At Can't Say That, we're all about saying what others won't — but when it comes to your data, we keep it locked up tighter than our most controversial designs. This policy explains what we collect, why we collect it, and what we do (and don't do) with it.
Short version: We collect what we need to sell you shirts and ship them to your door. We don't sell your info. We're not monsters.
INFORMATION WE COLLECT
When you place an order, we collect:
- Your name and email address
- Shipping address
- Order details (what you bought, quantity, price)
Note: We do not collect or store your payment details. That goes straight to Stripe. Ask them if you're nervous about it — they're great at security.
When you visit the site, standard server logs may collect your IP address, browser type, pages visited, and time spent. This is automatic and boring. It helps us understand what's working.
If you sign up for emails, we collect your email address. That's it. We will not ask for your blood type.
HOW WE USE YOUR INFORMATION
We use your information to:
- Process and fulfill your orders (obviously)
- Send order confirmation and shipping notifications
- Handle returns, exchanges, or support issues
- Send marketing emails, only if you opted in
- Improve the site and understand what chaos resonates with people
- Detect fraud or prevent unauthorized transactions
We do not sell, rent, trade, or otherwise hand over your data to third parties for their marketing purposes. We're a shirt company, not a data broker. Very different vibes.
DATA RETENTION
We keep order records as required for tax, accounting, and legal purposes (typically 7 years — not our choice, that's the IRS). Email subscriber data is kept until you unsubscribe.
If you'd like us to delete your personal data beyond legal requirements, contact us and we'll handle it. We're not hoarders.
YOUR RIGHTS
Depending on your location, you may have rights under GDPR, CCPA, or other privacy laws, including:
- The right to access the personal data we hold about you
- The right to correct inaccurate data
- The right to request deletion of your data
- The right to opt out of marketing communications
- The right to data portability
To exercise any of these rights, just email us. We respond within 30 days. California residents: we do not sell personal information and have not done so in the preceding 12 months.
CHILDREN'S PRIVACY
Our site and products are intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, contact us immediately and we'll delete it promptly.
Also: please don't buy our shirts for children. You've seen what's on them.
SECURITY
We implement reasonable technical and organizational measures to protect your data from unauthorized access, disclosure, or loss. Our site uses HTTPS. Sensitive settings (like API keys) are encrypted at rest.
No method of transmission over the internet is 100% secure. If you spot a vulnerability, please email us rather than exploiting it. We will thank you. Sincerely.
CHANGES TO THIS POLICY
We may update this policy from time to time. The "Last Updated" date at the top will reflect any changes. Significant changes will be announced via email to subscribers. Continuing to use the site constitutes acceptance of the updated policy.
QUESTIONS ABOUT PRIVACY?
We're humans behind this store and we take your privacy seriously.
Reach us anytime: