Privacy Policy
Last updated: October 9, 2026
This Privacy Policy explains what personal information Heirloom Hook (the "Store") collects, how we use and share it, and the choices you have. The Store is a Digital Shelf Lab store operated by Codigo Bro LLC, 1057 NW 136th Ave, Miami, FL 33182, United States ("we," "us"). Codigo Bro LLC is responsible for your information.
1. Information we collect
- Contact details you give us at checkout: your name and email address (and your phone number, only if the checkout asks for it).
- Order information: the products you bought, prices, currency, any gift or discount applied, the time of purchase, and the history of access to and downloads of your files.
- Payment information: your card is processed and stored by Stripe. We receive only the card brand, the last four digits, the billing country and postal code, and the result of Stripe's fraud checks — never your full card number.
- Security checks: Cloudflare Turnstile, an anti-bot and anti-fraud check, runs on the checkout page and on the purchase buttons of the offers that follow it.
- Device and visit information: your IP address, your browser's user agent (a technical description of your browser and device), the type of device, your approximate location (country, region and city) derived from your IP address or your billing details, the pages of the Store you view, and the ad or campaign that brought you (campaign parameters such as UTM tags, and click identifiers such as fbclid, a code Facebook adds to ad links).
- Cookie identifiers: see section 4.
- Your acceptance of our terms: the version of the terms and policies you accepted at checkout, with the time, IP address and device.
- Messages you send us for support.
2. How we use your information
- To process your order, deliver your products and send your order and access emails.
- To process payments, including the optional offers you choose to add to your order with one tap after checkout. Stripe keeps the card you paid with. We use it only for purchases you make with one tap, within 24 hours of your order and in the same browser. Stripe keeps it until you ask us to remove it.
- To provide customer support and handle refunds.
- To prevent fraud and to respond to payment disputes.
- To measure and improve our advertising, including by sharing information with Meta as described below.
- To comply with legal, tax and accounting obligations.
We only send emails about your order (access to your files and receipts); we do not send newsletters or marketing emails, and we do not track whether you open our emails or click their links.
3. Who we share it with
We do not sell your personal information for money. We share it only with:
- Stripe — payments, saved payment methods and fraud prevention.
- Meta Platforms (Facebook and Instagram) — to measure our ads, attribute orders to them and improve their delivery, through the Meta Pixel and the Meta Conversions API (see section 4). Meta uses this information under its own privacy policy.
- Service providers that process data on our behalf: Cloudflare (hosting, security, anti-bot checks, delivery of your files and visit statistics), Supabase (database hosting, in the United States), and Resend and Brevo (sending our emails).
- Professional advisors; authorities, when required by law; and a buyer of our business, if it is ever sold.
Under some U.S. state laws, sharing information with Meta for advertising may be considered a "sale" or "sharing" of personal information for targeted advertising. See section 6 for how to opt out.
4. Cookies, the Meta Pixel and the Conversions API
Meta Pixel (in your browser). When you view our pages or the checkout, the Meta Pixel reports events to Meta, such as a page view, a product view, the start of checkout, adding an offer to your order, submitting payment information, and a purchase.
Meta Conversions API (from our servers). We also send these events, including your purchases, from our servers. These can include your email address, name, phone number (only if the checkout asks for it), city, state, postal code and country. We scramble (hash, using SHA-256) these details before sending them. We also send, unhashed, your IP address, your browser's user agent, and the Meta cookie values _fbp and _fbc. The Pixel and the Conversions API share an event identifier so that Meta does not count the same event twice.
Cookies we use:
- Needed to run the checkout and your order (strictly necessary): cookies that keep your checkout session and the steps after payment working, including the one-tap offers. They last up to 24 hours.
visitor_id— our own cookie that identifies your browser, so we can count visitors and recognize the device used to place an order (fraud prevention). It lasts 1 year.dsl_attr— our own cookie that stores the campaign parameters (UTM tags) and click identifier you arrived with, for your first and your latest visit, so we can tell which ad brought you. It lasts 30 days._fbpand_fbc— Meta's cookies. If you arrive from a Meta ad with a click identifier (fbclid) and there is no_fbccookie yet, our server creates it so the ad can be matched to your order.
When you open the Store inside the Instagram or Facebook in-app browser, we may recover the campaign parameters (never click identifiers) from the page that referred you and keep them for 7 days.
Visit statistics. For each page load we record the store, the offer, the market, your country, the type of device, the ad and campaign that brought you (ad identifier, utm_content, and whether a click identifier was present) and your visitor_id. These records do not include your IP address, your email or your browser's user agent.
5. How long we keep it
- Orders, payments, consents and download records (including IP address and device information): at least 24 months after your purchase, to deliver your products, provide support, prevent fraud and respond to payment disputes, and longer when tax or accounting law requires it.
- Records of the events we sent to Meta (without IP address, email or user agent): up to 24 months.
- Visit records (without IP address, email or user agent): 3 months; daily visit totals: 24 months.
- Saved payment method: kept by Stripe until you ask us to remove it; we only use it for one-tap purchases within 24 hours of your order.
- Campaign parameters recovered in the in-app browser: 7 days.
- Cookies:
visitor_id1 year;dsl_attr30 days; checkout cookies up to 24 hours; Meta's cookies, as set by Meta. - Backups: daily backups are kept for 35 days.
- Support messages: as long as needed to resolve your request and keep a record of it.
6. Your choices and rights
- Opting out of advertising. To opt out of the sharing of your information with Meta for advertising, email support@digitalshelflab.com. You can also block or delete cookies in your browser settings, and manage how Meta uses your information in your Facebook or Instagram ad preferences. We do not currently respond to Global Privacy Control or "Do Not Track" browser signals, and we do not show a cookie banner.
- Your rights. Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy of it, to correct it, to have it deleted, and to appeal our decision on your request. You can use an authorized agent. To make a request, email support@digitalshelflab.com from the address you used at checkout. We will respond within 45 days, or sooner if your law requires it. We will not treat you differently for exercising your rights. When you ask us to delete your information, we delete or unlink what the law does not require us to keep; records of your purchases and of their delivery are kept as proof of the transaction (for payment disputes and taxes).
- EU and UK. If you are in the EU or the UK, you also have the rights to restrict or object to our processing and to data portability, and you may complain to your data protection authority. We rely on our contract with you (orders and delivery), legal obligations (tax and accounting), and our legitimate interests (fraud prevention, payment disputes, security and measuring our advertising).
7. International transfers
We and our service providers store and process information in the United States and other countries. Where required, these transfers rely on the safeguards our providers offer, such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses.
8. Security
We use reasonable technical and organizational measures to protect your information, such as encrypted connections, access controls and private storage for your files. No method of transmission or storage is completely secure.
9. Children
The Store is for adults. You must be at least 18 years old, or the age of majority where you live, whichever is higher, to buy from us. We do not knowingly collect information from children under 13, and we do not send information about them to advertising partners.
10. Changes to this policy
We may update this policy. We will publish the new version on this page with its date.
11. Contact
For privacy questions or requests:
- Email: support@digitalshelflab.com
- Phone: +1 (786) 403-0332
- Address: 1057 NW 136th Ave, Miami, FL 33182, United States
© 2026 Heirloom Hook. All rights reserved. Heirloom Hook is operated by Codigo Bro LLC (EIN: 42-3185729), registered in Wyoming, USA.