Privacy Policy

What to expect from this policy

Membership clarity

Approval remains the access rule
More about for Approval remains the access rule

Policy readers get the same public path as every visitor: browse first, then purchasing access only after approval, active membership, and no administrative hold.

Support path

Support explains process, not exceptions
More about for Support explains process, not exceptions

Support can help locate the right policy, explain account or order status, and escalate sensitive records or membership questions to authorized reviewers.

Privacy and payments

Data and payment topics stay governed
More about for Data and payment topics stay governed

Privacy, support records, refunds, credits, and payment concerns are handled through published policies and authorized review, not informal promises.

Last updated: 2026-06-01

Quick overview

Privacy Policy at a glance

Privacy, data collection, member records, support records, producer records, and operational data-use commitments.

Sections
31
Last updated
2026-07-16
Audience
Members, applicants, and site visitors
Related action
Review before membership activity
Browse sections

Plain-English summary: Privacy, data collection, member records, support records, producer records, and operational data-use commitments.

1. Purpose and scope

This Policy explains how information is collected, used, shared, protected, retained, corrected, and deleted in connection with Amish Products Association, the Member marketplace, Producer relationships, support, reporting, document systems, and related operations.

It applies to applicants, Members, Producers, site visitors, authorized household or business contacts, staff, contractors, service providers, and other persons whose information is processed for an approved purpose.

2. Separate entity roles

2.1 Association

Amish Products Association controls Association membership, application, approval, good standing, governance, Producer approval, Association communications, and related Association records.

2.2 Merchant

Amish Products Association, LLC is the Marketplace Entity and Merchant of Record. It controls marketplace transaction, payment, receipt, refund, credit, chargeback, order, and Producer-settlement records.

2.3 Fulfillment

Amish Products Fulfillment, LLC is the Operations Administrator. It processes information for the Association and Merchant when administering websites, accounts, support, Producer coordination, order routing, logistics, reporting, document systems, security, and low-technology workflows.

2.4 Producers

Approved Association Producers receive only the information reasonably necessary to prepare, fulfill, communicate about, account for, or resolve approved orders and related issues.

2.5 Service providers

Authorized service providers may process information under contracts, platform terms, professional duties, or other approved arrangements.

These parties are separate. Information is shared among them only for authorized purposes and does not merge their ownership, governance, or legal responsibilities.

3. Information collected

Information may include:

  1. Name, address, telephone, fax, and email.
  2. Household, business, or authorized-contact information.
  3. Membership application, approval, dues, status, agreement acceptance, notice, and communication records.
  4. Account identifiers, login, credential-recovery, security, verification, and access information.
  5. Order, product, payment, receipt, shipping, pickup, delivery, refund, credit, chargeback, and support information.
  6. Producer application, approval, product, schedule, settlement, communication, and operational records.
  7. Support requests, call notes, fax records, messages, photographs, recordings where authorized, and issue evidence.
  8. Website, device, browser, cookie, log, analytics, and security information.
  9. Preferences, communications, survey responses, and program participation.
  10. Accounting, tax, legal, fraud-prevention, incident, continuity, and audit records.
  11. Paper applications, signed forms, printed manifests, handwritten notes, fax confirmations, telephone logs, and mail records.
  12. Other information voluntarily provided or reasonably generated through authorized use of the systems.

Payment-card information may be processed by third-party payment providers rather than stored directly by the Association, Merchant, or Fulfillment.

4. Sources of information

Information may come from:

  1. The individual.
  2. An authorized household, business, guardian, or representative.
  3. The Association, Merchant, Fulfillment, or an approved Producer.
  4. Payment processors, banks, carriers, platforms, support providers, or other vendors.
  5. Account, security, fraud, reporting, or operational systems.
  6. Public records or lawful public sources.
  7. Former systems or records lawfully obtained for continuity, migration, support, or accounting.
  8. Counsel, accountants, insurers, auditors, or other professional advisers.
  9. Paper, telephone, fax, mail, in-person, print-shop, or other low-technology workflows.

