Bottle Blue LLC ("Bottle Blue," "we," "us," or "our") respects your privacy and is committed to protecting your personal information through our compliance with this Privacy Policy ("Policy").
This Policy describes: (a) the types of information we collect from you or that you provide when you use our Services; (b) how we use, store, protect, and disclose that information; and (c) your rights and choices regarding your information.
This Policy applies to information we collect through:
This Policy does not apply to:
Please read this Policy carefully. By accessing or using our Services, you agree to the data practices described herein. If you do not agree, please do not use our Services. If you have any questions, see Section 16.
This Policy is incorporated into and governed by our Terms of Use. Capitalized terms not defined here have the meanings given in the Terms of Use.
Our Services are not directed to, and we do not knowingly collect personal information from, children under 18 years of age. If you are under 18, do not use our Services, create an account, make a purchase, or submit any information about yourself.
If we learn that we have inadvertently collected personal information from a child under 18 without verifiable parental consent, we will promptly delete such information. If you believe we may have information from or about a child under 18, please contact us immediately at bottlebluellc@gmail.com.
For Services or features that may be used by minors aged 13–17 only with verified parental consent, we will implement age verification and parental consent mechanisms as required by the Children's Online Privacy Protection Act ("COPPA") and applicable state laws.
Throughout this Policy, "Personal Information" (or "Personal Data") means any information that identifies, relates to, describes, references, or could reasonably be linked, directly or indirectly, to a particular individual or household. It does not include de-identified, anonymized, or aggregated information that cannot be linked back to an individual.
We collect information you provide when you:
When you interact with our Services, we automatically collect certain technical and usage data, including:
We may receive information about you from third parties, including:
We do not intentionally collect sensitive categories of personal information (as defined under applicable law), such as social security or government ID numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, health or medical information, genetic or biometric data, sexual orientation, immigration status, financial account credentials, or contents of private communications, unless strictly necessary for a specific feature you opt into and with your explicit consent.
If you voluntarily include sensitive information in User Content or support communications, we will treat it with appropriate care but cannot always segregate it from other data you provide. Please avoid submitting sensitive personal information unnecessarily.
We do not use sensitive personal information to infer characteristics about you or for targeted advertising purposes.
We use the information we collect for the following purposes:
If you are located in the European Economic Area, United Kingdom, or Switzerland, we process your personal data on the following legal bases under the GDPR and applicable implementing legislation:
We do not sell, rent, or lease your personal information to third parties for their own independent marketing or advertising purposes. We may disclose your personal information in the following circumstances:
We share information with third-party vendors and service providers that perform services on our behalf, including:
All service providers are contractually required to process personal information only on our behalf, in accordance with our instructions, and with appropriate data protection safeguards in place.
In the event of a merger, acquisition, asset sale, financing, reorganization, bankruptcy, or other corporate transaction, your personal information may be transferred to the relevant successor entity. We will use reasonable efforts to notify you of such a transfer and to describe any material changes to data practices via this Policy or email.
We may disclose your personal information when we believe in good faith that disclosure is:
We may share your information with other third parties with your prior consent, including when you authorize integrations with third-party platforms.
We may share aggregated, anonymized, or de-identified information that cannot reasonably be linked back to you with third parties for research, analytics, marketing, or other purposes.
We and our service providers use cookies, web beacons, pixel tags, local storage, and similar technologies to collect information about your interactions with our Services.
| Category | Purpose | Can Be Disabled? |
|---|---|---|
| Strictly Necessary | Authentication, session management, security, fraud prevention. Required for core functionality. | No; disabling breaks core functionality |
| Functional | Remembering your preferences, language, and settings for a personalized experience. | Yes; may affect experience |
| Analytics | Measuring traffic, usage patterns, and feature engagement to improve our Services. | Yes |
| Advertising / Targeting | Displaying relevant advertisements and measuring ad effectiveness. May involve cross-site tracking by ad partners. | Yes; see Section 8 |
You can manage cookie preferences through our cookie consent banner (where presented) or through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or be notified when cookies are set. Note that disabling cookies may affect the functionality of our Services.
