Privacy Policy
PRIVACY STATEMENT
This is the privacy statement for Lodestone, the online store at trylodestone.org. It explains what personal information we collect, why we collect it, who else gets it, how long we keep it, and what you can ask us to do about it.
This Statement was amended as of 08-09-2026 and is effective as of that date. Last updated: 08-09-2026. It replaces every earlier version of our privacy statement.
We have written it to describe what this website and our systems actually do — not what a template says a store like ours might do. Where something is planned but not switched on yet, we say so. Where a choice we offer only works in part, we say that too. We would rather be accurate than reassuring.
Your use of trylodestone.org is also governed by our Terms of Service.
WHAT'S IN THIS STATEMENT
The Short Version
Who We Are, and Who Is Responsible
What Personal Information We Collect
What We Do Not Collect
How We Use Personal Information
Who We Share Personal Information With
Payment Processing
Sending Your Order to Our Fulfillment Partner in China
Cookies, Local Storage and Other Tracking Technologies
Advertising and Analytics Partners
Selling and Sharing Your Personal Information
How to Opt Out of Advertising and Analytics
Do Not Track and Global Privacy Control
Marketing Email
How Long We Keep Information
Your Choices, and How to Use Them
How We Protect Information
Children's Privacy
Submitting Information From Outside the United States
State Privacy Disclosures
Changes to This Privacy Statement
Contacting Us
THE SHORT VERSION
If you read nothing else, read this. Every point is expanded further down.
- We sell blankets, pajamas and shawls. This is a United States store — our prices are in US dollars, our advertising is aimed at the United States, and our Shipping Policy covers shipping within the United States.
- To take an order we need your name, email address and shipping address. Your card number goes straight to Stripe or PayPal — we never see it or store it.
- Our fulfillment partner is in China. To get your parcel to you we send that partner your name, email address, shipping address and what you ordered. This is an international transfer of your personal information and we want you to know about it before you buy.
- If you give us your email address through the discount pop-up or a sign-up form, we use it to send you marketing email. You can stop it at any time — one click on the unsubscribe link in any newsletter takes effect straight away.
- We advertise with Google and Meta. Their tags run on our pages, and they receive information about your visit including your IP address. Under California's definitions this is "sharing" for cross-context behavioral advertising, and we treat it as a "sale" too, because California's Attorney General reads the law that way. No money changes hands — what we get is better advertising.
- We run our own analytics on our own servers, and it records your IP address. We do not use Google Analytics.
- We do not sell your information to data brokers or list brokers, and we do not hand it to other companies for their own marketing. The only marketing-related transfers we make are the advertising ones described in this Statement.
- You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Email help@trylodestone.org. We answer these requests as a matter of policy, whether or not a law requires it of a store our size.
- There is no cookie banner on this site, and we explain honestly below what does and does not run without one.
WHO WE ARE, AND WHO IS RESPONSIBLE
Lodestone is a one-person business — a sole proprietorship based in Rhode Island, United States. When we say "we", "us" and "our" we mean that business, the operator of the online store at trylodestone.org. When we say "you" and "your" we mean you, the person reading this, visiting our site or buying from us.
The owner of that business is the controller of the personal data collected through trylodestone.org — the person who decides what is collected and why, and the person answerable for it. Rhode Island's Data Transparency and Privacy Protection Act requires a commercial website to designate a controller and to publish a working way to reach them. Ours is:
- Email: help@trylodestone.org — this is the address to use for anything in this Statement, and it is read by a person.
- Postal mail: Lodestone, 2093 Philadelphia Pike #2836, Claymont, DE 19703, United States.
By "personal information" we mean information that identifies you, or that can reasonably be linked to you — your name, email address, shipping address, IP address, the identifiers our site stores in your browser, and records of what you looked at and bought. Some privacy laws call this "personal data"; we use the two terms to mean the same thing here.
WHAT PERSONAL INFORMATION WE COLLECT
These are the categories of personal information we collect through trylodestone.org.
Information You Give Us
- Your email address — when you enter it in the scratch-card discount pop-up, the returning-visitor discount pop-up, the newsletter box in our footer or on our join page, our contact form, or the write-a-review form on a product page.
- Your name, email address and shipping address — when you place an order. These come to us from Stripe or PayPal after you pay; you type them on their checkout pages, not on ours.
- Your phone number — only if you choose to type one into our contact form. That field is optional, and we do not ask for a phone number at checkout.
- Whatever you write to us — the message in a contact form, the text and star rating in a review submission, or anything you put in an email to us.
- What you ordered — the products, quantities, prices and order total.
Information Collected Automatically When You Visit
- Your IP address. Every website receives this; it is how the page reaches your device. We also store it — see Our own first-party analytics below — and it is sent to Meta with our advertising events.
- Your browser and device information — the user-agent string your browser sends, and whether you are on a phone or a computer.
- What you do on the site — the pages you view, how long you stay on them, how far down you scroll, and store actions such as opening the cart, adding an item, starting checkout and completing a purchase. Also whether a pop-up was shown to you, and whether you dismissed it or signed up.
