Privacy Policy
Archery Specialty Store prioritizes individual user data security and transparent digital operations. Visiting our website or submitting transaction details grants us authorization to process essential order information. We designed this policy to inform you exactly what we collect, why we collect it, and how we protect it. No hidden clauses, no data broker deals, no ambiguous legalese.
What we collect and why
Customer identification data stays protected behind enterprise encryption systems. Order processing requires gathering buyer names, shipping destinations, payment credentials, and direct email communications sent through contact@archeryspecialtystore.com. We collect only what we need to fulfill your order, provide support, and comply with tax and shipping regulations.
We also collect non-identifying technical data automatically. This includes IP addresses, browser types, operating systems, and session timestamps. These metrics help us detect fraud, optimize site performance, and understand how users interact with our product pages. None of this automatic data links directly to your personal identity unless you log into an account or place an order.
Data Handling Protocols ┌───────────────────────────────┬──────────────────────────────────────────┐ │ Information Type │ Retention & Usage Scope │ ├───────────────────────────────┼──────────────────────────────────────────┤ │ Billing & Delivery Address │ Shipping fulfillment and tax compliance │ │ Financial Credentials │ Encrypted real-time processing only │ │ Email & Contact Metrics │ Order updates and direct support │ └───────────────────────────────┴──────────────────────────────────────────┘
Third-party logistics providers receive necessary delivery details solely to fulfill gear shipments. These partners include FedEx, UPS, and USPS. Each carrier receives only your name, shipping address, and order tracking number. They do not receive payment details, browsing history, or email content.
Payment processing occurs through encrypted gateway protocols, meaning financial accounts never reside on our internal servers. We use Stripe and PayPal as our payment processors. Both comply with PCI DSS Level 1 standards, the highest security benchmark in the payments industry. Your credit card number, CVV, and expiration date pass directly from your browser to these processors without touching our systems.
Cookie usage and browser controls
Cookies collect non-personal browser metrics to improve storefront functionality and user navigation. We use first-party session cookies to maintain your cart contents during browsing. Persistent cookies remember your preferences, such as currency selection or recently viewed items. Analytics cookies from Google Analytics help us understand traffic flow, popular categories, and checkout abandonment rates.
Browsers allow users to disable cookie tracking, though certain checkout features might experience technical limitations. If you disable cookies entirely, you may still browse products and view specifications, but placing an order requires session cookies to function correctly. We recommend enabling cookies during checkout and disabling them afterward if you prefer maximum privacy.
Third-party analytics tools evaluate general site traffic patterns without compromising personal anonymity. Google Analytics anonymizes IP addresses by truncating the last octet. This prevents any individual user from being identified geographically beyond a city level. We never combine analytics data with personally identifiable information.
Data sharing and third-party restrictions
Selling customer contact records or personal activity profiles to third-party marketers remains strictly prohibited under company policy. We do not rent, sell, or trade your email address, phone number, or physical address to any external entity. This policy applies to our subsidiaries, affiliates, and partner brands equally.
We do share data with service providers under strict contractual obligations. These include:
- Shipping carriers: name and address only
- Payment processors: billing name, card data (encrypted, not stored)
- Email delivery services: email address for order confirmations and shipping updates
- Fraud detection tools: IP address, device fingerprint, and order pattern data
- Regulatory authorities: tax and customs data when required by law
Each provider signs a data processing agreement that limits their use of your information to the specific service they provide. They cannot repurpose your data for advertising, training, or any secondary use.
Your rights and how to exercise them
Data privacy regulations grant consumers explicit rights regarding personal record modifications. Customers request data deletion or account record extracts by writing directly to support staff. Under GDPR and CCPA frameworks, you have the right to:
- Access a complete copy of all data we hold about you
- Correct any inaccuracies in your information
- Request deletion of your personal data, subject to legal retention requirements
- Opt out of targeted advertising or data sharing for cross-context behavioral advertising
- Restrict processing of your data for specific purposes
To exercise these rights, email privacy@archeryspecialtystore.com with your request. Include your full name, registered email address, and a brief description of your request. We verify your identity before fulfilling any request to prevent unauthorized access. Verification may require confirming recent order details or providing government-issued identification in certain cases.
We respond to all privacy requests within 30 days of receipt. For complex requests, we may extend this period by an additional 30 days and notify you of the extension. All responses come in plain text without legal jargon. We aim for clarity and action.
Data retention and security measures
Digital security measures prevent unauthorized data access. Our systems implement AES-256 encryption for stored data, TLS 1.3 for all transmitted data, and hardware-based firewalls that block unauthorized IP ranges. Security audits occur quarterly, and penetration testing happens annually by independent third-party firms.
We retain your personal data for as long as necessary to fulfill the purposes outlined in this policy. This includes:
- Order history: 7 years for tax and accounting compliance
- Contact emails: 3 years for customer service continuity
- Analytics metrics: 26 months in aggregated, anonymized form
- Cookies: up to 2 years depending on browser settings and user preferences
After retention periods expire, we permanently delete or anonymize your data. Hard drives used for storage undergo physical destruction when decommissioned. No soft deletion exists in our infrastructure; deletion means permanent, unrecoverable removal.
Children’s privacy policy
Archery Specialty Store does not knowingly collect personal data from children under 13 years of age. Our products are not marketed to minors, and our checkout process requires age confirmation. If we discover that a customer under 13 has provided personal information without parental consent, we delete that data immediately.
Parents or guardians who believe their child has submitted information to us should contact privacy@archeryspecialtystore.com. We verify parental identity and remove all relevant data within 48 hours. No fines, no penalties, just prompt correction.
International data transfers
For customers outside the United States, your data may transfer to and be processed in the United States. We comply with the EU-US Data Privacy Framework and the UK Extension. This framework ensures adequate protection for European and British users under their respective data protection laws.
International customers retain all rights granted by their local regulations. GDPR rights apply to EU residents. CCPA rights apply to California residents. PIPEDA rights apply to Canadian customers. We respect every jurisdiction’s requirements and adjust our processing accordingly.
Updates to this privacy policy
We reserve the right to update this Privacy Policy at any time. Changes take effect immediately upon posting. We notify users of significant changes via email to the address associated with their account and through a visible banner on our website.
Minor updates, such as grammatical corrections or partner name changes, do not trigger individual notification. We recommend reviewing this policy periodically. The date at the bottom indicates the most recent revision.
Your trust, our responsibility
Data protection guarantees customer safety. This is not a legal obligation we accept reluctantly. It is a core value embedded in every system we build, every email we send, and every transaction we process. Your privacy matters as much as your gear.
If you have concerns about how we handle your data, contact our Data Protection Officer at dpo@archeryspecialtystore.com. We escalate all privacy inquiries to senior management and resolve them with urgency. Thank you for trusting Archery Specialty Store with your information. We do not take that trust lightly.