Policy record · privacy
Privacy Policy
What we handle, why we need it, where it goes, how long we keep it, and how to ask us to act.
On this policy
§01 — Orientation
Scope and current facts
This policy explains how Bottomline Thermals LTD., also presented as Bottomline Thermals or Bottomline Thermals PCs (“Bottomline Thermals,” “we,” “us,” or “our”), handles personal information through blthermals.com, our PC configurator and checkout, custom-build and support requests, order service, and related communications.
The storefront does not currently offer customer accounts. The existing sign-in route is for authorized staff. Local carts and saved builds are browser features, not an account, cloud backup, or promise that another device can retrieve them.
We operate from the United States. If you use the site from another country, your information may be processed in the United States, where privacy laws may differ. A provider’s own notice applies when you use a provider-controlled payment, financing, or verification interface.
Current advertising position. At this policy’s effective date, our general advertising pixels, general analytics tags, and session-replay tools are disabled. We do not sell personal information for money or disclose it for cross-context behavioral advertising.
§02 — Collection record
Information we handle
The information involved depends on what you choose to do. We receive information from you, from the browser or device used to reach us, from our service providers, and from records created while we fulfill or support a request.
- Contact and delivery
- Name, email, phone number, company if supplied, billing and shipping address, and order or support reference.
- Build and transaction
- Cart contents, PC parts and customization choices, saved or shared builds, price, discount, shipping, tax, order status, returns, warranty, and service history.
- Payment and financing
- Payment method, amount, status, provider transaction identifiers, and limited payment details returned by Stripe or Affirm. Provider-entered card or financing information is described in Payments and financing.
- Requests and communications
- Custom-build details, quiz answers, support messages, requested emails, feedback, and consent or opt-out records. Please do not place unnecessary sensitive information in an open message field.
- Device, security, and operation
- IP address, browser and device information, user agent, timestamps, page addresses or paths and referring-page information, server and security events, anti-abuse or CAPTCHA signals, and first-party visitor or rollout identifiers. Page and referrer information can include URL details supplied by your browser or a form.
- Showcase material
- If provided or approved for display: build photography, review text, the name or display name supplied for publication, general location, build date, and limited build-progress information.
§03 — Purpose
Why we use information
- Operate the storefront, remember a cart or configuration, and provide requested features.
- Create quotes, process payment or financing, fulfill and ship orders, and provide receipts.
- Respond to custom-build, contact, quiz, warranty, order, and support requests.
- Send requested transactional messages and separately authorized recovery or marketing messages.
- Prevent fraud, abuse, duplicate actions, security incidents, and technical failures.
- Maintain, debug, and improve the site using necessary, sanitized, or aggregated information.
- Keep required business records and comply with tax, accounting, legal, and regulatory duties.
- Display customer-build material only under the approved display arrangement.
Submitting an order, quote, build, quiz, contact, or support request authorizes us to use the information to complete or respond to that request. It does not by itself enroll you in marketing.
§04 — Service map
Providers and other disclosures
We disclose the minimum information reasonably needed to providers that perform a service for us. Providers may use their own subprocessors. Their independent practices are governed by their notices and our applicable agreements.
Railway and hosting infrastructure
Application hosting, database operation, request delivery, security, and technical logs.
Railway privacy noticeStripe
Card-payment collection, authentication, fraud screening, processing, and payment status.
Stripe privacy noticeAffirm
Financing eligibility, application, authorization, transaction servicing, and status.
Affirm privacy noticeGoogle
reCAPTCHA abuse prevention on selected forms and Gmail-based delivery of requested, transactional, recovery, and marketing messages when each send is authorized.
Google privacy noticeTwilio
Phone number, recovery-link content, and delivery status when a separately authorized cart-recovery text is sent and the optional SMS service is configured.
Twilio privacy noticeFulfillment and professional services
Carriers, delivery and warranty support, accountants, insurers, attorneys, and other advisers receive information only when needed for that role.
Legal and business events
We may disclose information when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or evaluate a financing, sale, merger, or reorganization involving the business.
§05 — Transaction boundary
Payments and financing
Card numbers and security codes entered into Stripe-provided fields go to Stripe and are not stored by the Bottomline Thermals application. We receive the transaction identifier, amount, status, payment method category, and limited details needed to complete, support, reconcile, refund, or dispute an order.
If you choose Affirm, contact, billing, shipping, order, and financing application information is provided to Affirm. Affirm decides financing eligibility and services the financing relationship under its own terms and privacy notice. Do not rely on this policy as a substitute for the disclosures shown with a financing offer.
§06 — Device record
Browser storage, cookies, and tracking
We use browser storage to keep carts, PC configurations, saved builds, checkout progress, and interface state on your device. In the current checkout, this may include contact, billing, and delivery details entered to preserve progress. That information can remain after you close the browser until the site overwrites or removes it, the browser clears it, or you clear site data. Clear it before leaving a shared device.
A first-party visitor identifier may be stored in local storage and a cookie when a feature needs it; if you later submit contact details, the identifier may be linked to that request. The local-storage copy has no application-enforced expiry, while the cookie may last up to one year. Short-lived session storage may hold cart-editing state. A persistent first-party visitor profile can store an identifier, email address, name, phone number, and SMS-choice state without an application-enforced expiry. An approved storefront rollout may use a secure, HttpOnly, SameSite=Lax cohort cookie for up to 30 days. It contains a stable random browser-cohort value, expiry, and signature, but no direct name, email, account, cart, or route data.
Stripe, Affirm, and reCAPTCHA may use provider-controlled cookies or storage only on routes where their service is required. Their notices describe their technologies. At this policy’s effective date, general Google analytics tags, Meta and TikTok advertising pixels, tag-manager containers, and session replay are disabled.