5. Uses of information

Information may be used to:

  1. Review and administer membership applications and status.
  2. Verify eligibility, good standing, and document acceptance.
  3. Operate the Member marketplace.
  4. Process orders, payments, receipts, refunds, credits, chargebacks, and Producer settlements.
  5. Route orders and coordinate Producers, shipping, pickup, delivery, and support.
  6. Maintain product, Producer, Member, transaction, and accounting records.
  7. Communicate policies, statements, notices, status changes, order information, and operational instructions.
  8. Protect accounts, systems, people, property, and continuity.
  9. Detect and investigate fraud, misuse, security events, access problems, and operational issues.
  10. Provide support and resolve disputes.
  11. Perform accounting, tax, legal, insurance, audit, and compliance functions.
  12. Produce weekly, monthly, faxed, printed, or internal reports.
  13. Improve services, workflows, content, catalog quality, and Member experience.
  14. Carry out other authorized Association, Merchant, or Fulfillment purposes consistent with the affected relationship.

Each entity should use information only within its authority or under an approved service, processing, or delegation arrangement.

6. Sharing among the Association, Merchant, Fulfillment, and Producers

Information may be shared among the Association, Merchant, Fulfillment, and the applicable Producer when reasonably necessary for:

  1. Membership administration.
  2. Producer approval and standards administration.
  3. Product listing and availability.
  4. Order acceptance and fulfillment.
  5. Shipping, pickup, delivery, and route coordination.
  6. Payment, refund, chargeback, and settlement administration.
  7. Support and issue resolution.
  8. Security, fraud prevention, continuity, and incident response.
  9. Accounting, reporting, audit, and legal purposes.

Only information reasonably necessary for the authorized purpose should be shared.

Producer access to Member information does not transfer ownership of the Member relationship, Member list, marketplace account, or Merchant transaction record.

7. Service providers and professional advisers

Information may be shared with authorized:

  1. Payment processors and banks.
  2. Ecommerce, hosting, domain, and software providers.
  3. Carriers, logistics providers, route coordinators, and pickup locations.
  4. Support, phone, fax, mail, print-shop, and communications providers.
  5. Accountants, lawyers, insurers, auditors, and consultants.
  6. Security, fraud-prevention, backup, analytics, and reporting providers.
  7. Government, judicial, regulatory, or law-enforcement authorities when legally required or reasonably necessary to protect rights, records, or safety.
  8. A successor or permitted transferee in an authorized organizational or asset transaction.
  9. Another party with the individual's consent or direction.

Service-provider access should be limited by role, contract, platform control, professional duty, or another appropriate safeguard.

8. Producer and Member information limits

A Producer may use Member information only for approved order fulfillment, communication, support, product issue review, safety, accounting, settlement, or legal purposes.

A Producer may not use Member information for unrelated marketing, sale, disclosure, list building, solicitation, personal use, or transfer without authorization.

Members may not misuse Producer contact, personal, Farm, operational, pricing, settlement, route, or other private information.

Members may not scrape, publish, resell, redistribute, or disclose private Member or Producer information obtained through the marketplace.

9. Cookies, analytics, and online technologies

The website and authorized providers may use cookies, pixels, tags, logs, local storage, analytics, performance monitoring, fraud-prevention tools, and similar technologies for:

  1. Site functionality.
  2. Account access.
  3. Membership and checkout state.
  4. Security and fraud prevention.
  5. Preferences.
  6. Performance and reliability.
  7. Measurement and reporting.
  8. Authorized communications.
  9. Debugging and incident response.

Available choices may depend on the browser, device, provider, configuration, and applicable law.

Analytics and logs should avoid unnecessary personal information and should not expose Member-only prices, credentials, payment data, or protected internal records.

10. Payment information

Payment-card and bank information may be collected or processed by authorized payment providers.

The Association, Merchant, and Fulfillment should not store full payment-card numbers or security codes unless a specifically approved and appropriately controlled system requires it.