- How you arrived — the page you landed on, the website that referred you, and any advertising click identifiers and campaign tags in the link you clicked (for example gclid, fbclid, msclkid and utm_ parameters).
- Identifiers we store in your browser — random visitor and session identifiers, plus advertising cookies set by Meta. The full list is in Cookies, Local Storage and Other Tracking Technologies below.
Information We Receive From Our Payment Processors
After you pay, Stripe or PayPal sends us the limited information we need to fulfill and support the order: your name, email address, shipping address, what you bought, the amount, whether the payment succeeded, and (from Stripe) the card brand and the last four digits. We never receive your full card number, your PayPal login, or your bank details.
WHAT WE DO NOT COLLECT
Cloned privacy policies routinely describe collection that never happens. To be clear about ours:
- There are no accounts on this site. There is nothing to register for and no password to set.
- We never receive your card number. Payment credentials go from your browser directly to Stripe or PayPal.
- We do not collect your phone number at checkout, and we do not send marketing text messages.
- We do not buy personal information from data vendors, list brokers, enrichment services or advertising co-operatives, and we do not receive customer lists from anyone.
- We do not collect sensitive information — no government identifiers, no financial account numbers, no health, biometric, genetic, precise-location, racial, religious, political or sexual-orientation data.
- We do not record calls, use a camera or microphone, run session replay, or use a third-party chat widget.
- There are no public community features — no profiles, no comment threads, no public posting. Reviews submitted through the review form come to us by email; they are not published automatically.
- We do not knowingly collect anything from children under 13. See Children's Privacy below.
HOW WE USE PERSONAL INFORMATION
- To take and fulfill your order — process payment, send it to our fulfillment partner, and get it shipped to you.
- To email you about your order — confirmations, receipts and shipping updates. These are not marketing and you cannot unsubscribe from them while an order is open.
- To answer you — customer service, returns, warranty claims and replies to anything you send us.
- To send you marketing email, if you signed up. See Marketing Email below.
- To advertise — to measure which of our advertisements led to a visit or a purchase, and to show advertisements to people who have visited trylodestone.org before (remarketing).
- To understand how the store is used — which pages work, where people leave, which products get looked at, so we can fix and improve the site.
- To protect the store — detecting fraudulent orders, abuse and technical attacks, and to recognise and exclude our own visits from our statistics.
- To meet our legal and accounting obligations — keeping records of sales, tax and refunds, and responding to lawful requests.
WHO WE SHARE PERSONAL INFORMATION WITH
Below is every company that receives personal information from us, named. This list is meant to be complete; if you find something running on our site that is not on it, tell us at help@trylodestone.org and we will correct this Statement.
- Stripe, Inc. — payment processing. Receives your payment credentials directly from you, plus your name, email address and shipping address. Also receives the Meta advertising identifiers described below, attached to the checkout session.
- PayPal, Inc. — payment processing, if you pay with PayPal. Receives your payer details and the order.
- Our fulfillment partner in China — receives your name, email address, full shipping address and the items you ordered, so your parcel can be packed and shipped. See the next section.
- Resend, Inc. — email delivery, in the United States. Receives your name, your email address and the contents of the messages we send you. If you are on our mailing list, Resend also stores your membership of it and your unsubscribe status.
- Formspree, Inc. — form processing. Every contact-form submission (name, email address, optional phone number and your message), every review submission (name, email address, rating and review text), and a notification of every newsletter sign-up (email address and which form it came from) is delivered to us through Formspree.
- Google LLC — advertising and product listings. See Advertising and Analytics Partners below. Google also serves one web font used for our logo, which means Google receives your IP address and browser information on every page you load, whether or not you interact with anything.
- Meta Platforms, Inc. — advertising on Facebook and Instagram. See Advertising and Analytics Partners below.
- Microsoft Corporation — not yet. Nothing from Microsoft runs on this site today. See Advertising and Analytics Partners for what we plan.
- Vercel Inc. — hosting, in the United States. Our website and its ordering, email and analytics functions run on Vercel, so every request you make to the site passes through it.
- Neon — the managed database service, hosted in the United States, where our own analytics records and our order-fulfillment records are stored.
- Cloudflare, Inc. — our domain's DNS, and the email routing that delivers mail sent to help@trylodestone.org to the inbox we actually read. Anything you email us passes through Cloudflare and then through Google's Gmail service.
- Anthropic PBC — the AI service that writes the plain-English summary in our analytics dashboard. It receives only aggregated statistics — page counts, funnel totals, device splits. No names, no email addresses, no IP addresses, no visitor or session identifiers are sent to it.
- Tencent (WeChat) — the messaging service our fulfillment partner uses. Your order details, including your name and shipping address, are sent through it. See the next section.
- Law enforcement, regulators and courts — where we are legally required to disclose information, or where we believe in good faith that disclosure is necessary to prevent fraud, harm or an illegal act.
- A buyer of the business — if this business were ever sold or transferred, customer records would be part of what transfers. We would say so here first.
We do not sell or rent your information to data brokers, list brokers, marketing co-operatives or any other company for that company's own marketing. Whether our advertising transfers count as a "sale" under state law is a separate question, and we answer it plainly in Selling and Sharing Your Personal Information below.
