1Who this policy is about
Lydd & Yaffa, Inc. is a Florida corporation that designs neckties and pocket squares and sells them direct to customers online, and only online. You can reach us at hello@lyddandyaffa.com or through the contact form. Our legal name and address of record are stated in section 1 of the Terms of Sale.
This policy describes the personal information we collect, why we collect it, who else handles it, how long we keep it, and what you can ask us to do with it. It describes what we actually do. Where we do not do something that a privacy policy commonly claims — analytics, advertising trackers, data brokerage — we say so rather than reserving the right.
Where the shop sits. Our collection is sold at lyddandyaffa.com, which is this company's own website. This policy covers that site and the information that reaches Lydd & Yaffa, Inc. through it. Our sole shareholder and officer, Dr. Kareem Tannous, operates a separate personal website of his own; it is not part of buying a necktie, this policy does not cover it, and nothing you do here is shared with it.
2Where we sell and ship
We accept orders for delivery to United States addresses only. Our checkout collects a shipping address only for the United States. We do not market to, solicit orders from, or ship to customers in the European Union, the European Economic Area, the United Kingdom, or Canada. See section 11 for what that means for the GDPR.
3What we collect, and why
3.1When you buy or pre-order
| Category | Specific data | Why we have it |
|---|---|---|
| Identifiers | Your name; your email address | To confirm the order, send the shipping notice and tracking, and answer questions about it |
| Commercial information | Items ordered, colorway, quantity, order date, amount paid, tax charged, refunds and exchanges | To fulfill the order, run the books, and file tax returns |
| Postal address | Shipping address; billing address if it differs | To print the label and to calculate Florida sales tax where it applies |
| Order correspondence | Anything you write to us about an order | To answer you, and to have a record of what was agreed |
We do not ask for, and have no use for, your date of birth, gender, government identifiers, precise location, or any special or sensitive category of information. Do not send them to us.
3.2Payment information
Card, bank and wallet details never reach our systems. We take payment through Stripe Payment Links. When you pay, you are on a checkout page hosted by Stripe, Inc. and your card details go to Stripe. We never see, receive, transmit, or store a full card number, expiry, security code, or bank credential.
What Stripe passes back to us is the information needed to fulfill and account for the order: your name, email address, shipping address, the amount, the currency, the last four digits and brand of the card, and the outcome of the payment. Stripe handles your payment data under its own privacy policy and its obligations as a PCI-DSS Level 1 provider. See section 5 for the two capacities in which Stripe acts.
3.3When you ask to be notified, or write to us
If you email us to be told when a colorway is available, we keep your email address for that purpose, together with anything else you tell us in the message, such as your name and which colorway you asked about. Tell us to stop and we stop; that is the whole mechanism. Any announcement we send you carries our postal address and says how to stop receiving them — replying and saying so is enough, and we act on it within ten business days.
If you email us for any other reason, we keep the message and your address so we can reply.
The contact form. The form at lyddandyaffa.com/contact asks for your name, your email address and your message. Submitting it sends those three things, as one email, to hello@lyddandyaffa.com, with your address set as the reply address, and to nowhere else. The form does not store what you typed on this site and does not write it to a log; from then on it is handled exactly like an email you sent us yourself. The form also carries a hidden field that a person never sees and that must arrive empty; it exists to turn away automated senders, and it collects nothing.
3.4Pre-orders
Pre-orders are paid in full at the time of order, with the expected ship date stated before you pay. We use your email address to tell you when your order ships, and to tell you if the ship date changes and what your options are. Those are order notices, not marketing, and they are sent whether or not you have asked to hear from us otherwise.
4Cookies, analytics, and what the website does
No analytics service runs on the site. There is no Google Analytics, no Google Tag Manager, no Meta pixel, no advertising or conversion pixel of any kind, no session-replay or heatmap tool, and no A/B testing service. We do not build a profile of you and we do not track you from one website to another.
The site sets no cookies, and stores nothing in your browser. There is no cookie, no local storage value, and no session storage value of any kind. The site runs one script, on one page. The order tracker at lyddandyaffa.com/orders uses a small script of our own to send the order number and email address you type to our own server and to show the answer; it sends them nowhere else and stores nothing. Every other page is plain HTML, CSS, images and fonts served from this site's own address; the light and dark versions follow the setting your own device already reports, and nothing about that choice is recorded.
