Back to the offer

Privacy

Last updated 18 August 2026

We sell one digital product. We collect the least we can get away with: your email address, what you bought, and a token that opens your copy. We also measure how this page is used and whether our advertising pays for itself, and this page says exactly how and what leaves our hands.

Who we are

Brain Art LLC, 16192 Coastal Highway, Lewes, Delaware 19958, United States. We are the data controller for the information described here. Reach us at support@nofacepotterysales.com.

What we collect, and why

WhatWhy
Your email addressTo send your access link and to find your purchase if you lose it
Your name, if you give oneOptional, and the form works without it. If you do give one we keep it, use it to address you in your access email, and send a scrambled copy to Meta as described below. Leave it blank and we fall back to the name on your card, which Stripe holds anyway.
What you bought, the amount and the currencyTo know whether you have the add-on, and for our accounts
A random access tokenThe thing your link carries. It is what unlocks your copy.
The Stripe session referenceTo match a payment to a purchase and to handle refunds
A reference to the card you paid withStripe holds the card, we hold two reference strings that point at it. They are what let the optional extra offered right after payment be added with one press instead of a second checkout. They work only inside our own Stripe account, and nothing is charged without you pressing a button. Ask us and we delete them.
Date and time of purchaseTo run the guarantee window
How you arrived, if you came from an advertThe campaign tags in the link and the click identifier that comes with it, so we can tell which advert produced a sale
What you did on this pageThat the page was viewed, that checkout was started, and that a purchase completed. Also a recording of how far you scrolled and where you clicked, so we can see which parts of the page lose people. What you type into the form is hidden from that recording.

What we never see

Your card number, expiry, security code and billing address go straight to Stripe and are never sent to our servers. We could not show you your own card number if you asked us to. The reference described above is not your card and cannot be turned back into it.

Cookies

One, and it is strictly necessary. When you open your access link we set a cookie called nfp_access that proves you are allowed into your copy. It holds your purchase reference and which add-ons you own. It lasts 30 days, it is signed so it cannot be edited, and it is not used to track you anywhere.

There are others, and they are not strictly necessary. Google Analytics sets cookies beginning _ga to tell one visit from another. The Meta pixel sets _fbp, and _fbc if you arrived by clicking one of our adverts. PostHog sets one beginning ph_ and ending _posthog, which holds a random visitor id so a scroll recording can be joined to the rest of the same visit, and it lasts a year. All of them are set through Google Tag Manager, which is the thing that decides what loads on the page.

Measurement and advertising

We run adverts. Without measurement we cannot tell whether an advert paid for itself, which for a nine dollar product is the difference between carrying on and stopping. So three things watch this page, and only these three.

Google Analytics records that a page was viewed, that checkout was started and how much for, and that a purchase completed. Meta records the same three moments so it can match a sale back to the advert you clicked. PostHog records those moments too, and additionally makes a replay of your visit to this page: how far you scrolled, where you clicked, how long you stayed. We watch those to find the paragraph where people give up reading, and for nothing else.

The replay hides the contents of every form field, which is the standard behaviour of the tool and not something we switched on afterwards. Your name and your email address are not visible in it. Neither is anything you type anywhere else on the page.

There is one part worth spelling out, because it is the only place your email leaves us for advertising. After a purchase, our server sends Meta a hashed copy of your email address, a hashed copy of your first and last name if we have one, and the amount. Hashed means scrambled one way: Meta can check it against an address it already holds, and nobody can turn it back into your address. We send it from the server rather than the browser because it is the only way to count a sale that an ad blocker would otherwise hide, and because it lets Meta discard the duplicate rather than count your purchase twice.

None of this runs inside the product. The pages behind your access link carry no analytics, no pixel and no recording at all, so what you read, what you skip and how long you take are ours to never know.

If you would rather none of it happened, a browser that blocks third-party cookies or any common content blocker stops all of it, and nothing about your purchase or your access breaks. You can also email us and we will delete what is tied to you.

Who else touches your data

Only companies we need to run this. Each acts as our processor.

WhoWhat forWhere
StripeTaking payment and handling refundsUnited States
SupabaseStoring the purchase recordFrankfurt, Germany
ResendSending your access emailUnited States and Ireland
VercelHosting the site and the productUnited States
Google FontsServing two typefacesUnited States
Google Analytics and Tag ManagerCounting page views, checkouts started and purchasesUnited States
MetaTelling us whether an advert produced a saleUnited States and Ireland
PostHogReplaying visits to this page so we can see where it loses peopleUnited States

We do not sell your data and we do not add you to anything you did not ask for. The only thing shared for advertising is what the section above describes: the three moments, the amount, and hashed copies of your email and name that cannot be read back. Your address and what you do inside the product are never part of it.

How long we keep it

Your purchase record stays for as long as we are giving you access, which is indefinitely unless you ask us to delete it, because your link is meant to keep working. Payment records are kept for as long as tax and accounting rules require, which is generally seven years. Ask us to delete your record and we will, but be aware that this also switches off your access link.

Your rights

If you are in the UK, the European Economic Area or another place with similar law, you can ask us to show you what we hold, correct it, delete it, hand it over in a portable form, or stop using it. Email support@nofacepotterysales.com and we will do it. We do not charge for this and we will not make it difficult.

You can also complain to your local data protection authority. In the UK that is the Information Commissioner's Office.

Legal basis

We process your email and purchase record to perform the contract you entered when you bought the product. We keep payment records because the law requires it.

Transfers out of Europe

Some of the companies above are in the United States. Where that involves moving your data out of the UK or the European Economic Area, those transfers rely on the standard contractual clauses or an equivalent approved mechanism in each provider's own terms.

Changes

If we change this, we will change the date at the top. If the change is significant and you have bought from us, we will email you.