Privacy Policy
Last updated: August 26, 2025
Our Privacy Commitment
At Cottage CMS, we understand that your privacy is essential to building trust. As a platform designed specifically for cottage food entrepreneurs, we're committed to protecting your personal information and being transparent about how we collect and use your data.
1. Information We Collect
Personal Information You Provide
- Account Information: Name, email address, business name, and contact details when you create an account
- Payment Information: Billing address and payment details (processed securely through Stripe - we do not store credit card numbers)
- Subscription Details: Plan type (Free, Pro, Lifetime), trial status, and billing history
- Website Content: Text, images, product information, and other content you upload to your cottage food website
- Communications: Messages you send us through support channels, feedback forms, or email
- Business Information: Details about your cottage food business, state location, and compliance requirements
- Verification Data: Security verification responses through Cloudflare Turnstile
Information We Collect Automatically
- Usage Data: How you interact with our platform, features used, and time spent
- Device Information: Browser type, operating system, IP address, and device identifiers
- Analytics Data: Website performance metrics, error logs, and usage patterns via Google Analytics and Cloudflare Analytics
- Conversion Tracking: Marketing conversion data through Meta Pixel for registration and purchase events
- Cookies and Tracking: Session cookies for functionality, analytics cookies for service improvement, and marketing cookies for conversion tracking
2. Free Plan Advertising
Important Notice for Free Plan Users
If you use our Free Plan, we reserve the right to display relevant industry advertisements on your website in the future. This helps us provide free services while supporting the cottage food community.
- • Ads will be clearly marked and relevant to cottage food businesses
- • Your personal data will not be shared with advertisers
- • Pro and Lifetime plans are completely ad-free
- • We will notify Free Plan users before implementing advertising
3. How We Use Your Information
Service Delivery
- • Create and maintain your website
- • Process payments and billing
- • Provide customer support
- • Send service-related notifications
- • Backup and secure your data
Platform Improvement
- • Analyze usage patterns
- • Develop new features
- • Fix bugs and improve performance
- • Personalize your experience
- • Ensure platform security
Communication
- • Send important account updates
- • Share cottage food industry insights
- • Provide educational content
- • Announce new features
- • Respond to your inquiries
Legal Compliance
- • Meet regulatory requirements
- • Prevent fraud and abuse
- • Enforce our terms of service
- • Protect user safety
- • Respond to legal requests
4. Information Sharing and Disclosure
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
We may share your information only in these situations:
- Service Providers: Trusted third parties who help us operate our platform:
- Stripe for payment processing and subscription management
- Cloudflare for security, performance, and content delivery
- Resend for transactional email delivery
- Google Analytics for usage analytics
- Meta for conversion tracking (anonymized)
- Legal Requirements: When required by law, court order, or government regulation
- Business Protection: To protect our rights, prevent fraud, or ensure platform security
- Business Transfers: In the event of a merger, acquisition, or sale of assets (with advance notice)
- Your Consent: When you explicitly agree to share information for specific purposes
Public Information
Content you publish on your cottage food website (product descriptions, business information, photos) will be publicly visible to your customers. You control what information is made public through your website settings.
5. Data Security
We implement industry-standard security measures to protect your information:
Technical Safeguards
- • SSL/TLS encryption for data transmission
- • Encrypted data storage
- • Regular security updates and patches
- • Secure authentication systems
- • Automated backup systems
Operational Safeguards
- • Limited access to personal data
- • Employee privacy training
- • Regular security assessments
- • Incident response procedures
- • Data retention policies
While we implement strong security measures, no method of transmission over the internet is 100% secure. We continuously work to improve our security practices and will notify you of any significant data breaches as required by law.
6. Your Privacy Rights
You have the following rights regarding your personal information:
🔍 Access and Portability
Request a copy of your personal information and download your website data at any time through your account settings.
✏️ Correction and Updates
Update your personal information directly in your account or contact us to correct any inaccuracies.
🗑️ Deletion
Request deletion of your account and personal information (subject to legal retention requirements for business records).
📧 Communication Preferences
Opt out of marketing emails while continuing to receive essential service communications.
