Privacy Policy
Version 1.0-draft · Effective August 12, 2026
Plain-English summary: we collect what we need to run SneakBox — your identity and age, contact and shipping details, device and IP data to enforce state eligibility, and purchase history. Card numbers go straight to our payment processor and never touch our servers. We do not sell your personal information and we do not share it for cross-context behavioral advertising. You can access, correct, or delete your data at any time via privacy@sneakbox.app or the App.
This Privacy Policy explains how SneakBox, Inc. [Counsel: confirm legal entity name] (“SneakBox,” “we,” “us”) collects, uses, discloses, and retains personal information when you use the SneakBox iOS app, our websites, and related services (the “Service”). The Service is offered to residents of the United States who are 18 or older. This Policy is written to satisfy the California Consumer Privacy Act as amended by the CPRA (“CCPA”) and follows a structure compatible with the GDPR’s purpose-and-legal-basis framework, even though we do not offer the Service in the EU.
1. Personal Information We Collect
We collect the following categories of personal information. For each, we note the purpose and, in GDPR-style terms, the basis on which we process it.
Identity information
Legal name and date of birth, collected at account creation. Purpose: creating your account, verifying you are 18+, and enforcing our one-account-per-person rule. Basis: performance of our contract with you and compliance with legal obligations (age-restricted sales).
Age and identity verification data
When verification is required, a specialized verification vendor processes the data you submit (such as a government-ID image or date-of- birth check) and returns a pass/fail result and limited metadata to us. We store the result and reference identifiers, not raw ID images. Purpose: age gating, fraud prevention, and eligibility enforcement. Basis: legal obligation and our legitimate interest in preventing underage and fraudulent use.
Contact information
Email address and, optionally, phone number. Purpose: account access, receipts, Vault deadline notices (including the day-20 and day-27 reminders before auto-conversion), service announcements, and — only with your consent — marketing. Basis: contract performance; consent for marketing, withdrawable at any time.
Shipping address
Collected when you request shipment of a pair. Purpose: fulfillment, carrier handoff, customs of title transfer on delivery, and shipping-insurance claims. Basis: contract performance.
Payment information
Card and payment credentials are handled entirely by our payment processor and never touch our servers. We receive and store only a payment token, the card’s last four digits and brand, billing ZIP, and transaction records. Purpose: processing purchases, refunds for unopened Boxes, chargeback handling, and fraud prevention. Basis: contract performance and legal obligation (financial record-keeping).
Device, IP, and approximate location
Device identifiers, device model and OS version, IP address, and IP-derived approximate location. Purpose: determining state eligibility (we must block purchases from Washington and Idaho), detecting VPN/proxy circumvention, securing accounts, and preventing multi-accounting and fraud. Basis: legal obligation and legitimate interest in lawful operation and security. We do not collect precise GPS location.
Usage and transaction data
Boxes purchased and opened, odds-table versions applicable to your purchases, Reveal outcomes, Vault activity, Sell-Back and Store Credit history, fairness-verification seeds and nonces tied to your opens, and in-app analytics events. Purpose: operating the Service, proving fairness of outcomes, customer support, and improving the product. Basis: contract performance and legitimate interest in product improvement.
We do not collect sensitive personal information as defined by the CPRA except the limited identity-verification data described above, which we use only for the purposes permitted by CCPA regulations (verification, security, and legal compliance) and not to infer characteristics about you.
2. Service Providers and Processors
We share personal information with service providers who process it on our behalf under contracts that restrict their use of the data to providing services to us. By category:
- Payments — a payment processor that handles card data, tokenization, and settlement. Card numbers go directly from your device to the processor.
- Identity and age verification — a verification vendor that checks age and identity documents and returns results to us.
- Shipping and fulfillment — warehouse and carrier partners that receive your name and shipping address to pick, pack, insure, and deliver pairs.
- Analytics — a product-analytics provider that processes pseudonymous usage events for us. We configure analytics for first-party measurement, not advertising.
- Cloud hosting and infrastructure — cloud providers that host our systems and store our data in the United States.
We may also disclose information to comply with law (including anti-money-laundering and sanctions obligations), to enforce our Terms of Service, to protect the rights, safety, and property of SneakBox or others, and in connection with a merger, acquisition, or sale of assets (in which case this Policy continues to apply to previously collected data and we will notify you of any successor).
3. No Sale or Sharing of Personal Information
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined by the CCPA/CPRA. We have not done so in the preceding 12 months. If that ever changes, we will update this Policy first, provide a “Do Not Sell or Share My Personal Information” link on our website and in the App, and honor opt-out preference signals before any sale or sharing begins.
4. Retention
We keep personal information only as long as needed for the purposes above, then delete or de-identify it. Our schedule by category:
- Account and identity data — for the life of your account, plus up to 5 years after closure for fraud prevention, eligibility enforcement, and dispute resolution.
- Transaction and payment records (purchases, Reveals, Sell-Backs, Store Credit ledger, tax records) — at least 7 years, as required by financial, tax, and anti-money-laundering record-keeping obligations.
- Identity/age-verification results — verification outcome and reference ID for the life of the account plus 5 years; raw document images are retained by the verification vendor per its own schedule, not by us.
- Shipping records — 3 years after delivery, to cover insurance claims and disputes.
- Device/IP and eligibility logs — 24 months.
- Analytics events — 24 months, after which they are aggregated or deleted.
- Fairness data (server seeds, client seeds, nonces, odds-table versions) — 7 years, so past outcomes remain independently verifiable and disputes can be resolved.
5. Your Privacy Rights
Subject to verification and legal limits, you may request:
- Access / to know — a copy of the personal information we hold about you, including the categories collected, sources, purposes, and disclosures;
- Deletion — deletion of your personal information (note that we must retain transaction records required by law, and deleting your account forfeits any remaining Store Credit and Vault claims after the notices described in our Terms);
- Correction — correction of inaccurate information;
- Portability — a machine-readable export of the data you provided and your transaction history.
How to submit a request: email privacy@sneakbox.app or use the in-app privacy menu (Settings → Privacy). We verify requests by confirming control of the account email and, for sensitive requests, matching account details you provide against our records; we may ask for more information if we cannot verify you. We respond within 45 days (extendable once by 45 days with notice). We will never discriminate against you — in price, service quality, or availability — for exercising a privacy right.
6. California Notice at Collection
For California residents, the categories above map to CCPA categories as follows: identifiers (name, email, phone, address, device IDs, IP); personal information under Cal. Civ. Code §1798.80(e) (name, address, payment token metadata); protected classifications (age/date of birth only); commercial information (purchase and Sell-Back history); internet or network activity (usage and analytics data); geolocation (IP-derived approximate location only); and sensitive personal information (identity-verification data, used only for permitted purposes). We collect them from you, your device, and our verification and payment providers, for the purposes in Section 1, and retain them per Section 4.
“Sharing” under the CPRA means disclosure for cross-context behavioral advertising, whether or not for money. As stated in Section 3, we do not sell or share personal information. California residents may use an authorized agent to submit requests on their behalf; we require the agent to provide your signed permission, and we may still verify your identity directly. California’s “Shine the Light” law (§1798.83) requests can be sent to privacy@sneakbox.app; we do not disclose personal information to third parties for their own direct marketing.
[Counsel: confirm whether metrics-reporting thresholds under CCPA regulations apply at our volume, and whether any state privacy laws beyond California (Colorado, Connecticut, Texas, etc.) require additions before launch.]
7. Minors
The Service is strictly for adults 18 and older. We do not knowingly collect personal information from anyone under 18, and we do not direct any part of the Service to minors. If we discover that an account belongs to someone under 18, we will close the account, cancel unopened purchases, refund them to the original payment method, and delete the associated personal information except records we must keep by law. If you believe a minor has used the Service, contact privacy@sneakbox.app.
8. Cookies, Tracking, and Do Not Track
Our website uses only strictly necessary cookies and a minimal first-party analytics measurement (page views and referrers). We do not use third-party advertising trackers, ad pixels, or cross-site tracking on the website or in the App. Because we do not track you across third-party sites, there is nothing for a Do Not Track or Global Privacy Control signal to opt you out of today; if we ever begin selling or sharing personal information, we will treat GPC signals as a valid opt-out as the CPRA requires.
9. Security
We protect personal information with encryption in transit (TLS) and at rest, access controls with least-privilege and audit logging, tokenization of payment credentials (card data never touches our servers), network segmentation of production systems, and periodic third-party security testing. No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you and regulators as required by applicable state breach-notification laws without unreasonable delay, and we will tell you what happened, what data was involved, and what we are doing about it.
10. Changes to This Policy
We may update this Policy as the Service or the law changes. Each version carries a version number and effective date, and material changes will be announced in the App or by email at least 14 days before they take effect. We will not use previously collected personal information for a materially new purpose without notifying you and, where required, obtaining your consent.
11. Contact Us
Privacy questions and requests: privacy@sneakbox.app. General support: support@sneakbox.app. Legal notices: legal@sneakbox.app. [Counsel: add registered business address and, if required, a toll-free number for CCPA requests before launch.]