Privacy Policy
How we collect, use, and protect your information. The short version: we never sell your data.
1. Overview
Green Drain, Inc. ("Green Drain," "we," "us") respects your privacy. This policy explains what personal information we collect through greendrains.com, why we collect it, and how we protect it.
This policy applies to all visitors, form submitters, newsletter subscribers, and customers who interact with our website. By using greendrains.com, you agree to the practices described here.
2. Information we collect
Information you provide directly
When you fill out a form on our website, you choose to share information with us. This includes:
- Contact form: name, email, phone (optional), company (optional), inquiry type, and your message
- Quote request form: name, email, phone, company, role, facility type, facility name, location, drain sizes needed, estimated quantity, timeline, and project details
- Newsletter signup: email address
- Product orders: name, shipping address, billing address, email, phone, and payment information (processed by Shopify, not stored on our servers)
Information collected automatically
When you visit our website, we may automatically collect:
- Usage data: pages visited, time spent on pages, referring URLs, and click patterns
- Device data: browser type, operating system, screen resolution, and device type
- Network data: IP address and approximate geographic location (country/region level)
This data is collected through analytics tools and is used in aggregate to improve our website. We do not use this data to personally identify you.
3. How we use your information
We use the information we collect to:
- Respond to your inquiries: answer questions, provide quotes, and connect you with the right team member or distributor
- Process orders: fulfill product purchases, manage shipping, and handle returns
- Send communications: order confirmations, quote follow-ups, and (if you opted in) newsletter updates about products and industry research
- Improve our website: analyze usage patterns to make the site faster, more useful, and easier to navigate
- Comply with legal obligations: respond to lawful requests from authorities and enforce our terms
We do not use your information for purposes unrelated to those listed above.
4. What we do not do
To be clear:
- We never sell your personal information. Not to advertisers, data brokers, or anyone else.
- We never rent your email list. Your email is used only for the purposes you gave it to us for.
- We do not run targeted advertising based on your personal browsing behavior across other websites.
- We do not sell or share behavioral data collected through analytics or session recording tools with third parties for their own marketing purposes.
5. Cookies and tracking technologies
Our website uses cookies and similar technologies. We organize them into three categories:
Strictly necessary
These cookies are required for the website to function and cannot be switched off. They include security tokens, shopping cart state, and regional preferences.
Performance and analytics
We use Google Analytics 4 (GA4) and Microsoft Clarity to understand how visitors use our site. These tools collect usage data such as pages visited, time on page, scroll depth, click patterns, and referring URLs. GA4 sets cookies (such as _ga and _ga_*) to distinguish unique visitors. Clarity sets cookies (such as _clck and _clsk) and records anonymized session replays, including mouse movement, clicks, and scrolling behavior.
Session replay data does not capture text you type into form fields. It is used solely to identify usability issues and improve page layout.
These tools do not load until you provide consent (or, in the United States, until you opt out).
Targeting and advertising
We do not currently run any advertising cookies or retargeting pixels. If we add advertising tools in the future, they will require your explicit consent before loading, and this policy will be updated to reflect that change.
Your cookie choices
When you first visit our site, a consent banner lets you accept or reject non-essential cookies. You can change your preferences at any time by clicking the "Privacy" button in the bottom-left corner of any page. You can also disable cookies in your browser settings, though some website features may not function properly without essential cookies.
Our site honors the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, we automatically treat it as an opt-out of non-essential cookies and do not load analytics or tracking tools.
Cookie reference
| Cookie | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
__cf_bm |
Cloudflare | Bot management | 30 minutes | Strictly necessary |
cf_clearance |
Cloudflare | Security challenge clearance | 30 minutes | Strictly necessary |
cart, _shopify_y |
Shopify | Shopping cart and checkout | Session / 1 year | Strictly necessary |
_ga, _ga_* |
Google Analytics | Distinguish unique visitors, measure traffic | Up to 2 years | Performance |
_clck, _clsk |
Microsoft Clarity | Session recording, heatmaps, usage analytics | Up to 1 year | Performance |
MUID |
Microsoft Clarity | Cross-session user identification for Clarity | 1 year | Performance |
First-party localStorage keys (gd-region, gd-country, gd-consent) are used for regional preferences and storing your cookie consent choice. These are strictly necessary and do not transmit data to third parties.
6. Third-party services
We use a limited number of third-party services to operate our website and business. Each has access only to the information necessary for their function:
- Cloudflare: website hosting, CDN, security, and analytics orchestration (Zaraz). Cloudflare processes server-level data (IP addresses, request data) under their privacy policy.
- Google Analytics 4 (GA4): website traffic measurement. Collects pages visited, session duration, referral source, device type, and approximate location (country/region). Data is processed by Google under their privacy policy. IP addresses are anonymized. GA4 loads only after you consent to performance cookies (or, in the US, unless you opt out).
- Microsoft Clarity: session recording and heatmap analytics. Records anonymized replays of how visitors interact with pages (mouse movement, clicks, scrolling) to help us identify usability issues. Text entered in form fields is not captured. Data is processed by Microsoft under their privacy statement. Clarity loads only after you consent to performance cookies.
- Shopify: order processing and payment handling. Payment information is processed directly by Shopify and is not stored on our servers. See Shopify's privacy policy.
- Resend: transactional email delivery for form submissions (contact, quote requests, distributor applications). Resend processes your name and email address solely to deliver the message. See Resend's privacy policy.
We do not share your personal information with any third parties beyond those listed above.
