Privacy policy
What personal information Wehoz collects, how we use it, and the choices you have about it.
title: Privacy policy description: What personal information Wehoz collects, how we use it, and the choices you have about it. topic: policies order: 20 updated_at: "2026-05-30" effective_date: "2026-05-30" version: "v1.0" tags: [privacy, gdpr, ccpa, data]
1. Who this policy is for
This Privacy Policy applies to people who visit wehoz.com, place orders, or otherwise interact with the Wehoz Service. It describes how Wehoz, Inc. (“Wehoz”, “we”) collects, uses, shares, and protects personal information.
2. Information we collect
Account and contact details — name, email address, phone number (optional), shipping and billing addresses. Provided when you create an account or place an order.
Order history — items you've purchased, dates, amounts, shipping addresses, tracking numbers.
Payment information — handled by our payment processor (Stripe) and not stored in full on Wehoz systems. We retain the last four digits and card brand for receipts and chargeback handling.
Communication — emails or messages you send us, along with our replies. Phone is not in scope at launch; if we add it, recordings will require consent and a separate disclosure.
Device and usage data — browser type, IP address, pages viewed, time on site, referrer URL, device identifiers. Collected automatically by our analytics tools.
Cookies and similar technologies — see Section 6.
3. How we use it
- Fulfill orders — process payments, ship items, handle returns and refunds
- Communicate — send receipts, shipping notices, customer-service replies
- Improve the Service — understand which pages people use, fix bugs, plan new features
- Detect and prevent fraud — flag unusual orders, address verification, chargeback investigation
- Marketing (with appropriate consent) — newsletters, restock alerts, abandoned-cart reminders
- Legal compliance — respond to lawful requests, enforce our Terms
4. How we share it
We share personal information only with:
- Service providers — payment processing (Stripe), shipping (USPS, UPS, FedEx, EasyPost), email delivery (Resend), analytics (PostHog, Google Analytics), error monitoring (Sentry), infrastructure (Cloudflare, Vercel, Supabase). Each has a contract requiring appropriate handling.
- Brands and sellers — limited information needed to fulfill orders, such as your name and shipping address. Once Phase 3 multi-seller is live, the same applies for third-party sellers.
- Legal authorities — when required by law, court order, or a good-faith belief that disclosure is necessary to protect rights, safety, or property.
- Successors — if Wehoz is acquired or merged, personal information may transfer to the successor. We'd give notice before that happens.
We do not sell your personal information. We don't share it for cross-context behavioral advertising in a way that requires opt-out under CCPA. See CCPA notice for California-specific rights.
5. International transfers
If you're outside the United States, your information may be transferred to and processed in the United States, where data-protection laws may differ from those in your country. We rely on standard contractual clauses where applicable to provide appropriate safeguards.
6. Cookies and analytics
We use first-party cookies for essential functions (cart persistence, sign-in, fraud prevention) and a small set of analytics cookies (PostHog for product analytics, Google Analytics 4 for traffic measurement).
- Essential cookies can't be turned off — they're required for the cart and checkout to work.
- Analytics cookies can be turned off via the consent banner on first visit, and any time after via the Cookie preferences link in the footer.
We honor Global Privacy Control signals. If your browser sends a GPC header, we treat it as an opt-out of analytics and marketing tracking.
PostHog session replays mask all input fields by default; we cannot see what you type into a form. Sensitive elements are explicitly tagged for masking.
7. Data retention
| Category | Retention |
|---|---|
| Order records | 7 years (US tax and consumer-protection minimum) |
| Account profile | While the account is active, plus 30 days after closure |
| Marketing email lists | Until you unsubscribe |
| Customer-service emails | 3 years from last interaction |
| Analytics | 14 months in detailed form, then aggregated |
| Logs (security/audit) | 90 days |
8. Your choices
- Access — request a copy of the information we hold about you
- Correct — fix anything that's inaccurate
- Delete — ask us to delete what we have, subject to retention requirements above
- Opt out of marketing — unsubscribe link in any marketing email
- Opt out of analytics — via the consent banner or by sending a GPC signal
- California, Colorado, Connecticut, Virginia, Utah residents — additional state-specific rights, including the right to know, delete, and (where applicable) opt out of "sale" / "share". See CCPA notice.
To exercise any right, email privacy@wehoz.com. We respond within 30 days (45 with notice in complex cases).
9. Security
We use industry-standard safeguards:
- HTTPS everywhere — no unencrypted endpoints
- Cloudflare WAF + bot management at the edge
- Tokenized payments — full card numbers never reach our systems
- Row-level access controls on customer data
- Encryption at rest for sensitive fields (addresses, phone numbers)
- PCI-DSS SAQ-A scope (Stripe Elements handles card data)
No system is perfectly secure. If we become aware of a breach affecting your information, we'll notify you and applicable authorities as required by law.
10. Children
Wehoz is not directed at children under 13. We don't knowingly collect personal information from children. If you believe a child has given us information, email privacy@wehoz.com and we'll delete it.
11. Third-party links
Our Service may link to third-party sites (brand pages, manufacturer warranty portals, carrier tracking). Their privacy practices are their own — we're not responsible for what they do.
12. Changes to this policy
We may update this Privacy Policy as our practices evolve or laws change. The Effective date at the top reflects the current revision. Material changes are announced by email if you have an account, with at least 30 days' notice before they take effect.
13. Contact
Privacy questions, requests, or complaints: privacy@wehoz.com.
Wehoz, Inc. Attn: Privacy [Entity address — to be finalized at incorporation]