What we collect
When you join the Insiders List, we collect: your email address, an optional display name (an alias is welcome), an optional phone number with country code, your preferred contact channel, your notification opt-ins (opening-day reminders, featured items, new arrivals, deals), the collection categories you select, up to five free-text custom interests, the exact consent text shown to you at submission, the timestamp of your consent, and which form on the site you submitted from. Nothing else. We do not store your IP address, your location, your device fingerprint, or your browsing behavior on this site.
What we do not collect
We do not collect or store IP addresses on our own servers. The IP visible to our servers at the moment you submit a form is used transiently to enforce rate limits (counters in Upstash Redis, keyed on IP) and is never persisted to our contact database. Google reCAPTCHA, which protects the join form from bots, receives technical signals including your IP under Google's own privacy policy. We do not use third-party advertising cookies, behavioral retargeting, or cross-site tracking.
How we use what we collect
We use your information to send the updates you opted in to, to maintain a record of your consent, to remember the preferences you set on the management page, to recognize you if you sign up again with the same email, and to honor requests to update or delete your record. The site has no online checkout — we do not collect or process payment information here.
We do not sell or share your personal information
We do not sell, rent, license, or trade your personal information to third parties for money or other valuable consideration, as those terms are defined under California (CCPA / CPRA) and Nevada (SB-220) law. We do not share your information for cross-context behavioral advertising. If this ever changes, we will update this page and notify Insiders List members by email before the change takes effect.
How long we keep your information
We keep your record until you delete it or until twenty-four (24) months pass with no activity from you. "Activity" means opening or clicking a link in one of our emails, updating your preferences on the management page, or signing up again. If twenty-four months elapse without activity, we send a reminder email and wait sixty (60) more days; if you take no action in that window, we permanently delete the record. You can also delete your record at any time from your management link, no waiting period.
How to update or delete your record
Every confirmation email includes a personal management link that goes to /manage on this site. From there you can update your name, phone, contact preferences, and opt-ins, or delete your record entirely (a hard delete — the row is removed, not soft-flagged). If your management link is lost or expired, visit /manage/discern and enter your email. We will send the appropriate next step privately, and any older management link tied to your address stops working as soon as a new one is issued.
Your rights under CCPA, CPRA, and Nevada SB-220
If you are a California resident, you have the right to know what personal information we hold about you, to receive a copy of it, to correct inaccuracies, to delete it, and to opt out of any sale or sharing. If you are a Nevada resident, you have the right to opt out of the sale of covered information under SB-220. We do not sell your information in either jurisdiction, but you may still exercise these rights. Email the address listed in the "Contact us about privacy" section below; we respond within forty-five (45) days. We will not discriminate against you for exercising any of these rights.
Cookies and analytics
This site uses Google Analytics 4 to count visits and understand which pages get read, and Vercel Analytics to measure performance. Both are configured for aggregate measurement only — we do not enable Google's advertising features and Vercel Analytics is cookie-less by design. The site sets only a small number of strictly functional cookies (none for advertising). reCAPTCHA loads on the join form and runs invisibly to score whether a submission is human; that script is loaded only on pages with a form.
How we secure the data
All traffic to this site is served over HTTPS with HSTS. Form submissions are protected by Google reCAPTCHA v3 and per-IP rate limits backed by Upstash Redis. The management link is the only credential needed to read or change your record — no password, no account — and tokens are valid for one year and rotate when you request a fresh link. We do not store any password derivatives because there are no passwords. Database access is restricted to our application and to authorized staff under the employer's administrative controls.
Children's privacy
This site is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has submitted information, email the privacy address below and we will delete the record.
Contact us about privacy
Privacy questions, access requests, deletion requests, and any concerns about this policy go to [email protected]. We respond within forty-five (45) days. The mailing address for Authentiques Boutique is 801 Bridge St Suite E, Verdi, NV 89439.
Changes to this policy
We will note the "Last updated" date at the top of this page when we change the policy. For changes that materially affect what we collect, how we use it, or how long we keep it, we will email Insiders List members at the address on file before the change takes effect. The version of this policy you agreed to at signup is preserved on your record as the literal text of the consent statement shown to you at the time.