PAYMENT PROCESSING
All payments made through our online store are processed by third-party payment processors; we currently use Stripe, Inc. ("Stripe") to process card payments and to offer the additional payment methods shown at checkout, such as Apple Pay, Google Pay, Link and Klarna. When you make a purchase, your payment card number and other payment credentials are provided by you directly to Stripe through Stripe's own secure checkout pages; we never receive or store your full payment card number. Stripe's collection and use of your personal information is governed by Stripe's own privacy policy, available at https://stripe.com/privacy. From Stripe we receive only the limited transaction information needed to fulfill your order and provide customer service: your name, email address, shipping address, the items purchased, the payment status, and the card brand and last four digits.
If you choose to pay with PayPal, your payment is processed by PayPal, Inc. ("PayPal") and is governed by PayPal's own privacy statement, available at https://www.paypal.com/us/legalhub/privacy-full. From PayPal we receive your name, email address, shipping address and payment status — never your PayPal login or funding details. Loading the PayPal button on our pages is itself a connection to PayPal, so PayPal receives your IP address and browser information when a page with that button loads. If you choose a wallet or pay-later option at checkout, your use of that method is also governed by that provider's own terms and privacy policy.
SENDING YOUR ORDER TO OUR FULFILLMENT PARTNER IN CHINA
We do not hold stock ourselves. Our products are shipped from a warehouse in China by a fulfillment partner there, and this is how your order reaches you.
What we send them. When your payment succeeds, your order is recorded in our own order system and then passed to our fulfillment partner. What they receive is: your order number, your name, your email address, your full shipping address, and the items and quantities you bought. They do not receive your payment details.
How it is sent. It is sent to them as a message on WeChat, a messaging service operated by Tencent. That means your name and address pass through Tencent's systems as well.
Where it goes. China. This is an international transfer of your personal information to a country whose privacy laws are different from those in the United States, and outside the reach of United States regulators. There is no practical way for us to ship a physical product to you without it. We are telling you plainly because you deserve to know before you buy, and because a privacy statement that hid this would be worthless.
COOKIES, LOCAL STORAGE AND OTHER TRACKING TECHNOLOGIES
There is no cookie banner on trylodestone.org. The technologies below run when you load the site. We are not going to pretend you were asked. What you can do about them is in How to Opt Out of Advertising and Analytics below, and you can block or clear all of them in your browser at any time.
Cookies — small files stored by your browser:
- _fbp — set by Meta's script. Meta's own browser identifier, used to link your visit to an advertising profile. About 90 days.
- _fbc — set by our site when you arrive from a Meta advertisement, recording that ad click so the purchase can be attributed to it. 90 days.
- _gcl_ cookies — set by Google's advertising tag to attribute a visit or purchase to a Google advertisement. Google documents the main one, _gcl_au, as lasting about 90 days.
Local storage — items kept in your browser that are not cookies, and that clearing your cookies will not remove. None of them expire on a timer; they stay until you clear them, except where a line below says otherwise. You can clear them through your browser's "site data" or "storage" controls:
- _pl_vid, _pl_sess — a random visitor identifier and a session identifier for our own analytics. They contain no name or email address.
- _pl_attr — how you arrived: landing page, referring site, advertising click identifiers and campaign tags.
- am_email — your email address, in readable form, saved once you submit it to one of our forms. We use it to pass a one-way encrypted (hashed) version to Meta so it can match your activity. Clearing your browser storage removes it.
- store_cart, cart_timer_deadline, pending_purchase — your cart, the cart countdown, and the order details we hold briefly between checkout and the thank-you page. pending_purchase is deleted when you reach the thank-you page.
- sg_scratch_seen, sg_subscribed, sg_last_visit — which pop-ups you have already seen, so we do not show them again.
- sg_gads_click — the Google advertising click identifier (a value Google appends to the web address when you arrive from one of our Google advertisements), with the time you arrived. We keep it for up to 90 days so that, if you make a purchase, our server can report that purchase to Google Ads as described under Advertising and Analytics Partners. It contains no name or email address, and it is only ever set if you arrive from an advertisement.
Session storage — one item, which lives only in the browser tab you are using and is erased automatically when you close that tab:
- sg_comeback_shown — records that the returning-visitor pop-up has already appeared in this tab, so it is not shown to you twice in one sitting.
Some content on our pages comes from other companies, and their technologies collect information about you when the page loads. We do not control what they do with it.
ADVERTISING AND ANALYTICS PARTNERS
This section names the specific companies that help us advertise and measure, and explains what each of them receives.
What is running today, and what we plan to add. As of the amendment date at the top of this Statement, the advertising and analytics technologies active on trylodestone.org are the Meta pixel and the Meta Conversions API, the Google advertising tags, and our own first-party site analytics, all described below. We also publish a product data feed for Google. We plan to add the Microsoft measurement technology described below; it is not switched on yet, and we describe it here so that you have notice in advance. We do not use Google Analytics on trylodestone.org. We will update the amendment date at the top of this Statement when any of this changes.