Resources for managing cookies: allaboutcookies.org | youronlinechoices.eu.
We honor the Global Privacy Control ("GPC") signal. If your browser or device transmits a GPC opt-out signal, we will treat it as a request to opt out of the sale and sharing of your personal information for cross-context behavioral advertising, consistent with the requirements of the California Privacy Rights Act ("CPRA") and other applicable laws.
Some browsers send a "Do Not Track" (DNT) signal. At this time, there is no uniform industry standard for responding to DNT signals; we do not currently alter data collection practices in response to DNT signals. However, we do honor GPC as described above.
We may work with third-party advertising networks that serve interest-based advertisements. These networks may use cookies or other tracking technologies to collect information about your activities across websites over time to provide relevant ads. You can opt out of interest-based advertising from participating companies through:
Bottle Blue LLC does not sell your personal information to third parties for monetary compensation.
We may share certain personal information with advertising or analytics partners in ways that may constitute "sharing" under the California Privacy Rights Act or "selling" under other applicable state laws. You have the right to opt out of such sharing at any time.
To opt out of the sale or sharing of your personal information:
We will not discriminate against you for exercising your opt-out rights. Opting out of data sharing may affect the relevance of advertisements you see on our Services.
We may use automated systems, algorithms, and artificial intelligence tools to process your data for purposes such as fraud detection, security screening, content personalization, usage analytics, and AI-powered feature delivery.
We do not make decisions that produce legally significant or similarly significant effects on you based solely on automated processing, without human review, unless you have explicitly consented or such processing is required by law. If we implement such processing in the future, we will update this Policy and provide appropriate disclosure.
When you interact with AI-powered features, the inputs (prompts, queries, text submissions) you provide may be processed by our AI systems or by third-party AI service providers under confidentiality and data processing agreements. We do not use your identifiable prompts or inputs to train general-purpose AI models without your explicit consent.
We may create aggregate usage profiles or personas to understand how groups of users interact with our Services. These are used to improve product design and are not used to make individual decisions about you without human involvement.
If you are located in the EEA, UK, or a US state that grants rights related to profiling (see Section 11), you may have the right to opt out of or object to certain profiling activities.
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying legal, regulatory, accounting, or reporting requirements. The criteria we use to determine retention periods include:
| Data Category | Typical Retention Period | Basis |
|---|---|---|
| Account information | Duration of account + 3 years after closure | Contractual obligation; legal compliance |
| Transaction and billing records | 7 years from transaction date | Tax and accounting law requirements |
| Usage and log data | 12–24 months | Security, fraud detection, analytics |
| Support and correspondence | 3 years from last interaction | Dispute resolution; quality assurance |
| Marketing consent records | 5 years from consent or last contact | Legal compliance (demonstrating consent) |
| AI feature inputs/outputs | 90 days (unless otherwise disclosed at feature level) | Service delivery; quality improvement |
| De-identified/aggregate analytics | Indefinite | No personal data; product development |
When the applicable retention period expires, we securely delete or anonymize personal information. In some cases, we may retain data longer if required by a legal hold, ongoing litigation, regulatory investigation, or to comply with a specific legal obligation.
You may request earlier deletion of your personal information as described in Section 11. Certain data cannot be deleted if retention is required by law (e.g., financial records) or if deletion would impair our legitimate legal interests.
Depending on where you reside, you may have specific rights regarding your personal information. We honor all rights that apply to you under applicable law. To exercise any right, see Section 16.
Regardless of location, all users may:
California residents have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:
To submit a verifiable consumer request, contact us as described in Section 16. We will verify your identity before fulfilling requests. You may designate an authorized agent to make requests on your behalf.
Categories of personal information collected in the past 12 months include: identifiers; commercial information; internet or other network activity information; geolocation data (approximate); inferences drawn from the above; and professional or employment-related information (for business customers). We have not sold personal information as defined under CCPA/CPRA and have not disclosed personal information for cross-context behavioral advertising except as described in Section 7.5.