7. Data retention
We retain your personal information only as long as necessary for the purposes described in this policy:
- Contact and quote inquiries: retained for up to 3 years to support ongoing customer relationships and follow-up
- Order records: retained as required by tax and accounting regulations (typically 7 years)
- Newsletter subscriptions: retained until you unsubscribe
- Analytics data: aggregated data is retained indefinitely. Individual-level data is deleted or anonymized within 26 months.
8. Data security
We take reasonable measures to protect your information:
- All data transmitted to and from our website is encrypted via HTTPS/TLS
- Our website is hosted on Cloudflare's infrastructure with enterprise-grade DDoS protection and Web Application Firewall
- Payment information is processed by Shopify's PCI DSS Level 1 compliant systems and is never stored on our servers
- Access to customer data is limited to authorized team members who need it to respond to your inquiry or fulfill your order
No method of electronic storage or transmission is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
9. Your rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: request a copy of the personal information we hold about you
- Correction: request that we update or correct inaccurate information
- Deletion: request that we delete your personal information, subject to legal retention requirements
- Opt-out: unsubscribe from marketing emails at any time using the link in any email we send
- Data portability: request your data in a commonly used, machine-readable format
To exercise any of these rights, email [email protected]. We will respond within 30 days.
10. California residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), provides you with specific rights regarding your personal information.
Categories of personal information we collect
| Category | Examples | Source | Business purpose |
|---|---|---|---|
| Identifiers | Name, email, phone, IP address | You (forms), automatic collection | Respond to inquiries, fulfill orders, site security |
| Commercial information | Order history, products purchased | Shopify (orders) | Fulfill orders, customer support |
| Internet activity | Pages visited, click patterns, session replays, referral source | GA4, Clarity (automatic) | Website improvement, usability analysis |
| Geolocation | Country and region (approximate, from IP) | Cloudflare (automatic) | Regional content, analytics |
Your rights
- Right to know: request what personal information we collect, use, and disclose
- Right to delete: request deletion of your personal information, subject to legal exceptions
- Right to correct: request correction of inaccurate personal information
- Right to opt out of sale/sharing: we do not sell personal information and do not share it for cross-context behavioral advertising
- Right to limit use of sensitive PI: we do not collect sensitive personal information as defined by CPRA
- Right to non-discrimination: we will not treat you differently for exercising your privacy rights
Do Not Sell or Share
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. Our analytics tools (GA4, Clarity) process data on our behalf as service providers under written contracts, not as third parties receiving data for their own purposes.
Global Privacy Control
We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request under CCPA/CPRA. If your browser sends a GPC signal, we automatically treat it as a request to opt out of the sale or sharing of personal information and do not load non-essential analytics tools.
How to submit a request
To exercise any of these rights, email [email protected] with the subject line "CCPA Request." We will verify your identity and respond within 45 days. You may also designate an authorized agent to submit a request on your behalf.
Retention
We retain personal information only as long as necessary for the business purposes described in this policy. See Section 7 (Data retention) for specific timeframes.
11. European Economic Area and United Kingdom (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom (UK), the General Data Protection Regulation (GDPR) and UK GDPR provide you with additional protections.
Legal basis for processing
- Consent: analytics and session recording tools (GA4, Clarity) load only after you consent via our cookie banner. You may withdraw consent at any time by clicking the "Privacy" button on any page.
- Legitimate interest: website security (Cloudflare), bot management, and aggregated analytics for site improvement.
- Contract performance: processing your order, delivering products, and responding to your quote or contact requests.
- Legal obligation: retaining order records for tax and accounting purposes.
International data transfers
Green Drain, Inc. is based in the United States. When you submit information to us, your data may be transferred to and processed in the US. We rely on the following transfer mechanisms:
- Cloudflare: EU-US Data Privacy Framework participant
- Google (GA4): EU-US Data Privacy Framework participant, Standard Contractual Clauses
- Microsoft (Clarity): EU-US Data Privacy Framework participant, Standard Contractual Clauses
- Shopify: Standard Contractual Clauses
Your rights under GDPR
- Access: obtain a copy of the personal data we hold about you
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your personal data ("right to be forgotten")
- Restriction: request that we limit processing of your data
- Data portability: receive your data in a structured, machine-readable format
- Object: object to processing based on legitimate interest
- Withdraw consent: withdraw consent for analytics at any time via the Privacy button
To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
12. Australia (Privacy Act)
If you are located in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to our handling of your personal information.
- We collect personal information only for purposes directly related to our business functions (providing products, responding to inquiries, improving our website).
- We do not disclose personal information to overseas recipients except as described in this policy (data is processed in the United States by the third parties listed in Section 6).
- You may request access to or correction of your personal information at any time.
- If you believe we have breached the APPs, you may lodge a complaint with us or with the Office of the Australian Information Commissioner (OAIC).
To request access, correction, or to make a complaint, email [email protected].
13. Children's privacy
Our website is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it promptly.
14. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Changes take effect immediately upon posting. The "last updated" date at the bottom of this page reflects the most recent revision.
For significant changes that affect how we handle your personal information, we will make reasonable efforts to notify you (such as a banner on the website or email to known contacts).
15. Contact us
If you have questions about this Privacy Policy or how we handle your data:
- Privacy inquiries: [email protected]
- General inquiries: greendrains.com/contact
- Mailing address: Green Drain, Inc., North Carolina, United States
For CCPA requests, we will respond within 45 days. For GDPR requests, we will respond within 30 days. For all other requests, we aim to respond within 30 days.
This policy was last updated on April 6, 2026.
Questions about our products?
We're here to help. Reach out anytime.