Privacy Policy
What we collect, what we don't, and where your information actually lives.
This policy covers glowresearch.shop, operated by Glow Research. It describes what information the site collects, how it's used, and what's stored only in your own browser rather than sent to us.
1. Information You Provide
If you use the contact form, create an account, or place an order, you may give us your name, email address, phone number, shipping and billing address, and company name. We use this to respond to inquiries, process orders, and ship products.
If you create an account, we also store a password. We never keep the password itself: it is put through a one-way scrypt hash with a random salt before it is stored, so the stored value cannot be turned back into your password, by us or by anyone who obtained the record. Checking a password at sign-in re-runs the same hash and compares the results.
Card details are a deliberate exception. They are entered into fields hosted by Stripe, our payment processor, and sent directly to Stripe. They do not pass through our servers, and we never see or store a full card number.
2. Information Stored in Your Browser
Glow Research uses your browser's own storage to remember a small set of functional details on the device you're using:
- Cart contents: what you've added, so it's still there if you reload the page.
- Age and RUO gate confirmation: so the entry screen doesn't reappear on every visit.
- Signed-in hint: a flag recording that you are signed in, so the header can show "Account" instead of "Sign In". It is a display hint and grants no access on its own: the session cookie described in section 5 is what actually authenticates you, and every request is re-checked against it on the server.
- Visit identifier: a random ID held for the length of the browser session, used by the page-view logging described in section 4. It is not tied to your name, email, or account.
- Device identifier: a second random ID, held until you clear your browser's site data rather than just for the session, used only to tell whether a visit is from a new or returning device for that same logging. It carries no name, email, or account either.
Clearing your browser's site data for glowresearch.shop removes all of it.
3. What We Don't Do
Glow Research does not run general cross-site tracking scripts of the kind that follow you across other, unrelated sites to build a profile of you. There is no Google Analytics and no data broker on this site. Fonts are served from our own domain rather than a font provider, so loading a page makes no request to a third party. We don't sell or rent personal information to anyone. We do not currently run an advertising pixel of any kind. We do not currently run a TikTok advertising pixel either. We do not currently run an X (Twitter) advertising pixel either.
4. Third-Party Services
A small number of outside services support the site. Each receives only what it needs to do its job:
- Stripe (payments): receives your card details directly, along with your email address, billing address, and the contents and total of your order, in order to process the charge. Stripe handles this under its own privacy policy.
- WooCommerce (order and account records): stores your customer record, order history, shipping details, and the hashed password described in section 1.
- Resend (email): receives your email address and the contents of transactional messages, such as order confirmations and password resets, in order to deliver them.
- Fulfilment partner: once an order is placed, your shipping details are shared with the third-party partner who picks, packs, and dispatches it on our behalf. See Terms & Conditions for how that relationship works.
- Our own traffic dashboard: each page view sends the page address, the referring address, the visit and device identifiers from section 2, and, if you arrived through a marketing link, the campaign parameters on that link (source, medium, and campaign name) to a dashboard we run ourselves. City-level location is resolved from your connection at the same time; the address itself is never stored. Adding an item to your cart, opening it, starting checkout, and completing an order send the same identifiers along with which product and price were involved, so we can see where people stop rather than only that they visited. None of it carries a name, email, account, or IP address, it sets no cookie of its own, and it is not shared with anyone.
- Meta (advertising measurement): We do not currently send Meta any data about your visit or purchases. If that changes, this line will say exactly what is shared and why.
- TikTok (advertising measurement): We do not currently send TikTok any data about your visit or purchases. If that changes, this line will say exactly what is shared and why.
- X, formerly Twitter (advertising measurement): We do not currently send X any data about your visit or purchases. If that changes, this line will say exactly what is shared and why.
5. Cookies
This site sets no advertising cookies. It sets one functional cookie, and only if you sign in:
- glow_session: a signed session token that keeps you signed in. It is marked HttpOnly, so page scripts cannot read it, and Secure, so it is only ever sent over an encrypted connection. It expires after 30 days, and signing out clears it immediately.
Stripe may set its own cookies on the checkout page as part of processing a payment and detecting fraud. Those are governed by Stripe's privacy policy.
6. Your Choices
You can clear everything the site has stored in your browser at any time through your browser's settings. This removes your cart and the signed-in hint, and signs you out. To ask about, correct, or delete the information held against your account or an order, contact us using the details below.
7. Children's Privacy
Glow Research products are restricted to buyers 21 and older, and this site is not directed at anyone under that age. We do not knowingly collect information from minors.
8. Data Security
The site is served over an encrypted connection throughout. Passwords are stored only as one-way scrypt hashes, session cookies are HttpOnly and Secure, and card numbers never reach our servers. We take reasonable steps to protect the information you provide, but no method of transmission or storage is completely secure, and we can't guarantee absolute security for information sent over the internet.
9. Changes to This Policy
We may update this policy as the site changes. Continued use of the site after an update constitutes acceptance of the revised policy.
10. Contact
Questions about this policy or a request about your information can be sent to support@glowresearch.shop.