RetailRoarports — Privacy Policy

The short version

Here is the plain-English summary. The numbered sections below control if there is ever any conflict.

1. Introduction

This Privacy Policy explains how we handle personal information when you visit https://retailroarports.com (the "Site") and use the RetailRoarports subscription service (together, the "Service").

In this policy, "RetailRoarports," "we," "us," and "our" mean RetailRoarports, the trade name of the independent sole proprietor who operates the Service in the United States. "You" means the person using the Service or visiting the Site. The Service is intended for business users in the United States; it is not directed to, or offered to, individuals in the European Economic Area (EEA) or the United Kingdom.

This policy covers the Service only. It does not cover any third-party website, product, or service that we do not own or control, even if the Service links to it or loads content from it (see Section 15).

By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service. This policy works together with our Terms of Service. The Terms include important sections on disclaimers, our liability limits, governing law, and how disputes are handled — please read them too.

2. Who we are and what the Service does

RetailRoarports is a small, independent research product. We provide compiled market intelligence — maps, metro-area rollups, comparative charts, search-interest trends, growth indices, social-reach leaderboards, downloadable datasets, and deep brand reports ("Roarports") — covering retail health & wellness brands across several industries.

We are not affiliated with, sponsored by, or endorsed by the brands we track or by Google, Instagram, TikTok, or YouTube. Brand names and marks shown in the Service belong to their owners and are used for identification and reference only.

3. Information we collect

In plain terms: we collect the minimum we need to sign you in, bill you, keep the Service secure, and remember your interface preferences. We do not build profiles about you, and we do not run advertising or marketing trackers.

We collect the following limited categories of personal information:

a. Account email. When you sign up or sign in, we collect the email address you provide. Sign-in is passwordless: we send a one-time "magic link" (a single-use sign-in link) to your email. That link carries a single-use access token, so anyone who can open the email can sign in — which is why keeping your email account secure matters (see Section 10). There are no passwords anywhere in the Service, so there is no password for you to manage or for anyone to compromise.

b. Billing and subscription data (handled by Stripe). Stripe (our payment processor) collects your name, card or payment details, and billing address directly to charge your US$49/month subscription. That information goes straight to Stripe — it never passes through us. We never see or store your full card number. We keep only a Stripe customer ID, your Stripe subscription ID, your subscription status (for example, active, past due, or canceled), and your current billing-period end date.

c. Technical and usage data (via Cloudflare). When you access the Service, our hosting and security provider, Cloudflare, automatically receives and may log standard technical information as your requests pass through it. This includes your IP address, your device and browser type (user-agent), the pages and resources you request, response status, approximate location derived from your IP, and security-related signals. We use this to deliver, secure, and troubleshoot the Service.

d. Authentication tokens. After you sign in, your browser stores a session token (and a refresh token) so you stay signed in. These are kept in your browser's local storage and are used only to keep your session active.

e. Interface preferences (browser local storage). We save a few non-identifying interface settings in your browser's local storage under keys prefixed with "rr." — for example, your selected map filters, display modes, and which panels are open. This is preference data, not tracking data, and it stays in your browser.

f. Profile and subscription records. In our database we keep a small profile record tied to your account: your email, your role (standard user or admin), account timestamps, and the subscription fields synced from Stripe described above. We also keep a short technical log of Stripe webhook event IDs so we do not process the same billing event twice.

We do not collect or store payment card numbers, and we do not use analytics SDKs, advertising pixels, or third-party marketing trackers in the Service.

4. How we collect it

In plain terms: you give us your email, our systems record basic technical data as you use the Service, and Stripe sends us your subscription status.

We collect information in three ways:

  1. You provide it. Your email when you sign up or sign in, and your billing details, which you enter directly with Stripe.
  2. Automatically, as you use the Service. Technical and usage data is generated and logged as your requests pass through Cloudflare, and your interface preferences and session tokens are saved by your browser.
  3. From our processors. We receive your subscription status and related billing metadata from Stripe after you subscribe or change your plan.

A note on our product data: the market-intelligence data about brands that the Service displays is compiled from third-party and publicly available sources. That product data is described in our Terms of Service; this Privacy Policy is about your personal information, not the brand data we publish.

