This policy explains how Crestline Row LLC (“we”) collects, uses, stores and shares personal information when you visit this website or buy from us. The data controller is Crestline Row LLC, 631 Horseshoe Rd, Cannon Ball, ND 58528, United States, crestlinerow2@outlook.com, (701) 997-6923.
1. Information we collect
- Order and transaction data: name, email address, phone number, billing and shipping address, items purchased, order amount and order history.
- Payment data: card details are entered directly on our payment processor's secure checkout page. We receive only limited information such as card brand, last four digits, expiry and payment status. We never receive or store your full card number or security code.
- Communications: messages you send us by email or phone.
- Technical data: IP address, browser and device type and pages requested, recorded in standard server logs for security and to prevent abuse (for example, limiting repeated checkout attempts).
- Site storage: your bag contents (session storage, cleared when you close the tab) and your cookie choice. See our Cookie Policy.
We do not use third-party analytics or advertising trackers on this website.
2. How we use it
- To process payments, fulfil and ship orders, and handle returns, refunds and cancellations (performance of a contract).
- To send order confirmations, shipping updates and customer-service replies.
- To detect and prevent fraud, card testing and misuse, and to keep the site secure (legitimate interests; legal obligation).
- To meet tax, accounting and legal obligations.
- Marketing: we only send marketing emails if you have separately and expressly opted in. Starting or completing checkout does not add you to a marketing list. Every marketing email includes an unsubscribe link, and you can opt out at any time by emailing crestlinerow2@outlook.com. We honour opt-outs promptly and within 10 business days.
We do not sell your personal information and we do not share it for cross-context behavioural advertising.
3. Payment processing — Stripe and Square
We use Stripe and/or Square for payment processing. When you check out, you are taken to their hosted checkout page, and the information you provide there (such as your name, email, phone number, billing and shipping address, card details and order information) is collected and processed by that provider to complete the payment.
- Fraud prevention: Stripe and Square use payment and device data, including data from failed or declined transactions, to detect and prevent fraud.
- Incomplete checkouts: information you enter on a checkout page may be collected by the processor even if you do not finish your purchase.
- Cookies at checkout: the processors set cookies and similar technologies on their checkout pages for fraud detection, security and, where you choose, saved-details features such as Stripe Link.
- Security: Stripe and Square are PCI-DSS Level 1 certified service providers. We do not store card details.
- International transfers: Stripe and Square may process data in the United States and other countries (Stripe may also process data in India), using safeguards such as Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Stripe's privacy policy is available at stripe.com/privacy. Square's privacy notice is available at squareup.com/legal/general/privacy.
4. Other service providers
We share only what is necessary with our website host, email provider and shipping carriers so they can perform services for us. They may use it only on our instructions. We may disclose information if required by law or to protect our rights, customers or others from fraud.
5. Identity verification
We do not use biometric identity verification (such as Stripe Identity selfie or ID checks). If we ever introduce it, we will ask for your explicit consent first and update this policy.
6. Data retention
We keep order and transaction records for as long as needed to fulfil your order and then for up to 7 years to meet tax, accounting and legal obligations. Transaction data may be retained for regulatory and fraud prevention purposes even after you stop using our website. Customer-service emails are kept for up to 3 years. Server logs are kept for up to 90 days.
7. Security
This website is served only over encrypted HTTPS connections. Payments are processed by Stripe or Square (PCI-DSS compliant); we do not store card details. Access to order data is limited to people who need it to serve you.
8. Your rights
Depending on where you live (for example under the GDPR/UK GDPR, the California Consumer Privacy Act and other US state privacy laws), you may have the right to:
- access the personal information we hold about you and receive a copy;
- correct inaccurate information;
- delete your information (subject to records we must keep by law, such as transaction records);
- object to or restrict certain processing, and withdraw consent at any time;
- opt out of marketing and of any sale or sharing of personal information (we do not sell or share);
- data portability; and
- lodge a complaint with your local data-protection authority.
To make a request, email crestlinerow2@outlook.com (subject: “Privacy request”) or call (701) 997-6923. We will verify your request and respond within 30 days (45 days where US state law allows). We will not discriminate against you for exercising your rights. For data held by Stripe or Square in their own right, you can also contact them directly.
9. Children
Our services are not directed to individuals under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
10. Changes
We will post any changes on this page with a new “last updated” date. Last updated September 16, 2026.