Privacy policy
Written to be read rather than to be complied with. The short list of things that are not happening is first.
Gocognimary collects order details, support correspondence, marketing preferences and aggregate page counts. It does not sell personal information, does not hold card details, and does not use anything you say about your health for marketing.
Deletion requests are handled inside thirty days. Email [email protected] with “privacy” in the subject line.
What we do not do with your data
Privacy policies are usually a list of permissions the company is claiming. It is more useful to read the short list of things that are not happening, so here it is.
- We do not sell your personal information to third parties.
- We do not publish your name, your order, or anything you write to us.
- We do not use anything you tell this desk about your health for marketing. If you mention a condition in an email about an order, it stays in that email.
- We do not enrol you in a subscription or a mailing list because you bought something. Marketing email requires you to opt in, and every one has an unsubscribe link that works.
If you believe any of those has been broken, that is a complaint worth making directly: [email protected] or +1 (302) 200-3480, and say in the first line that it is a privacy complaint so it is routed properly.
What we collect, and why
- Order details
- Name, delivery address, email, and what you ordered. Collected because a parcel cannot be sent without them.
- Payment details
- Not held by us. The payment processor holds them; we see the last four digits and the authorisation result.
- Support correspondence
- What you write to us and what we write back, so a repeat problem does not start from nothing.
- Marketing preferences
- Whether you opted in, and when. Held so that an unsubscribe can be honoured and proved.
- Website analytics
- Aggregate page counts. We want to know which pages get read, not who read them.
That is the whole list. This site carries no third-party advertising pixels, no social-media trackers and no external fonts, which is partly a privacy decision and partly a performance one.
How long we keep things
Data that is kept forever is data that can leak forever. These are the periods we work to.
| Record | Kept for | Why |
|---|---|---|
| Order and delivery records | As long as tax and accounting law requires | Not a choice we get to make |
| Payment card details | Not held by us at all | The processor holds them; we see the last four digits |
| Support emails | Two years from the last message in the thread | Long enough for a repeat problem, short enough not to be an archive |
| Marketing subscribers | Until you unsubscribe, then removed | An unsubscribe is a deletion, not a flag |
| Website analytics | Aggregated; not tied to your name | We want page counts, not a profile |
Scroll this table sideways →
Deletion requests are handled inside thirty days. Where an order record has to be kept for tax reasons we will tell you which record and why, rather than quietly keeping it.
Cookies, in the boring detail
This site uses the smallest set of cookies it can and still function. There are three kinds and only one of them is optional.
- Strictly necessary
- Your cart, your session, and the security tokens that stop someone else submitting a form as you. These cannot be turned off without breaking checkout.
- Preference
- Small settings such as whether you have dismissed a notice. Harmless, expire quickly, and hold nothing about who you are.
- Measurement
- Aggregate page counts so we know which pages get read. Optional. Declining them changes nothing about how the site works for you.
Your browser can block all of them. If you block the strictly necessary set, checkout will not work — a limitation of how carts work rather than a choice we made.
Your rights
- A copy of what we hold about you.
- A correction if any of it is wrong.
- Deletion, subject to records we are legally required to keep.
- An opt-out of marketing at any time, which is also one click in any marketing email.
- An explanation of anything on this page that is not clear.
Email [email protected] with “privacy” in the subject line. We handle these inside thirty days and we will tell you what we did rather than just confirming receipt.
Children
This site is for adults. It is not directed at anyone under 18 and we do not knowingly collect information from anyone under 18. If you believe a child has given us information, write to [email protected] and we will delete it.
How this site is built, from a privacy angle
A privacy policy is easier to trust when the site's construction backs it up. Five things about how these pages are built.
- No third-party fonts. Every typeface on this site is one already on your device. No request leaves your browser to a font host.
- No advertising pixels. There is no Meta pixel, no advertising tag and no remarketing script anywhere on this site.
- No social embeds. Embedded posts and share widgets load third-party scripts that see your visit. There are none here.
- No external images. Every image is served from this domain.
- One script, written by us. The site loads a single JavaScript file that handles the menu, the reveal animations and the blend slider. It sends nothing anywhere.
The practical result is that loading a page on this site tells nobody but this site's own server that you did. That is unusual and it is deliberate.
It is also why the pages are fast, which is the sort of coincidence that suggests the privacy decision was not a sacrifice.
Marketing email, if you opt in
- How you get on the list
- Only by opting in. Buying something does not subscribe you and an order confirmation is not marketing.
- How often
- Rarely. We do not have a daily-email business and we are not going to build one.
- What is in it
- Changes to what this site publishes — a certificate of analysis if one arrives, a correction to a page, a new guide.
- How you get off
- One click in any message, or email [email protected]. An unsubscribe is a deletion, not a suppression flag.
- What we will never do
- Sell or rent the list, or share it with another company for their own marketing.
If you get marketing email from us that you did not ask for, that is a failure on our side and we want to know: [email protected] with “privacy” in the subject line.
Security, honestly described
Promising that data is completely safe is the one claim no organisation can make truthfully. Here is the accurate version.
- This site is served over HTTPS, so what passes between your browser and the server is encrypted in transit.
- Payment card details are handled by the payment processor and are not stored by us. We see the last four digits and the authorisation result.
- Access to order and support records is limited to the people who need it to do the job.
- No system is immune to compromise. If a breach affected your data we would tell you what happened, what was affected and what to do, rather than issue a statement about taking security seriously.
The last point is the only one of the four that is a commitment rather than a description, and it is the one worth holding us to.
Who else sees your data
A short list, because a long one would mean something had gone wrong.
| Who | What they see | Why |
|---|---|---|
| The payment processor | Your card details and billing address | To take the payment. We never hold the card |
| The carrier | Your name and delivery address | To deliver the parcel |
| The fulfilment centre | Your name, address and what you ordered | To pack it |
| Our email provider | Your email address and what we wrote to each other | To send and receive support messages |
| Nobody else | — | There is no advertising or data-broker relationship |
Scroll this table sideways →
Each of those is doing a job that cannot be done without the data listed. If a supplier appears on that list in future who does not meet that test, this page changes and the date at the top of it moves.
In short
We collect what an order needs and what a support conversation needs, we do not hold your card, we do not sell anything about you, the site loads no third-party trackers at all, and a deletion request is handled inside thirty days. If any of that turns out not to be true, [email protected] and say so in the first line.
Who to write to
Every privacy matter on this site goes to one place: [email protected], with the word privacy in the subject line so it is routed correctly rather than sitting in a queue of order questions.
If your request concerns an order specifically — a record you want corrected or removed — include the order number, because it is what lets us find the record without asking you for more information than you already gave us.
Changes to this policy
If this policy changes in a way that affects what we collect or how long we keep it, the date at the top of this page moves and the change is described here rather than quietly folded into the text.
Last updated September 22, 2026. If you want to know what changed since a previous version, ask at [email protected] and we will tell you.