01 What we collect
Here's the complete list:
| What | When we collect it | Why |
| Email address |
When you sign up for the newsletter, purchase the Playbook, or subscribe to monthly updates |
To send receipts, updates, and the content you bought |
| Name (optional) |
At checkout or account creation |
To address you properly in emails |
| Payment information |
At checkout |
To process payment. Handled entirely by Stripe — we never see or store your card number. |
| IP address and device info |
Automatically on any page visit |
For security, fraud prevention, and understanding which pages work. We don't tie this to your identity unless you sign up. |
| Page and event analytics |
Automatically on any page visit |
To know which modules are being read, which emails get opened, which pages convert. Aggregated and anonymous by default. |
| Communication you send us |
When you email or use a contact form |
To respond to you. Stored for reasonable support history. |
What we don't collect: your phone number (we don't ask), your location beyond country-level (from IP), your social media profiles, or information about your dog beyond what you voluntarily tell us in a support email.
02 Who we share data with
A short list of service providers we use to run the business. Each is contractually required to use your data only to provide their service to us — not for their own marketing.
- Stripe — payment processing. Your card data lives with them, not us.
- Loops (or an equivalent email platform) — to send transactional emails (receipts, access links) and optional newsletter content.
- PostHog (or an equivalent) — to understand site usage in aggregate. Configured with privacy-first defaults: no cross-site tracking, no data sold.
- Vercel — our website hosting. They see server logs, which include IP and request paths.
- Google Workspace / an email inbox provider — if you email us, that email lives in our inbox.
- QuickRefund (in Phase 2, when NMI integration goes live) — for pre-dispute automation. Transaction metadata is shared to enable dispute interception and refund automation.
What we never do: we never sell your data, rent it, or share it with advertisers or data brokers. We don't have affiliate-network pixels or Facebook Custom Audiences uploaded with your information.
03 How long we keep it
- Account and purchase data: for as long as you have an active account, plus 7 years after account closure (for tax and accounting reasons).
- Email list data: until you unsubscribe, at which point we delete your email from active marketing lists within 24 hours.
- Analytics data: anonymized after 90 days; aggregated and retained for internal reporting.
- Support correspondence: retained for 2 years to help us help repeat customers.
04 Your rights
Wherever you are in the world, you can do any of the following by emailing privacy@bigdoglongevity.com:
- See a copy of everything we have about you. We'll send it within 30 days — usually within a few days.
- Correct anything that's wrong. We fix it immediately.
- Delete everything. We delete within 7 days of your request (except the minimum we must retain for legal/tax purposes — e.g., purchase records).
- Export your data in a portable format. We send a JSON or CSV file, your choice.
- Opt out of marketing emails at any time by clicking "unsubscribe" in any email — or emailing us.
- Revoke consent to our processing of your data. We'll confirm the implications and proceed.
If you're in the EU/UK (GDPR), California (CCPA), or any other jurisdiction with specific privacy rights — all the above applies, and we'll work with you on any jurisdiction-specific requests we're missing.
05 Cookies and tracking
We use two kinds of cookies:
- Essential cookies — for login sessions, checkout, and basic functionality. Without these, the site doesn't work.
- Analytics cookies — to understand aggregate site usage. Configured in privacy-first mode: no cross-site tracking, no fingerprinting, anonymized after 90 days.
We do not use advertising cookies. We do not integrate Facebook Pixel, Google Ads Pixel, or similar remarketing trackers on our site pages with customer data. We may run paid advertising on platforms like Meta, but attribution happens on the platform side, not via pixels embedded on our content pages.
06 Security
We take security seriously. Specifics:
- All data is transmitted over HTTPS/TLS.
- Payment card data is handled exclusively by Stripe (PCI DSS Level 1 certified). We never see or store card numbers.
- Our service providers are all SOC 2 Type II certified or equivalent.
- Access to customer data is limited to team members who need it and is logged.
- In the event of a data breach affecting your personal information, we will notify affected users within 72 hours of confirming the breach.
07 Children's privacy
Big Dog Longevity is a service for adults. We don't knowingly collect data from anyone under 13, and we expect our customer base to be 18 or older. If you believe we've inadvertently collected data from a child, email us at privacy@bigdoglongevity.com and we'll delete it immediately.
08 Changes to this policy
When we make material changes, we publish the change date at the top and email active customers a summary of what changed. If you don't like the changes, you can request deletion of your data at any time.