Privacy Policy
Effective date: February 2026. This policy explains what personal information Birthright Foundation collects, why, how we protect it, and your choices. Contact: privacy@birthright.live.
1. What We Collect
- From you: name, email, phone, shipping/billing address, account password (stored as a bcrypt hash), community posts, dispute messages, files you upload for vendor orders, workshop registrations, and questions you ask our AI Help Assistant.
- Automatic: IP address, device and browser metadata, referring URL, pages viewed. See our Cookie Notice.
- From third parties: Stripe payment metadata (charge id, last-4, status — never the full card number or CVV); Cloudflare routing metadata.
- Partners: if you sign up as a partner, we also collect payout method (encrypted; only type + last-4 kept in plaintext) and, when US thresholds require, W-9 information.
2. How We Use It
- Operate the Services (accounts, checkout, workshops, community).
- Communicate with you (receipts, reminders, dispute replies, newsletter — only with your consent).
- Fulfil orders (share address with Printful, Lulu, or the vendor).
- Pay partners and reconcile earnings.
- Improve the Services (analytics, image-caption search, security).
- Comply with law.
3. Legal Bases (EU / UK Users)
Contract necessity, legitimate interests (balanced by your opt-out), your consent (marketing and non-essential cookies), and legal obligation.
4. Who We Share With
- Payment: Stripe.
- Fulfilment: Printful, Lulu, and the specific vendor of your order.
- Email: Resend.
- Hosting & security: Emergent, Cloudflare, MongoDB Atlas.
- AI features: Anthropic (Claude) and Google (Gemini/Nano Banana). We send only the content needed to answer your request, not your account credentials.
- Legal & safety: when required by law or to protect people.
We do not sell your personal information.
5. Retention
- Account data: while your account is active + 3 years.
- Order data: 7 years (tax).
- Community posts: until you delete them or your account.
- Security-audit logs: 365 days.
- Marketing consent records: while your consent is active + 2 years.
6. Your Rights
Anywhere: request access, correction, deletion, or export at privacy@birthright.live. We respond within 30 days.
EU/UK/CA residents additionally have the right to object to processing, restrict processing, and complain to your local supervisory authority (EU: https://edpb.europa.eu · UK: https://ico.org.uk · California: https://oag.ca.gov/privacy).
California residents: we do not "sell" or "share" personal information under the CCPA; we honour Global Privacy Control signals where technically feasible.
7. Security
TLS in transit; encryption at rest for payout data; role-based access; bcrypt hashing for passwords; audit logging of admin actions and security-relevant user events. No system is perfectly secure — we disclose confirmed material breaches without undue delay.
8. Children
Not for anyone under 18. If you believe a minor has an account, email privacy@birthright.live and we will remove it.
9. Automated Decisions
We do not use automated decision-making that produces legal effects about you. AI features are labelled as such and remain human-in-the- loop.
10. Changes
Material changes take effect 30 days after posting; we email account-holders as well.
11. Contact
privacy@birthright.live · Mail: 2148 W Farill Dr, Phoenix, AZ 85015. DPO/EU rep contact (once designated): dpo@birthright.live.
EU / UK Compliance Addendum
Where an EU or UK resident's mandatory local rights conflict with this document, the local rules prevail. Key points:
- GDPR (EU) 2016/679 and UK GDPR govern personal-data processing. Lawful bases: contract necessity, legitimate interests (with opt-out), consent (marketing / non-essential cookies), and legal obligation.
- ePrivacy Directive (2002/58/EC) — non-essential cookies require prior opt-in consent (see our Cookie Notice).
- Consumer Rights Directive (2011/83/EU) — 14-day right of withdrawal on distance sales of goods and most digital services. Fully-performed digital content with prior consent may lose that right.
- Digital Services Act (Reg. 2022/2065) — community features (posts, DMs, disputes) fall in scope. Single point of contact: eu-contact@birthright.live.
- Cross-border transfers — EU SCCs (2021/914) + UK IDTA with a transfer-impact assessment per sub-processor.
- DSAR window — 30 days (extendable to 90) at privacy@birthright.live.
- Supervisory authority — EU: your national DPA (https://edpb.europa.eu). UK: ICO (https://ico.org.uk).
