We’re a small studio in Meridian, Idaho, and we keep our shopper data the same way we keep our formulas — minimal, considered, and never sold. This page spells out exactly what we hold, what we do with it, and what we won’t do with it.
What we collect
We collect only what we need to ship your order, answer your messages, and run the parts of the storefront you choose to use:
- Order details — name, email, shipping address, phone number, the items in your basket, and the total. Used to fulfill the order and email confirmation.
- Abandoned basket — if you leave the site with items still in your basket, a copy of it — the products, quantities, prices, and total, with the random identifier described under Cookies and storage — is sent to the ecommerce platform that runs our store. It carries no name, email, or address. This happens automatically rather than at your request, and we do not currently use it to send you email. The platform normally keeps one current record per browser, updated on later captures; an older record can also be replaced or deleted. A 90-day cleanup process has been delivered, but automatic daily deletion has not been verified as active for this storefront, and 90 days is not a guaranteed maximum. Unless another deletion or replacement happens, a record may remain until our account with the platform is closed. We will update this page when active cleanup is verified.
- Contact form / email — the message you send us and your email address, kept so we can reply and look up the conversation later if you write back. Support conversations are handled in a third-party support platform, where an AI assistant may draft or send replies.
- Mailing-list signup — if you sign up in the footer or opt in at checkout, your email address, confirmed by a follow-up email before we send anything else. Used only for occasional studio email. Every one of them can be unsubscribed from, and we drop the address when you do.
- Back-in-stock requests — if a product or variant is sold out and you ask to be notified, your email address and which product or variant you asked about. Used for that restock email and nothing else.
- Product reviews — your rating, an optional headline and review text, the name you enter, and your email address. Reviews are moderated before they appear. Your name and review are published; your email address is never published — we keep it only so we can contact you about your review.
- Account sign-in — if you use My Account, your email address and the single-use sign-in code we email you. Used to sign you in and show you your own orders, addresses, and returns.
- Guest order lookup — the order number and email address you enter to find an order without signing in. Used to confirm the order is yours before showing it to you.
- Return requests — the items you select and whatever you write in the reason box. Used to process the return, and read so the next batch is better.
- Basket and checkout progress stored in your browser — see Cookies and storage below for what is kept, why, and when the storefront stops using it or clears it. Some coordination values have no timed expiry.
- Server logs — request timestamps, IPs, and user-agents from our hosting platform, kept only as long as needed to detect and investigate abuse, then rotated out. Your IP address is also passed to the ecommerce platform that runs our store on mailing-list, back-in-stock, and review submissions, which are rate-limited per IP so they can’t be abused. The platform retains its own request logs for 30 days, after which they age out automatically; they are not forwarded to any third party, and where an email address is involved only its domain is logged, never the full address.
What we use it for
- Fulfilling and shipping orders.
- Answering questions and resolving order issues.
- Sending order-related email (confirmation, tracking, occasional follow-up about your purchase). We don’t send marketing email unless you ask us to.
- Improving the storefront — anonymous server-side metrics on which pages load slow or error out.
What we don’t do
- We don’t sell your personal information for money, and we don’t rent or trade it. Some privacy laws use “sell” or “share” more broadly than that — broadly enough to cover advertising activity — so we describe what we actually do under Advertising and remarketing below rather than relying on that word.
- We don’t store payment card numbers on our servers — checkout is handled by a PCI-compliant payment processor that returns only a confirmation token to us.
- We don’t give anyone your shipping address for advertising.
Who we share data with
A short list, and what each one receives:
- Payment processor — receives the card details directly from your browser at checkout; we receive only a confirmation.
- Shipping carrier — receives your name, shipping address, and parcel weight to deliver the package.
- Hosting + email providers — store our order data and outbound emails to you on our behalf, under contractual data-processing terms.