Residents of the following states have privacy rights under their respective state laws. Where applicable, those rights include rights to access, correct, delete, and obtain a portable copy of personal data, to opt out of targeted advertising and profiling in furtherance of decisions that produce legal or similarly significant effects, and to appeal our decisions:
We honor all rights granted to you under the law of your state of residence. To exercise your rights, contact us as described in Section 16. We will respond within the timeframe required by applicable law (generally 45 days, with a possible 45-day extension for complex requests). If we deny your request, you may have the right to appeal; we will describe the appeal process in our denial notice.
If you are located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and/or the UK GDPR, as applicable:
Our data controller contact for GDPR purposes is: Bottle Blue LLC, 415 3rd Street SW, Montgomery, MN 56059, USA | bottlebluellc@gmail.com.
You have the right to lodge a complaint with your local supervisory authority. In the EU, this is the data protection authority in your member state. In the UK, this is the Information Commissioner's Office (ICO): ico.org.uk.
Canadian residents may have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) or applicable provincial privacy legislation, including rights to access and correct personal information we hold about you. Contact us at bottlebluellc@gmail.com to submit a request.
We implement administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, alteration, disclosure, and destruction. Our security measures include:
Despite our efforts, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security. You are also responsible for maintaining the security of your account credentials (see our Terms of Use, Section 5).
Data Breach Notification: In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals and applicable regulatory authorities as required by law (e.g., within 72 hours under GDPR, or within applicable state law timeframes in the U.S.). Notifications will include the nature of the breach, categories and approximate number of individuals affected, likely consequences, and steps we are taking to address it.
If you discover or suspect any security vulnerability or breach involving our Services, please report it promptly to bottlebluellc@gmail.com.
Bottle Blue LLC is based in the United States. If you are located outside the United States, please be aware that information we collect about you will be transferred to and processed in the United States, which may not provide a level of data protection equivalent to your home country's laws.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on the following lawful transfer mechanisms as applicable:
We update our transfer mechanisms as required when regulatory frameworks change. To obtain a copy of the safeguards applicable to your personal data transfer, contact us at bottlebluellc@gmail.com.
Your personal data may also be processed in other countries where our service providers operate. We require all processors to adhere to appropriate data protection standards via contractual data processing agreements.
Our Services may contain links to third-party websites, applications, and services. This Policy does not apply to third-party platforms, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access through our platforms.
When you connect third-party integrations or extensions to our Services, those third parties may independently collect data about you subject to their own privacy policies.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. When we make changes, we will update the "Last Modified" date at the top of this page.
For material changes, meaning changes that affect how we collect, use, or share your personal information in ways you would not reasonably expect based on this Policy, we will provide advance notice by: (a) posting a notice on our Website or in the Mobile App; and/or (b) sending an email to the address associated with your account, where required by law.
Your continued use of our Services following the posting of any changes to this Policy constitutes your acceptance of those changes. If you do not accept the revised Policy, you must discontinue use of the Services.
We maintain an archive of prior versions of this Policy. To request a prior version, contact us at bottlebluellc@gmail.com.
If you have any questions, concerns, or complaints about this Privacy Policy, our data practices, or our handling of your personal information, or if you wish to exercise any privacy rights described in this Policy, please contact us at:
Bottle Blue LLC
Attn: Privacy & Data
415 3rd Street SW
Montgomery, MN 56059
United States
Email: bottlebluellc@gmail.com
Website: https://bottlebluellc.com
When submitting a privacy rights request, please include your full name and email address associated with your account, the right you wish to exercise, and a description of your request. We will verify your identity before processing requests involving personal data access, correction, deletion, or portability.
We will acknowledge receipt of your request within five (5) business days and respond substantively within the timeframe required by applicable law (typically 30–45 days). If we need additional time, we will notify you and explain the reason.
For verifiable requests from authorized agents (California and other applicable states), the agent must provide written authorization from you, and we may separately verify your identity directly with you.
EEA/UK/Swiss Supervisory Authorities: If you are not satisfied with our response, you have the right to lodge a complaint with the data protection authority in your country or region of residence.