What We Collect
- The email you submit through our subscribe form (newsletter sign-up, exit-intent, or drip capture).
- Order details collected by Stripe at checkout: name, shipping and billing address, items purchased, amount paid, payment status, and a Stripe-issued order ID.
- A SHA-256 hash of your IP address (we hash it on receipt so the raw IP never touches our database).
- Your browser's User-Agent string and the page that referred you to us.
- Any UTM parameters present in the URL when you landed on a marketing page (source, medium, campaign, term, content).
- Aggregated conversion events: which pages you viewed and which buttons you clicked on our marketing pages.
We do not collect any data from you after you leave our site, and we do not see or store the card number, expiry, or CVC you enter at checkout — Stripe handles that on their own servers.
How We Use It
We use the data above for exactly four things — and nothing else:
- To fulfill your order: print the shipping label, hand it to USPS, and email you the tracking number.
- To send you transactional and drip emails about your order and the product (via the Polsia Email Proxy).
- To understand, in aggregate, which pages and ads are working — so we can stop running the ones that aren't and double-down on the ones that are.
- To spot and prevent fraud or abuse of coupons, returns, or any other feature on the site.
We will never sell your email or order data to a third party. We will never share it with an advertiser. We don't have a "marketing partners" list because we don't have marketing partners.
Who Else Sees Your Data
We use a small number of trusted vendors to actually run the store. Each one receives only the data they need to do their job:
Stripe, Inc.
Payment processor. Receives your name, billing address, card details (handled entirely on Stripe's servers — we never see the card number), order amount, and order ID. We see the payment status and your shipping address back from Stripe.
Polsia Email Proxy
Outbound mail. Sends transactional emails (order confirmation, tracking notice) and our two-step drip sequence through POST /api/proxy/email/send via our hosted POLSIA_API_TOKEN. Your email and order metadata are passed through that proxy for delivery.
Render / Neon PostgreSQL
Hosting and database. Render runs the application server; Neon hosts the PostgreSQL database where we store subscribers and page_events rows.
Google Analytics 4 & Meta Pixel
Conversion analytics. Loaded only on our marketing pages (home, product, compare, order-confirmation) to measure page-views and which checkout buttons get clicked. Record pseudonymous identifiers; do not include any order details.
USPS
Shipping. Generates the USPS label for your package. Receives your name and shipping address; nothing else.
How Long We Keep It
We try not to keep anything we don't need:
- Subscriber rows — kept until you ask us to delete them, or until your email bounces for more than 90 days.
- Page-views and conversion events — kept as raw rows for 90 days, then collapsed into aggregate daily counts and the raw rows purged.
- Stripe payment records — retained according to Stripe's own data-retention policy; we receive no card data, so there is nothing sensitive on our side to delete.
Deletion requests are honored within 30 days — the same window as our SDR (Secure Decommissioning Return) refund flow, so the customer-facing timelines stay consistent.
How to Ask Us to Delete Your Data
Email drydock@polsia.app from the address on file in our system. Tell us what you'd like removed — your subscriber row, your conversion events, or both.
We'll confirm receipt within 1 business day, then purge the requested rows within 30 days. We follow the same chain-of-custody pattern as our SDR refund flow so the deletion is auditable end-to-end.
You can also ask us what we have on file for a given email address — we'll send you a plain-English summary within 30 days, same window.
Questions about your data? Email drydock@polsia.app — we read every message.