- Ecommerce platform — runs this storefront, our checkout, and our order records on our behalf, as our data processor; we remain responsible as the controller of that information. Checkout itself is completed on a page hosted by that platform, which sets its own cookies and browser storage. See the platform’s Cookies and browser storage notice for the current inventory and lifetimes.
- Advertising and analytics partners — receive the identifiers and activity described under Advertising and remarketing below.
- Customer-support platform — Intercom provides our support inbox and Fin, an AI assistant that may answer first. Intercom processes the messages and any contact or order details you choose to include in an email or chat so EKGIS can respond. When you choose to start public website chat, EKGIS does not attach your customer account or automatically send your email, order, cart, payment, or storefront-session data to Messenger. Intercom nevertheless processes technical information used to operate Messenger, including first-party browser, device, and session identifiers; browser and operating-system information; IP-derived location; and recent EKGIS page URLs. Fin cannot retrieve your individual account or order through this public chat. You can ask to speak with an EKGIS teammate. When Fin answers a catalog question, it may send a short product-search term to litecommerce and receive public product information such as names, prices, availability, and product links. This public connector does not retrieve customer or order records. See Intercom’s Product Privacy Notice and subprocessor list.
Cookies and storage
Here is what this storefront itself keeps in your own browser. These run the shop — they are not used to advertise to you. Advertising cookies and identifiers are described separately under Advertising and remarketing below.
- Your basket — the in-progress cart, in localStorage, so it survives a reload. Clearing browser data clears it. If you leave the site with items still in it, a copy is sent to the ecommerce platform that runs our store — see Abandoned basket under What we collect.
- Your last receipt — after an order is confirmed, a summary including its items, amounts, shipping method, and order reference or number is saved in localStorage so the confirmation page survives a reload. The storefront uses it for up to 24 hours, then refuses it and removes it when it is next read. It does not include your name, email, or address.
- A checkout marker — while a checkout is in progress, the current tab holds a checkout session token in sessionStorage together with the minimum basket identity needed to reconcile a confirmed purchase: a whole-basket write token and, for each line, the item and variant identifiers, quantity, and a line-generation token. It holds no product names, prices, or customer details. Closing the tab clears it. If the tab stays open, the storefront stops honoring it after one hour and removes it when it is next read.
- Checkout return record — localStorage keeps a random checkout attempt identifier, its start time, checkout-time basket identifiers and quantities (including the requested coupon and change tokens), and coordination/outcome values. It helps reconcile a confirmed purchase without removing items you added to your basket later, including after a return in another tab. It contains no checkout-session credential, product names, prices, or customer details. The storefront stops accepting an attempt after four hours and cleans expired records on later writes; this is not automatic removal at the four-hour mark. Clearing browser data clears it.
- Checkout return cookie — each hosted-checkout attempt has a separate Secure, httpOnly first-party cookie holding its checkout-session credential and start time so our server can check its outcome when you return in another tab. Page scripts cannot read its value. Its lifetime is bounded to the remaining part of the four-hour attempt window, and it may be cleared sooner when an attempt is retired or evicted. It holds no basket or customer details.
- Order confirmation proof — the current tab’s sessionStorage can hold a public order reference, checkout-session credential, and save time to verify the exact final order without putting that credential in a URL. Closing the tab clears it. It is accepted for less than one hour; an invalid or expired proof is removed when it is next read.
- Checkout-update coordination — localStorage holds random coordination and claim values to keep overlapping tabs from making conflicting updates to the same hosted checkout. It holds no checkout credential, basket contents, or customer details. It has no timed expiry: a matching claim is cleared only when the storefront can validate that the update is finished or has not yet been sent. An unresolved claim can remain until browser data is cleared.
- Abandoned-basket identifier — a random identifier in localStorage, created the first time a basket copy is sent and reused on later visits, so a repeat basket from this browser is recognised as the same one rather than as a new shopper. It holds no name, email, or address. It has no expiry and is not cleared automatically; clearing browser data clears it.