§07 — Permission
Messages, marketing, and consent
- Transactional and requested messages include order, payment, delivery, support, custom-build, consultation, and one-time “email my build” communications.
- Email marketing requires a separate email-marketing choice. Identification, an order, or a service request is not marketing consent. Marketing email includes a way to unsubscribe; necessary order and service messages can continue afterward.
- Cart-recovery messages require the authority appropriate to that channel. A saved cart or email address alone does not authorize a marketing campaign.
- Automated cart-recovery texts may be sent through Twilio when the optional service is configured and a separate, purpose-specific SMS choice is recorded with a phone number. Consent is not a condition of purchase. Message frequency varies; message and data rates may apply. Reply STOP to the sending number or contact us to opt out.
We may retain the existing consent and suppression record after withdrawal so that we do not restart the message type you stopped and can document the choice. That record can include the email address, consent and withdrawal status, dates, source page or referrer, IP address, user agent, profile linkage, and unsubscribe token.
§08 — Link custody
Saved builds, recovery links, and showcases
Builds saved on your device stay in that browser until you or the browser removes them. The legacy public saved-build list, create, read, email, raw-ID, and edit routes are unavailable and return the same generic gone response without caching. That retirement does not itself delete existing database rows or establish a deletion date. Browser-local saves remain device features, not a private customer account or cloud backup.
A cart-recovery link is intended to expire after 30 days. Expiry stops the link from restoring the cart but does not necessarily delete the related operational record that same day. A working build-tracker or receipt link may display customer, delivery, order, or build information to someone who has the link. Treat these links as private and send them only to people you trust.
With the customer’s permission, a completed build, photo, review, the name or display name supplied for publication, general location, order date, or selected progress details may appear in a customer-build gallery or featured build record. Contact us to question or withdraw a display permission; legal or operational records may still remain where required.
§09 — Retention
How long we keep information
We do not currently have one application-enforced deletion schedule covering every category. Retention varies by the record and provider, and some records can remain until manually deleted, overwritten, or removed under a provider schedule. We use the following criteria rather than promising one period for every record:
- Orders and payments
- Fulfillment, delivery, returns, warranty, tax, accounting, fraud, chargeback, and legal-claim needs.
- Requests and support
- Time needed to answer, document the work, prevent duplicate requests, and meet business or legal duties.
- Consent and suppression
- Time needed to prove a choice and continue honoring a withdrawal.
- Recovery, visitor, and security records
- The requested recovery life, abuse prevention, debugging, security, and dispute needs. A link expiry is not a deletion promise.
- Browser-stored information
- Until the site removes or overwrites it, an applicable expiry runs, or you or the browser clear it.
- Backups and provider logs
- Until overwritten under applicable backup, security, and provider schedules; access remains limited to the relevant purpose.
We are formalizing a documented deletion process. We delete or deidentify information when required and operationally feasible, but this sentence is not a promise that every current record is automatically removed as soon as its original use ends. A lawful preservation duty may extend a period.
§10 — Safeguards
How we protect information
We use reasonable administrative, technical, and organizational safeguards designed for the nature of the information we handle. These include access restrictions, secure transport, provider boundaries, response protections, and review of sensitive changes. No internet transmission, browser, provider, or storage system is completely secure.
You can reduce risk by protecting your device and email, clearing site data on shared devices, keeping private order and build links private, and contacting us promptly if a link or transaction appears to be misused.
§11 — Customer control
Your choices and privacy rights
Depending on where you live and subject to legal exceptions, you may ask us to confirm, access, correct, or delete personal information; provide a portable copy; opt out of a sale, targeted advertising, or certain profiling; or limit certain uses of sensitive personal information. You may also appeal a denied request and exercise applicable rights without unlawful discrimination.
Email [email protected] with “Privacy Request,” use our support form, or write to the address in Contact Bottomline Thermals. To appeal, reply with “Privacy Appeal.” We will verify only what is reasonably necessary, may recognize an authorized agent where required, and will respond within the time required by applicable law.
Browser privacy signals
Our current site does not use personal information for sale, cross-context behavioral advertising, or targeted advertising, so a Global Privacy Control signal does not require an additional change to those disabled practices. Before enabling a covered practice, we will treat a legally recognized opt-out preference signal, including GPC, as required. Legacy “Do Not Track” signals do not express a standardized choice, so we do not respond to them differently.
§12 — Age boundary
Children's privacy
The storefront is a general-audience service and is not directed to children under 13. We do not knowingly collect personal information online from a child under 13. If we learn that we have done so, we will delete it or otherwise comply with applicable law. A parent or guardian may contact us using the methods below. We do not knowingly sell or share the personal information of anyone under 16.
§13 — Planned capability
Future customer accounts
We hope to offer customer accounts in the future. They are not available today, and the staff sign-in is not a customer account. Before customer accounts launch, we will update this policy and any notice shown when account information is collected. We will describe the account data, purposes, storage, sharing, retention, security, controls, and deletion process then in effect, and will obtain fresh consent when law requires it.
A future account will not silently turn an order, saved build, support request, or email address into marketing permission. We will also explain whether and how earlier records can be linked to the account before that linking occurs.
§14 — Revision control
Changes to this policy
We will post changes on this page and update the effective or last-reviewed date. If a change materially affects how previously collected information is used, we will provide additional notice or obtain consent when required. An archived or requested copy can be identified by the policy version shown at the top of this page.
§15 — Accountable contact
Contact Bottomline Thermals
Questions, privacy requests, appeals, and concerns about a data practice can be sent to:
Bottomline Thermals LTD. Attn: Privacy 200 East Randolph Street, Suite 5100-38 Chicago, IL 60601 United States [email protected] (312) 718-7567If what this policy says differs from what you observe, tell us. Michael Giblin is the accountable policy owner and will investigate the discrepancy.