Privacy Policy
This policy explains what personal information Dragon Labs LLC collects when you use dragonlab.us, why we collect it, who we share it with, and what control you have over it.
1. Introduction
Dragon Labs LLC ("Dragon Labs", "we", "us") is the controller of the personal information described in this policy. We are based at 7537 East McDonald Drive, Scottsdale, AZ 85250, United States, and you can reach us about anything on this page at support@dragonlab.us.
The short version. We collect what we need to take your order, ship it and answer your questions — and nothing more. We do not sell your personal information. We never see your full card number. We do not run advertising or tracking pixels on this site.
2. Information we collect
Information you give us
- Order and delivery details — name, email address, phone number, shipping address and the configuration you ordered.
- Account details — if you choose to create an account, your name and email address, and a password which we store only as a secure one-way hash and never in readable form. An account is optional; you can check out as a guest.
- Enquiry details — anything you type into our contact form, including your name, email, company and the content of your message.
- Business details — where you ask us to invoice against a purchase order, the institutional and billing details needed to do that.
Information collected automatically
- Server logs — IP address, date and time, the page requested, HTTP status, referring page and browser user-agent string. These are written by the web server for security and diagnostics.
- Session cookie — a single first-party cookie that remembers what is in your shopping cart, keeps you signed in if you are using an account, and secures your form submissions.
Information we receive from Stripe
- Confirmation of payment status, the amount and currency, the card brand and last four digits, and the billing and shipping details you entered at Stripe's checkout.
We do not collect special categories of personal data, we do not ask for government identifiers, and we do not build behavioural profiles.
3. Where the information comes from
Almost all of it comes directly from you — through the order form, the Stripe checkout page or the contact form. The remainder is generated automatically by our web server, or passed to us by Stripe once a payment completes. We do not buy contact lists or enrich your record from third-party data brokers.
4. How we use your information
- To take payment, fulfil your order and arrange delivery.
- To send transactional messages — order confirmation, dispatch and tracking notices, account email verification, and anything we need to ask you about your order.
- Where you create an account, to authenticate you and show you your own order history and tracking.
- To answer your enquiries and provide pre-sales and technical support.
- To handle warranty claims, damage claims and disputes.
- To keep accounting and tax records as United States law requires.
- To detect and prevent fraud, abuse of the website, and chargeback fraud.
- To improve our product information where an enquiry shows something was unclear.
We do not use your information for advertising, we do not add you to a marketing list because you bought something, and we do not send promotional email unless you have asked us to.
5. Our legal basis
Where data protection law requires us to identify a basis for processing, we rely on: performance of a contract (taking and fulfilling your order); legitimate interests (securing the website, preventing fraud, answering enquiries and keeping business records); legal obligation (tax and accounting retention); and consent where you have specifically asked us to contact you about something. You may withdraw consent at any time.
6. Payment information and Stripe
Card payments are processed by Stripe, Inc. Our checkout form is served on our own site, but the card fields themselves are hosted by Stripe inside a secure frame: your card number, expiry date and security code are submitted directly to Stripe and are never transmitted to, processed by or stored on our server.
Stripe acts as an independent controller of the payment data it collects and processes it under its own privacy policy, which you can read at stripe.com/privacy. Stripe may use device and transaction signals for fraud prevention. We receive back only the confirmation details listed in section 2.
PCI DSS compliance. Because card data is captured and handled entirely by Stripe — a PCI Service Provider Level 1 certified provider, the highest level defined by the Payment Card Industry Data Security Standard — our systems never touch cardholder data. Our own compliance is therefore assessed under the simplest self-assessment questionnaire (SAQ A), and we do not store, process or transmit full card numbers on our servers at any point.
7. Who we share information with
We share personal information only with the following categories of recipient:
- Stripe, Inc. — payment processing and fraud prevention.
- Shipping carriers — the name, address and phone number needed to deliver your parcel and to let you track it.
- Our web host and email provider — who store the site, its database and our mail on our behalf under contract.
- Manufacturers and service agents — where a warranty or spare-parts claim requires it, and then only the details needed to process that claim.
- Our accountant and, where required, tax authorities — for record keeping and tax compliance.