- Abandoned-basket token — a random value in localStorage, generated by your browser, sent alongside that identifier so only your browser can update its own basket copy. Same durability as above.
- Older order-lookup proof — an already-issued older guest-order link can leave the email address you supplied, the order identifier, and a random account-state generation in this tab’s sessionStorage so its return pages can recognise your proof. Current public-reference flows do not create new entries of this kind. Closing the tab clears it; sign-out clears entries in that tab where browser storage permits, and an account-state change makes an older entry unusable.
- Support chat — Support chat is optional. On eligible EKGIS storefront pages, Intercom Messenger does not load merely because you open a page; it loads only if you select Start support chat. Selecting Not now leaves it off. Once started, Intercom sets first-party cookies and browser storage to identify the browser or device, maintain the chat session, protect the service, and cache Messenger. Intercom’s Product Privacy Notice describes the current identifiers and their lifetimes. You can select Stop and clear support chat in Chat privacy choices. That action ends further chat activity in this browser and removes the Intercom cookies and browser storage created for Messenger on this site. It does not delete messages or other records already delivered to EKGIS or Intercom. Contact support@ekgisnaturals.com to ask about those records or exercise privacy rights.
- Account-tab coordination — localStorage holds a random generation value to keep My Account, order, and returns views in different tabs on the same account state, so an older response cannot put customer information back after sign-out or another identity change. It holds no name, email, customer ID, order details, or session token. It has no timed expiry; the storefront replaces or clears it as account state changes, and clearing browser data clears it.
- Authenticated-account marker — after an account response proves the httpOnly sign-in cookie is valid, localStorage holds a marker scoped to the current random account generation. It helps reject account responses begun under older state. The value is that opaque generation, not a customer identifier or bearer credential. It has no timed expiry; only a marker matching the current generation is accepted. The storefront attempts to clear older markers as identity changes, and clearing browser data clears them.
- Sign-in cookie — signing in to My Account sets one first-party cookie holding your session token. It is flagged httpOnly, so page scripts cannot read it; it is sent only to authenticate your own account requests; and signing out clears it.
None of the items in this list follow you to other websites. If we change what we keep in your browser, we’ll update this page.
Advertising and remarketing
We work with third-party advertising and analytics services — among them Google, Meta (Facebook and Instagram), and OpenAI — to measure how our advertising performs and to show our ads to you on other websites, apps, and services after you’ve visited this storefront. Those services set or read cookies and similar identifiers in your browser, and we may give them:
- identifiers such as cookie and device IDs, and your IP address;
- what you did here — pages and products viewed, items added to the basket, and whether an order was completed, including its value;
- contact details such as an email address, which we may provide in hashed form so an audience can be matched without handing over the address in the clear.
This is what lets us build audiences of people who have visited the storefront and reach them with our ads elsewhere, and what lets us see which ads led to an order. For some of this these partners act as businesses in their own right rather than purely on our behalf, and they may combine what they receive with information they already hold about you.
If you’d rather we didn’t use your information this way, write to us at support@ekgisnaturals.com and we’ll take you out of it. You can also limit it at the source: browsers let you block or delete cookies, and Google, Meta, and OpenAI each provide their own advertising and data controls in your account settings with them.
Your rights
You can ask us at any time to:
- Tell you what we have on file about you.
- Update or correct any of it.
- Delete it (subject to any tax/recordkeeping minimums we’re legally required to retain — typically 7 years for order records).
- Opt out of marketing email (if you ever opted in).
Email support@ekgisnaturals.com with your request. We answer within a day or two and confirm in writing when the action is complete.
Changes to this policy
If we ever materially change how we handle data, we’ll update this page and refresh the date below. Where a change materially affects an order you’ve already placed, we’ll aim to tell you directly as well — but this page is the reliable place to check.
Get in touch
Questions, deletion requests, or anything else — write to support@ekgisnaturals.com. We read every message and answer between batches, usually within a day or two.
Last updated: September 27, 2026.