What We Collect
We collect information you share with us directly — your name, email address, and shipping address when you place an order. We also collect payment information during checkout, which is processed securely by Stripe and never stored on MINK servers.
When you create an account or manage a Ritual Refill, we store your preferences and order history so we can fulfill your requests. We also collect basic browsing behavior through Google Analytics 4, including which pages you visit and how long you spend on them. This data is completely anonymous — no personal identifiers are attached.
How We Use Your Information
Your information helps us deliver the Ritual to you. We use your contact details and address to process and ship your orders. We use your Ritual Refill preferences to manage deliveries on your schedule.
We use your email to send transactional messages — order confirmations, shipping notifications, and delivery updates. These can't be opted out of because they're essential to your purchase experience. If you've opted in to marketing communications, we use your email to share new releases, rituals, and occasional stories about the house. Every marketing email includes a one-click unsubscribe link.
We use analytics data to understand how people move through our site, which helps us improve the experience and fix technical problems. We never use this data to identify you or track you across other websites.
What We Share
We share your information only with the service providers necessary to operate the house. These include:
- Stripe — processes all payment transactions securely
- Supabase — provides secure database, authentication, and file storage for our website and account systems
- Vercel — hosts and serves our website infrastructure
- SMTP2GO — delivers our transactional and marketing emails on our behalf
- Cloudflare — provides DNS and security for our domain
- Shipping carriers — receive your address to deliver your orders
- Google Analytics — aggregates anonymous browsing behavior
MINK does not sell, rent, trade, or share your personal information with third parties for their own marketing purposes. Ever. We have no incentive to because we're focused on the ritual, not exploitation.
Cookies & Analytics
We use Google Analytics 4 to understand how people interact with our site. This generates aggregate, anonymous data about traffic patterns, popular pages, and technical issues. We may track basic email engagement (opens and clicks) on our marketing emails through tracking pixels and link redirects to understand whether our emails are useful to you. This data stays inside our own systems and is not used for advertising or cross-site tracking.
No advertising cookies or retargeting pixels are present on our site. No social media tracking scripts follow you around. We keep analytics minimal and anonymous.
Email Communications
Transactional emails (order confirmations, shipping notifications, password resets) are part of your purchase and can't be opted out of.
Marketing emails require your explicit opt-in through our website or account preferences. You control this. We send updates on new releases, seasonal rituals, and stories about the house — no spam, no flooding your inbox. Every marketing email includes a one-click unsubscribe. We respect that boundary.
We never sell, rent, or trade your email address. It stays with us, and it's yours to manage.
Your Rights
You have the right to know what information we hold about you, to request corrections if something is inaccurate, and to request deletion of your data. To exercise any of these rights, reach out to us and we'll respond within 30 days.
If you want to delete your account entirely, we'll remove all personal information we store — though we'll keep transaction records as required by law. Account deletion is processed within 30 days.
Data Security
All communication between your browser and our site is encrypted with SSL. Payment data is handled exclusively by Stripe, which is PCI-DSS compliant — meaning it meets the highest standards for payment security. MINK never stores credit card numbers. Once your transaction is complete, Stripe returns only a secure token, and that's what we keep.
Children's Privacy
MINK does not knowingly collect personal information from anyone under 13 years old. If we learn that we have, we'll delete it immediately. If you believe a child's information has been collected, please contact us.
Data Retention
We retain your account and order information for as long as your account is active or as needed to fulfill your orders and provide ongoing service. If you request account deletion, we remove your personal information within 30 days. We retain transaction records and invoices as required by tax and accounting law — typically seven years. Anonymous analytics data is retained indefinitely because it contains no personal identifiers.
Do Not Track
Some browsers send a "Do Not Track" signal when you visit websites. Our site does not currently respond to DNT signals because there is no industry-standard way to interpret them. However, since we do not use advertising cookies, retargeting pixels, or cross-site tracking of any kind, your browsing on our site is already private by default.
California & State-Specific Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information. These include the right to know what personal information we collect and how it is used, the right to request deletion of your personal information, the right to correct inaccurate information, and the right to opt out of the sale or sharing of your personal information.
MINK does not sell or share your personal information as defined under the CCPA/CPRA. We have no financial incentive to do so, and it is contrary to how we operate.
Residents of Virginia, Colorado, Connecticut, and other states with consumer privacy legislation have similar rights under their respective laws. To exercise any of these rights, contact us and we will respond within the timeframe required by applicable law. We will not discriminate against you for exercising your privacy rights.
Changes to This Policy
We may update this policy as our business evolves or regulations change. We'll post any changes here with an updated effective date. If changes are material — meaning they significantly affect your privacy — we'll email existing customers to let them know.
Contact Us
Questions about your privacy or this policy? We're here to help.
Effective March 2026. Last updated April 3, 2026.