Privacy

Privacy Policy.

GoldenLeaf uses customer information to process orders, provide support, and improve the shopping experience.

Information use

Order and contact details are used to process payments, send orders to our production partner, provide receipts and tracking, secure customer accounts, and respond to support requests.

Support sessions

Support requests store the contact details, messages, product or order reference, and delivery status needed to continue the conversation. Guest sessions are protected by a random browser token; signed-in customers may also reopen sessions linked to their verified account or email. Authorized staff can access these records through the protected GoldenLeaf Control workspace.

Accounts

Customer sign-in is provided by Supabase using email and, when enabled, Google, Apple, or phone authentication. We store the account identifier, email or phone number, profile details you choose to provide, and the purchase history linked to that account. GoldenLeaf staff access requires password authentication and a time-based one-time password.

Partner applications

If you apply as a creator affiliate or Shopify retailer, GoldenLeaf stores the name, business email, public store or channel URL, program selection, application message, consent record, and review status needed to evaluate and respond to the application. Do not submit passwords, payment-card details, bank information, or government identifiers. Applications do not create automatic program access or earning rights.

Service providers

Stripe and PayPal process checkout and payment information. Apliiq receives the order and shipping details required to manufacture and deliver products. Supabase stores account, order, support, and partner-application records. Resend may deliver transactional and support email. Shopify may coordinate approved affiliate or retailer program activity when the relevant integration is enabled. Advertising and marketplace providers receive data only when their integrations are enabled.

Payments and security

GoldenLeaf does not store full payment-card details or PayPal passwords. Payment and integration credentials remain with the payment provider or on protected server infrastructure, and privileged staff actions are logged.

Your choices

You may request access, correction, or deletion of your profile or partner application by contacting support. Financial and fulfillment records may be retained where required for fraud prevention, tax, legal, and contractual obligations.

Business and privacy contact

GoldenLeaf is based in Vancouver, British Columbia, Canada. Privacy questions and data requests can be sent to support@goldenleaf.design.

Last updated: August 24, 2026.

Optional analytics and advertising measurement

With your permission, GoldenLeaf records first-party session, page, product, search, checkout, and support-opening counts so we can monitor storefront reliability and improve the shopping experience. These records use a random session identifier and do not store raw IP addresses, payment-card details, support messages, passwords, names, email addresses, or private account fields.

When separately enabled by GoldenLeaf, the same permission may load Meta Pixel, TikTok Pixel, and Snap Pixel. These services may receive browser or device identifiers, page and referrer information, network metadata, onsite product-search terms, product identifiers, quantity, currency, order value, and pseudonymous event or transaction identifiers for campaign measurement. Vendor page-view events are suppressed on the private order-confirmation page.

After you grant optional analytics and a purchase is confirmed, GoldenLeaf may also send Meta through Conversions API normalized SHA-256 hashes of your email, phone, name, city, region, postal code, country, and GoldenLeaf account identifier, together with order, product, currency, and value data, for matching and browser/server event deduplication. Hashing is pseudonymization, not anonymity; Meta may be able to match these hashes to an account. GoldenLeaf does not send passwords, payment-card details, or support messages.

GoldenLeaf keeps a protected consent receipt containing the decision, policy version, source page, and decision timestamps. The browser stores only an opaque random receipt identifier; the server stores its SHA-256 hash. A confirmed-purchase measurement may wait in a protected delivery queue until it is sent or safely cancelled. Consent is checked again immediately before delivery, and withdrawing permission cancels pending measurement bound to that receipt.

You can choose Only essential or withdraw permission at any time using the Privacy choices control in the footer. Declining optional analytics does not affect account access, checkout, fulfillment, or customer support.