Old Soul Manufacturing

Privacy Policy

Last updated June 20, 2026

This policy explains what personal information we collect, why we collect it, who we share it with, and the choices and rights you have. We do not sell your personal information.

1. Who we are

[LEGAL ENTITY NAME — e.g. Old Soul Manufacturing LLC] (“Old Soul Manufacturing,” “we,” “us”) is the controller responsible for the personal information processed through oldsoulmfg.com. You can contact us using the details at the end of this policy.

2. Information we collect

We collect the following categories of information:

  • Information you provide: name, email address, shipping and billing address, phone number, account credentials, order and product configuration details, and any messages or feedback you send us.
  • Payment information: payment card details are collected and processed directly by our payment processor (Stripe). We receive limited confirmation and transaction data, not your full card number.
  • Automatically collected information: device and browser type, IP address, pages viewed, referring pages, and similar usage data, collected through cookies and similar technologies (see our Cookie Policy). Some of this is collected only when analytics cookies are active, which depends on your cookie choices.

3. How we use your information

We use personal information to:

  • process, fulfill, and deliver your orders;
  • create and manage your account and authenticate sign-ins;
  • communicate with you about orders, support requests, and important service notices;
  • operate, secure, debug, and improve the site and our products;
  • understand how the site is used through analytics (subject to your cookie choices); and
  • comply with legal obligations and enforce our terms and policies.

4. Legal bases (EEA/UK)

If you are in the European Economic Area or the United Kingdom, we rely on these legal bases under the GDPR / UK GDPR:

  • Performance of a contract — to process and deliver orders and manage your account;
  • Legitimate interests — to secure, maintain, and improve the site, and to prevent fraud, balanced against your rights;
  • Consent — for analytics and similar non-essential cookies, which you can withdraw at any time; and
  • Legal obligation — to comply with tax, accounting, and other legal requirements.

5. How we share information

We do not sell your personal information and do not share it for cross-context behavioral advertising. We share information only with service providers who process it on our behalf, under contract, and only as needed to run the business:

  • Stripe — payment processing;
  • WorkOS — account authentication and sign-in;
  • Convex — application database and backend;
  • Vercel — website hosting, file/image storage, and performance/usage analytics;
  • Microsoft Clarity — product analytics and session insights (loaded according to your cookie choices);
  • Resend — transactional and account email delivery; and
  • Shipping carriers — to deliver your orders.

We may also disclose information when required by law, to protect our rights and the safety of others, or in connection with a business transfer such as a merger or acquisition.

6. International data transfers

We are based in the United States, and our service providers may process your information in the United States and other countries. When we transfer personal information from the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses where required.

7. Data retention

We keep personal information for as long as needed to provide the site, fulfill orders, and meet our legal, tax, and accounting obligations, after which we delete or anonymize it. Order records are typically retained for the period required by applicable tax and commercial law.

8. Security

We use reasonable administrative, technical, and organizational measures to protect personal information, including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent.

EEA / UK residents

You have the rights described above under the GDPR / UK GDPR, including the right to lodge a complaint with your local data protection authority.

California residents (CCPA/CPRA)

You have the right to know what personal information we collect, to request access and deletion, to correct inaccurate information, and to not be discriminated against for exercising these rights. We do not sell or share your personal information as those terms are defined under California law.

To exercise any of these rights, contact us using the details below. We will verify your request and respond within the timeframe required by applicable law. You may use an authorized agent where permitted.

10. Cookies and analytics

We use strictly necessary cookies to run the site and, subject to your region and choices, analytics cookies to understand and improve it. Where consent is required (such as the EEA and UK), analytics stays off until you opt in. You can change your choice at any time using “Cookie settings” in the footer. See our Cookie Policy for details.

11. Children's privacy

The site is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. The “Last updated” date shows the latest version, and material changes will be posted on this page.

13. Contact us

To exercise your rights or ask questions about this policy, contact:

[LEGAL ENTITY NAME — e.g. Old Soul Manufacturing LLC][STREET ADDRESS][CITY, STATE ZIP]United StatesSupport: [support@oldsoulmfg.com]Privacy requests: [privacy@oldsoulmfg.com]