The site is served with a content security policy that restricts network connections, scripts, fonts, images and styles to the site's own origin. In practice that means a third-party tracker cannot load on the page even if one were added by mistake.
Server logs. As with any web server, the platform that hosts this site records ordinary request logs, which include IP addresses, for operating and securing the service. The host is named in the table in section 5. We do not use those logs to identify or profile visitors.
There is no chat or assistant on this site. The two ways to write to us are email and the contact form, both covered in section 3, and both end in the same mailbox.
Do Not Track and Global Privacy Control. We do not track visitors across third-party websites, so there is no cross-site tracking for a Do Not Track browser signal to switch off, and we do not respond to DNT signals. We do not sell or share personal information, so a Global Privacy Control signal has nothing to opt out of. If that ever changes, we will honor GPC as an opt-out signal and will say so here before the change takes effect.
5Who else handles your information
Each provider below receives only what it needs for its role. Their contracts and published terms limit what they may do with it. Where a provider also acts for its own purposes, the table says so.
| Provider | What it handles | Role |
|---|---|---|
| Stripe, Inc. | Payment details; your name, email, shipping address, order amount | Processes payments, receipts and refunds on our instructions. Stripe also acts on its own account, as an independent controller, for fraud prevention, risk and legal compliance under its own terms |
| Our shipping carrier and label service [TO BE STAMPED] | Recipient name and shipping address | Printing the label and delivering the parcel. The carrier is not chosen yet; it is named in this table before this policy takes effect, and again at checkout before you pay |
| Intuit (QuickBooks Online) | Order and payment records for bookkeeping | Accounting |
| Service | What it handles | Who engages it |
|---|---|---|
| Microsoft 365 | Email you send us and we send you | Our mailbox is hosted in a Microsoft 365 tenant administered by an organization affiliated with our officer, not by this company. Its administrators can access the mailbox |
| Our website host [TO BE STAMPED] | Website hosting and request logs | Engaged by this company. The host is named here before this policy takes effect |
We also disclose information when the law requires it — a subpoena, a court order, a tax audit — and we would disclose it to a buyer or successor if the business were sold, in which case this policy would continue to govern the information until a replacement policy was published.
We do not use advertising networks. No advertising or social media platform receives customer or visitor data from us.
6We do not sell your personal information
We have never sold personal information, and we do not sell it now. We also do not “share” it in the sense that California law uses that word — that is, we do not disclose it to anyone for cross-context behavioral advertising. We do not use it for targeted advertising or for profiling that produces legal or similarly significant effects. We do not trade, rent, or license mailing lists.
If that ever changes, we will publish a revised policy with an opt-out mechanism before the first such disclosure.
7How long we keep things
| Record | Retention |
|---|---|
| Order records: name, address, email, items, amounts, tax | Seven years after the end of the calendar year of the order |
| Payment records held by Stripe | Under Stripe's own retention schedule |
| Notify-me list | Until you tell us to stop, or after 24 months with no order and no reply from you, whichever comes first |
| General correspondence not tied to an order | 24 months after the last message |
| Web server request logs | As retained by the hosting platform's default configuration |
| A record that you asked us to delete your information | Kept indefinitely, so that we can honor the request |
Seven years for order records is not arbitrary. A Florida dealer must keep sales-tax records until the assessment period expires, which runs three years in the ordinary case (Fla. Stat. §§ 212.13(2) and 95.091(3)) and longer where a return was not filed or was substantially understated; federal assessment periods run three years and can run six. Seven years covers both with margin and matches how we keep the company's books.
8Your choices, and how to exercise them
You can ask us to:
- Tell you what we have about you, and give you a copy of it.
- Correct anything that is wrong.
- Delete what we hold, subject to section 8.2.
- Stop emailing you anything other than notices about an order you placed.
8.1How to ask
Email hello@lyddandyaffa.com with the subject line “Privacy request” and tell us what you want. Use the email address you gave us when you ordered, or give us the order number, so we can match the request to a record. If we cannot verify that the request is yours, we will say so rather than act on it — refusing an unverified request is how we protect you from someone else asking about your order.
We answer within 45 days. If a request is complex and needs longer, we will tell you within those 45 days and take no more than 45 additional days. We do not charge for these requests.
You can appeal a decision by replying to it. We will review the appeal and respond in writing, with our reasons, within 45 days.
An authorized agent may act for you if you give us written permission we can verify.
8.2What we cannot delete
We keep, and will not delete on request:
- Records of a completed sale that we are required to keep for tax and accounting purposes, for the period in section 7.
