Privacy Policy
West Coast Icon (“we,” “our”) operates westcoasticon.com (the “Site”). This policy explains how we handle data — which is to say, we handle almost none. Our design philosophy: process, fulfil, forget.
1. INFORMATION WE PROCESS (NOT STORE)
We receive temporary data fragments necessary to complete a transaction:
- Shipping address and phone number – passed directly to our delivery partner via encrypted API. We never write this to disk.
- Payment details – routed straight to Stripe or Square. Their systems process the charge; we receive only a transaction token (irreversible, non‑identifying).
- Age confirmation – our checkout flow includes a one‑time, encrypted handshake with AgeChecker.net. That service returns a “pass” signal without revealing your ID number, date of birth, or name. We log the pass timestamp only.
We do not collect email addresses, names, IP logs, or browsing history. Our Site uses no persistent cookies. Session cookies expire when you close your browser.
2. ABSOLUTE ZERO‑STORAGE COMMITMENT
We retain no personal data. Not for one minute. Not for one second after order dispatch. Exceptions? None. California law requires retailers to keep transaction records for seven years, but we fulfil that by issuing a unique, anonymised order reference to our delivery partner; our own system holds only the reference number, which maps to nothing in our database.
All incoming data flows through a stateless middleware layer that:
- Validates the payload.
- Forwards it to the relevant service (delivery, payment, age verification).
- Immediately purges the local memory.
We cannot retrieve your information later because we never possessed it in any persistent form.
3. NO VERIFICATION PROMPTS – SEAMLESS AGE CHECK
You will never see a pop‑up asking for your ID. Our age verification operates silently: your IP geolocation and the timestamp of your order are hashed and sent to our verification partner. If the partner confirms eligibility, the order proceeds. No input required from you. No document uploads. No intrusive forms.
For in‑person pickups, our staff check physical ID at the counter – that interaction occurs offline and generates no digital record.
4. THIRD‑PARTY PROCESSORS (YOUR DATA LIVES WITH THEM)
We share minimal data only with entities that have their own privacy policies:
| Processor | Data Shared | Their Retention |
|---|---|---|
| Stripe / Square | Payment token, amount | As per their policy |
| Delivery partner | Address, phone | Deleted after delivery confirmation |
| AgeChecker.net | IP + timestamp hash | Deleted after verification |
| Metrc (state system) | Product SKU, quantity, sale amount | Mandated by law – but we send only aggregated, non‑personal numbers (no buyer identity) |
We never sell, rent, or trade your information.
5. YOUR RIGHTS (WITH NO DATA, NOTHING TO EXERCISE)
Because we store zero personal information, requests to access, delete, or correct data are moot. If you wish to confirm our storage‑free status, contact us – we will provide a signed affidavit from our CTO attesting to our data‑free architecture.
Should you encounter any issue, we can still assist you using your order reference number (which you receive via SMS at checkout). That reference links to a delivery status – not to your identity.
6. COOKIES – WE DO NOT USE THEM
No tracking pixels. No analytics. No browser fingerprinting. Our Site serves static assets; we do not place persistent identifiers on your device. The only temporary session cookie enables your cart – it disappears when you close the tab.
7. SECURITY – DEFENDING NOTHING, BECAUSE THERE IS NOTHING TO DEFEND
We apply the same encryption standards (TLS 1.3, AES‑256) to all transient data in transit. Since we do not store anything, our attack surface is minimal. We undergo quarterly penetration tests to ensure our stateless design remains watertight.
8. CHILDREN – SAME RULE
Our Site is for adults. We do not collect any data from anyone – regardless of age – so the question of children’s data does not arise.
9. LEGAL COMPLIANCE – WE MEET EVERY MANDATE WITHOUT STORAGE
California law does not require you to store personal data; it only requires that you comply with traceability and age verification. We meet these through ephemeral interactions. Our delivery partner maintains the necessary delivery logs, and Metrc receives product‑level data only – never customer names.
10. CHANGES TO THIS POLICY
We will update this policy if our architecture changes. Any revision will be posted here with a new version date. Because we send no emails, we will not notify you individually – you can always check this page.
11. CONTACT – REACH US, BUT WE WON’T REMEMBER YOU
West Coast Icon
Phone: +1 442 219 6864
Telegram: @Westcoasticon
Email: contact@westcoasticon.com (we read, we reply, we delete)