We use data to do the work.
That includes responding to you, processing purchases, delivering files, maintaining accounts, providing support, and securing the site.
Privacy · Commerce · Forms · Cookies
We collect the information needed to run the site, answer inquiries, fulfill orders, deliver downloads, support customers, and protect the system. This policy explains what that means in practice.
Effective: August 29, 2026
That includes responding to you, processing purchases, delivering files, maintaining accounts, providing support, and securing the site.
We do not rent personal information or use it for third-party targeted advertising or profiling that produces legal or similarly significant effects.
The payment provider handles full card or account credentials. We receive limited billing, transaction, and fulfillment information.
Do not submit classified information, CUI, credentials, government identifiers, payment-card data, health data, or similarly sensitive material through ordinary site forms.
01 · Scope & Our Role
This Privacy Policy explains how 9th Story Foundry LLC (“9th Story Foundry,” “Foundry,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you visit the Site, submit a form, create an account, place an order, access a download, request support, subscribe to a communication, or otherwise interact with us online.
For ordinary Site, account, order, and direct business interactions, 9th Story Foundry determines why and how the information is used and acts as the business or data controller.
A signed agreement may separately govern information handled during a consulting, advisory, assessment, implementation, vFSO, research, or other client engagement. When we process personal information inside a customer-controlled system or solely on a customer’s documented instructions, the customer may be the controller and we may act as its processor or service provider. The applicable agreement, security requirements, and customer privacy notice will control that processing to the extent they differ from this Site policy.
This policy does not apply to third-party sites or services that merely link to or from the Site.
02 · Information We Collect
Full payment-card or bank credentials are handled by the payment provider. They are not intended to be stored in the ordinary 9th Story Foundry WordPress database.
03 · Sensitive Information
Do not submit classified information, Controlled Unclassified Information (CUI), export-controlled technical data, government-system credentials, passwords, private keys, Social Security numbers, complete payment-card data, precise medical or health information, biometric identifiers, criminal-history records, or other information that requires a specifically authorized security boundary.
If an authorized engagement requires sensitive information, we will work with the customer to establish an appropriate system, access model, transfer method, retention rule, and contractual basis before collection. If you send sensitive material through an inappropriate channel, we may delete it, isolate it, or ask you to resubmit it securely.
04 · How We Use Information
Depending on the interaction, we use personal information to:
Where applicable, our legal bases may include performing or taking steps toward a contract; our legitimate interests in operating, securing, improving, and communicating about the business; compliance with legal obligations; protection of legal rights; and consent when consent is required. You may withdraw consent prospectively, but withdrawal does not make earlier lawful processing unlawful.
We do not sell or rent personal information. We do not use Site personal information for third-party targeted advertising or for profiling in furtherance of decisions that produce legal or similarly significant effects.
05 · Cookies & Site Technologies
Cookies, local storage, session identifiers, pixels, scripts, and similar technologies can remember a cart, maintain a login, store a preference, prevent fraud, measure performance, or help a third-party service deliver requested content.
| Category | Examples and purpose | Typical status |
|---|---|---|
| Essential commerce | woocommerce_cart_hash and woocommerce_items_in_cart help detect cart changes; wp_woocommerce_session_* connects a visitor to server-side cart data. Checkout, fraud-prevention, tax, account, and download functions may use related identifiers. |
Required for requested store functions |
| Account and security | WordPress and security tools may use authentication, session, preference, anti-abuse, and administrative cookies to maintain login state and protect the Site. | Required when the feature is used |
| Consent and preferences | These remember language, display, privacy, or cookie choices so the Site does not repeatedly ask the same question. | Functional |
| Forms and anti-spam | Form, CAPTCHA, bot-detection, and email-delivery providers may use technical identifiers to validate submissions, limit abuse, and route messages. | Required for the submitted form; provider-dependent |
| Analytics and performance | If enabled, these tools help us understand aggregate visits, errors, page performance, and conversion. Non-essential analytics should be controlled through the available consent mechanism where law requires. | Optional when non-essential |
At the effective date of this policy, portions of the Site may request the Archivo typeface from Google-hosted font services and certain front-end animation libraries from the jsDelivr content-delivery network. When a browser requests an external file, the provider receives ordinary technical request information such as IP address, browser or device details, requested URL, referring page, and timestamp. We may self-host or replace these resources later, in which case this description will be updated when the change is material.