- Records needed to complete a transaction you have not yet received, to process a return or exchange, or to handle a chargeback or dispute.
- Records needed to detect or defend against fraud or a legal claim.
- The minimal record of your deletion request itself.
Where we cannot delete something, we will tell you what we are keeping and why.
9Children
The site is not directed to children, and our products are not marketed to them. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has given us information, write to hello@lyddandyaffa.com and we will delete it. We also do not knowingly process the personal information of anyone under 18 for targeted advertising or sale — which we do not do for anyone at any age.
10Which US privacy laws apply to a company our size
A privacy policy that claims compliance with statutes that do not apply to the company is itself a misleading statement. Here is the accurate position.
10.1What applies to us now, regardless of size
These have no revenue or volume threshold, and we follow them:
- California Online Privacy Protection Act (Cal. Bus. & Prof. Code § 22575 et seq.) — a commercial website that collects personal information from a California resident must conspicuously post a privacy policy, identify the categories of information collected and the categories of third parties it is disclosed to, describe how changes to the policy are announced, carry an effective date, and disclose how the site responds to Do Not Track signals. The statute's review-and-change disclosure applies only where the operator maintains such a process (§ 22575(b)(2)); we do maintain one, and section 8 describes it. Sections 3, 4, 5, 8 and 13 of this policy exist to meet those points.
- Delaware Online Privacy and Protection Act — the equivalent obligation for Delaware residents.
- Nevada (NRS 603A.300–360) — a right to direct an operator not to sell covered information. We do not sell it (section 6), so there is nothing to opt out of, but a Nevada resident may send the request to the address in section 14 and we will confirm in writing within 60 days.
- Florida Information Protection Act (Fla. Stat. § 501.171) — applies to any commercial entity that handles personal information of Florida residents, with no size threshold. It requires reasonable measures to protect the data and, in the event of a breach, notice to affected individuals within 30 days of determining that the breach occurred, and notice to the Florida Department of Legal Affairs, on the same 30-day clock from determination, where 500 or more Florida residents are affected; a 15-day extension is available for good cause. We maintain a breach response procedure on that basis.
- Children's Online Privacy Protection Act — section 9.
- CAN-SPAM Act — any commercial email we send carries our physical postal address and a working way to stop receiving further messages, and we honor opt-outs within ten business days.
- Section 5 of the FTC Act and the Florida Deceptive and Unfair Trade Practices Act — a privacy policy is a representation to consumers, and an inaccurate one is actionable. That is why this document describes what we do rather than what we might reserve the right to do.
- Texas Data Privacy and Security Act and Nebraska Data Privacy Act — these two use no numeric threshold. They apply to any business that is not a small business as defined by the US Small Business Administration. We are a small business by that standard, so their main obligations do not currently bind us; however, their prohibition on selling sensitive personal data without consent applies to small businesses too. We sell no personal data of any kind.
10.2The comprehensive state laws, and why they do not bind us yet
Every comprehensive US state privacy law has an applicability threshold. We are below all of them. These are the ones that set the boundary:
| Law | It applies when a controller | Our position |
|---|---|---|
| California CCPA/CPRA | has annual gross revenue above $25,000,000, adjusted for inflation by the CPPA ($26,625,000 as adjusted; figure current as of the effective date of this policy); or buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year; or derives 50% or more of annual revenue from selling or sharing personal information | None of the three. Our revenue is a small fraction of the threshold, we are far below 100,000 California consumers, and we derive no revenue from personal information |
| Virginia VCDPA | controls or processes data of 100,000 Virginia consumers in a year; or 25,000 consumers and derives over 50% of gross revenue from the sale of personal data | Below both. Virginia sets no revenue-only trigger |
| Colorado CPA | 100,000 Colorado consumers in a year; or 25,000 consumers and derives revenue or a discount from selling personal data | Below both |
| Connecticut CTDPA | 100,000 consumers, excluding data processed solely to complete a payment transaction; or 25,000 consumers and over 25% of gross revenue from the sale of personal data | Below both. The payment-transaction carve-out means most of our customer records would not count |
| Utah UCPA | annual revenue of $25,000,000 or more and 100,000 consumers (or 25,000 consumers and over 50% of revenue from the sale of personal data) | Below the revenue floor, which is a required element |
| Delaware DPDPA | 35,000 Delaware consumers; or 10,000 consumers and over 20% of gross revenue from the sale of personal data | Below both |
| New Hampshire | 35,000 consumers; or 10,000 consumers and over 25% of gross revenue from the sale of personal data | Below both |
| Maryland MODPA | 35,000 consumers; or 10,000 consumers and over 20% of gross revenue from the sale of personal data | Below both |
| Other comprehensive state laws (including Oregon, Montana, Iowa, Indiana, Tennessee, Minnesota, New Jersey, Rhode Island, Kentucky) | thresholds generally in the range of 25,000 to 100,000 residents of that state per year, some with an additional revenue-share test | Below all of them |
Florida's own comprehensive law does not apply to us. The Florida Digital Bill of Rights (Fla. Stat. § 501.701 et seq.) reaches only entities with more than $1 billion in global gross annual revenue that also meet one of several additional conditions. That threshold is not one this company approaches at any plausible volume. Being a Florida seller does not put us under Florida's comprehensive privacy statute; it puts us under the Florida Information Protection Act in section 10.1, which does apply.