Our own first-party analytics. We measure how trylodestone.org is used with our own analytics tool, which we built and which sends its data to our own database rather than to an analytics company. It records the pages you view, how long you stay, how far you scroll, store actions such as adding to the cart and completing a purchase, your browser and device type, how you arrived at the site, and your IP address.
Being straight about the IP address, because it is the most sensitive thing in that list: we store it, we can see it in our dashboard, and our dashboard can show us the whole history of visits from one IP address — the pages, the sessions, and any purchases. We use this to recognise and exclude our own visits from the statistics, to spot fraud and abusive traffic, and to understand how visits turn into orders. This information is not published, not sold, and not sent to any advertising company. It is held in our database with our hosting and database providers (Vercel and Neon), who are named above. The raw visit records, including the IP address, are automatically deleted after 90 days by a scheduled job that runs daily against that database. We have checked that the job is configured and answering; what we are describing is how the system is built to behave, not a guarantee about any single day. If a run fails, the records it would have removed are cleared by the next run that succeeds. The random visitor and session records — which carry no name, no email address and no IP address — and the daily totals we derive are kept for longer, as described under How Long We Keep Information.
Meta Platforms, Inc. (Facebook and Instagram). We use the Meta pixel, a small piece of code on our pages, together with the Meta Conversions API, which sends equivalent information from our own server. Together they tell us which advertisements led to a visit or a purchase, and they let us show advertisements on Facebook and Instagram to people who have visited trylodestone.org. These run on every visit, whether or not we are currently buying advertising.
What Meta receives: the pages and products you viewed, what you added to your cart, whether you began or completed a purchase, the value and currency of that purchase, your IP address, your browser and device type, the page address you were on, the Meta cookies _fbp and _fbc, and — where you have given us your email address — a one-way encrypted (hashed) version of that email address, which Meta uses to match your activity to an account it already holds. When you complete a purchase, our server also sends Meta a hashed version of your first and last name, and — if the payment method you chose passed a phone number to our payment processor — a hashed version of that phone number, for the same matching purpose. We never ask you for a phone number at checkout, but some wallet and pay-later methods hand one over on your behalf, and when that happens it goes to Meta in hashed form with the purchase. Hashing scrambles the value so that it cannot be read directly; it does not stop Meta from matching it to a person, which is the entire point of sending it. We do not send Meta your postal address or your payment details.
Google LLC. We publish a product data feed — the names, descriptions, images, prices and availability of the items we sell — so that our products can appear in Google's free product listings and in Google Shopping advertisements. That feed describes our products; it does not contain information about you. Separately, Google's advertising tags are installed on trylodestone.org. They tell Google that a visit or a purchase followed one of our listings or advertisements, and they let us show advertisements to people who have previously visited trylodestone.org, a practice known as remarketing. Third-party vendors, including Google, use cookies to serve advertisements based on a person's prior visits to trylodestone.org and to other websites on the internet. Google receives your IP address, browser and device information, the pages you viewed and purchase details through these tags. When you complete a purchase after arriving from a Google advertisement, our server also reports that purchase to Google Ads directly — the advertising click identifier described under Cookies, Local Storage and Other Tracking Technologies, the order number, and the amount and currency of the purchase — so the sale is counted even if your browser never loads our thank-you page. This server report contains no name, email address or shipping address, and we only send it for orders shipped within the United States. Separately, our logo font is served by Google, so Google also receives your IP address and browser information on every page load.
Microsoft Corporation (Bing and the Microsoft Advertising network). Nothing from Microsoft is installed on trylodestone.org today. We intend to submit the same product data feed to Microsoft so that our products can appear in Bing Shopping listings, and if we begin advertising with Microsoft we will install Microsoft's Universal Event Tracking tag, known as UET. It works in the same way as the Google advertising tags described above, and Microsoft may likewise use cookies to serve advertisements based on your prior visits to trylodestone.org and to other websites. We will amend this Statement when that happens.
Customer lists and audience matching. Advertising platforms let a business upload a list of customer email addresses so it can advertise to those customers, exclude them from advertising, or reach people with similar interests. We do not do this today. If we start, we will upload only a one-way encrypted (hashed) form of your email address and never the address itself, and under the terms we accept with each platform the list may be used only to perform that service for us. You can ask now, before any such list exists, to be left off it — email help@trylodestone.org and we will hold your address on the suppression side instead. We can promise that one because the list would be ours to build.
These companies use what they receive for their own purposes too. Once Google, Meta or Microsoft receives information from us, each also handles it under its own privacy policy and for its own purposes, which we do not control:
- Google – How Google uses information from sites or apps that use our services
- Meta – Meta Privacy Policy
- Microsoft – Microsoft Privacy Statement
SELLING AND SHARING YOUR PERSONAL INFORMATION
This is the question we get asked most, so here is a direct answer.
What actually happens. When you load a page on trylodestone.org, the Google and Meta advertising tags fire. Those companies receive your IP address, your browser and device information, the page you are on, what you looked at or bought, their own cookies from your browser, and — if you have given us your email address — a hashed copy of it. They use that to attribute our advertising, to build advertising audiences, and to show you advertisements later, on other websites and apps. That is the whole mechanism. Nothing is hidden behind it.
