Privacy Policy

Last updated: March 18, 2026

1. Introduction

Solid Surface Shop("we," "us," or "our") operates the website solidsurfacecountertopsny.com. Solid Surface Shop is a brand of North Shore Woodworks LLC, located at 178A Miller Place, Hicksville, NY 11801. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or place an order.

2. Information We Collect

Personal Information

When you create an account or place an order, we may collect:

  • Name (first and last)
  • Email address
  • Phone number
  • Delivery address (street address, city, state, ZIP code)
  • Account credentials (email and password, managed securely through Firebase Authentication)

Order Information

When you use our countertop customizer or place an order, we collect:

  • Countertop specifications (dimensions, color, edge profile, sink configuration)
  • Order history and status
  • Delivery preferences

Payment Information

Payment processing is handled entirely by Stripe, a PCI-compliant third-party payment processor. We do not store your credit card number, CVV, or full payment details on our servers. Stripe's privacy policy governs the handling of your payment data.

Automatically Collected Information

We do not use analytics tracking, advertising cookies, or third-party tracking pixels. Our website sets a single functional cookie to remember your sidebar preference (see Section 5). Our hosting infrastructure (Google Cloud Run) may automatically log basic request data such as IP addresses and browser user-agent strings as part of normal server operations. These logs are used solely for security monitoring and debugging and are not used for tracking or marketing purposes.

3. How We Use Your Information

We use the information we collect to:

  • Process and fulfill your countertop orders
  • Create and manage your account
  • Send order confirmations, status updates, and delivery notifications via email or SMS
  • Calculate shipping and delivery options
  • Verify service area availability based on your ZIP code
  • Respond to your inquiries and provide customer support
  • Comply with legal and tax obligations

4. Third-Party Services

We use the following third-party services to operate our website:

  • Firebase (Google) — for user authentication, database storage, and order management
  • Google Cloud Run — for hosting and serving our website application. Cloud Run may process and temporarily log request metadata (such as IP addresses) as part of normal infrastructure operations.
  • Google Cloud Storage — for storing order-related files
  • Stripe — for secure payment processing
  • Google Fonts — for website typography (this may involve your browser connecting to Google servers)
  • USPS — for shipping rate calculations

Each of these services has its own privacy policy governing how they handle your data. We encourage you to review their respective policies.

5. Cookies

Our website uses a single functional cookie:

  • sidebar_state — Remembers whether the navigation sidebar is open or collapsed. This cookie expires after 7 days and is strictly functional (not used for tracking or advertising).

We do not use analytics cookies, advertising cookies, or any third-party tracking cookies. Firebase Authentication may use local storage and session storage to maintain your login session (including authentication tokens and session identifiers), but these are not cookies and are cleared when you sign out.

6. Communications

Transactional Messages

When you place an order or create an account, we may send you transactional communications by email or SMS, including order confirmations, fabrication status updates, delivery scheduling, and customer service responses. These messages are necessary to fulfill your order and are not marketing communications.

Promotional Messages

We do not currently send promotional or marketing emails or SMS messages. If we begin offering promotional communications in the future, we will obtain your consent before sending them, and you will be able to opt out at any time. This Privacy Policy will be updated to reflect any changes to our marketing practices, including disclosure of any third-party services used to send such communications.

Phone Number Usage

Your phone number is collected solely for order-related communications (such as delivery coordination and customer support). We do not share your phone number with third parties for marketing purposes.

7. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following circumstances:

  • Service providers: We share data with third-party service providers (listed in Section 4) solely to operate our website and fulfill your orders. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
  • Legal requirements: We may disclose your information if required to do so by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Business transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website of any change in ownership or use of your personal information.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including reasonable safeguards as required by the New York SHIELD Act (General Business Law §899-bb). User authentication is managed through Firebase Authentication with secure token-based sessions. Payment data is processed through Stripe's PCI-compliant infrastructure and is never stored on our servers. All data transmitted between your browser and our servers is encrypted using TLS (HTTPS).

9. Data Breach Notification

In compliance with the New York SHIELD Act (General Business Law §899-aa), if we become aware of a breach of the security of your private information, we will notify affected New York residents in the most expedient time reasonable and without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

10. Data Retention

We retain your personal information as follows:

  • Active accounts: Your account information and order history are retained for as long as your account remains active.
  • Closed accounts: If you request account deletion, we will delete your account credentials and personal profile information. However, we retain order records (including associated name, address, and transaction details) indefinitely for tax compliance, legal obligations, warranty support, and business record-keeping purposes.
  • Server logs:Infrastructure logs containing IP addresses and request metadata are retained for a limited period and are automatically purged in accordance with Google Cloud's default retention policies.

If you wish to delete your account, please contact us using the information in Section 15.

11. Your Rights

Depending on your location, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information (subject to the retention exceptions described in Section 10)
  • Opt out of marketing communications (if applicable)
  • Receive a copy of your personal data in a portable format

To exercise any of these rights, please contact us at the email address below. We will respond to your request within 30 days.

12. Do Not Track Signals

Our website does not use tracking technologies and therefore does not respond to Do Not Track ("DNT") signals. We do not track users across third-party websites and do not allow third-party behavioral tracking on our Service.

13. Children's Privacy

Our website is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us so we can promptly delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. For material changes that affect how we use your personal information, we will make reasonable efforts to notify you by email or by a prominent notice on our website prior to the change taking effect. Your continued use of our website after changes are posted constitutes your acceptance of the revised policy.

15. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us: