Privacy Policy

1. Introduction

At Cotopaxi ("we," "us," or "our"), your trust is as essential as the gear we craft. This Privacy Policy explains how we collect, use, store, and protect your personal data when you interact with our website (catapoxii.com), purchase our products, or engage with our services. We adhere to global data protection standards including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) to ensure your information is handled fairly, transparently, and legally.

2. What Personal Data We Collect

We only gather data necessary to fulfill our commitments to you—following the data minimization principle. The information we collect falls into two categories:

2.1 Information You Provide

  • Order & Account Details: Name, email address (e.g., service@catapoxii.com for communications), shipping/billing address, phone number, and payment information (processed securely through trusted third parties).
  • Communication Data: Content of messages sent to our support team, feedback, or story submissions for our community initiatives.

2.2 Automatically Collected Information

  • Technical Data: IP address, browser type, device information, and website usage patterns (e.g., pages visited, products viewed) to improve our site functionality.
  • Cookies & Tracking Technologies: We use cookies only with your explicit consent—no default opt-in or forced authorization. You can manage or disable cookies in your browser settings at any time.

3. How We Use Your Data

We process your information for specific, legitimate purposes and never beyond what’s disclosed:
  • Fulfill and manage your orders (e.g., shipping, processing returns/refunds as outlined in our 60-day return policy).
  • Provide customer support and respond to your inquiries promptly.
  • Improve our products and services (e.g., analyzing usage trends to enhance outdoor gear design).
  • Send updates about your order or important service changes (never unsolicited marketing without your consent).
We will never use your data for personalized marketing without separate, explicit permission.

4. Data Sharing & Disclosure

We value your privacy and only share data in limited circumstances:
  • Trusted Service Providers: Third-party vendors who assist with order fulfillment, payment processing, or website maintenance (e.g., shipping partners who need your address to deliver orders). These partners are bound by strict confidentiality agreements and cannot use your data for other purposes.
  • Legal Requirements: We may disclose data if compelled by law, or to protect our rights, safety, or the safety of our community—always as a last resort.
We do not sell your personal information to third parties. California residents can exercise their right to opt out of any potential data sales (though we do not engage in this practice).

5. Data Security & Storage

5.1 Security Measures

We implement technical and organizational safeguards to protect your data from unauthorized access, loss, or damage, including:
  • Encryption for sensitive data (e.g., payment information).
  • Regular security audits and employee training on data protection protocols.

5.2 Storage Period

We retain your data only as long as needed to fulfill the purposes for which it was collected:
  • Order data is stored for 3 years after transaction completion (per e-commerce best practices).
  • Account data is kept until you request deletion (see Section 6).
  • Anonymized, non-identifiable data (e.g., aggregated usage stats) may be retained indefinitely for business insights.

6. Your Data Rights

You have full control over your personal information, and we make exercising these rights simple—no unnecessary barriers:
  • Access & Correction: Request a copy of your data or ask to update inaccurate information.
  • Deletion ("Right to be Forgotten"): Request removal of your data, subject to legal or operational retention requirements.
  • Withdraw Consent: Revoke permission for cookie usage or marketing communications at any time.
  • Data Portability: Request your data in a machine-readable format to transfer to another service provider.
To exercise these rights, contact us at service@catapoxii.com. We will acknowledge your request within 10 days and resolve it within 45 days (or notify you of any reasonable extension).

7. Cross-Border Data Transfers

As a global brand, your data may be transferred to our facilities in the United States (275 South Holland Drive, Muscle Shoals Alabama) or to our international service providers. We ensure all transfers meet GDPR "equivalent protection" standards through approved safeguards like standard contractual clauses.

8. Changes to This Policy

We may update this Privacy Policy periodically to reflect legal changes or business needs. When we make material updates, we will notify you via email or a prominent notice on our website—and seek re-consent if required by law.

9. Contact Us

For questions about this policy or to exercise your data rights, reach out to:
  • Address: 275 South Holland Drive, Muscle Shoals Alabama 35661, United States