1. Overview
The Farm To You, Inc. ("The Farm To You," "we," "us," or "our") respects your privacy. This Privacy Policy explains what personal information we collect when you use our website, mobile experiences, and services (collectively, the "Service"), why we collect it, how we use and share it, and the choices you have. By using the Service, you agree to the practices described here.
2. Information We Collect
2.1 Information you provide to us
- Account information — name, email address, password (stored as a salted hash), and optional phone number.
- Order information — shipping address, recipient name, products purchased, and order history.
- Payment information — handled entirely by Stripe; we receive only a non-sensitive customer reference and the last four digits / expiration of a card for receipts.
- Communications — content of messages you send via our Contact page or in reply to our emails.
- Preferences — favorites, recipe saves, recently-viewed items, dietary tags, and notification settings.
2.2 Information we collect automatically
- Device & usage data — IP address, browser type and version, operating system, referring page, and pages viewed within the Service.
- Cookies and similar technologies — see the Cookies section below.
- Diagnostics — non-personal performance metrics and error reports collected to keep the Service reliable.
2.3 Information from third parties
- Sign-in providers — if you choose to sign in with Google, we receive your name, email address, and profile photo as authorized by you.
- Payment processor — Stripe shares minimal billing status updates with us (charge succeeded, refunded, etc.) so we can keep your account current.
3. How We Use Information
We use personal information to:
- Create and operate your account, authenticate sign-ins, and provide member benefits;
- Process orders, communicate shipping updates, and provide customer support;
- Send transactional notifications (order confirmations, shipping updates, password resets);
- Send membership-related communications such as drop announcements and the weekly digest — you can unsubscribe at any time from the link inside each email or text;
- Improve and personalize the Service (recipe recommendations, drop relevance, search results);
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Comply with legal obligations and enforce our Terms & Conditions.
6. Third-Party Services
7. Your Rights & Choices
- Access & correction — sign in to your account dashboard to view and edit your profile, addresses, and preferences. You may also request a copy of your data by contacting us.
- Deletion — you may request deletion of your account at any time. We will delete or anonymize personal information that is not required for tax, fraud, or legal-compliance recordkeeping.
- Marketing opt-outs — unsubscribe from any non-transactional email using the link inside the message, or reply STOP to opt out of SMS.
- Portability — request a machine-readable export of the information you have provided to us.
8. California Privacy Rights (CCPA / CPRA)
California residents have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act, including the right to know what categories and specific pieces of personal information we collect, the right to delete personal information we hold about you, the right to correct inaccurate information, and the right to opt out of "sales" or "sharing" of personal information for cross-context behavioral advertising. We do not "sell" personal information as that term is defined under California law. To exercise any of these rights, contact us via the Contact page.
9. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service. After account closure we may keep limited information for legitimate business reasons (such as fraud prevention, accounting, or legal compliance) for up to seven (7) years, after which it is deleted or anonymized.
10. Security
We use industry-standard safeguards to protect personal information, including TLS encryption in transit, salted bcrypt hashing for passwords, restricted-access database controls, rate-limiting on authentication endpoints, and continuous security monitoring. No system is perfectly secure, however, and we cannot guarantee absolute security. Please notify us immediately if you suspect unauthorized access to your account.
11. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. If we learn that a child has provided us with personal information, we will delete it as quickly as possible. Parents or guardians who believe a child has provided us with information may contact us via the Contact page.
12. International Users
The Service is operated from the United States. By using the Service from outside the U.S., you understand that your information will be transferred to, processed, and stored in the United States, where data-protection laws may differ from those of your country.
13. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be highlighted at the top of this page and, where appropriate, communicated by email. Continued use of the Service after a change takes effect constitutes your acceptance of the updated Policy.
14. Contact
For privacy-related questions, data-access requests, or to exercise any right described in this Policy, contact our privacy team via the Contact page.
© 2026 The Farm To You, Inc. All rights reserved.