Is that a "sale"? California law defines selling as making a consumer's personal information available to a third party for monetary or other valuable consideration, and defines sharing as making it available to a third party for cross-context behavioral advertising, whether or not money changes hands. We receive no money for any of this. What we receive is advertising that works better and measurement we could not otherwise get, and California's Attorney General has treated exactly that as valuable consideration. So our answer is: this is "sharing" for cross-context behavioral advertising, and we assume it is also a "sale" as those words are defined in California, and we would rather tell you that than argue about it.
What we do not do. We do not sell or rent your name, email address or postal address to data brokers, list brokers, marketing co-operatives, or any other company that would market to you on its own behalf. We have never done that and we have no plans to.
Why there is no "Do Not Sell or Share My Personal Information" link on this site. That link is required of companies that qualify as a "business" under the California Consumer Privacy Act. A company qualifies if it has annual revenue above roughly $26.6 million — that figure is adjusted for inflation and is the one in force as of the date at the top of this Statement — or buys, sells or shares the personal information of 100,000 or more California consumers or households in a year, or makes half its revenue from selling personal information. We are a one-person store and we meet none of those tests, so the CCPA does not currently apply to us and we are not going to claim it does. We have not posted a "Do Not Sell or Share" link because a link that led to nothing would be worse than no link at all.
What we do instead. We honour as much of the substance as we actually can, and we are going to be exact about where that ends, because a privacy statement that promises a switch the business does not have is worse than one that admits the limit.
What we can do for you. Email help@trylodestone.org with the subject "Opt out of ad tracking" and a person will:
- Take you off our mailing list, so no more marketing email is sent to you.
- Delete what we hold from our forms — your contact-form and review-form submissions, the sign-up notification, and the correspondence in our inbox.
- Delete your rows from our own analytics, including the ones carrying your IP address. Those records are not filed under your name, so we need the IP address you browsed from or the visitor identifier your browser stored in order to find them; we then run the deletion as a query against our database. See Your Choices, and How to Use Them.
- Keep you off any customer list we ever upload to an advertising platform. We do not upload one today. If we start, your address goes on the suppression side of it rather than into an audience.
What we cannot do, and will not pretend to. We cannot reach into Google's or Meta's systems and pull you out of an advertising audience their tags have already built from your visit. Advertisers are not given that control: those audiences are assembled and held by the platform, and membership falls away on the platform's own clock — Meta caps a website-based audience at 180 days from your last activity, and a Google remarketing list can run longer than that. Anyone who offers to delete you from a tag-built audience by email is describing a button that does not exist. The controls that genuinely reach those audiences are the platform, industry and browser controls in the next section — including your own Google and Meta ad settings — and they are what to use if that is the part you want stopped.
You can also send a Global Privacy Control signal from your browser. Read Do Not Track and Global Privacy Control below before you rely on it, because on our site it currently reaches Google and not Meta, and we are not going to overstate it.
If our size ever changes enough that these laws apply to us, we will build the machinery they require and say so here.
HOW TO OPT OUT OF ADVERTISING AND ANALYTICS
You can limit or switch off interest-based advertising in several ways. These controls are saved per browser and per device, so you may need to repeat them on each browser and device you use.
- Email us. Write to help@trylodestone.org and we will do the four things listed under What we can do for you in the section above — mailing list, form submissions, your rows in our own analytics, and any future customer list. Please note what it does not do: it cannot remove you from Google's or Meta's own advertising audiences. The controls below are the ones that reach those.
- Google. Manage or turn off personalized advertising at My Ad Center. We do not use Google Analytics on trylodestone.org; if you want to opt out of Google Analytics on the many other sites that do use it, Google publishes the Google Analytics Opt-out Browser Add-on.
- Meta. Manage your advertising choices in Facebook Ad Preferences.
- Microsoft. Manage your advertising choices at Microsoft ad settings or at choice.microsoft.com.
- Industry-wide tools. The Digital Advertising Alliance at optout.aboutads.info, the Network Advertising Initiative at optout.networkadvertising.org, and, in Europe, the European Interactive Digital Advertising Alliance at youronlinechoices.eu let you opt out of many participating advertising companies at once.
- Global Privacy Control. Some browsers and privacy extensions can send a GPC signal on every site you visit, without you doing anything per-site. On trylodestone.org it puts Google's advertising tag into a limited mode. Do Not Track and Global Privacy Control below sets out exactly how far it reaches and where it stops.
- Your browser and your device. Most browsers let you block or delete cookies and site data in their settings — that is also how you clear the local-storage items listed above. On a phone or tablet you can reset or limit your advertising identifier in the operating system's privacy settings. Blocking third-party scripts stops these tags at the source.
- Our own analytics. It has no advertising cookie to switch off, and it does not follow you to other websites. If you want your records removed from it, email help@trylodestone.org — see Your Choices, and How to Use Them for what we need from you to find them.
Opting out stops advertising from being tailored to you. It does not stop you from seeing advertisements, and it never affects your ability to shop with us or the price you pay.