Transaction records may include processor identifiers, payment status, amount, last four digits or a similar limited identifier, authorization and capture status, refund status, dispute status, and other information reasonably necessary to administer the transaction.

No person should request full card details by ordinary email, unprotected fax, or an unapproved support channel.

11. Security safeguards

Reasonable administrative, technical, physical, and operational safeguards are used based on the sensitivity and purpose of the information.

Safeguards may include:

  1. Least-privilege access.
  2. Separate admin and day-to-day accounts.
  3. Credential vaults and recovery controls.
  4. Multi-factor authentication where practical for digital users.
  5. Logging and audit records.
  6. Encryption where appropriate.
  7. Backups and continuity plans.
  8. Vendor and service-provider controls.
  9. Training and confidentiality obligations.
  10. Paper-file, fax, mail, and physical-record controls.
  11. Incident response.
  12. Offboarding and credential rotation.
  13. Manual fallback procedures.

No system can guarantee absolute security. Suspected unauthorized access, disclosure, loss, or misuse should be reported promptly through the approved support or security channel.

12. Security incidents and unauthorized disclosure

A suspected privacy or security incident should be handled under the Incident Response and Stop-Sale Policy, System Access and Credential Control Policy, Data Governance and Records Policy, and applicable service agreements.

The response may include:

  1. Preserving evidence.
  2. Limiting access.
  3. Rotating credentials.
  4. Suspending an account, integration, or workflow.
  5. Identifying affected records and systems.
  6. Notifying the appropriate Association, Merchant, Fulfillment, Producer, provider, professional adviser, or authority.
  7. Correcting records or controls.
  8. Recording decisions, communications, and closure evidence.

Any notice to affected persons or authorities must be determined from the actual facts, applicable obligations, and authorized professional direction.

13. Retention, archiving, and destruction

Information is retained for as long as reasonably needed for membership, transactions, Producer relationships, support, accounting, tax, legal, insurance, security, dispute, continuity, audit, and recordkeeping purposes.

Retention periods and archive rules are governed by the Data Governance and Records Policy, document-version system, applicable agreements, and actual obligations.

When information is no longer required, it may be deleted, destroyed, anonymized, de-identified, or retained in a restricted archive according to an approved disposition process.

Paper, fax, printed, handwritten, and digital copies should be included in retention and destruction decisions.

A request for deletion does not require deletion of records that must or reasonably should be retained for legal, accounting, security, transaction, dispute, privilege, continuity, or other legitimate purposes.

14. Access, correction, deletion, and other requests

A person may request access to, correction of, or deletion of appropriate personal information through the designated contact method.

A request may also concern communication preferences, account information, membership records, or other available rights under applicable policy or law.

Identity, account ownership, guardianship, business authority, or representative authority may be verified before a request is fulfilled.

Requests may be submitted by approved electronic, mail, telephone-confirmed, fax, paper, personal-delivery, or other practical methods.

The response should record:

  1. Request date and method.
  2. Requester and verified authority.
  3. Scope of request.
  4. Systems and records reviewed.
  5. Decision and reason.
  6. Action taken.
  7. Response date and method.
  8. Any retained records and retention basis.

15. Request limitations and protected records

Access, correction, or deletion may be limited when reasonably necessary to protect:

  1. Another person's privacy.
  2. Security controls or credentials.
  3. Legal privilege or work product.
  4. Fraud, abuse, or incident investigations.
  5. Accounting, tax, settlement, or transaction records.
  6. Chargeback, dispute, or claim records.
  7. Association governance or Producer-discipline confidentiality.
  8. Contractual or professional obligations.
  9. Records that cannot be reliably separated from protected information.
  10. Other legitimate and applicable requirements.

A denial or limitation should be documented with the reason and appropriate response path.

The Association, Merchant, Fulfillment, and authorized providers may send essential communications concerning:

  1. Membership status and dues.
  2. Required documents and policy changes.
  3. Orders, payments, refunds, and chargebacks.
  4. Shipping, pickup, delivery, and availability.
  5. Support, security, and account status.
  6. Producer, route, or product changes affecting an order.
  7. Governance notices and authorized Member votes.

