CheckoutFirst

Privacy Policy

How CheckoutFirst collects, uses, shares, and protects your data, including analytics, cookies, and your rights as a California resident.

The short version

What this page covers in plain terms.

TL;DR

We collect only what we need to run the platform. We do not sell your data.

Last updated April 23, 2026.

CheckoutFirst collects the information needed to operate a perfumery marketplace: your account details, order and transaction data, and usage analytics. We use Google Analytics and Firebase Analytics to understand how the platform is used. We never sell your personal information or share it with advertising networks. You can request access to your data or ask us to delete it at any time.

↑ Back to top

What information we collect

A full list of the data CheckoutFirst gathers and when.

Sections 1 – 2

We collect information you provide directly and data generated by your activity on the platform.

1. Account and profile information

  • Email address: Required to create an account or complete a guest checkout.
  • Password: Stored as a secure hash. We never store your password in plain text.
  • Display name: Optional name shown on your public seller profile.
  • Seller profile data: Bio, seller slug (URL handle), and profile image, if you set up a seller profile.

2. Order and transaction data

  • Buyer name: Collected at checkout to address fulfillment.
  • Shipping address: Collected for physical goods orders only.
  • Purchase history: Order IDs, product names, quantities, and amounts paid.
  • Buyer notes: Any instructions you add to an order at checkout.
  • Sale channel: Whether an order came through a direct link or marketplace discovery. Used to calculate the correct platform fee.
Payment data is handled by StripeCheckoutFirst never stores or processes your card number, bank details, or CVV. All payment data is handled directly by Stripe and is subject to Stripe's privacy policy.

3. Messaging and communication data

  • Conversation messages: Messages you send to a seller (or receive as a seller) through the platform's messaging feature.
  • Support inquiries: Feedback, feature requests, or support messages you send to the CheckoutFirst team.

4. Formula and resource data

  • Saved formulas: If you use the formula workspace and save a formula, we store the formula name, notes, and ingredient rows you entered. This data belongs to you and is only accessible to your account.
  • Resource subscriber email: If you sign up for resource updates or the email list, we store your email address for that purpose.

5. Analytics and usage data

  • Page views and events: Which pages you visit and actions you take (such as starting a checkout or signing up).
  • IP address (hashed): Your IP address is processed as a one-way hash for analytics deduplication. We do not store your IP address in an identifiable form.
  • Attribution tokens: Short-lived tokens (2-hour expiry) used to determine whether a sale came through the marketplace or a direct link. These are not tied to your identity.
↑ Back to top

Third-party services we use

The external services that receive or process your data as part of platform operation.

Section 3

We work with a small set of trusted third-party services. We do not share your data with advertisers.

  • Stripe: Handles all payment processing and seller payouts. Card numbers and banking details go directly to Stripe. Stripe is PCI DSS compliant. Your Stripe relationship is governed by Stripe's own privacy policy and terms.
  • Resend: Delivers transactional emails on our behalf, including order confirmations, fulfillment notifications, and conversation access links. Resend receives the recipient email address and email content necessary to send each message.
  • Firebase and Google Cloud: Power the platform's database (Firestore), user authentication, file storage, and server-side functions. All platform data lives on Google Cloud infrastructure in the United States.
  • Google Analytics 4: Collects aggregated usage data to help us understand how the platform is used. See the Cookies and Analytics section for details.
  • Vercel: Hosts the CheckoutFirst web application. Vercel processes web requests and may log standard server access data (IP addresses, request paths, timestamps) in accordance with Vercel's privacy policy.
We do not sell your dataCheckoutFirst does not sell, rent, or trade your personal information to any third party for marketing or advertising purposes.
↑ Back to top

Cookies and analytics

How we use cookies, browser storage, and analytics tools.

Section 4

We use cookies to keep you logged in and analytics tools to understand how the platform is used.

Essential cookies

Firebase Authentication sets a session cookie when you sign in. This is required for you to stay logged in while using the platform. Blocking this cookie will prevent login from working.