DO NOT TRACK AND GLOBAL PRIVACY CONTROL
Do Not Track. Some browsers can send a "Do Not Track" ("DNT") signal. We do not respond to DNT signals, because there is no agreed standard for what responding would mean. We are required to tell you what we do, and that is what we do.
Global Privacy Control. Some browsers and extensions send a "Global Privacy Control" ("GPC") signal, which is a request to opt out of the sale or sharing of your personal information. When our site sees a GPC signal, it does one specific thing: it switches Google's advertising tag into a restricted mode, in which Google may use what it receives only as our service provider — for measurement, security and billing — and not to personalise advertising to you.
What GPC does not currently do on our site, stated plainly: it does not stop the Meta pixel or the Meta Conversions API, and it does not stop our own analytics from recording your visit and your IP address. We would rather write that down than let you believe a signal is doing more than it is. If you want as much of this stopped as can be stopped, do both: email help@trylodestone.org for the parts that are in our hands — our mailing list, the submissions we hold, and your rows in our own analytics — and use the platform, industry and browser controls in How to Opt Out of Advertising and Analytics for the parts only Google and Meta can switch off. Neither one alone covers everything, and we would rather say so than let one email carry a promise it cannot keep.
Other parties collecting information across sites. We are required to tell you whether third parties may collect personally identifiable information about your online activities over time and across different websites when you use our site. They may, and they do. Google and Meta both do exactly that through the tags described above. That is what remarketing is.
MARKETING EMAIL
Our mailing list is built from email addresses submitted through the sign-up forms and the promotional pop-up on trylodestone.org — the scratch-card offer, the returning-visitor offer, and the newsletter boxes in our footer and on our join page.
The consent we rely on. Both discount pop-ups state, next to the button you press, that submitting your email address signs you up for recurring marketing email from Lodestone and that you can unsubscribe at any time, and that your consent is not a condition of purchase. Submitting the form is how you give that consent. If you gave us your address and did not mean to join the list, tell us at help@trylodestone.org and we will take you off it — no questions.
What you get. New arrivals, sales and offers, usually a few times a month. That is all we use the list for.
Buying something does not sign you up. Placing an order does not add you to the mailing list, and unsubscribing does not stop your order emails.
Writing to us does not sign you up either. Email addresses from our contact form and our review form are not added to the mailing list. Two other things do happen to them, and you should know both. They are retained — held in our Formspree account and in our email inbox alongside the rest of our customer correspondence, as described under How Long We Keep Information. And, as with any address typed into a form on this site, the address is saved in your browser under am_email and a one-way encrypted (hashed) copy of it is sent to Meta with our advertising events so Meta can match your activity, exactly as described under Advertising and Analytics Partners. So "we only use it to answer you" would not be the whole truth, and we are not going to write it. Clearing your browser storage removes the stored address, and emailing help@trylodestone.org gets the retained submissions deleted.
How to stop. Every newsletter carries an unsubscribe link at the bottom, and one click is enough — no login, no form, no reason required. Clicking that link takes effect immediately — it is handled automatically by the service that sends our email, with no person in the loop. You can also email help@trylodestone.org at any time and we will remove you; that route depends on a person reading the inbox, so we hold ourselves to the deadline federal law sets, which is 10 business days. In practice it is usually the same day. Unsubscribing stops marketing email only; you will still receive confirmations and shipping notices for anything you buy, because those are not marketing.
Our postal address. Federal law requires a valid physical postal address in every commercial email. Ours is printed here, it goes in the footer of the newsletters we send to our mailing list, and you may also use it for written privacy requests. To be exact rather than flattering: the automatic welcome email that delivers your discount code when you sign up does not carry it — that message gives our support address and our web address instead — so this Statement, not that email, is where you will find it. It is:
Lodestone
2093 Philadelphia Pike #2836
Claymont, DE 19703
United States
No text messages. We do not collect phone numbers at checkout, we do not run an SMS marketing programme, and we do not use automatic dialers. If that ever changes we will ask for your consent separately and amend this Statement first.
Who delivers our email. Resend sends it. Resend receives your email address, your name where we have it, the contents of the message, and your subscription status.
HOW LONG WE KEEP INFORMATION
- Order records — name, email address, shipping address and what you bought — are kept for as long as we are in business. We need them for accounting and tax, for warranty and return claims, and to defend against payment disputes. Our order system is deliberately built so that order numbers are never reused, which means order rows are marked cancelled rather than removed.
- Mailing list — until you unsubscribe. After you unsubscribe we keep a record that you did, so that we do not email you again by accident.
- Raw analytics visit records, including IP addresses — 90 days, then deleted by a scheduled daily job rather than by hand, so it does not depend on anyone remembering. We are describing how it is set up, not guaranteeing that no record ever survives a day or two past the mark: if a run fails, the next successful one clears the backlog.
- Analytics visitor and session records — the random identifier, the page you first landed on, where you came from, and any advertising tags attached to that visit, with no name, email address or IP address — are kept until we delete them. We do not currently delete them on a schedule, and we are telling you that rather than publishing a limit we do not enforce.
