HEIRLOOM AMERICAN FORGE·Hand-poured in Cleveland·25-year flat-bottom guarantee
H Hearthstone Iron Co.
— Legal & Information

Privacy Policy

A plain-English explanation of what data we collect when you visit hearthstoneiron.com or place an order, how we use it, who we share it with, and how to ask us to delete it.

Last updated · May 21, 2026

The short version

We're a small family-run foundry. We don't sell, rent, or trade your information. We collect the minimum we need to ship you a skillet, communicate about your order, and run a tiny analytics setup so we know which ads are bringing visitors to the site. That's it.

If you want us to delete your data

Email privacy@hearthstoneiron.com with the email address you used at checkout, and we'll wipe everything we have on file within 30 days. We'll keep a minimal record of the deletion request itself, as required by U.S. and EU law.

1. Who we are

Hearthstone Iron Co. is a manufacturer of cast iron cookware based in Cleveland, Ohio. Our registered address is 2840 W. 25th Street, Cleveland, OH 44113. When we say "we," "us," or "the company" in this policy, we mean Hearthstone Iron Co. When we say "you," we mean a visitor to hearthstoneiron.com or a customer who has placed an order.

2. What we collect

Information you give us directly

When you place an order through our checkout, we collect:

Information we collect automatically

When you load a page on hearthstoneiron.com, the following is collected by our hosting provider's standard logs and our analytics:

This is the same kind of information almost every website on the internet collects in its server logs.

3. Cookies and similar technology

We use a small number of first-party cookies to keep your cart contents during your visit and to remember whether you've accepted the cookie banner. We use one analytics service (described below) which sets its own cookies to count returning visitors. We do not use third-party advertising cookies on the site itself. You can disable cookies in your browser at any time; the site will still work, but your cart may be emptied between page loads.

4. Who we share data with

We share order information only with the small set of vendors required to fulfill your order and run a small business. Each of these vendors is bound by their own contract and privacy obligations:

We do not sell, rent, or trade your personal information to anyone. If we ever change ownership through a merger or sale, you'll be notified before any data is transferred and given the chance to opt out.

5. How long we keep it

Order records (so we can honor the 25-year warranty): kept indefinitely so you don't lose your proof of purchase. We can shorten this on request — see the callout at the top of the page. Server logs and analytics: retained for 90 days, then rotated out automatically.

6. Your rights

U.S. residents (CCPA / state privacy laws)

If you live in California, Virginia, Colorado, Connecticut, Utah, or any state with comparable privacy legislation, you have the right to (a) ask what personal information we hold about you, (b) ask for a copy of it, (c) ask us to correct anything that's wrong, and (d) ask us to delete it. We respond to requests within 45 days. We will not penalize you for exercising these rights — your warranty stays valid, your account stays open, you pay the same prices.

EU / UK residents (GDPR / UK-GDPR)

You have the same access, correction, and deletion rights as U.S. customers, plus the right to portability (we'll provide your data in a machine-readable format), the right to restrict processing, and the right to lodge a complaint with your national supervisory authority. Our lawful basis for processing your order data is contractual necessity (we can't ship you a pan without your address); for analytics, our basis is legitimate interest in understanding traffic. You can object to analytics processing at any time using the cookie banner.

7. Children

The site is not directed at children under 13 and we do not knowingly collect data from anyone under 13. If you believe a child has provided us with information, email us at the address below and we'll delete it.

8. Security

The site is served over HTTPS. Payment data is handled by a PCI-DSS-certified processor; we don't store full card numbers. Order records are kept in a controlled-access database with backups encrypted at rest. No system is unbreakable; if we ever discover a breach that affects your information, we'll notify you by email within 72 hours of confirmation.

9. International transfers

The company and our hosting infrastructure are located in the United States. If you order from outside the U.S., your information will be transferred to the U.S. for fulfillment. For EU / UK customers, we rely on the Standard Contractual Clauses adopted by the European Commission as the legal mechanism for that transfer.

10. Changes to this policy

If we make a meaningful change to this policy, we'll update the "Last updated" date at the top of the page and post a notice on the home page for 30 days. Substantive changes (for example, adding a new category of third party we share data with) require your renewed consent for any new processing.

11. How to reach us

For privacy questions, deletion requests, or any general concerns about how we handle your information:

Email: privacy@hearthstoneiron.com
Mail: Hearthstone Iron Co., Attn: Privacy, 2840 W. 25th Street, Cleveland, OH 44113

For order issues, warranty claims, or general customer service, please use the Contact page instead — it routes to a faster queue.