Who we are
Boots & Briskets Soap Co. is a handcrafted tallow soap and personal care products business located in Austin, Texas. Our website is located at https://bnbsoapco.com. We are committed to protecting your privacy and ensuring you have a positive experience on our website and when purchasing our products.
What Personal Data We Collect and Why
Information You Provide Directly
Contact and Account Information
- When you create an account, leave comments, or contact us, we collect your name, email address, phone number, and any other information you voluntarily provide.
- We use this information to respond to your inquiries, create and manage your account, and provide customer service.
Order and Payment Information
- When you purchase our soap products, we collect billing address, shipping address, phone number, and payment information (credit card details are processed securely through third-party payment processors and are not stored on our servers).
- We use this information to process orders, fulfill shipments, manage inventory, and maintain transaction records for accounting and legal purposes.
Communication Preferences
- If you opt in to receive emails, newsletters, or promotional materials, we collect and store your email address and communication preferences.
- We use this information only to send you requested updates about products, special offers, and business news. You can unsubscribe at any time.
Information Collected Automatically
Website Activity
- Our website collects data about your browsing behavior, including pages visited, time spent on the site, and referring websites.
- We use this information to improve our website functionality, understand user preferences, and enhance your shopping experience.
IP Address and Browser Information
- When you visit our website, we automatically collect your IP address, browser type, operating system, and device information.
- This information helps us with fraud detection, security, spam prevention, and understanding visitor traffic patterns.
Cookies and Tracking Technologies
- We use cookies for website functionality (remembering login information, shopping cart items, and display preferences).
- Cookies may persist for varying durations: session cookies expire when you close your browser; persistent cookies may last up to one year or longer, depending on the purpose.
- If you leave a comment, we may save your name, email address, and website in cookies for your convenience on future visits.
- If you log in, temporary cookies determine whether your browser accepts cookies; login cookies last for two days, and screen option cookies last for one year. Selecting “Remember Me” extends login persistence for two weeks.
- You can control cookie settings through your browser; disabling cookies may affect website functionality.
Email Communications
- If you request a password reset, your IP address and email will be included in the password reset email.
- This is a standard security measure to verify your identity and protect your account.
Gravatar and Third-Party Services
If your comment is approved, your profile picture will be visible publicly in the context of your comment.
An anonymized string created from your email address (a hash) may be provided to the Gravatar service to check if you use a profile picture there.
The Gravatar service privacy policy is available at https://automattic.com/privacy/.
Media and Images
Image Upload Guidelines
If you upload images to our website (such as product reviews or testimonials), please note:
For your privacy, we recommend removing EXIF data from images before uploading them.
Avoid uploading images that contain embedded location data (EXIF GPS coordinates).
Visitors and website administrators can download and extract any location data from images on our website.
Who We Share Your Data With
We do not sell, trade, or rent your personal information to third parties. However, we may share data in the following limited circumstances:
Payment Processors
- Payment information is shared with trusted third-party payment processors (such as Stripe, PayPal, or Square) solely for transaction processing. These processors have their own privacy policies and are bound by payment industry security standards (PCI DSS).
Shipping and Fulfillment Partners
- Shipping and billing address information is shared with our shipping carriers and fulfillment partners solely to deliver your orders.
Spam Detection Services
- Comments may be checked through automated spam detection services (such as Akismet) to protect against abuse.
Legal Requirements
- We may disclose your information if required by law, court order, government request, or to protect the rights, safety, and property of BNB Soap Co., our customers, or the public.
Service Providers
We may share necessary information with service providers who assist us in operating our website and conducting our business (such as website hosting, email services, analytics providers), provided they agree to maintain confidentiality.
Embedded content from other websites
Our website may include embedded content such as videos, images, or articles from external websites (YouTube, social media platforms, etc.). Embedded content behaves the same as if you visited the external website directly. Third-party websites may:
- Collect data about your behavior
- Use cookies and tracking technologies
- Embed additional third-party tracking and monitoring
- Track your interactions with embedded content, particularly if you have an account and are logged in
We are not responsible for the privacy practices of embedded content providers. Review their privacy policies directly.
How long we retain your data
Comments
- Comments and associated metadata are retained indefinitely to recognize and approve follow-up comments automatically, reducing moderation delays.
User Accounts
- If you register on our website, we retain your personal information in your user profile indefinitely until you request deletion.
- You can view, edit, or delete your personal information at any time (except your username, which cannot be changed).
- Website administrators can view and edit account information for account maintenance and customer service purposes.
Order Information
- We retain order records for a minimum of seven years for accounting, tax compliance, and legal purposes as required by law.
- You can request access to or deletion of your order data, subject to legal and business retention requirements.
Email Lists
- Email addresses for newsletters and marketing are retained until you unsubscribe.
- Unsubscribed email addresses are removed from our active mailing list but may be retained in archives for compliance records.
Log Files
Server logs containing IP addresses and access information are typically retained for 90 days for security and technical troubleshooting purposes.
Your rights over your data
Access
- You have the right to request an exported file containing all personal data we hold about you, including information you have provided to us.
Rectification
- You have the right to request correction of inaccurate or incomplete personal information.
Deletion
- You have the right to request deletion of your personal data, subject to exceptions for information we are legally or contractually obliged to retain (such as tax records, legal disputes, or security purposes).
Marketing Preferences
- You have the right to opt out of marketing communications and newsletters at any time by clicking the unsubscribe link in emails or contacting us directly.
Portability
- You have the right to request your data in a portable, machine-readable format.
To exercise any of these rights, please contact us using the information provided below.
Data Security
We implement reasonable administrative, technical, and physical security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. However, no data transmission over the internet or electronic storage method is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Children and Minors
Our website and products are not intentionally directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will promptly delete such information and notify parents or guardians. If you believe we have collected information from a child under 13, please contact us immediately.
International Data Transfers
If you are located outside the United States, your personal information may be transferred to, stored in, and processed in the United States. By using our website, you consent to such transfers and our use and disclosure of your personal information in accordance with this privacy policy.
Your California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know what personal information we collect
- Right to delete personal information we collect
- Right to opt out of the “sale” of personal information
- Right to non-discrimination for exercising your rights
To exercise these rights, please contact us using the information below. We will respond to verified requests within 45 days.
Your Nevada Privacy Rights
Nevada residents have the right to opt out of the sale of covered information. We do not sell personal information, but if you wish to make an opt-out request, please contact us using the information below.
Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the “Last Updated” date (November 20th, 2025) of this policy and, where appropriate, by sending you an email notification or displaying a notice on our website. Your continued use of our website following any changes constitutes your acceptance of the updated privacy policy.
Contact Us
If you have questions about this privacy policy, wish to exercise your rights, or need to report a privacy concern, please submit a request through our Contact Us page at https://bnbsoapco.com/contact. We use this form to securely route messages and reduce spam.
Boots & Briskets Soap Co.
Austin, TX
Website: https://bnbsoapco.com
We will respond to your inquiry within 10 business days.
Additional Information for EU Residents (GDPR)
If you are located in the European Union, your personal information is processed in accordance with the General Data Protection Regulation (GDPR). We rely on the following legal bases to process your data: consent, contractual necessity (to fulfill and manage your orders), legitimate interests (such as security, fraud prevention, and marketing), and compliance with legal obligations.
You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated. To contact us about GDPR or your data rights, please submit a request through our Contact Us page at https://bnbsoapco.com/contact.