- Daily totals and statistics derived from the above are kept indefinitely. They describe traffic, not people.
- Contact-form, review and sign-up submissions — held by Formspree for as long as our account with them is active, and in our email inbox alongside the rest of our customer correspondence.
- Cookies and browser storage — the advertising cookies expire on their own timers, given in the cookie section (roughly 90 days each). The local-storage items have no timer at all: they stay in your browser until you clear them, other than pending_purchase, which is removed when you reach the thank-you page. The one session-storage item is erased when you close the browser tab.
YOUR CHOICES, AND HOW TO USE THEM
Comprehensive state privacy laws mostly apply to companies far larger than us, and we are not going to quote you rights under statutes that do not cover this business. Instead, here is what we will actually do for anyone who asks, wherever you live. Email help@trylodestone.org.
- See what we hold about you. Tell us the email address you used with us and we will send you the personal information we hold under it: your order history, your mailing-list status, and what came in through our forms.
- Correct it. If your name, email address or shipping address is wrong, tell us and we will fix it. This is also the route to use if an order is in flight and the address needs changing — the sooner the better.
- Delete it. We will remove you from the mailing list, and delete the form submissions and correspondence we hold. What we cannot delete: records of completed orders, which we keep for the accounting, tax and dispute reasons above, and anything a payment processor holds independently as its own record of a transaction. We will tell you exactly what we kept and why.
- Delete your analytics records. These are not filed under your name, so we need something to find them by — the IP address you browsed from, or the visitor identifier your browser stored. If you send us either, we will run the deletion against our database and remove the matching rows. Otherwise the raw records carrying your IP address are cleared by the 90-day job described above.
- Stop the advertising tracking. See Selling and Sharing Your Personal Information and How to Opt Out of Advertising and Analytics above.
- Get a copy you can take elsewhere. Ask, and we will send what we hold in a readable file.
We will not charge you for any of this, and we will never treat you differently — different prices, different service, a worse offer — because you asked. We aim to respond within 30 days. We may ask you to confirm you control the email address in question, because handing someone else's order history to the wrong person would be the worse mistake. If you are unhappy with our answer, reply and say so; a person reads it.
HOW WE PROTECT INFORMATION
Our site is served over HTTPS, so traffic between your browser and us is encrypted. Payment credentials never touch our systems. Our database provider encrypts stored data, and access to our systems is limited to the owner of the business.
We are a small business, not a bank, and we are not going to claim our security is perfect — no honest website can. No method of transmitting or storing information is completely secure. What we can tell you is that we deliberately hold as little as possible: no accounts, no passwords, no card numbers.
New York's data security law requires a business that holds New York residents' private information to keep reasonable administrative, technical and physical safeguards in place, and to give notice if that information is exposed. If personal information we hold were ever exposed in a security breach, we would notify the people affected, and any regulator we are required to notify, without unreasonable delay.
CHILDREN'S PRIVACY
trylodestone.org is a general-audience store meant for adults, and it is not directed to children. We do not knowingly collect personal information from children under 13, and we do not ask anyone's age or date of birth anywhere on the site. If we learn that we have collected personal information from a child under 13, we will delete it. If you are a parent or guardian and believe your child has given us information, email help@trylodestone.org or write to the postal address above and we will remove it.
SUBMITTING INFORMATION FROM OUTSIDE THE UNITED STATES
We operate this store from the United States and it is built for customers here. Our prices are in United States dollars, our advertising is aimed at the United States, and our Shipping Policy covers shipping within the United States.
We are not going to tell you that ordering from abroad is impossible, because our checkout does not enforce that. Card payments run through Stripe, and that checkout accepts United States shipping addresses only. PayPal behaves differently: it uses whichever address is already on your PayPal account, and we do not currently block a non-United States address on that route. An order from outside the country can therefore get through. We would rather write this down than publish a restriction our own code does not impose.
Our website and database are hosted in the United States, so information collected here is stored and processed in the United States. As described above, order details are also sent to our fulfillment partner in China.
If you are in the European Economic Area, the United Kingdom or Switzerland. Our advertising is aimed at the United States, our prices are in United States dollars, and our Shipping Policy says we ship to addresses within the United States. We are not going to take the further step of telling you we have nothing to do with those regions, because our own pages would contradict it: the Shipping & Returns panel on every product page still quotes delivery times for Europe, the United Kingdom, Australia, Canada and the rest of the world. That text is on the site today. It is also the kind of thing European and United Kingdom data protection law weighs when it asks whether a business is offering goods to people in those regions, so we are not going to pretend the question cannot arise. What happens if you actually try to order from outside the United States is described in the paragraph immediately above.
What we are not equipped to do is run the process that European and United Kingdom data protection law expects of a business that offers goods there. We have not appointed a representative in the European Union or the United Kingdom, and we are not going to print a list of statutory rights with deadlines we have no machinery to meet — a right published without a process behind it is a false promise, and the point of this Statement is to avoid those. What we do instead is extend to you the same choices we extend to everyone, everywhere: the ones set out in Your Choices, and How to Use Them. They are real, a person performs them, and where you live makes no difference to whether you get them. Email help@trylodestone.org. Separately, Google's advertising tags on this site are set to a denied-by-default consent state for visitors from those countries, so the personalisation signals are withheld from Google before you do anything at all.
