06 · THE DATA
IN PLAIN LANGUAGEHow we keep your data
EFFECTIVE AUGUST 17, 2026 · WYOMING LLC · WORKSHOP 202 CENTRAL AVE, BRADFORDSVILLE, KY 40009
1 · Our principle. Collect little, keep it briefly, and tell the truth about it. We’re a workshop that sews robes, not a company that harvests data — and the safest data is data we never took. The full accounting lives in the Privacy Policy; this page is the plain summary, plus the promises behind the robes themselves.
2 · What we hold. Four things: quote requests from the quote form, whatever you write us or say on a call, order and invoice records, and routine server logs. That’s the whole list — no accounts, no stored cards, no tracking profiles. Quotes and correspondence are kept 24 months, order records 7 years for tax and warranty reasons, and server logs about 30 days.
3 · Where it lives. On Cloudflare servers in the United States, in Migadu mailboxes, and in Resend’s United States region for quote mail. Termly holds consent records; tawk.to holds chat only after you allow that category. Everything between your browser and this site travels encrypted over HTTPS/TLS, with HSTS so the browser prefers HTTPS on later visits. The padlock in your browser is doing its job. This is not a PCI DSS certification.
4 · Who can see it. The small team at the workshop, on a need-to-know basis. The person cutting your robe doesn’t need your email, and the person answering your email doesn’t need your invoice. Outside the workshop, only the providers above hold it — and only to do their jobs for us.
5 · How payments work. Never through the website today. Orders and invoices are arranged by email or phone. When card payments open, they will run on full-page Stripe-hosted Checkout, not as a card form on bathgowns.com. Full card numbers never touch our systems. This page is not a PCI DSS certification, SAQ, AOC, or QSA assessment — those remain with Stripe and the eventual acquiring path after real Checkout is live.
6 · What we never do. Sell, rent, or share your personal information for advertising. We do not run ad pixels or analytics suites. We do use Termly consent cookies and, if you allow it, optional tawk.to chat. Details: Cookie Policy. No newsletters — we only write back.
7 · If something goes wrong. We investigate, we contain it, and we tell you. Anyone affected hears from us without undue delay and within 72 hours of confirming a breach — in plain words: what happened, what it touched, and what we’re doing about it. Where GDPR applies, the supervisory authority is notified within 72 hours too, as the law requires.
8 · Found a hole. If you spot a security hole in bathgowns.com, write privacy@bathgowns.com. We answer within one business day, we won’t take it personally, and we’ll thank you.