not work.
- Login. Only if you create an account and log in. These keep you signed in and are cleared when you log out.
That is the entire list. No advertising cookies, no analytics cookies, no third-party cookies set by us. Your browser settings can block or clear cookies, but note that blocking the cart cookies will break checkout.
3. Who else touches your information
Only the companies that have to, and only for the job in front of them:
| Who | What they get | Why |
|---|---|---|
| [WooPayments / Stripe] | Card details, billing name and address, amount | To process the payment and screen for fraud |
| [USPS / UPS / FedEx] | Name, shipping address, phone or email for delivery notices | To deliver the package and handle claims |
| [WEB HOST] | Whatever passes through the server, including logs | To run and secure the site |
| Our accountant and attorney | Transaction records as needed | Tax filings and legal advice, under professional confidentiality |
We will also hand over information if a law, subpoena, or court order requires it, or if the business is ever sold, in which case the buyer inherits these same commitments. We will tell you about a legal demand for your data unless we are barred from doing so. Note that any such legal demand will require a proper warrant and/or subpoena and that the minimal information we keep probably won’t be helpful anyway.
That is the complete list. There is no data broker, no advertising network, no analytics vendor, and no marketing platform in the chain.
4. How long we keep it
Customer data is deleted on a schedule automatically, rather than waiting for you to ask. All records are kept to IRS and legal minimums.
| What | How long |
|---|---|
| Abandoned, failed, and cancelled orders | 30 days, then deleted |
| Completed orders | 4 years, then the name, address, phone, and email are stripped out and only the anonymous sales figures remain |
| Account that has not been used to log in or order | 1 years, then deleted |
| Email you send us | 1 year |
| Server logs | 30 days |
The retention period on completed orders exists because Colorado requires retailers to keep the books and records needed to determine the correct tax for a minimum of three years, and the state has three years from the filing date to assess sales tax. We keep a margin past that and then strip the personal elements.
5. Email
We send marketing email only to people who actively ask for it. Subscribing is a separate checkbox, never bundled into checkout, and never automatically enabled. Every message has a one-click unsubscribe. When you unsubscribe we keep only your email address on a do-not-contact list so we do not accidentally add you back.
5. Your choices
- See what we have. Ask and we will send you a copy.
- Fix it. Ask, or log in and edit it yourself.
- Delete it. Ask and we will delete what we are not legally required to keep.
- Close your account. Ask, or use the account page.
Email [email protected] with “Privacy Request” in the subject. We do not require you to create an account to make a request. We may ask a question or two to confirm you are the person the data belongs to.
Colorado residents. State law gives you rights to access, correct, delete, and get a portable copy of your data that we posses, but in fact all data we posses is available to you in your account page.
Browser opt-out signals. We honor the Global Privacy Control. There is nothing for it to switch off on our site, but we recognize it.
7. Minors
Because there are laws regarding businesses targeting minors, we require that all orders must be placed by someone 18 or older. See our Terms and Conditions for further information. We do not knowingly collect information from anyone under 18, we do not create accounts for anyone under 18, and if we find out we have, we delete it. Parents or guardians who think we have their child’s information can email us and we will search for and remove it.
We do not run design features meant to keep anyone on the site longer, we do not profile anyone, and we do not collect precise location. Those are not just policies for minors, they are how the site is built.
8. Security
The site runs on HTTPS with strong encryption and has advanced intrusion detection and prevention measures. WordPress, WooCommerce, and site plugins are kept current. Administrative access is limited to the people who need it (Principal of Least Privilege). Credit card data is handled by the payment processor and does not reach our servers. That said, no Internet site is unbreakable, and we will not pretend otherwise – if a breach exposes your personal data we will notify you to the best of our ability, and as required by law.
9. Other sites
We link to places we do not control, and we may embed a map or a video from sites we do not control. Embedded content behaves as if you had gone to that site yourself and might set its own cookies.
10. Where your data lives
All data is retained within the continental United States.
11. Changes
Revisions get posted here with a new date. If we ever start doing something materially different, particularly anything involving advertising or analytics, this page will be updated and such changes clearly indicated.