Privacy policy
Last updated: 30 September 2026 · GoFamely is operated by [GoFamely operator: set LEGAL_ENTITY_NAME].
1. Who we are
This policy explains how GoFamely (https://gofamely.com) handles personal data. The data controller is:
[GoFamely operator: set LEGAL_ENTITY_NAME], [business address], [country]. Email: [contact email].
For any privacy question or request, write to the email above. We answer within 30 days.
2. What we collect and why
| Data | Why we use it | Legal basis (GDPR) |
|---|---|---|
| Email address | Order confirmation and tracking, sign-in codes, account | Contract |
| Password (only as a salted scrypt hash, never readable) | Signing you in | Contract |
| Google account ID and name (if you sign in with Google) | Signing you in | Contract |
| Links you order for, quantities, notes and comment text | Delivering the order | Contract |
| Order history and amounts | Your account, customer support, bookkeeping | Contract; legal obligation (tax records) |
| Crypto payment details: sending wallet address, transaction hash | Matching payments to orders, refunds | Contract |
| Payout wallet address (affiliates) | Paying commissions | Contract |
| IP address, browser type | Security, fraud and abuse prevention, rate limiting, free-trial limits | Legitimate interest |
| Newsletter subscription and when/where you gave it | Sending deals and news you asked for | Consent (withdraw any time) |
| Partner (affiliate) code you arrived with | Crediting the partner who referred you | Consent (cookie banner) |
We never ask for your social media passwords, and we never see your card number: card, Apple Pay and Google Pay payments are entered on Stripe's page, PayPal payments on PayPal's.
3. Who receives data
- Fulfilment partner: the public link and quantity of each order (no name, no email) so it can be delivered.
- Payment providers: Stripe and PayPal process card and PayPal payments under their own privacy policies.
- Blockchain: crypto payments are recorded on a public blockchain by their nature; anyone can see the addresses and amounts, though not who owns them.
- Email provider: to deliver sign-in codes and order emails.
- Hosting and security providers: our server host and our network protection provider (e.g. Cloudflare), which process traffic and IP addresses to keep the site online and safe.
- Authorities: only where the law requires it.
We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.
4. International transfers
Some providers above may process data outside the EU/UK. Where they do, the transfer is covered by an adequacy decision or the European Commission's Standard Contractual Clauses.
5. How long we keep data
- Account data: until you delete your account.
- Order and payment records: as long as tax and accounting law requires (typically 6–10 years), with the email address removed if you delete your account.
- Sign-in codes: 15 minutes. Browser sign-in sessions: up to 30 days.
- Server logs: up to 30 days. Backups: 14 days.
- Newsletter: until you unsubscribe.
6. Your rights
You can access, correct, download (portability), restrict, object to or delete your data, and withdraw consent at any time. Signed-in customers can download their data and delete their account themselves on the account page; everything else by email. You may also complain to your data protection authority (in the UK, the ICO; in the EU, the authority of your country).
California residents: you have the right to know, delete and correct your personal information and to not be discriminated against for using these rights. We do not sell or share personal information as defined by the CCPA/CPRA.
7. Cookies and browser storage
We use only what the site needs to work, plus a partner code if you agree. See the cookie policy.
8. Children
The store is for people aged 18 or older. We don't knowingly collect data from children; if you believe a child has given us data, contact us and we will delete it.
9. Security
All traffic is encrypted (HTTPS). Passwords are hashed with scrypt, sessions are signed, the admin area is protected by a password and can require two-factor authentication, and access to data is limited to the people running the store. No system is perfectly secure; if a breach affects your data we will tell you and the authorities as the law requires.
10. Changes
We will post changes here and update the date at the top. Significant changes are announced by email to account holders.
This document is a template prepared for this store. Have it checked by a lawyer for the country you operate from before relying on it.