Privacy Policy
How CheckoutFirst collects, uses, shares, and protects your data, including analytics, cookies, and your rights as a California resident.
The short version
What this page covers in plain terms.
TL;DR
We collect only what we need to run the platform. We do not sell your data.
Last updated April 23, 2026.
CheckoutFirst collects the information needed to operate a perfumery marketplace: your account details, order and transaction data, and usage analytics. We use Google Analytics and Firebase Analytics to understand how the platform is used. We never sell your personal information or share it with advertising networks. You can request access to your data or ask us to delete it at any time.
What information we collect
A full list of the data CheckoutFirst gathers and when.
Sections 1 – 2
We collect information you provide directly and data generated by your activity on the platform.
1. Account and profile information
- Email address: Required to create an account or complete a guest checkout.
- Password: Stored as a secure hash. We never store your password in plain text.
- Display name: Optional name shown on your public seller profile.
- Seller profile data: Bio, seller slug (URL handle), and profile image, if you set up a seller profile.
2. Order and transaction data
- Buyer name: Collected at checkout to address fulfillment.
- Shipping address: Collected for physical goods orders only.
- Purchase history: Order IDs, product names, quantities, and amounts paid.
- Buyer notes: Any instructions you add to an order at checkout.
- Sale channel: Whether an order came through a direct link or marketplace discovery. Used to calculate the correct platform fee.
3. Messaging and communication data
- Conversation messages: Messages you send to a seller (or receive as a seller) through the platform's messaging feature.
- Support inquiries: Feedback, feature requests, or support messages you send to the CheckoutFirst team.
4. Formula and resource data
- Saved formulas: If you use the formula workspace and save a formula, we store the formula name, notes, and ingredient rows you entered. This data belongs to you and is only accessible to your account.
- Resource subscriber email: If you sign up for resource updates or the email list, we store your email address for that purpose.
5. Analytics and usage data
- Page views and events: Which pages you visit and actions you take (such as starting a checkout or signing up).
- IP address (hashed): Your IP address is processed as a one-way hash for analytics deduplication. We do not store your IP address in an identifiable form.
- Attribution tokens: Short-lived tokens (2-hour expiry) used to determine whether a sale came through the marketplace or a direct link. These are not tied to your identity.
Third-party services we use
The external services that receive or process your data as part of platform operation.
Section 3
We work with a small set of trusted third-party services. We do not share your data with advertisers.
- Stripe: Handles all payment processing and seller payouts. Card numbers and banking details go directly to Stripe. Stripe is PCI DSS compliant. Your Stripe relationship is governed by Stripe's own privacy policy and terms.
- Resend: Delivers transactional emails on our behalf, including order confirmations, fulfillment notifications, and conversation access links. Resend receives the recipient email address and email content necessary to send each message.
- Firebase and Google Cloud: Power the platform's database (Firestore), user authentication, file storage, and server-side functions. All platform data lives on Google Cloud infrastructure in the United States.
- Google Analytics 4: Collects aggregated usage data to help us understand how the platform is used. See the Cookies and Analytics section for details.
- Vercel: Hosts the CheckoutFirst web application. Vercel processes web requests and may log standard server access data (IP addresses, request paths, timestamps) in accordance with Vercel's privacy policy.
How we use your data
What your data is used for and what we never do with it.
Section 5
Your data is used to operate the platform, fulfill orders, and improve the product.
We use your data to:
- Create and manage your account.
- Process orders and facilitate fulfillment between buyers and sellers.
- Send transactional emails such as order confirmations, fulfillment links, refund notices, and conversation access links.
- Provide platform support and investigate fraud or policy violations.
- Operate formula tools and store formulas you choose to save to your account.
- Send resource or platform updates to subscribers who have opted in.
- Analyze usage patterns in aggregate to fix problems and improve features.
- Calculate the correct platform fee by determining whether a sale was direct or marketplace-attributed.
How long we keep your data
Specific retention periods for different categories of data.
Section 6
We keep data as long as it is needed for the purpose it was collected.
- Account and profile data: Retained while your account is active. Deleted or anonymized upon verified deletion request, subject to the exceptions below.
- Order and transaction records: Retained for 7 years to comply with financial recordkeeping and tax reporting obligations.
- Conversation messages: Retained until the conversation is closed and archived, or until deletion is requested.
- Saved formulas: Retained until you delete them from your account, or until your account is deleted.
- Analytics events: Retained in aggregated, de-identified form. Raw event data may be retained indefinitely for platform analysis.
- Attribution tokens: Automatically expire after 2 hours.
- Resource subscriber email: Retained until you unsubscribe.
Children's privacy
CheckoutFirst is not intended for children under 13.
Section 7
We do not knowingly collect data from anyone under 13 years old.
CheckoutFirst is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account or submitted information through our platform, please contact us at info@checkoutfirst.com and we will promptly delete the data.
California residents (CCPA)
Your additional rights under the California Consumer Privacy Act.
Section 8
California residents have the right to know, delete, and not be discriminated against for exercising their privacy rights.
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the following rights:
- Right to know: You can request a summary of the personal information we have collected about you, the sources it came from, the purposes for which it was collected, and any third parties it was shared with.
- Right to delete: You can request that we delete your personal information, subject to legal and transactional retention requirements.
- Right to non-discrimination: We will not deny you service, charge you different prices, or provide a lower quality of service because you exercised a CCPA right.
- Right to opt out of sale: CheckoutFirst does not sell personal information, so there is nothing to opt out of. We state this explicitly for clarity.
To exercise any of these rights, contact us at info@checkoutfirst.com. We will respond to verified requests within 45 days.
Your rights and how to contact us
How to access, update, or request deletion of your data.
Section 9
You have the right to access your data or request its deletion at any time.
9. Your rights
Regardless of where you are located, you can:
- Request a copy of the personal data CheckoutFirst holds about you.
- Request correction of inaccurate data.
- Request deletion of your personal data, subject to legal retention requirements (such as 7-year order records).
- Unsubscribe from any non-transactional emails via the unsubscribe link in those emails.
To submit a request, email info@checkoutfirst.com from the address associated with your account. We will verify your identity before processing the request.