What we collect

Account data: name, email, business information (vendors and wholesale buyers only), shipping addresses for order fulfillment.

Transaction data: order history, payment method tokens (never raw card numbers - tokenization handled by Square, Stripe, or PayPal), tracking numbers.

Usage data: pages visited, search queries, click patterns. Used to improve the marketplace, never sold.

Photo evidence: photos uploaded to support DOA or non-delivery claims. Retained for the life of the claim plus 7 years for audit compliance.

Carrier and weather data: tracking events, delivery timestamps, destination weather forecasts at order time. Used to administer the climate hold and DOA systems.

What we share

With vendors: your name, shipping address, and order details so they can fulfill your order. Vendors may not use your data for marketing without separate opt-in.

With payment processors: the minimum required to process your transaction (Square, Stripe, or PayPal as applicable per the vendor's connected processor).

With carriers: shipping address and order summary required to print labels and provide tracking.

With service providers: Resend for email delivery, Supabase for database hosting, Netlify for site hosting. All bound by data processing agreements.

For legal compliance: when required by law, valid subpoena, court order, or to protect Fast Aquatics' rights.

Fast Aquatics does not sell your personal data to advertisers, brokers, or any third party.

How we use email

Transactional email (order confirmations, claim updates, shipping notifications) is sent automatically and cannot be opted out of for active orders.

Marketing email (newsletters, launch alerts, promotions) requires explicit opt-in. Unsubscribe is one click on every marketing email.

Cookies

Fast Aquatics uses essential cookies for cart state, login session, and CSRF protection. We do not use third-party advertising cookies. Analytics cookies (anonymous, aggregated) help us understand traffic patterns.

Your rights

  • Access: request a copy of your personal data
  • Correction: update inaccurate data through your account or by emailing us
  • Deletion: request deletion of your data, subject to legal retention requirements (claim records, tax records)
  • Portability: request your data in a machine-readable format
  • CCPA / GDPR: California and EU residents have additional rights under those laws; we honor them

Exercise any right by emailing privacy@wetyr.com.

Retention

Account data: retained while your account is active plus 1 year. Transaction records: 7 years (tax). Claim records: life of claim plus 7 years. Marketing email lists: until you unsubscribe.

Security

Data encrypted in transit (TLS 1.3) and at rest. OAuth tokens stored encrypted. Service-role database access restricted to backend functions. Regular security review.

Contact

WETYR Corporation. Privacy questions: privacy@wetyr.com. General contact: info@wetyr.com.