Embedded video, social feeds, maps, scheduling widgets, or other third-party content may behave as though you visited the provider directly and may set cookies or collect interaction data under that provider’s policy. A simple outbound link ordinarily does not transmit the same level of interaction data until you follow it.
You can use the Site’s cookie or privacy controls when available and can also block or delete cookies through your browser. Blocking essential cookies may prevent carts, checkout, accounts, downloads, forms, or other requested functions from working. Browser “Do Not Track” signals are not interpreted consistently across the industry. We will honor legally recognized opt-out mechanisms where they apply to our actual processing.
06 · How Information Is Shared
We may disclose personal information to the following categories of recipients, limited to what is reasonably necessary for the purpose:
Service providers may process information in the United States or other locations and are governed by their own legal obligations and our contracts with them where applicable. Payment providers independently determine some uses of transaction data, such as authorization, fraud prevention, compliance, and dispute handling.
07 · Retention
Retention depends on the type of information, why it was collected, account and order status, customer instructions, security needs, applicable limitation periods, and tax, accounting, employment, contracting, certification, regulatory, or other legal requirements.
In general:
We may retain information longer when required by law, legal hold, audit, insurance, dispute, investigation, or security need. We may retain aggregate or de-identified information that no longer reasonably identifies an individual. When retention is no longer justified, we delete, anonymize, or securely dispose of the information using methods appropriate to its sensitivity and the systems involved.
08 · Security
We use administrative, technical, and organizational measures designed for the nature of the Site and information involved. Measures may include access restrictions, role-based administration, encryption in transit where supported, protected payment processing, account controls, patching, backups, logging, anti-spam and security services, vendor review, and procedures for responding to suspected incidents.
No website, email system, cloud platform, transfer method, or storage system can be guaranteed completely secure. You are responsible for using a strong unique password, protecting credentials and download links, maintaining secure copies of purchased files, limiting internal access, and notifying us promptly of suspected unauthorized access.
If a security incident involving personal information occurs, we will investigate and provide notices to affected individuals, customers, regulators, or others when required by applicable law or agreement.
09 · Your Rights & Choices
Depending on where you live and the law that applies, you may have the right to:
We do not currently sell personal information or use it for third-party targeted advertising or qualifying high-impact profiling. You may unsubscribe from marketing emails using the link in the message. Transactional, account, security, order, and service communications may continue when needed to provide a requested product or fulfill an obligation.
Email info@9thstory.io with the subject line Privacy Request and describe the request. We may need to verify identity, authority, account ownership, or residency before acting. An authorized agent may submit a request where law permits, but we may require proof of authority and direct verification with the individual.
Some information cannot be deleted or disclosed because of another person’s rights, privilege, security, fraud prevention, tax or accounting duties, transaction records, legal claims, customer instructions, or other lawful exceptions. We will explain a denial when required. Even when a particular privacy law does not formally apply to us or to the request, we will make reasonable efforts to honor legitimate access, correction, and deletion requests that do not conflict with legal, contractual, security, or operational obligations.
9th Story Foundry does not use Site personal information to make solely automated decisions that produce legal or similarly significant effects. Payment, fraud-prevention, security, and platform providers may use automated tools to evaluate transactions or misuse under their own terms and policies.
10 · International Use & Children
9th Story Foundry is based in Kentucky, United States. If you access the Site from another country, your information may be transferred to, stored in, or processed in the United States and other locations where our providers operate. Those locations may have different data-protection laws. Where required, we rely on contractual, consent, necessity, adequacy, or other lawful transfer mechanisms.
The Site and its business products and services are not directed to anyone under 18. We do not knowingly collect personal information online from a child under 13. If you believe a child provided personal information without appropriate authorization, contact us so we can investigate and delete it when required.
11 · Third-Party Sites & Services
The Site may link to or integrate with payment providers, scheduling tools, social networks, professional platforms, standards bodies, certification bodies, government sites, software vendors, video providers, maps, or other services. Their privacy notices and settings—not this policy—govern information they collect for their own purposes.
Review a third party’s terms and privacy practices before providing information or connecting an account. We are not responsible for a third party’s independent content, security, availability, or data practices merely because the Site links to or interoperates with it.
12 · Changes & Contact
We may revise this Privacy Policy to reflect changes in the Site, products, providers, business practices, or law. The effective date at the top identifies the current version. When a change is material, we may also provide notice through the Site, account, checkout, or email as appropriate.
Questions, concerns, or privacy requests may be sent to:
9th Story Foundry LLCFor purchase-related requests, include the order number and account email. Do not include sensitive credentials or protected information in the request.