Who controls your personal information
The Big Hit Card Company is a United States-based online retailer and is the controller of the personal information described in this policy when we determine why and how that information is processed.
Privacy questions and requests may be sent to info@thebighitcardcompany.com.
The Big Hit Card Company2976 E State St.
Ste 120
Unit #2049
Eagle, ID 83616
We currently sell and ship products only within the United States. If our international operations materially change, we will review and update any additional representative or contact obligations that apply.
Information we collect
We collect information you provide to us, including account details, name, email address, telephone number when provided, billing and shipping details, order history, refund and fulfillment information, support communications, consent choices, and privacy requests.
We also collect limited technical and transaction information such as IP address, device and browser information, security events, authentication and session information, cookie and consent status, checkout events, fraud-prevention signals, application logs, and similar information needed to operate, secure, and troubleshoot the store.
Payment-card numbers are entered directly with our payment processor. We do not store complete payment-card credentials in our application database. We do not intentionally request special-category or similarly sensitive personal information unless it is necessary and lawful to do so.
Where information comes from
Most personal information comes directly from you when you create an account, make a purchase, contact us, change a privacy preference, or submit a privacy request.
We may also receive limited information from service providers involved in authentication, payments, fraud prevention, shipping, email delivery, hosting, security monitoring, and other store operations. If you interact with us through a marketplace, social network, or other third-party service, we may receive information that you or that service lawfully provides to us.
Why we use information and our legal bases
Depending on the activity and the law that applies, we process personal information under one or more of the following legal bases:
- Contract. We process information needed to create and maintain requested accounts, accept and fulfill orders, reserve inventory, process payments and refunds, provide shipping and order updates, and respond to service requests.
- Legal obligations. We may process and retain information to comply with tax, accounting, consumer protection, recordkeeping, lawful process, regulatory, and other legal requirements.
- Legitimate interests. We may process information when reasonably necessary to secure the store, prevent fraud and abuse, investigate incidents, maintain reliable services, improve performance and accessibility, establish or defend legal claims, and operate the business. Where GDPR or similar law applies, we consider the impact on your rights before relying on legitimate interests.
- Consent. We rely on consent where required for optional analytics or another optional use that requires consent. You may withdraw consent at any time as described below.
Information required to provide the store
Some information is necessary to enter into or perform a transaction with you. For example, we generally need contact information, a valid delivery address, and payment-related information to accept and fulfill an order.
If required information is not provided, we may be unable to create an account, complete a purchase, deliver an order, process a refund, verify a request, or provide another service you asked for. Optional analytics is not required to use the store.
Service providers and recipients
We disclose personal information only as reasonably necessary to operate the store, complete transactions, protect customers, comply with law, and support the purposes described in this policy.
Our service-provider categories include authentication and database services such as Supabase, payment services such as Stripe, hosting services such as Hostinger, transactional email services such as Resend, privacy-filtered operational error monitoring such as Sentry, shipping carriers when an order is fulfilled, and Google Analytics only when optional analytics consent has been provided.
We may also disclose information to accountants, attorneys, insurers, auditors, fraud-prevention resources, government authorities, or other professional advisers where reasonably necessary or legally required.
Selling, sharing, and advertising
We do not sell personal information. We do not currently share personal information for cross-context behavioral advertising, and advertising cookies are currently disabled.
If our practices change, we will update this policy and provide any notice, consent mechanism, or opt-out right required by applicable law before the new practice is used.
Cookies and analytics
Necessary cookies and similar storage support authentication, account security, shopping carts, checkout, fraud prevention, load balancing, and remembering privacy choices.
Google Analytics is optional and is not loaded until you choose to allow analytics. You can change that choice at any time through Privacy Choices. See our Cookie Policy for additional details.
International data transfers
We operate from the United States, and some service providers may process information in the United States or other countries. This means personal information may be processed outside the country where it was collected.
When GDPR, UK GDPR, or another law requires a transfer safeguard, we use an available lawful mechanism appropriate to the transfer, which may include an adequacy decision, approved contractual protections such as Standard Contractual Clauses, the applicable UK transfer addendum or agreement, or another legally recognized safeguard.