To exercise these rights, contact us at privacy@cottagecms.comor use the privacy controls in your account settings.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to improve your experience:
Essential Cookies
Required for basic functionality:
- • Authentication and login sessions
- • Security features and fraud prevention
- • Shopping cart for subscription purchases
Analytics & Marketing Cookies
Help us improve our service:
- • Google Analytics (_ga, _gid) for usage statistics
- • Meta Pixel (fbp, fbc) for conversion tracking
- • Cloudflare Analytics for performance monitoring
Third-Party Services
These services may set their own cookies:
- • Stripe: Payment processing and fraud prevention
- • Cloudflare: Security and performance optimization
- • Google Analytics: Anonymous usage analytics
- • Meta Pixel: Marketing attribution (can be opted out)
You can control cookie settings through your browser preferences. Disabling essential cookies may affect platform functionality. To opt out of marketing cookies, visit aboutads.info.
8. Data Retention
We retain your information for different periods based on its purpose:
- Account Data: Retained while your account is active and for 90 days after deletion for recovery purposes
- Free Plan Content: May be deleted after 6 months of inactivity with 30 days notice
- Pro/Lifetime Content: Retained indefinitely while account is active
- Payment Records: Kept for 7 years for tax and legal compliance purposes
- Subscription History: Retained indefinitely for trial eligibility tracking
- Analytics Data: Aggregated data retained indefinitely; personal identifiers removed after 2 years
- Support Communications: Retained for 3 years to improve customer service
- Security Logs: Retained for 1 year for security and fraud prevention
9. Children's Privacy
Cottage CMS is designed for cottage food entrepreneurs. While some states allow minors to operate cottage food businesses, our platform requires special handling for users under 18:
For Minor Operators (Under 18)
- • Parent or guardian must create and manage the account
- • We collect information from the parent/guardian, not directly from minors
- • Parent/guardian consent is required for all account activities
- • Parents may request deletion of their child's information at any time
COPPA Compliance: For operators under 13, we comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information directly from children under 13. All account management must be done by a parent or legal guardian.
10. International Users
Cottage CMS is based in the United States and our servers are located in the US. If you access our service from outside the US, your information will be transferred to, stored, and processed in the United States.
We comply with applicable international privacy laws and provide appropriate protections for cross-border data transfers.
11. California Privacy Rights (CCPA)
For California Residents
Under the California Consumer Privacy Act (CCPA), you have additional rights:
Right to Know
Request information about the personal data we collect, use, and share
Right to Delete
Request deletion of your personal information (subject to legal exceptions)
Right to Opt-Out
We do not sell personal information, but you can opt-out of marketing cookies
Right to Non-Discrimination
We will not discriminate against you for exercising your privacy rights
To exercise these rights, email us at admin@cottagecms.com. We will respond within 45 days.
Categories of Information We Collect
- Identifiers (name, email, IP address)
- Commercial information (purchase history, subscription details)
- Internet activity (usage data, cookies)
- Geolocation data (state location for compliance)
- Professional information (business details)
12. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Legal Basis: We process your data based on consent, contract performance, or legitimate interests
- Data Portability: Receive your data in a structured, machine-readable format
- Rectification: Request correction of inaccurate personal data
- Restriction: Request restriction of processing in certain circumstances
- Object: Object to processing based on legitimate interests
- Automated Decision Making: Right not to be subject to solely automated decisions
For GDPR requests, contact our Data Protection Officer at dpo@cottagecms.com.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will:
- Notify you by email of significant changes
- Post the updated policy on our website with the effective date
- Continue to honor the policy that was in place when you provided your information
- Provide at least 30 days notice for material changes
14. Contact Us
If you have questions about this Privacy Policy or how we handle your information, please contact us:
General Privacy Questions
Email: admin@cottagecms.com
Response time: Within 48 hours
Data Rights Requests
Email: admin@cottagecms.com
Response time: Within 30 days
Last Updated: August 26, 2025
Effective Date: August 26, 2025
This policy applies to all current and future users of Cottage CMS.