Legal
Privacy policy
This policy explains how Rooted Branch Workshop handles personal information when you browse the site, create an account, place an order, download a file, request a quote, or contact the workshop. It is effective July 21, 2026.
Information you provide
We receive information you choose to provide, including your name, email address, account details, order and shipping information, support messages, quote-request details, and files, links, or references you include in a request. Stripe processes payment-card details; Rooted Branch Workshop does not receive or store your complete card number or security code.
Google sign-in data
If you choose Google sign-in, Google and our authentication provider, Clerk, may provide the basic identity information you authorize, such as your name, email address, profile image, and account identifiers. We use that information only to authenticate and secure your account, display account details, prefill forms, and match eligible orders and downloads to your verified email. We do not request access to Gmail, Google Drive, Google Contacts, or Google Calendar.
Information collected automatically
When you use the site, our hosting and security systems may receive network and request information such as your IP address, browser or device details, request headers, requested pages, timestamps, and error or security events. Public support and quote requests use the IP address to derive a keyed one-way rate-limit identifier; the raw IP address is not intentionally stored in that rate-limit record. We use this information to deliver the site, prevent abuse, investigate failures, and protect customers and the service.
How information is used
We use personal information to operate and secure accounts, process and fulfill orders, deliver digital files, send transactional messages, provide support, prepare custom-service quotes, prevent fraud and abuse, troubleshoot errors, maintain required business records, and improve the reliability of the service.
Cookies and local storage
The site uses cookies and browser storage that are necessary for authentication, customer-support sessions, guest-checkout confirmation, cart and checkout continuity, and security. We do not currently use third-party advertising cookies or behavioral advertising trackers.
Service providers
We use service providers to run the site: Clerk and Google for optional account authentication; Stripe for checkout, payment, and refunds; Supabase for orders, download entitlements, private file delivery, support records, and operational data; Resend and the workshop mailbox provider for transactional and support email; Vercel for application hosting; and Sanity for catalog content and images. They process information only as needed to provide their services and under their own applicable terms and privacy commitments.
When information is shared
We share information with the service providers above, when needed to complete a transaction or respond to you, when required by law or a valid legal process, to protect customers or the service, or as part of a business transfer. We do not sell personal information or share it for cross-context behavioral advertising.
Retention
We keep information for as long as reasonably needed to provide the service, maintain financial and transaction records, resolve disputes, enforce agreements, meet legal obligations, and protect the service. Short-lived session, email-delivery, and operational records expire or are purged on bounded schedules. Core order, refund, account-linkage, download, and support records do not currently have a fixed automatic deletion deadline; they are retained until no longer needed or a verified deletion request can be honored. Some transaction and security records may need to remain after an account or conversation is closed.
Your choices
You may update supported account details through the account interface or contact us to ask about access, correction, or deletion of personal information. We will honor applicable rights after verifying the request, subject to records we must keep for legal, transaction, fraud-prevention, or security reasons. You may choose another available sign-in method instead of Google sign-in.
Security and children
We use access controls, private storage, signed links, scoped sessions, and other safeguards designed to protect personal information, but no system is completely secure. The shop is intended for adults and is not directed to children under 13. If you believe a child provided personal information, contact us so we can review and remove it when appropriate.
Policy changes
We may update this policy when the service or our data practices change. The effective date above will be revised, and material changes will be communicated when required. Continued use after an update is subject to the revised policy.
Questions are welcome. Use the site chat, or email info@rootedbranchworkshop.com.