You may contact us for additional information about safeguards relevant to a transfer of your personal information.
How long we retain information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to satisfy applicable legal, accounting, security, fraud, warranty, dispute, and recordkeeping obligations.
Retention depends on the type of information. Account information may be kept while an account remains active and for a reasonable period afterward. Order, tax, refund, and payment records may be retained for the applicable statutory and financial-record periods. Security and access logs are retained for a more limited period reasonably needed to detect, investigate, and prevent misuse. Consent and privacy-request records may be retained long enough to honor choices and demonstrate compliance.
When information is no longer required, we delete, anonymize, or otherwise dispose of it as appropriate, subject to backups, legal holds, and other lawful retention requirements.
AI-assisted processing and automated decisions
We may use artificial intelligence to assist with product descriptions, support triage, fraud and operational review, and internal drafting. AI systems can make mistakes, so material product facts and consequential decisions should receive human review.
We do not intentionally submit complete payment-card credentials to AI systems. AI is not the sole decision-maker for privacy-rights requests.
We do not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects on customers. Payment, fraud, or other service providers may independently use automated systems under their own terms and privacy practices. If our own practices change, we will provide any additional notice and rights required by applicable law.
Your general privacy rights
Depending on where you live, you may have rights to request access to personal information, correct inaccurate information, request deletion, receive a portable copy, opt out of certain processing, restrict certain processing, object to certain uses, or appeal a denied request.
Submit a request through Privacy Choices. We may verify your identity before completing a request. We will not discriminate against you for exercising a privacy right. Certain requests may be limited where information must be kept for tax, accounting, fraud prevention, security, order fulfillment, chargebacks, legal claims, or another lawful reason.
EEA and UK privacy rights
If GDPR or UK GDPR applies to our processing of your personal information, you may have the right to be informed, obtain access, request rectification, request erasure, restrict processing, receive applicable information in a portable format, object to processing based on legitimate interests, and exercise rights relating to qualifying automated decisions.
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before consent was withdrawn.
For GDPR requests, we generally respond without undue delay and within one month, subject to any extension permitted by law. You also have the right to lodge a complaint with the data protection or supervisory authority in the country where you live or work or where you believe an infringement occurred. UK residents may also complain to the UK Information Commissioner's Office.
United States state privacy rights
Residents of states with comprehensive privacy laws may have additional rights regarding access, correction, deletion, portability, opt-outs, appeals, sensitive-data processing, or targeted advertising, depending on the law and whether it applies to us.
We do not currently sell personal information or use cross-context behavioral advertising. Requests can be submitted through Privacy Choices.
Global Privacy Control
We treat a recognized Global Privacy Control signal as an opt-out signal for that browser where required or supported. Because advertising tracking is currently disabled, a recognized signal also keeps optional analytics off unless you later make a separate affirmative choice.
Children
Our store is not directed to children under 13, and we do not knowingly collect personal information from a child under 13 without authorization required by applicable law.
Where GDPR, UK GDPR, or another law imposes a different age or parental-authorization requirement for consent-based online processing, we will apply the legally required standard. If you believe a child has provided personal information inappropriately, contact us so we can investigate and take appropriate action.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include scoped access, row-level security, encryption in transit, protected server secrets, multi-factor authentication for privileged access, monitoring, rate limiting, audit controls, and restricted administrative functions.
No online service can guarantee absolute security. If a qualifying personal-data breach occurs, we will provide notifications required by applicable law.
Third-party websites
Our site may link to eBay, Whatnot, Facebook, X, Instagram, and other third-party services. Their privacy practices apply after you leave our site or interact directly with their services. We encourage you to review their privacy notices before providing information to them.
Changes to this policy
We may update this policy when our business, technology, processing practices, service providers, or legal obligations change. We will post the revised effective date and provide additional notice or obtain consent when applicable law requires it.
Contact us
Questions may be sent to info@thebighitcardcompany.com or mailed to:
The Big Hit Card Company2976 E State St.
Ste 120
Unit #2049
Eagle, ID 83616