Optional marketing or educational communications should be distinguished from essential operational notices where practical.

Records may include the communication type, content or template version, recipient, channel, date, delivery status, consent or preference status, and related transaction or membership record.

17. Children, minors, and household participation

The marketplace is not intended for independent use by children who cannot lawfully enter the applicable agreements.

A parent, guardian, or authorized adult should manage any household participation involving a minor.

Information about a minor should be collected only when reasonably necessary for an authorized household, support, delivery, safety, legal, or other approved purpose.

Third-party websites, carriers, processors, applications, telephone systems, fax providers, platforms, and services have their own privacy and security practices.

This Policy does not control a third party's independent practices.

A link or integration does not imply that every third-party practice is adopted or controlled by the Association, Merchant, or Fulfillment.

Authorized providers should be reviewed and documented according to the Data Governance and System Access policies.

19. Paper, telephone, fax, mail, and in-person records

Privacy and security obligations apply to low-technology records as well as digital records.

Paper applications, printed orders, packing manifests, handwritten notes, fax transmissions, mail, telephone logs, and in-person records should be:

  1. Limited to information needed for the task.
  2. Delivered only to authorized persons or locations.
  3. Stored securely when not in use.
  4. Logged when materially important.
  5. Entered into the system of record when practical.
  6. Retained or destroyed under approved rules.
  7. Protected from unnecessary public or household exposure.

Fax cover sheets, recipient verification, page counts, confirmation records, and secure storage should be used where appropriate.

20. Remote, hosted, and cross-border processing

Information may be processed or stored through remote, hosted, cloud, carrier, payment, support, communications, or professional-service systems.

The location of processing may depend on the actual provider and service configuration.

No specific provider, country, or storage location should be represented as current unless supported by the system inventory, contract, or provider record.

Provider selection and review should consider access, security, continuity, export, deletion, and transfer requirements.

21. Organizational changes and continuity

Information may be transferred to an authorized successor, service provider, custodian, or permitted transferee in connection with an approved organizational change, service transition, asset transfer, continuity event, or ownership change.

The transfer must preserve applicable membership, transaction, confidentiality, access, and recordkeeping obligations.

A helper, contractor, administrator, or provider change must not cause loss of access to Member, Producer, order, settlement, support, or governance records.

22. Public and private information boundaries

Public or Member-facing materials may identify approved entity roles, Producers, products, policies, and practical marketplace information.

Private ownership, royalty, banking, legal strategy, privileged communications, credential, security, internal distribution, settlement, Member, Producer, or incident information is not made public merely because the entities share a marketplace or brand relationship.

Publication decisions must follow the governing document hierarchy, approval authority, and access classification.

23. Contact and request channels

Current privacy, support, mailing, telephone, and fax contact methods will be published on the website, receipts, Member materials, or official notices.

A request should be routed to the entity or administrator responsible for the affected record.

Fulfillment may administer intake and coordination without changing which entity controls the underlying membership, transaction, governance, or Producer record.

This Policy should be read with:

  1. By-Laws.
  2. Membership Agreement.
  3. Marketplace Terms of Sale.
  4. Data Governance and Records Policy.
  5. System Access and Credential Control Policy.
  6. Support Policy.
  7. Incident Response and Stop-Sale Policy.
  8. Producer Standards.
  9. Producer Participation Agreement.
  10. Merchant-Producer Supply and Settlement Agreement.
  11. Applicable service, processing, confidentiality, and professional agreements.

25. Changes, approval, notice, and version records

Material changes will be recorded in the document system.

The Association, Merchant, or Fulfillment will determine whether notice, acknowledgment, or reacceptance is required based on the nature of the change and the affected relationship.

Records may show the Policy version or hash, approval authority, effective date, publication date, notice method, acknowledgment, and superseded version.