Analytics cookies

Google Analytics 4 (Measurement ID: G-Y1P8WY4QT1) and Firebase Analytics collect page view and event data to help us improve the platform. This includes pages visited, events like sign-ups and checkouts, general location (country or region), and device type. No advertising cookies are used. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

Browser localStorage

We use your browser's localStorage to save in-progress formula workspace data and UI preferences on your device. This data stays local and is not transmitted to our servers.

↑ Back to top

How we use your data

What your data is used for and what we never do with it.

Section 5

Your data is used to operate the platform, fulfill orders, and improve the product.

We use your data to:

  • Create and manage your account.
  • Process orders and facilitate fulfillment between buyers and sellers.
  • Send transactional emails such as order confirmations, fulfillment links, refund notices, and conversation access links.
  • Provide platform support and investigate fraud or policy violations.
  • Operate formula tools and store formulas you choose to save to your account.
  • Send resource or platform updates to subscribers who have opted in.
  • Analyze usage patterns in aggregate to fix problems and improve features.
  • Calculate the correct platform fee by determining whether a sale was direct or marketplace-attributed.
We do not use your data for advertisingCheckoutFirst does not use your personal information to serve ads, build advertising profiles, or share data with marketing platforms.
↑ Back to top

How long we keep your data

Specific retention periods for different categories of data.

Section 6

We keep data as long as it is needed for the purpose it was collected.

  • Account and profile data: Retained while your account is active. Deleted or anonymized upon verified deletion request, subject to the exceptions below.
  • Order and transaction records: Retained for 7 years to comply with financial recordkeeping and tax reporting obligations.
  • Conversation messages: Retained until the conversation is closed and archived, or until deletion is requested.
  • Saved formulas: Retained until you delete them from your account, or until your account is deleted.
  • Analytics events: Retained in aggregated, de-identified form. Raw event data may be retained indefinitely for platform analysis.
  • Attribution tokens: Automatically expire after 2 hours.
  • Resource subscriber email: Retained until you unsubscribe.
↑ Back to top

Children's privacy

CheckoutFirst is not intended for children under 13.

Section 7

We do not knowingly collect data from anyone under 13 years old.

CheckoutFirst is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account or submitted information through our platform, please contact us at info@checkoutfirst.com and we will promptly delete the data.

↑ Back to top

California residents (CCPA)

Your additional rights under the California Consumer Privacy Act.

Section 8

California residents have the right to know, delete, and not be discriminated against for exercising their privacy rights.

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the following rights:

  • Right to know: You can request a summary of the personal information we have collected about you, the sources it came from, the purposes for which it was collected, and any third parties it was shared with.
  • Right to delete: You can request that we delete your personal information, subject to legal and transactional retention requirements.
  • Right to non-discrimination: We will not deny you service, charge you different prices, or provide a lower quality of service because you exercised a CCPA right.
  • Right to opt out of sale: CheckoutFirst does not sell personal information, so there is nothing to opt out of. We state this explicitly for clarity.

To exercise any of these rights, contact us at info@checkoutfirst.com. We will respond to verified requests within 45 days.

↑ Back to top

Your rights and how to contact us

How to access, update, or request deletion of your data.

Section 9

You have the right to access your data or request its deletion at any time.

9. Your rights

Regardless of where you are located, you can:

  • Request a copy of the personal data CheckoutFirst holds about you.
  • Request correction of inaccurate data.
  • Request deletion of your personal data, subject to legal retention requirements (such as 7-year order records).
  • Unsubscribe from any non-transactional emails via the unsubscribe link in those emails.

To submit a request, email info@checkoutfirst.com from the address associated with your account. We will verify your identity before processing the request.

Privacy-related requestsContact info@checkoutfirst.com for data access requests, deletion requests, or any privacy-related questions. General support goes to support@checkoutfirst.com.
↑ Back to top