Privacy Policy

Effective Date: January 1, 2026  |  Last Modified: June 1, 2026  |  Version 3.0

Summary of Key Points
We collect information you provide to us, information collected automatically when you use our Services, and information from third-party processors such as Stripe. We use this data to operate and improve our Services, communicate with you, and comply with the law. We do not sell your personal information to third parties for their own marketing. You have meaningful rights over your data, including access, correction, deletion, portability, and opt-outs, depending on where you live. See Section 11 for your state- or country-specific rights.

Table of Contents

  1. Introduction and Scope
  2. Children's Privacy
  3. Information We Collect
  4. Sensitive Personal Information
  5. How We Use Your Information
  6. Disclosure and Sharing of Your Information
  7. Advertising, Tracking, and Cookies
  8. Do Not Sell or Share My Personal Information
  9. Automated Decision-Making and AI Processing
  10. Data Retention
  11. Your Privacy Rights by Jurisdiction
  12. Data Security
  13. International Data Transfers
  14. Third-Party Links and Services
  15. Changes to This Privacy Policy
  16. Contact Us and How to Exercise Your Rights

1. Introduction and Scope

Bottle Blue LLC ("Bottle Blue," "we," "us," or "our") respects your privacy and is committed to protecting your personal information through our compliance with this Privacy Policy ("Policy").

This Policy describes: (a) the types of information we collect from you or that you provide when you use our Services; (b) how we use, store, protect, and disclose that information; and (c) your rights and choices regarding your information.

This Policy applies to information we collect through:

This Policy does not apply to:

Please read this Policy carefully. By accessing or using our Services, you agree to the data practices described herein. If you do not agree, please do not use our Services. If you have any questions, see Section 16.

This Policy is incorporated into and governed by our Terms of Use. Capitalized terms not defined here have the meanings given in the Terms of Use.

2. Children's Privacy

Our Services are not directed to, and we do not knowingly collect personal information from, children under 18 years of age. If you are under 18, do not use our Services, create an account, make a purchase, or submit any information about yourself.

If we learn that we have inadvertently collected personal information from a child under 18 without verifiable parental consent, we will promptly delete such information. If you believe we may have information from or about a child under 18, please contact us immediately at bottlebluellc@gmail.com.

For Services or features that may be used by minors aged 13–17 only with verified parental consent, we will implement age verification and parental consent mechanisms as required by the Children's Online Privacy Protection Act ("COPPA") and applicable state laws.

3. Information We Collect

Throughout this Policy, "Personal Information" (or "Personal Data") means any information that identifies, relates to, describes, references, or could reasonably be linked, directly or indirectly, to a particular individual or household. It does not include de-identified, anonymized, or aggregated information that cannot be linked back to an individual.

3.1 Information You Provide Directly

We collect information you provide when you:

3.2 Information Collected Automatically

When you interact with our Services, we automatically collect certain technical and usage data, including:

3.3 Information from Third-Party Sources

We may receive information about you from third parties, including:

4. Sensitive Personal Information

We do not intentionally collect sensitive categories of personal information (as defined under applicable law), such as social security or government ID numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, health or medical information, genetic or biometric data, sexual orientation, immigration status, financial account credentials, or contents of private communications, unless strictly necessary for a specific feature you opt into and with your explicit consent.

If you voluntarily include sensitive information in User Content or support communications, we will treat it with appropriate care but cannot always segregate it from other data you provide. Please avoid submitting sensitive personal information unnecessarily.

We do not use sensitive personal information to infer characteristics about you or for targeted advertising purposes.

5. How We Use Your Information

We use the information we collect for the following purposes:

5.1 Service Delivery and Operations

5.2 Communications

5.3 Product Development and Research

5.4 Legal and Compliance

5.5 Legal Bases (for EEA/UK/Swiss Users)

If you are located in the European Economic Area, United Kingdom, or Switzerland, we process your personal data on the following legal bases under the GDPR and applicable implementing legislation:

6. Disclosure and Sharing of Your Information

We do not sell, rent, or lease your personal information to third parties for their own independent marketing or advertising purposes. We may disclose your personal information in the following circumstances:

6.1 Service Providers and Processors

We share information with third-party vendors and service providers that perform services on our behalf, including:

All service providers are contractually required to process personal information only on our behalf, in accordance with our instructions, and with appropriate data protection safeguards in place.

6.2 Business Transfers

In the event of a merger, acquisition, asset sale, financing, reorganization, bankruptcy, or other corporate transaction, your personal information may be transferred to the relevant successor entity. We will use reasonable efforts to notify you of such a transfer and to describe any material changes to data practices via this Policy or email.

6.3 Legal Requirements and Protection

We may disclose your personal information when we believe in good faith that disclosure is:

6.4 With Your Consent

We may share your information with other third parties with your prior consent, including when you authorize integrations with third-party platforms.

6.5 Aggregated and De-identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be linked back to you with third parties for research, analytics, marketing, or other purposes.

7. Advertising, Tracking, and Cookies

7.1 Cookies and Similar Technologies

We and our service providers use cookies, web beacons, pixel tags, local storage, and similar technologies to collect information about your interactions with our Services.

Category Purpose Can Be Disabled?
Strictly Necessary Authentication, session management, security, fraud prevention. Required for core functionality. No; disabling breaks core functionality
Functional Remembering your preferences, language, and settings for a personalized experience. Yes; may affect experience
Analytics Measuring traffic, usage patterns, and feature engagement to improve our Services. Yes
Advertising / Targeting Displaying relevant advertisements and measuring ad effectiveness. May involve cross-site tracking by ad partners. Yes; see Section 8

7.2 Managing Cookies

You can manage cookie preferences through our cookie consent banner (where presented) or through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or be notified when cookies are set. Note that disabling cookies may affect the functionality of our Services.

Resources for managing cookies: allaboutcookies.org | youronlinechoices.eu.

7.3 Global Privacy Control

We honor the Global Privacy Control ("GPC") signal. If your browser or device transmits a GPC opt-out signal, we will treat it as a request to opt out of the sale and sharing of your personal information for cross-context behavioral advertising, consistent with the requirements of the California Privacy Rights Act ("CPRA") and other applicable laws.

7.4 Do Not Track

Some browsers send a "Do Not Track" (DNT) signal. At this time, there is no uniform industry standard for responding to DNT signals; we do not currently alter data collection practices in response to DNT signals. However, we do honor GPC as described above.

7.5 Third-Party Advertising

We may work with third-party advertising networks that serve interest-based advertisements. These networks may use cookies or other tracking technologies to collect information about your activities across websites over time to provide relevant ads. You can opt out of interest-based advertising from participating companies through:

8. Do Not Sell or Share My Personal Information

Bottle Blue LLC does not sell your personal information to third parties for monetary compensation.

We may share certain personal information with advertising or analytics partners in ways that may constitute "sharing" under the California Privacy Rights Act or "selling" under other applicable state laws. You have the right to opt out of such sharing at any time.

To opt out of the sale or sharing of your personal information:

We will not discriminate against you for exercising your opt-out rights. Opting out of data sharing may affect the relevance of advertisements you see on our Services.

9. Automated Decision-Making and AI Processing

9.1 Automated Processing

We may use automated systems, algorithms, and artificial intelligence tools to process your data for purposes such as fraud detection, security screening, content personalization, usage analytics, and AI-powered feature delivery.

9.2 No Solely Automated Decisions with Significant Legal Effects

We do not make decisions that produce legally significant or similarly significant effects on you based solely on automated processing, without human review, unless you have explicitly consented or such processing is required by law. If we implement such processing in the future, we will update this Policy and provide appropriate disclosure.

9.3 AI Feature Inputs

When you interact with AI-powered features, the inputs (prompts, queries, text submissions) you provide may be processed by our AI systems or by third-party AI service providers under confidentiality and data processing agreements. We do not use your identifiable prompts or inputs to train general-purpose AI models without your explicit consent.

9.4 Profiling

We may create aggregate usage profiles or personas to understand how groups of users interact with our Services. These are used to improve product design and are not used to make individual decisions about you without human involvement.

If you are located in the EEA, UK, or a US state that grants rights related to profiling (see Section 11), you may have the right to opt out of or object to certain profiling activities.

10. Data Retention

We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying legal, regulatory, accounting, or reporting requirements. The criteria we use to determine retention periods include:

Data Category Typical Retention Period Basis
Account information Duration of account + 3 years after closure Contractual obligation; legal compliance
Transaction and billing records 7 years from transaction date Tax and accounting law requirements
Usage and log data 12–24 months Security, fraud detection, analytics
Support and correspondence 3 years from last interaction Dispute resolution; quality assurance
Marketing consent records 5 years from consent or last contact Legal compliance (demonstrating consent)
AI feature inputs/outputs 90 days (unless otherwise disclosed at feature level) Service delivery; quality improvement
De-identified/aggregate analytics Indefinite No personal data; product development

When the applicable retention period expires, we securely delete or anonymize personal information. In some cases, we may retain data longer if required by a legal hold, ongoing litigation, regulatory investigation, or to comply with a specific legal obligation.

You may request earlier deletion of your personal information as described in Section 11. Certain data cannot be deleted if retention is required by law (e.g., financial records) or if deletion would impair our legitimate legal interests.

11. Your Privacy Rights by Jurisdiction

Depending on where you reside, you may have specific rights regarding your personal information. We honor all rights that apply to you under applicable law. To exercise any right, see Section 16.

