Privacy Policy
Privacy Policy
Effective Date: October 18, 2025
Heartlee (CycleStick.com) respects your privacy and is committed to protecting your personal data. This policy explains how we collect, use, and safeguard your information when you visit our website, place an order, or interact with our digital celebration platform. By using this site, you agree to the terms of this Privacy Policy.
When you use CycleStick.com, we collect certain information to process your order and deliver your experience. This may include your name, email address, phone number, shipping details, payment information (processed securely through Stripe), and any optional data you provide, such as recipient details or uploaded media. When friends or family submit messages through QR codes or forms, we collect their display name, message, photo, video, and optional email for confirmation. If you participate in our crowdfunded gift feature, we collect contributor names, payment details, and amounts to manage contributions securely. All media uploads are stored safely using encrypted WordPress and Gravity Forms systems.
We also automatically collect device and technical data such as IP address, browser type, and activity on our site to improve performance and prevent abuse. Cookies are used to keep you logged in, remember password-protected galleries, and analyze site usage. You can disable cookies in your browser, but some features may not function properly.
Your data is primarily used to fulfill orders, process payments, send order confirmations, generate QR code sheets, display event galleries, manage contributions, and provide customer support. We do not sell or rent your personal data. Payments are handled by Stripe using PCI-compliant encryption, and Heartlee never stores full credit card information. For optional gift card integrations, limited details are securely shared with Tango Card Inc. via encrypted API to process your transaction. All such transfers occur over HTTPS using secure authentication tokens.
Event galleries on CycleStick.com can be public, private, or password-protected depending on the organizer’s choice. Passwords are encrypted and never stored in plain text. Friends submitting content can choose to stay anonymous, and their display names will be hidden if selected. Uploaded media remains private unless the event visibility allows public display.
We retain order records and financial data for up to three years for legal and accounting purposes. Media and submissions are stored as long as the organizer keeps the event active or until a deletion request is made. You can contact us anytime to access, correct, or delete your information, or to request data export. Requests should be sent to privacy@sicklestick.com, and we typically respond within 10 business days.
We use WordPress security tools, SSL encryption, and daily backups to protect all stored information. Our hosting environment includes firewall protection, malware scanning, and restricted database access. All communication with external services, such as Stripe, Tango, and Google reCAPTCHA, is encrypted and follows industry-standard security protocols. Transactional emails (order confirmations, password resets, gallery links) are sent automatically, while marketing emails are only sent to users who have opted in. You may unsubscribe anytime.
If you contact us through our website, we collect your name, email, and message to reply to your inquiry. Messages are stored for reference but are not used for marketing unless you give consent. For wholesale or partnership requests, contact partners@sicklestick.com. Our support team may use your data only to provide the requested service or assistance.
Our website and services are hosted in the United States, and by using them, you consent to the transfer and processing of your data in the U.S. We comply with major data protection principles including GDPR and CCPA requirements. We do not knowingly collect data from children under 13, and any such information will be deleted immediately upon request.
We may update this Privacy Policy to reflect improvements in our services or changes in law. Any updates will be published here with a new “Last Updated” date. Your continued use of the site after such updates constitutes acceptance of the revised policy. For all privacy inquiries or requests, please contact us at privacy@sicklestick.com or by mail at Heartlee HQ, 123 Celebration Lane, Orlando, FL 32819, United States.
Heartlee is a family-owned business built on trust, creativity, and care. Your memories are precious, and we treat your privacy with the same respect — secure, confidential, and always protected.