Privacy Policy
Last updated: August 6, 2026
Honeybee Delivery LLC ("Honeybee," "we," "us") operates honeybeedelivery.inktoprintz.com to help food, beverage, and CPG brand owners get their product onto major supermarket shelves. This policy explains what personal information we collect when you use this website, why we collect it, who we share it with, how long we keep it, and how you can access or delete it.
We treat visitor data as a liability: we collect as little as possible, secure what we hold, and delete it when we no longer need it.
1. What we collect
Information you give us directly
- "Become a Client" application (via vendors form): your name, business name, contact email, phone number, product category, target retailers, production capacity, and anything else you type into the form or attach.
- Contact form (via contact page): your name, email, and message.
- Owner sign-in: reserved for Honeybee staff. Not open to the public. Uses a hashed password and a signed session cookie.
Information we collect automatically
- Server logs. IP address, user agent, referrer, and requested URL for each page load. Kept for security investigations for up to 90 days, then rotated out.
- Essential cookies. A signed session cookie is set only after owner sign-in. No tracking cookies are set for anonymous visitors.
- Analytics cookies — only if you accept them on the cookie banner. Details below.
2. Why we collect it (lawful basis)
- Application & contact data — to reply to you and decide whether to work together (contract / legitimate interest).
- Server logs — to keep the site online, defend against abuse, and diagnose problems (legitimate interest).
- Analytics — only with your consent, so we can understand which pages help brand owners and improve them.
3. Cookies & analytics
Analytics scripts do not load until you explicitly accept them on the cookie banner. If you accept, we use:
- Google Analytics 4 — anonymous, aggregated page-view and event data. IP addresses are truncated. Google Privacy Policy.
- Microsoft Clarity — anonymous heatmaps and session recordings to see where visitors get stuck. No form-input contents are captured. Microsoft Privacy Statement.
You can change your mind any time by clearing your hb_consent_v1 localStorage entry, or by clicking the "reset cookie choice" link in your browser’s dev tools.
4. Who we share it with
We do not sell your data. We share it only with the vendors we need to run the site and reply to you:
- DigitalOcean — hosts the web server and database.
- SendGrid (Twilio) — sends transactional email (contact-form receipts, application confirmations, password resets to Honeybee staff).
- Let’s Encrypt — issues our TLS certificate.
- Google Analytics 4 & Microsoft Clarity — only if you accept analytics cookies.
- Cloudflare Turnstile — protects the vendor and contact forms from bots. Cloudflare receives your IP and a challenge token to distinguish humans from bots.
- Sentry — captures anonymous error reports so we can fix bugs. No form contents are captured.
We do not share your data with advertisers, data brokers, or third-party marketing platforms.
5. How long we keep it
- Applications and messages — kept while active and for 24 months after the last interaction, then archived or deleted.
- Owner accounts — kept while the account is active.
- Server logs — up to 90 days.
- Analytics data — retained per Google Analytics 4’s default (14 months) and Microsoft Clarity’s default (13 months). Both are anonymous / aggregate.
6. Your rights
You can email lucner@honeybeedelivery.com to:
- Ask what we hold about you;
- Correct anything that’s wrong;
- Delete your data ("right to be forgotten") — subject to any legal-hold obligations;
- Withdraw analytics consent;
- Object to processing or ask for a copy of your data in a portable format.
If you are in California, the CCPA/CPRA gives you the same rights plus the right to opt out of "sale" of personal information (we don’t sell any). If you are in the EU/UK, the GDPR gives you the same rights plus the ability to lodge a complaint with your local data protection authority.
7. Security
The site is served over HTTPS with modern TLS. Owner passwords are hashed. Public write endpoints are rate-limited. Sessions are signed HTTP-only cookies. We follow the OWASP Top 10 and our internal Ink To Printz Security Standard. If you believe you’ve found a vulnerability, please email us and we’ll credit you if you’re the first to report it.
8. Children
This is a business-to-business site. We do not knowingly collect information from anyone under 16. If you believe a child has submitted a form, contact us and we’ll delete it.
9. Changes
If we change this policy in a way that affects what we collect or share, we’ll bump the "Last updated" date at the top and — if you have a stored analytics preference — prompt you again on your next visit.
