Privacy Policy
Last updated: June 19, 2026
Run-a-muck Farms (“we,” “us,” or “our”) operates runamuckfarmspa.com. This policy explains what personal information we collect, how we use it, and the choices you have. By using our site you agree to the practices described here.
Information we collect
- Account & contact details — name, email, phone, and password (stored only as a secure hash) when you create an account or contact us.
- Order & booking information — items purchased, pickup/delivery details, booking dates, and order history.
- Payment information — processed by Stripe. We never receive or store your full card number; we keep only a Stripe reference (token) for your transaction.
- Liability waivers — for on-farm visits we collect the information on the waiver, including your signature, the date/time, your IP address, and browser details, to evidence agreement.
- Marketing preferences — your email/SMS opt-in status and newsletter subscription.
- Usage & device data — basic analytics (pages visited, approximate location, device/browser) collected through our hosting and analytics providers to operate and improve the site.
How we use your information
- Fulfilling and supporting your orders, bookings, and farm visits.
- Sending transactional messages (order/booking confirmations and reminders).
- Sending marketing emails only where you have opted in, and only until you opt out.
- Operating, securing, and improving our website.
- Complying with legal, tax, and recordkeeping obligations.
Service providers we share with
We share information only as needed with vendors who help us run the business. These currently include:
- Stripe — payment processing
- Resend / our email provider — transactional and marketing email
- Vercel — website hosting and basic analytics
- Cloudflare R2 — file and document storage
- Turso — database hosting
- Upstash — rate limiting and caching
- Sentry — error monitoring
We do not sell your personal information. We may disclose information if required by law or to protect our rights and the safety of our visitors.
Cookies & analytics
We use cookies and similar technologies that are strictly necessary for the site to function (for example, to keep you signed in and to maintain your cart). These are always active. We use optional analytics and marketing cookies only with your consent.
When you first visit, our cookie banner lets you accept all, reject optional cookies, or choose by category. You can change your choice at any time using the “Cookie Settings” link in the footer or on our Your Privacy Choices page. You can also control cookies through your browser settings; disabling some cookies may affect site functionality.
Legal bases for processing (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR/UK GDPR:
- Contract — to create your account and fulfill orders, bookings, and farm visits you request.
- Consent — for marketing email/SMS and optional analytics/marketing cookies. You may withdraw consent at any time.
- Legal obligation — to keep tax, accounting, and transaction records.
- Legitimate interests — to secure, operate, and improve our site and prevent fraud, balanced against your rights.
Your choices & rights
- Unsubscribe from marketing email at any time using the link in any marketing message, or by contacting us.
- Update your contact details and communication preferences in your account settings.
- If you have an account, download a copy of your data or delete your account from Account → Privacy & Data.
- Request access to, correction of, or deletion of your personal information by emailing hello@runamuckfarmspa.com. We will respond as required by applicable law and will not discriminate against you for exercising your rights.
Depending on where you live, you may have additional rights to access, correct, delete, port, or restrict processing of your information, to object to processing, and to lodge a complaint with your local data protection authority. EEA/UK residents can also withdraw consent at any time without affecting prior processing.
California privacy rights (CCPA/CPRA)
In the past 12 months we may have collected the following categories of personal information: identifiers (name, email, phone), customer records (orders, bookings), commercial information (purchase history), internet activity (basic usage analytics), and approximate geolocation. We collect it for the business purposes described above and retain it as described below.
We do not sell or share your personal information for money or for cross-context behavioral advertising. California residents have the right to know, access, delete, and correct their personal information, and to not be discriminated against for exercising these rights. To exercise them, use our Your Privacy Choices page or contact us. You may also use an authorized agent.
Data retention & security
We keep personal information only as long as needed for the purpose it was collected. As a general guide: account information is kept while your account is active; order, booking, and payment records are kept for up to seven years to meet tax and accounting obligations; waiver records are kept as needed to evidence agreement; and marketing subscription records are kept until you unsubscribe (plus a suppression record so we honor your opt-out). When you delete your account we anonymize information we are required to retain. We use industry-standard safeguards, including hashed passwords, encrypted connections, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Children
Our site and products are intended for adults. We do not knowingly collect personal information from children under 13. Hemp-derived products are sold only to customers 21 and older.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
