CheckoutFirst

Privacy Policy

How CheckoutFirst collects, uses, shares, and protects your data, including analytics, cookies, and your rights as a California resident.

The short version

What this page covers in plain terms.

TL;DR

We collect only what we need to run the platform. We do not sell personal information for money.

Last updated August 5, 2026.

CheckoutFirst collects the information needed to operate a makers marketplace: your account details, order and transaction data, and usage analytics. We use privacy-limited first-party analytics and Google Analytics to understand how the platform is used. If you allow Advertising in Privacy Choices, we also use Meta tools to measure seller campaigns. We do not sell personal information for money. You can change optional tracking choices or request access and deletion at any time.

↑ Back to top

What information we collect

A full list of the data CheckoutFirst gathers and when.

Sections 1 – 2

We collect information you provide directly and data generated by your activity on the platform.

1. Account and profile information

  • Email address: Required to create an account or complete a guest checkout.
  • Password: Stored as a secure hash. We never store your password in plain text.
  • Display name: Optional name shown on your public seller profile.
  • Seller profile data: Bio, seller slug (URL handle), and profile image, if you set up a seller profile.

2. Order and transaction data

  • Buyer name: Collected at checkout to address fulfillment.
  • Shipping address: Collected for physical goods orders only.
  • Purchase history: Order IDs, product names, quantities, and amounts paid.
  • Buyer notes: Any instructions you add to an order at checkout.
  • Sale channel: Whether an order came through a direct link or marketplace discovery. Used to calculate the correct platform fee.
Payment data is handled by StripeCheckoutFirst never stores or processes your card number, bank details, or CVV. All payment data is handled directly by Stripe and is subject to Stripe's privacy policy.

3. Messaging and communication data

  • Conversation messages: Messages you send to a seller (or receive as a seller) through the platform's messaging feature.
  • Support inquiries: Feedback, feature requests, or support messages you send to the CheckoutFirst team.

4. Formula and resource data

  • Saved formulas: If you use the formula workspace and save a formula, we store the formula name, notes, and ingredient rows you entered. This data belongs to you and is only accessible to your account.
  • Resource subscriber email: If you sign up for resource updates or the email list, we store your email address for that purpose.

5. Analytics and usage data

  • Page views and events: Which pages you visit and actions you take (such as starting a checkout or signing up).
  • Marketplace searches: Search terms, result counts, and selected category or craft filters. Obvious email addresses and long phone-number patterns are redacted before storage.
  • IP address (hashed): Your IP address is processed as a one-way hash for analytics deduplication. We do not store your IP address in an identifiable form.
  • Attribution tokens: Short-lived tokens (2-hour expiry) used to determine whether a sale came through the marketplace or a direct link. These are not tied to your identity.
↑ Back to top

Third-party services we use

The external services that receive or process your data as part of platform operation.

Section 3

We work with a small set of service providers and use optional advertising measurement only when you allow it.

  • Stripe: Handles all payment processing and seller payouts. Card numbers and banking details go directly to Stripe. Stripe is PCI DSS compliant. Your Stripe relationship is governed by Stripe's own privacy policy and terms.
  • Resend: Delivers transactional emails on our behalf, including order confirmations, fulfillment notifications, and conversation access links. Resend receives the recipient email address and email content necessary to send each message.
  • Firebase and Google Cloud: Power the platform's database (Firestore), user authentication, file storage, and server-side functions. All platform data lives on Google Cloud infrastructure in the United States.
  • Google Analytics 4: Collects aggregated usage data to help us understand how the platform is used. See the Cookies and Analytics section for details.
  • Meta: If you allow Advertising in Privacy Choices, the Meta Pixel and Conversions API receive limited seller-funnel events for campaign measurement, attribution, and optimization. Meta receives events only from the seller acquisition flow, not private messages, formulas, payment details, or listing content.
  • Vercel: Hosts the CheckoutFirst web application. Vercel processes web requests and may log standard server access data (IP addresses, request paths, timestamps) in accordance with Vercel's privacy policy.
We do not sell personal information for moneyOptional Meta measurement may be treated as sharing for targeted advertising under some U.S. privacy laws. It stays off unless you allow Advertising, and Global Privacy Control signals keep it off.
↑ Back to top

Cookies and analytics

How we use cookies, browser storage, and analytics tools.

Section 4

We use cookies to keep you logged in and analytics tools to understand how the platform is used.

Essential cookies

Firebase Authentication sets a session cookie when you sign in. This is required for you to stay logged in while using the platform. Blocking this cookie will prevent login from working.

Analytics cookies

Google Analytics 4 (Measurement ID: G-Y1P8WY4QT1) and privacy-limited first-party analytics collect page view and event data to help us improve the platform. This includes pages visited, events like sign-ups and checkouts, general location (country or region), and device type. These tools stay off unless you allow Analytics in Privacy Choices.