11.1 Rights Available to All Users

Regardless of location, all users may:

11.2 California Residents (CPRA / CCPA)

California residents have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:

To submit a verifiable consumer request, contact us as described in Section 16. We will verify your identity before fulfilling requests. You may designate an authorized agent to make requests on your behalf.

Categories of personal information collected in the past 12 months include: identifiers; commercial information; internet or other network activity information; geolocation data (approximate); inferences drawn from the above; and professional or employment-related information (for business customers). We have not sold personal information as defined under CCPA/CPRA and have not disclosed personal information for cross-context behavioral advertising except as described in Section 7.5.

11.3 Residents of Other U.S. States

Residents of the following states have privacy rights under their respective state laws. Where applicable, those rights include rights to access, correct, delete, and obtain a portable copy of personal data, to opt out of targeted advertising and profiling in furtherance of decisions that produce legal or similarly significant effects, and to appeal our decisions:

We honor all rights granted to you under the law of your state of residence. To exercise your rights, contact us as described in Section 16. We will respond within the timeframe required by applicable law (generally 45 days, with a possible 45-day extension for complex requests). If we deny your request, you may have the right to appeal; we will describe the appeal process in our denial notice.

11.4 EEA, UK, and Swiss Residents: GDPR and UK GDPR

If you are located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and/or the UK GDPR, as applicable:

Our data controller contact for GDPR purposes is: Bottle Blue LLC, 415 3rd Street SW, Montgomery, MN 56059, USA | bottlebluellc@gmail.com.

You have the right to lodge a complaint with your local supervisory authority. In the EU, this is the data protection authority in your member state. In the UK, this is the Information Commissioner's Office (ICO): ico.org.uk.

11.5 Canadian Residents: PIPEDA / Bill C-27

Canadian residents may have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) or applicable provincial privacy legislation, including rights to access and correct personal information we hold about you. Contact us at bottlebluellc@gmail.com to submit a request.

12. Data Security

We implement administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, alteration, disclosure, and destruction. Our security measures include:

Despite our efforts, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security. You are also responsible for maintaining the security of your account credentials (see our Terms of Use, Section 5).

Data Breach Notification: In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals and applicable regulatory authorities as required by law (e.g., within 72 hours under GDPR, or within applicable state law timeframes in the U.S.). Notifications will include the nature of the breach, categories and approximate number of individuals affected, likely consequences, and steps we are taking to address it.

If you discover or suspect any security vulnerability or breach involving our Services, please report it promptly to bottlebluellc@gmail.com.

13. International Data Transfers

Bottle Blue LLC is based in the United States. If you are located outside the United States, please be aware that information we collect about you will be transferred to and processed in the United States, which may not provide a level of data protection equivalent to your home country's laws.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on the following lawful transfer mechanisms as applicable:

We update our transfer mechanisms as required when regulatory frameworks change. To obtain a copy of the safeguards applicable to your personal data transfer, contact us at bottlebluellc@gmail.com.

Your personal data may also be processed in other countries where our service providers operate. We require all processors to adhere to appropriate data protection standards via contractual data processing agreements.

14. Third-Party Links and Services

Our Services may contain links to third-party websites, applications, and services. This Policy does not apply to third-party platforms, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access through our platforms.

When you connect third-party integrations or extensions to our Services, those third parties may independently collect data about you subject to their own privacy policies.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. When we make changes, we will update the "Last Modified" date at the top of this page.

For material changes, meaning changes that affect how we collect, use, or share your personal information in ways you would not reasonably expect based on this Policy, we will provide advance notice by: (a) posting a notice on our Website or in the Mobile App; and/or (b) sending an email to the address associated with your account, where required by law.

Your continued use of our Services following the posting of any changes to this Policy constitutes your acceptance of those changes. If you do not accept the revised Policy, you must discontinue use of the Services.

We maintain an archive of prior versions of this Policy. To request a prior version, contact us at bottlebluellc@gmail.com.

16. Contact Us and How to Exercise Your Rights

If you have any questions, concerns, or complaints about this Privacy Policy, our data practices, or our handling of your personal information, or if you wish to exercise any privacy rights described in this Policy, please contact us at:

Bottle Blue LLC
Attn: Privacy & Data
415 3rd Street SW
Montgomery, MN 56059
United States
Email: bottlebluellc@gmail.com
Website: https://bottlebluellc.com

When submitting a privacy rights request, please include your full name and email address associated with your account, the right you wish to exercise, and a description of your request. We will verify your identity before processing requests involving personal data access, correction, deletion, or portability.

We will acknowledge receipt of your request within five (5) business days and respond substantively within the timeframe required by applicable law (typically 30–45 days). If we need additional time, we will notify you and explain the reason.

For verifiable requests from authorized agents (California and other applicable states), the agent must provide written authorization from you, and we may separately verify your identity directly with you.

EEA/UK/Swiss Supervisory Authorities: If you are not satisfied with our response, you have the right to lodge a complaint with the data protection authority in your country or region of residence.