pRivacy policy

Preview build. These documents are drafts pending review by counsel and are not legal advice. Numbers and terms may change before launch.

Version 1.0.0Effective July 23, 2026

A description of what personal information getDARC.com collects, on what basis, how long it is kept, and the rights you hold; a preview draft pending counsel review.

1. Who we are and how to contact us

getDARC.com (the Service) is operated by Tombatossals Softworks LLC (DARC, we, us), a US limited liability company serving the United States. This Privacy Policy explains what personal information we collect, why, on what legal basis, how long we keep it, and the rights you have.

For any privacy question or request, contact [email protected]. This is a preview draft pending legal review and is not legal advice.

2. Data we collect

We collect only what a stated purpose needs. The categories of personal information we hold are listed below.

  • Account identity: email, display name, locale, and role.
  • Authentication secrets: passkey public keys and an encrypted TOTP secret; we never store these in readable form.
  • Addresses: shipping and billing name, address, and phone.
  • Payment: tokens only (Stripe payment and refund identifiers). We never receive or store your full card number.
  • Order history: line items, build snapshots, and order events.
  • Forum content: posts, votes, reports, and reputation.
  • Support and RMA: the reason and resolution of a return or repair.
  • Analytics: product events and feature exposure, only after you opt in.
  • Marketing state: email sends, opens, and unsubscribe timestamp.

3. Lawful bases for processing

We build to a GDPR-grade structure even though the Service is US-first. We rely on the following bases.

  • Contract: to create your account and fulfill orders, addresses, payments, shipping, and warranty or RMA.
  • Legitimate interests: fraud prevention, security logging, service operation, and non-intrusive aggregate analytics.
  • Consent: non-essential cookies, product analytics, and marketing email; consent is opt-in and withdrawable.
  • Legal obligation: tax and accounting record retention.

4. How we use your data

We use personal information to operate the Service: to authenticate you, process and fulfill orders, calculate tax and shipping, prevent fraud, provide support and warranty service, run the forum, and, where you have opted in, measure product usage and send marketing email.

We do not use your data for automated decisions that produce legal effects without human review, and we do not build advertising profiles.

5. We do not sell or share personal information; GPC

We do not sell your personal information and we do not share it for cross-context behavioral advertising. Because we do not sell or share, no data broker receives your information from us.

We honor the Global Privacy Control (GPC) signal as an opt-out, and we publish an opt-out control for analytics. You do not need an account to exercise these choices.

6. Cookies and analytics

Strictly necessary cookies, for sign-in, security, and the cart, are always on because the Service cannot function without them. Non-essential trackers, being product analytics through PostHog and functional cookies, load only after you opt in.

The consent banner offers accept, reject, and granular choice with equal prominence, and you can withdraw consent at any time from the footer. Details are in the Cookie Policy.

7. Sub-processors

We use a small set of vendors that process personal information on our behalf under data processing agreements. The current list follows.

  • Stripe: payments, fraud scoring, and tax calculation (holds card data; we do not).
  • Cloudflare: CDN, web application firewall, and bot management (IP addresses, request metadata).
  • Cloudflare R2: object storage for uploaded images and documents.
  • Resend: transactional and lifecycle email (email address, name, content).
  • Sentry: error and performance monitoring, with PII scrubbing enabled.
  • Axiom: structured application logs (identifiers only; PII is redacted before logs reach it).
  • PostHog: product analytics and feature flags (pseudonymous identifiers; consent-gated).

8. Your privacy rights and how to exercise them

You may request access to, a portable export of, or deletion of your personal information, and you may ask us to correct inaccurate data. We verify the request, through your signed-in account or a verified email, to protect you from anyone impersonating you.

We acknowledge a request within 10 days and complete it within 30 days. Deletion is honored subject to records the law requires us to keep, for example order and tax records for their retention period, and the tamper-evident audit log, where a deletion is recorded rather than erased.

  • Access: a copy of the data we hold about you.
  • Export: a machine-readable copy of that data.
  • Deletion: removal or anonymization, minus legal carve-outs.
  • Correction: fixing inaccurate data.

9. How long we keep data

We keep data only as long as a purpose or the law requires.

  • Order, invoice, and tax records: 7 years after the order.
  • Application logs: 90 days, then dropped.
  • Product analytics: 14 months or less.
  • Audit log: 7 years, as financial, security, and dispute evidence.
  • Account data: for the life of the account; on deletion, purged or anonymized except for the carve-outs above.
  • Marketing state: until you unsubscribe, with a suppression record kept to honor your opt-out.

10. Security

Card data never touches our servers: payment fields are hosted by Stripe and tokenized in your browser, keeping us within PCI DSS SAQ-A scope. We hold only payment tokens and integer amounts.

We do not write personal information to application logs; a redaction rule strips emails, addresses, and card-shaped values before logs are stored. We use a strict content security policy, parameterized queries, object-level access checks, and 2FA for accounts with purchase history.

11. Children's privacy

The Service is for adults. You must be at least 18 to hold an account, and the Service is not directed to children. We do not knowingly collect personal information from anyone under 13; consistent with COPPA, if we learn that we hold such data, we delete it.

12. California rights, international transfers, and changes

California residents have rights under the CCPA as amended by the CPRA: to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share, and we build to this standard whether or not the statutory thresholds apply to us; the request flow above serves these rights.

We operate in the United States and process data in the United States; we do not currently transfer personal information internationally. This Policy is versioned with an effective date; when we make a material change we bump the version, update the date, and surface it. This is a preview draft pending legal review.