- Legal and professional advisers, courts or law enforcement — where we are legally required to disclose, or need to establish or defend a legal claim.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. If our business were ever sold or merged, customer records could transfer to the buyer as part of the assets — the buyer would remain bound by this policy in respect of that information.
8. Cookies and similar technologies
This site uses one strictly necessary first-party cookie: the PHP session cookie. It holds a random identifier that lets the server remember your shopping cart between pages and validate that a form submission came from you. It contains no personal information itself, and it expires when you close your browser or after a period of inactivity.
We also store the item count of your cart in your browser's sessionStorage, so the cart icon can animate when the count changes. That value never leaves your device.
We do not use analytics cookies, advertising cookies, social media
pixels or cross-site trackers. Fonts are loaded from Google Fonts, which means your
browser makes a request to fonts.googleapis.com and
fonts.gstatic.com; Google receives your IP address as part of that request
and states that it does not use it to build advertising profiles.
Stripe sets its own cookies on Stripe's checkout page, and uses them for fraud detection. That happens on Stripe's domain and is covered by Stripe's privacy policy.
You can block or delete cookies in your browser settings. Blocking the session cookie will stop the shopping cart and checkout from working.
9. How long we keep information
- Order records — for at least seven years from the order date, to satisfy United States tax and accounting requirements and to support warranty claims.
- Contact-form enquiries — normally up to 24 months, then deleted, unless the enquiry became an order or a dispute.
- Account records — for as long as you keep the account. Ask us to close it and we delete the account login (your order records are retained separately as above for tax and warranty purposes).
- Server access logs — typically 30 to 90 days, depending on our host's rotation schedule.
- Session cookie — until your browser session ends.
When a retention period ends we delete the information or irreversibly anonymise it.
10. How we protect information
The whole site is served over HTTPS. Card data never reaches our systems. Our database credentials and API keys are stored outside the public web root and are not accessible over the web. Administrative access to order records requires a password-protected login with a rolling session timeout, and passwords are stored only as salted hashes. Order forms are protected against cross-site request forgery.
No system is perfectly secure. If a breach ever affected your personal information in a way that posed a risk to you, we would notify you and any regulator we are required to notify, without undue delay.
11. Your rights and choices
Subject to the law that applies to you, you may ask us to:
- Access — give you a copy of the personal information we hold about you.
- Correct — fix information that is wrong or incomplete.
- Delete — erase information we no longer have a lawful reason to keep. We cannot delete order records we are legally required to retain.
- Restrict or object — pause or stop a particular use of your information.
- Port — receive certain information in a portable, machine-readable format.
- Withdraw consent — where we relied on your consent.
Email support@dragonlab.us and we will respond within 30 days. We may need to verify your identity before acting — usually by confirming details of an order you placed. Exercising these rights is free, and we will never treat you differently for doing so.
12. Notice for California residents
If you are a California resident, the California Consumer Privacy Act as amended gives you the rights to know, delete, correct and opt out of sale or sharing, and the right not to be discriminated against for exercising them.
In the preceding twelve months we have collected the categories of personal information described in section 2 — identifiers, commercial information, and internet activity information — for the business purposes in section 4, and disclosed them to the service providers in section 7.
We have not sold or shared personal information, and we do not sell or share the personal information of any consumer, including anyone under 16. Because we do not sell or share, there is no opt-out for you to exercise; you may still make an access, deletion or correction request using the contact details in section 16.
13. Children
This website and our products are intended for professional and institutional buyers. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.
14. International transfers
We operate in the United States and our servers and service providers are located there. If you contact or order from us from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection rules from your own country. By using the site you understand that transfer.
15. Changes to this policy
We will update this page when our practices change, and we will change the "last updated" date at the top. Where a change is material we will make it prominent on the site. Continuing to use dragonlab.us after a change means you accept the updated policy.
16. How to contact us
For any privacy question, or to exercise a right described above:
Dragon Labs LLC — Privacy
7537 East McDonald Drive, Scottsdale, AZ 85250
United States
support@dragonlab.us
Related: Terms & Conditions · Returns & Refunds · Shipping Policy