STATE PRIVACY DISCLOSURES
California. This Statement is our notice under the California Online Privacy Protection Act. It identifies the categories of personally identifiable information we collect and the categories of third parties we may share it with (What Personal Information We Collect and Who We Share Personal Information With); it describes the process for reviewing and requesting changes to your information (Your Choices, and How to Use Them — email help@trylodestone.org); it describes how we notify you of material changes (Changes to This Privacy Statement); it carries an effective date at the top; it discloses how we respond to Do Not Track signals and to Global Privacy Control; and it discloses that other parties may collect personally identifiable information about your online activities over time and across different websites when you use our site (Do Not Track and Global Privacy Control). As explained above, we are not a "business" under the California Consumer Privacy Act, and we do not claim to be. California's "Shine the Light" law does not apply to a business with fewer than 20 employees.
Rhode Island. Under the Rhode Island Data Transparency and Privacy Protection Act we designate a controller and publish a way to reach them (Who We Are, and Who Is Responsible). The categories of personal data we collect through this website are identifiers (name, email address, postal address, IP address, and the browser identifiers listed above), commercial information (orders and products viewed), and internet activity (pages visited, referral source, device and browser information). We clearly disclose that we process personal data for targeted advertising, as that term is defined in that Act — the Meta pixel and Google's remarketing tags do exactly that. The third parties to whom we have transferred, or may transfer, personally identifiable information in a way that may be treated as a sale are Google LLC and Meta Platforms, Inc., and, if we begin advertising there, Microsoft Corporation. You may contact us about any of this at help@trylodestone.org.
Connecticut. Connecticut amended its Data Privacy Act with effect from 1 July 2026, and one of the tests it added carries no size threshold at all: a business that offers consumers' personal data for sale in trade or commerce is covered however small it is. Whether ordinary advertising tags amount to offering personal data for sale has not been settled by a Connecticut court or by the Attorney General there. We are not going to guess in our own favour on that, having already told you above that we assume our advertising transfers are a sale. So if you are in Connecticut: ask, and we will do everything set out in Your Choices, and How to Use Them — tell you what we hold, correct it, delete it, send you a copy you can take elsewhere — and everything listed under What we can do for you, which is our opt-out route for advertising and analytics. Email help@trylodestone.org. Two limits, so this paragraph is not read as more than it is: we cannot remove you from an advertising audience Google or Meta has already built from your visit, for the reasons given in Selling and Sharing Your Personal Information, and the Global Privacy Control signal currently reaches Google's tag on this site but not Meta's, as set out in Do Not Track and Global Privacy Control. We are not claiming either of those gaps is closed.
Nevada. Nevada requires the operator of a commercial website to publish notice of the information it collects and to designate an address where you can ask it to stop selling covered information about you. This Statement is that notice, and help@trylodestone.org is that designated address — the same inbox used everywhere else in this Statement, and it is read by a person. Nevada's exemption for small operators is open only to businesses located in Nevada, so we do not rely on it. Nevada also defines a sale narrowly, as an exchange of covered information for money, and we receive no money for any of the transfers described here, so on our reading there is no Nevada sale to stop. You do not have to accept our reading: ask anyway, and we will do everything under What we can do for you and Your Choices, and How to Use Them. Nevada allows 60 days to answer a request of this kind; we aim at 30, as we do for every other request in this Statement.
Texas. Texas prohibits a business from selling sensitive personal data without the consumer's prior consent, and that prohibition applies whatever the size of the business. We do not collect sensitive personal data at all — no government identifiers, no financial account numbers, no health, biometric, genetic, precise-location, racial, religious, political or sexual-orientation data — as set out in What We Do Not Collect. There is therefore none of it here for us to transfer to anyone. Nebraska and Minnesota restrict small businesses the same way, and the same answer applies.
Everywhere else. Most other state privacy laws apply only above customer or revenue thresholds this store does not reach. Thresholds are not the whole story, though — as the paragraphs above show, some statutes bind a business of any size — so rather than try to track each one, we extend the choices in Your Choices, and How to Use Them to everyone who asks, regardless of where they live.
CHANGES TO THIS PRIVACY STATEMENT
We may change this Statement. When we do, we will post the new version on this page and change the amendment and effective date at the top. That date is how you can tell whether anything has changed since you last read it.
If we make a material change — one that meaningfully affects what we collect, who we share it with, or what we do with it — we will say so at the top of this page for at least 30 days, and, where the change affects information we already hold about you and we have your email address, we will email you about it. Information we have already collected stays governed by the version of this Statement that was in place when we collected it, unless you agree otherwise.
CONTACTING US
If you have a question about this Statement, or want to make any of the requests described in it, contact us. A person reads these.
Email: help@trylodestone.org
Postal mail: Lodestone, 2093 Philadelphia Pike #2836, Claymont, DE 19703, United States