Advertising measurement

If you allow Advertising, the Meta Pixel measures visits to the seller acquisition flow and the Conversions API confirms completed registration and a seller's first sellable listing. We do not send listing titles, descriptions, formula content, messages, Stripe account data, or bank information. Advertising remains off when a Global Privacy Control signal is present.

Browser localStorage

We use your browser's localStorage to save in-progress formula workspace data and UI preferences on your device. That content stays local and is not transmitted to our servers.

One exception: if you allow Analytics, we also store a randomly generated visitor ID in localStorage and send it with page views so we can count returning visitors instead of raw page loads. It is a random value, it is not linked to your account, name, or email, and it tells us nothing about you personally. Turning Analytics off in Privacy Choices deletes it from your browser.

↑ Back to top

How we use your data

What your data is used for and what we never do with it.

Section 5

Your data is used to operate the platform, fulfill orders, and improve the product.

We use your data to:

  • Create and manage your account.
  • Process orders and facilitate fulfillment between buyers and sellers.
  • Send transactional emails such as order confirmations, fulfillment links, refund notices, and conversation access links.
  • Provide platform support and investigate fraud or policy violations.
  • Operate formula tools and store formulas you choose to save to your account.
  • Send resource or platform updates to subscribers who have opted in.
  • Analyze usage patterns in aggregate to fix problems and improve features.
  • Calculate the correct platform fee by determining whether a sale was direct or marketplace-attributed.
Optional advertising measurement is your choiceMeta measurement stays off unless you allow Advertising in Privacy Choices. You can withdraw that choice at any time from the footer. CheckoutFirst does not sell personal information for money.
↑ Back to top

How long we keep your data

Specific retention periods for different categories of data.

Section 6

We keep data as long as it is needed for the purpose it was collected.

  • Account and profile data: Retained while your account is active. Deleted or anonymized upon verified deletion request, subject to the exceptions below.
  • Order and transaction records: Retained for 7 years to comply with financial recordkeeping and tax reporting obligations.
  • Conversation messages: Retained until the conversation is closed and archived, or until deletion is requested.
  • Saved formulas: Retained until you delete them from your account, or until your account is deleted.
  • First-party analytics events: Raw page-view and marketplace-search events are retained for up to 90 days, then deleted. Aggregated statistics may be retained without a set expiration when they no longer identify a browser or person.
  • Advertising measurement: CheckoutFirst keeps conversion-deduplication records for up to 2 years. Meta may retain event data under its own terms and settings.
  • Attribution tokens: Automatically expire after 2 hours.
  • Resource subscriber email: Retained until you unsubscribe.
↑ Back to top

Children's privacy

CheckoutFirst is not intended for children under 13.

Section 7

We do not knowingly collect data from anyone under 13 years old.

CheckoutFirst is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account or submitted information through our platform, please contact us at info@checkoutfirst.com and we will promptly delete the data.

↑ Back to top

California residents (CCPA)

Your additional rights under the California Consumer Privacy Act.

Section 8

California residents may have rights to know, correct, delete, and opt out of sale or sharing, subject to the law's coverage and exceptions.

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the following rights:

  • Right to know: You can request a summary of the personal information we have collected about you, the sources it came from, the purposes for which it was collected, and any third parties it was shared with.
  • Right to delete: You can request that we delete your personal information, subject to legal and transactional retention requirements.
  • Right to non-discrimination: We will not deny you service, charge you different prices, or provide a lower quality of service because you exercised a CCPA right.
  • Right to correct: You can request correction of inaccurate personal information we maintain about you.
  • Right to opt out of sale or sharing: CheckoutFirst does not sell personal information for money. You can stop optional advertising measurement by rejecting Advertising in Privacy Choices. We also honor Global Privacy Control.

To exercise any of these rights, contact us at info@checkoutfirst.com. We will respond to verified requests within 45 days.

↑ Back to top

Your rights and how to contact us

How to access, update, or request deletion of your data.

Section 9

You have the right to access your data or request its deletion at any time.

9. Your rights

Regardless of where you are located, you can:

  • Request a copy of the personal data CheckoutFirst holds about you.
  • Request correction of inaccurate data.
  • Request deletion of your personal data, subject to legal retention requirements (such as 7-year order records).
  • Unsubscribe from any non-transactional emails via the unsubscribe link in those emails.

To submit a request, email info@checkoutfirst.com from the address associated with your account. We will verify your identity before processing the request.

Privacy-related requestsContact info@checkoutfirst.com for data access requests, deletion requests, or any privacy-related questions. General support goes to support@checkoutfirst.com.
↑ Back to top