Last updated: July 20, 2026
Privacy Policy
This Privacy Policy describes how thefrostycone LLC, a California limited liability company doing business as The Frosty Cone and based in San Diego, California (“we,” “us,” or “our”), handles personal information when you interact with us through thefrostycone.com (the “Site”), email at [email protected], direct messages on Instagram, Facebook, or TikTok, or in-person purchases at our cart, farmers markets, and Southern California events. We sell NZ-style real fruit ice cream in person; the Site is for information and contact, not online checkout.
This notice is provided for transparency and to support compliance with California’s Online Privacy Protection Act (CalOPPA) and, where applicable, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). We are a small retail food business — not a data broker — and we collect only what we need to respond to you and run in-person sales.
Information we collect
We do not operate customer accounts, newsletters, or online payment on the Site. We do not collect email addresses in person at our cart or events as part of a loyalty or marketing list. We do not intentionally collect sensitive personal information (such as government ID numbers, precise geolocation tracking, or health data). If you include extra details in a message, we use them only to respond.
Categories of personal information (California notice)
Depending how you interact with us, we may collect the following categories of personal information:
- Identifiers — name, email address, social media username, and IP address
- Customer records / commercial information — inquiry or booking messages, and in-person purchase/transaction details available to us through Square’s merchant tools
- Internet or electronic activity — pages viewed, referring URL, browser type, and timestamps in server logs; bot-protection signals when you use the contact form
- Audio/visual information — photos or video we take at public markets or events that may incidentally include people near our cart (see Photos below)
Website contact form
- Fields: name, email address, selected topic, and message.
- Delivery: submissions are emailed to our business inbox via SMTP (Google Workspace). We keep those emails and messages for business records and follow-up — we do not maintain a separate customer marketing database beyond that correspondence.
- Bot protection: Cloudflare Turnstile may verify that a human submitted the form. When enabled, your IP address and related browser signals are sent to Cloudflare for verification.
- Server logs & rate limiting: our hosting may log IP address, browser type, referring page, pages viewed, and timestamps for operation and security. The contact API may use IP address for short-term rate limiting to reduce abuse.
- Maps and schedule: the Find Us section uses OpenStreetMap tiles through Leaflet. Outbound “Open in Google Maps” links go to Google. Loading our public schedule does not require you to provide personal information. Third-party map providers have their own privacy practices.
Email and Google Workspace
When you email us or we reply, your email address, name (if provided), message content, and related metadata are stored in our Google Workspace account. That includes Site contact-form messages and direct email about bookings, questions, or events.
Social media direct messages
If you message us on Instagram, Facebook, or TikTok, we receive what you send (such as username, profile information visible on the platform, and message content). Each platform processes data under its own privacy policy; we use what you send only to respond and coordinate.
In-person payments (Square)
Card payments at our cart, farmers markets, and events are processed by Square. Square collects and processes payment card information and related transaction data. We do not receive or store your full card number on our own systems. As a Square merchant, we may see normal point-of-sale records in Square’s dashboard (for example, transaction amount, time, payment method details Square provides, and any customer information Square associates with a sale under its standard POS features). We do not run custom online data collection beyond contact-form emails and ordinary Square use.
Square’s practices are described in Square’s Privacy Notice.
Photos and video at markets and events
We occasionally take photos or video at our cart, farmers markets, and public events to share on the Site and social media. These may incidentally include people near our cart in a public setting. We do not intentionally feature identifiable customers without asking first. If you appear in content we posted and want it removed, email [email protected] and we will take it down promptly.
How we use information
We use personal information to:
- Respond to inquiries and coordinate bookings or events
- Operate, maintain, and secure the Site
- Process and record in-person sales
- Maintain business, tax, and accounting records
- Comply with applicable law
We do not use your information for third-party advertising, and we do not sell your personal information.
How we share information
We do not sell your personal information. We also do not “share” personal information for cross-context behavioral advertising as defined under California law. Because we do not sell or share personal information in those ways, we do not offer a “Do Not Sell or Share My Personal Information” link — there is nothing to opt out of. If our practices change, we will update this policy and provide any required opt-out method.
We disclose information to service providers that help us operate, including:
- Google Workspace (email storage and business communications)
- SMTP / hosting infrastructure used to deliver the contact form
- Square (in-person payment processing and merchant dashboard records)
- Cloudflare Turnstile (contact-form bot verification)
- Instagram, Facebook, and TikTok (when you contact us on those platforms)
- Map tile / link providers you choose to use (OpenStreetMap via Leaflet; Google Maps when you follow an outbound link)
These providers process information on our behalf or under their own terms when you interact with their services directly. We do not share your contact information with third parties for their own direct marketing.
California’s “Shine the Light” law (Civil Code § 1798.83) gives certain California customers the right to request information about personal information disclosed to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes as described in that statute.
Cookies, analytics, and advertising
We do not use third-party advertising, marketing pixels, or retargeting pixels on the Site. We do not use third-party analytics services (such as Google Analytics) that track you across other websites for advertising purposes.
The Site may use essential cookies or similar technologies for basic operation and security. Cloudflare Turnstile may set cookies or use browser storage when you complete contact-form verification. These are not used for third-party ads or cross-site marketing tracking.
Do Not Track: Some browsers transmit “Do Not Track” (DNT) signals. Because there is no uniform industry standard for responding to DNT, we do not alter our practices based solely on a DNT signal.
Retention
Contact-form emails and other messages are kept in our inbox for records and follow-up as long as reasonably needed for business, legal, and accounting purposes. Social media messages remain on those platforms according to their settings. Square transaction records are retained per Square’s policies and our accounting needs. Server logs and short-term rate-limit data are retained according to our hosting configuration.
Security
We use reasonable administrative, technical, and organizational measures to protect information. Payment card data is handled by Square, not stored on our systems. No method of transmission over the Internet is completely secure.
Children
Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us so we can delete it.
California residents — privacy rights
As a small business, we may fall below the revenue or volume thresholds that make the CCPA/CPRA’s full set of obligations legally applicable. Regardless, we honor the following requests for California residents in good faith:
- Know what personal information we collect, use, and disclose
- Access a copy of personal information we hold about you
- Request deletion of personal information we collected from you
- Request correction of inaccurate personal information
- Opt out of the “sale” or “sharing” of personal information (we do not sell or share as described above)
- Limit use of sensitive personal information (we do not collect sensitive personal information for the purposes CCPA/CPRA regulates)
Some information may be retained where allowed or required (for example, completed sales records needed for tax or accounting, or information we must keep to secure our systems). We will explain if we cannot fully delete something for those reasons.
To exercise these rights, email [email protected] with “California Privacy Request” in the subject line. We will verify your request (typically by confirming control of the email address used to contact us) and respond within the timeframes California law allows when applicable (generally 45 days, with a possible extension where permitted). You may designate an authorized agent in writing where permitted.
We will not discriminate against you for exercising privacy rights under California law.
Accessibility
We aim to make the Site usable for people with disabilities and welcome feedback. If you encounter a barrier, please email [email protected].
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date above.
Contact
Questions about this policy or privacy requests: [email protected]