Privacy policy · Pre-launch draft
Privacy Policy
Data categories, first-party analytics, newsletter processing, future orders, service providers, retention, security, and U.S. privacy rights.
1. Operator and policy status
The current website already operates first-party analytics and an email signup. Those live practices are described below; future checkout practices are clearly labeled as future.
This is a pre-launch operational draft. It is deliberately not represented as attorney-approved, and it must not be treated as a substitute for product-specific legal advice.
The final policy must name the legal entity responsible for personal information, provide a mailing address and monitored privacy contact, and identify the effective date. Until then, commerce must remain disabled.
2. Information collected
Current collection includes an email address submitted to the field-note list and first-party analytics events. Analytics records may include randomly generated visitor and session identifiers, page path, event type, botanical slug, referring hostname, and timestamp. The application is designed not to intentionally store a raw IP address or full browser user-agent string in the analytics table.
Future commerce may collect name, email, telephone number when needed, billing and shipping addresses, order contents, transaction identifiers, tax information, customer-service communications, return details, fraud signals, legal-consent versions, and carrier tracking data. Full card details should be collected directly by the payment provider rather than stored by Lot & Leaf.
Information may come directly from a person, from the browser or device, from service providers involved in a requested transaction, or from lawful public and anti-fraud sources.
3. Purposes of use
Information may be used to operate and secure the site, maintain the subscriber list, send requested communications, measure content and catalog interest, prevent abuse, troubleshoot, comply with law, and establish or defend legal rights.
When commerce launches, information may also be used to validate eligibility and inventory, process payment, calculate tax, fulfill and track orders, provide support, administer returns, investigate complaints, conduct withdrawals or recalls, and maintain accounting and consent records.
4. Cookies, local storage, analytics, and preference signals
The current analytics system uses browser storage to maintain random visitor and session identifiers. It measures page views, botanical views, clicks, and future funnel events. It excludes private admin paths and is designed to stop collection when the browser sends Do Not Track or Global Privacy Control.
Lot & Leaf does not currently use cross-site behavioral advertising pixels or sell analytics profiles. Any future advertising technology must undergo a new consent, contract, disclosure, and state-law review before deployment.
5. Service providers and disclosures
Information may be disclosed to vendors acting for Lot & Leaf, such as Vercel for hosting, Neon for database infrastructure, Resend for email-list services, and future approved providers for payment, tax, fraud prevention, shipping, customer support, analytics, security, and professional advice.
Information may also be disclosed when reasonably necessary to comply with law, protect rights or safety, investigate abuse, respond to a valid legal process, or complete a financing, merger, acquisition, reorganization, or asset transfer subject to applicable safeguards.
Lot & Leaf does not currently sell personal information, share it for cross-context behavioral advertising, or offer a financial incentive in exchange for personal information.
6. Email marketing
Submitting an email through the field-note form requests occasional catalog, Herbarium, and launch messages. Every commercial campaign must identify the sender, use accurate subject and routing information, include a valid postal address, provide a clear unsubscribe method, and honor opt-out requests within the legally required period.
A suppression record may be retained after unsubscribe so the address is not re-added accidentally. Transactional order, safety, recall, or account messages may still be sent where permitted and necessary even after marketing opt-out.
7. Retention and deletion
Launch blocker: a policy promise is not enough; retention periods must match deployed database and vendor deletion behavior.
Information should be kept only for a documented business, safety, tax, accounting, fraud-prevention, consent, dispute, recall, or legal purpose and then securely deleted or de-identified.
An automated retention and deletion schedule has not yet been deployed. Before commerce launches, Lot & Leaf must approve category-specific periods for analytics, subscribers, orders, customer service, complaints, adverse events, security logs, tax records, and suppression records and implement the corresponding jobs and legal holds.
8. Security and incident response
Lot & Leaf uses measures intended to reduce risk, including restricted owner access, one-time email authentication for the admin area, transport encryption, server-side environment secrets, input validation, and limited analytics fields. No system can guarantee absolute security.
Before commerce, the business must complete least-privilege review, vendor access review, backups, restoration testing, vulnerability response, incident escalation, breach-notification assessment, and documented secure disposal.
9. U.S. privacy choices and requests
Depending on residence and applicable law, a person may have rights to know or access information, correct inaccuracies, delete information, obtain a portable copy, opt out of certain sales, sharing, targeted advertising, or profiling, limit certain sensitive-information uses, and appeal a denied request.
Lot & Leaf intends to offer a baseline access, correction, deletion, and portability process to U.S. residents even when a particular state threshold does not apply, subject to identity verification and lawful exceptions. A monitored request channel, verification procedure, response calendar, appeal method, and authorized-agent process must be operational before commerce.
Global Privacy Control is currently honored by the first-party analytics client. Because Lot & Leaf does not currently sell or share data for targeted advertising, no separate opt-out sale is presently needed; this conclusion must be revisited before adding advertising technology.
10. Children
The site and products are not directed to children under 13, and Lot & Leaf does not knowingly collect personal information from a child under 13. A person who believes a child submitted information should use the final privacy contact so the record can be investigated and deleted where required.
Future purchasing requires an adult with legal capacity. Lot & Leaf will not use age language as a substitute for any higher product-specific age-verification requirement.
11. California and other state notices
California’s online privacy law requires conspicuous disclosure of collection and tracking practices even for many businesses below the CCPA’s larger-business thresholds. If Lot & Leaf later meets a comprehensive state privacy-law threshold, the final policy and request workflow must include all additional required notices and metrics.
The separate U.S. State & California Consumer Notices page explains the current working approach to notice at collection, sensitive information, financial incentives, and nondiscrimination.
12. Changes and contact
Material changes will be dated and, where required, separately communicated or presented for renewed consent. The final policy will provide a monitored privacy email and postal address. No request deadline begins through a placeholder contact channel.
Primary-source trail
Official guidance used for this draft
These links explain the regulatory baseline behind this policy. They are not an endorsement of Lot & Leaf and do not replace product-specific professional advice.
- California DOJ — Online privacy policy requirements
CalOPPA background for commercial sites collecting information from Californians.
- FTC — Start with Security
Data minimization, need-based retention, access, and reasonable security principles.
- FTC — COPPA FAQs
General-audience sites, actual knowledge, and information from children under 13.
- FTC — CAN-SPAM compliance guide
Commercial email identification, postal address, opt-out, and vendor oversight.