This Privacy Policy explains how Turtally Awesome LLC (“we,” “us,” “our”) collects, uses, and protects your personal information when you use our website at steady-turtle.com or our services. If you don't agree with these policies, don't use the services.
Data Controller
Turtally Awesome LLC
1209 Mountain Road PL NE Ste N
Albuquerque, NM 87110
United States
Privacy inquiries: privacy@steady-turtle.com
Information We Collect
Personal information
Name and email address — provided voluntarily when you contact us, subscribe to the newsletter, or make a purchase.
Payment data
Processed and stored by Stripe. We don't store payment details on our servers. Stripe's privacy notice covers how they handle that data.
Website analytics
We use Umami Cloud — privacy-friendly, cookieless analytics that doesn't track personal data or store PII. Only anonymous usage statistics to help us improve the site.
How We Use It
We use collected information for:
- ·Processing orders and delivering products.
- ·Providing customer support and responding to inquiries.
- ·Complying with legal obligations.
- ·Improving the website and services.
- ·Marketing or advertising beyond our own newsletter.
- ·Data sales to third parties.
- ·Tracking across other websites.
- ·Creating detailed user profiles.
Information Sharing
Two third-party services, each limited to a specific purpose:
- ·Stripe: payment processing only.
- ·Umami Cloud: anonymous website analytics only.
We do not sell, rent, or share personal information for commercial purposes.
Data Retention
We retain personal information only as long as necessary for business purposes or as legally required:
- ·Customer records: as long as you have an account, or as required by tax/legal retention rules.
- ·Support inquiries: until resolved, plus a reasonable retention period for quality assurance.
- ·Payment records: typically 7 years, as required for tax and accounting.
Data Security
We implement appropriate technical and organizational measures to protect your information:
- ·Secure hosting infrastructure in the United States.
- ·Encrypted data transmission (SSL/TLS).
- ·Limited access to personal information on a need-to-know basis.
- ·Regular security assessments and updates.
No electronic transmission or storage method is 100% secure. We do everything reasonable, but we can't guarantee absolute security — and neither can anyone else. If that's a dealbreaker, don't use the services.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
General rights (everyone)
- ·Access: request a copy of your personal data.
- ·Correction: request correction of inaccurate data.
- ·Deletion: request deletion.
- ·Objection: object to processing based on legitimate interests.
- ·Portability: receive or transfer your data in a structured format.
- ·Withdraw consent: where processing is based on consent.
US residents (CCPA, VA CDPA, etc.)
- ·Right to know what personal information we process.
- ·Right to non-discrimination for exercising your rights.
- ·Right to opt out of targeted advertising (we don't do this).
- ·Right to opt out of data sales (we don't sell data).
EU residents
Under GDPR you have comprehensive data-protection rights, including the right to lodge a complaint with your local data protection authority. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects (GDPR Art. 22).
To exercise any of these rights, email privacy@steady-turtle.com. We'll respond within the legally-required timeframe for your jurisdiction.
International Transfers
Our services are operated from the United States. If you're accessing them from outside the US, your information is transferred to and processed in the US. By using the services you consent to this transfer; we ensure appropriate safeguards are in place for international data transfers in compliance with applicable data-protection laws.
Minors
We do not knowingly collect personal information from individuals under 18 years of age. If you believe we have inadvertently done so, email us immediately and we'll delete it.
Third-Party Services & Cookies
We don't set cookies directly. Third-party services may use essential cookies:
- ·Stripe: may use cookies for payment processing and fraud prevention.
- ·Browser functionality: your browser may use technical cookies for basic functionality.
You can control cookies through your browser settings, though this may affect payment processing.
Data Breach Notification
In the event of a data breach that may compromise your personal information:
- ·We will notify affected users within 72 hours of discovery.
- ·Notification will be sent via email to your registered address.
- ·We will provide information about the nature of the breach and steps to protect yourself.
- ·We maintain incident-response procedures in compliance with applicable laws.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes are posted prominently on the website or communicated directly. Review periodically to stay informed.
Questions about this policy or our data practices: privacy@steady-turtle.com.