5. How we use your information

In plain terms: we use your information to run the Service, bill you, keep it secure, communicate with you, follow the law, and improve our product.

We use the personal information described above for these purposes:

6. Cookies, local storage & similar technologies

In plain terms: we use only essential storage to sign you in and remember your preferences. We do not use advertising or marketing trackers. (Because there are no passwords, your signed-in session lives in these browser tokens — see Section 10 on account security.)

We keep our use of cookies and similar technologies to the essentials:

We do not use third-party advertising or marketing trackers, analytics pixels, or cross-site tracking technologies in the Service. You can clear local storage or block cookies in your browser settings, but doing so may sign you out, reset your preferences, or prevent the Service from working properly.

7. How we share your information, and our service providers

In plain terms: we share data only with the providers we need to run the Service, with parties whose assets your browser loads, when the law requires it, and if our business is ever transferred. We do not sell your personal information.

We share personal information only as described here.

a. Service providers. We rely on a small set of outside companies (sometimes called "subprocessors") that handle data on our behalf so we can run the Service. They process data only as needed to provide their service to us:

b. Third parties whose assets load in your browser. To display the Service, your browser loads certain assets from third parties. When it does, those third parties may receive your IP address simply because your browser is requesting their content:

These third parties handle that information under their own privacy policies, which we do not control (see Section 15).

c. Legal and protective disclosures. We may disclose information when we believe in good faith it is necessary or appropriate to:

Where permitted, we may do this without telling you first.

d. Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business or assets (including during due diligence for a potential transaction), your information may be transferred or disclosed as part of that transaction. The recipient will be bound by this Privacy Policy or will provide notice as required by law.

e. Affiliates. If we create affiliates or subsidiaries, we may share information with them to operate the Service consistently with this Privacy Policy.

8. We do not sell your personal information; aggregated and de-identified data

In plain terms: we never sell your personal information. We may use data that no longer identifies you.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising (that is, tracking you across other sites to target ads). We also do not knowingly sell or share the personal information of anyone under 16. A transfer of information as part of a business transaction (Section 7.d) is not a "sale."

We do not collect, use, or disclose sensitive personal information as defined under the CPRA, so we do not offer a separate right to limit its use.

We may create aggregated or de-identified information — data that has been combined or stripped of identifiers so that it no longer identifies you. Once information is aggregated or de-identified, it is not personal information, and we may use, retain, and disclose it for any lawful purpose, including operating, analyzing, and improving the Service. We do not attempt to re-identify it except to confirm our de-identification works.

9. Data retention

In plain terms: we keep your information for as long as your account is active and as long as we need it for legitimate business and legal reasons, then delete or de-identify it.

We retain your personal information for as long as your account is active and for as long as reasonably necessary for the purposes described in this policy — including providing the Service, maintaining billing and financial records, resolving disputes, preventing fraud and abuse, and complying with our legal obligations.

When information is no longer needed, we delete or de-identify it at our discretion. Some records may be kept longer — for example, billing records we must keep for legal or accounting reasons; a minimal record that you asked us to delete your data or opt out, so we can keep honoring that request; and short technical logs (such as Stripe webhook event IDs and Cloudflare access logs). Copies may also persist briefly in backups. Your browser-stored session tokens and interface preferences are deleted from your browser when you sign out or clear your browser storage.

10. Data security

In plain terms: we take reasonable, industry-standard steps to protect your information, but no system is perfectly secure.

We use reasonable, industry-standard measures designed to protect the personal information we hold. These include server-side access controls, default-deny database rules that restrict access, cryptographic verification of authentication tokens, and not storing payment card data (Stripe handles cards on its own secure, PCI-compliant systems).

That said, no method of transmission or storage over the internet is completely secure. We cannot and do not guarantee absolute security, and we provide the Service without any warranty of security. Because sign-in works through a single-use link sent to your email, anyone with access to your email inbox could request a magic link and sign in as you — so you are responsible for keeping access to your email account secure. We will notify you of a security incident where and as required by applicable law.

11. International users and U.S. processing

In plain terms: we run everything from the U.S., so your information is processed in the U.S.