10.3What would change this
Two things move us across a line, and neither depends on us growing enormous:
- Resident counts, not order counts. Thresholds count consumers whose personal information we control or process in a year — not sales. A large notify-me or marketing list of residents of one state counts toward that state's threshold even if none of them ever buys. Delaware, New Hampshire and Maryland at 35,000 residents are the first lines we would cross.
- Selling or sharing data. Every one of these laws has a lower threshold, or none at all, for a business that sells personal data or derives revenue from it. Our answer to that is section 6, and it is a standing rule, not a current fact.
We re-check our position at each fiscal year end, and immediately if any single state's list of contacts passes 10,000 people. That review covers the thresholds above, the CPPA's biennial inflation adjustment to the California figure, the terms on which our providers process data, and who holds administrative access to the mailbox named in section 5. If we cross a threshold, we will publish a revised policy carrying the rights that law requires — including the right to opt out of sale, sharing, targeted advertising and certain profiling, and a formal appeal process — before the obligation takes effect.
We honor access, correction, deletion and opt-out requests from residents of any state on the terms in section 8, whether or not a statute requires it.
11The GDPR and the UK GDPR
We do not offer goods or services to people in the European Union, the European Economic Area, or the United Kingdom. As stated in section 2, we accept orders for delivery to United States addresses only, our checkout collects a shipping address only for the United States, we do not price in euros or pounds, and we do not direct any marketing to those regions. On that basis we do not offer goods or services to people in those territories within the meaning of Article 3(2), and the EU General Data Protection Regulation and the UK GDPR do not apply to our sale and fulfillment of orders.
A website being reachable from abroad does not by itself make the GDPR apply; what matters is whether a business is targeting people in those territories, and we are not.
If we begin accepting orders for delivery outside the United States, we will publish a revised policy first, carrying the legal bases, transfer safeguards, retention statements and data subject rights that those laws require. We will not accept the first such order before that page is live.
12Security
- The site is served only over HTTPS, with strict transport security enforced.
- No payment credential ever touches our systems — card details are entered on Stripe's hosted checkout page and stay with Stripe.
- Access to order records is limited to the company's officer, the administrators of the Microsoft 365 tenant that hosts our mailbox (section 5), and the service providers listed in section 5.
- The site's application secrets and keys are held in a managed key vault, not in files, documents, or email.
- The website's content security policy blocks third-party scripts and connections.
No system is perfectly secure, and we will not tell you otherwise. What we can tell you is that the most sensitive thing about a purchase — the payment instrument — is never in our custody to lose. If a breach affecting Florida residents occurs, we follow the notification requirements in section 10.1.
13Changes to this policy
If we change this policy, we post the revised version on this page and update the effective date at the top. Where a change materially affects how we handle personal information we already collected — for example, a new category of recipient, a new purpose, or any form of sale or sharing — we will describe the change at the top of this page and, where we hold your email address, tell you by email before the change takes effect. Continuing to use the site after a posted change means the revised policy applies to information collected from then on.
14How to contact us
Lydd & Yaffa, Inc. Email: hello@lyddandyaffa.comForm: lyddandyaffa.com/contact
Lydd & Yaffa, Inc. sells online only. Its legal name and address of record are stated in section 1 of the Terms of Sale.
For a privacy request, use the subject line “Privacy request” and follow section 8.1. For anything about an order — shipping, returns, exchanges — see our Terms of Sale and Returns Policy.