We run the Service from the United States, and we and our providers process your information there. The Service is intended for business users in the United States. If you access the Service from outside the United States, you do so on your own initiative and at your own risk, and you consent to your information being transferred to and processed in the United States, where privacy laws may differ from — and may be weaker than — those in your own country.

12. Children's privacy

The Service is built for business and professional users and is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us personal information, please contact us at admin@retailroarports.com, and we will take reasonable steps to delete it.

13. Your privacy rights

In plain terms: you can ask us to access, correct, or delete your personal data. Email us and we'll handle it, subject to a few legal limits.

Depending on where you live, you may have rights over your personal information. We honor these rights as described below.

a. Rights available to you. Subject to applicable law, you may ask us to:

b. How to exercise your rights. Email us at admin@retailroarports.com and tell us what you would like to do. We will respond within the time required by applicable law. You may use an authorized agent to make a request on your behalf where the law allows; we may ask the agent for proof of your permission and may still ask you to verify your identity directly.

c. Verification and limits. To protect you, we must verify your identity before acting on a request — usually by confirming you control the account email on file. We may decline or limit a request where the law allows. Examples include:

Aggregated and de-identified information is not subject to these rights, and we are not required to re-identify data to respond to a request. We will not discriminate against you for exercising your privacy rights.

d. Appeals. If we deny your request and you are in a state that provides an appeal right (or you simply disagree with our decision), you may ask us to reconsider by replying to our response or emailing admin@retailroarports.com. We will review the appeal and tell you the outcome within the time the law allows.

e. California residents (CCPA/CPRA). If you are a California resident, you have the rights to know, access, correct, and delete your personal information, and to opt out of the sale or sharing of personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

In the past 12 months, the categories of personal information we have collected are:

The sources of this information are: directly from you (your email); automatically as you use the Service (technical and usage data via Cloudflare); and from Stripe (your subscription and billing metadata) after you subscribe. We collect it for the business purposes described in Section 5.

We disclose these categories of personal information for business purposes only to: our service providers (Supabase, Stripe, and Cloudflare); recipients of legal or protective disclosures; and a successor in a business transfer — all as described in Section 7. We retain each category for the periods and on the criteria described in Section 9. We do not collect, use, or disclose sensitive personal information as defined under the CPRA.

You may exercise your California rights by emailing us at admin@retailroarports.com, and we will not discriminate against you for doing so.

f. Residents of other U.S. states. If your state gives you similar privacy rights (for example, to access, correct, or delete your personal information, or to opt out of its "sale" or "sharing"), you may exercise them the same way — by emailing us at admin@retailroarports.com. As noted, we do not sell or share your personal information.

14. Do-Not-Track

In plain terms: browsers have no agreed "Do Not Track" standard, so we don't act on that signal — but we don't track you for ads anyway.

Because there is no common industry standard for browser "Do Not Track" (DNT) signals, the Service does not respond to them. Where we are legally required to honor a recognized opt-out preference signal (such as Global Privacy Control), we will treat it as a valid opt-out for the browser and device on which it is sent. In any case, we do not sell or share your personal information or use advertising trackers.

15. Third-party sites and links

In plain terms: when the Service links to or loads content from other companies, their own privacy policies apply, not ours.

The Service may reference, link to, or load content from third-party websites and services that we do not own or control — for example, the public sources behind our brand data, and the Google Fonts and CARTO/MapLibre map-tile providers whose assets load in your browser. This Privacy Policy does not apply to those third parties. We are not responsible for their content, privacy practices, accuracy, or security. Their handling of your information is governed by their own privacy policies, which we encourage you to review.

16. Changes to this Privacy Policy

In plain terms: if we change this policy in a meaningful way, we'll tell you — usually by email to your account address or a notice in the Service.

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or the law. When we do, we will revise the "Last updated" date at the top and post the updated version. If the changes are material, we will provide reasonable notice — by email to your account address and/or a prominent notice in the Service. Because the Service is passwordless and your account email is our main way to reach you, please keep that address current and able to receive our messages. Your continued use of the Service after the updated policy takes effect means you accept it.

17. Contact us

If you have questions about this Privacy Policy or how we handle your information, or if you want to exercise your privacy rights, contact us at admin@retailroarports.com