Privacy Policy

BREW SHOCKALAKA

Privacy Policy

Effective Date: June 13, 2026

Last Updated: June 13, 2026


1. Introduction and Scope

Brew Shockalaka ("Company," "we," "us," or "our") operates the website located at https://brewshock.com (the "Site") and provides related e-commerce services, subscription programs, military and first-responder discount programs (the "Heroes Program"), and marketing communications (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information about you when you visit or use our Services.

By accessing or using the Site, placing an order, creating an account, subscribing to our products, or participating in any of our programs, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use our Services.

This Policy applies to all users of the Site worldwide, with additional provisions applicable to residents of California, Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws, as well as to users in the European Economic Area ("EEA"), United Kingdom, and Canada where applicable.


2. Information We Collect

2.1 Information You Provide Directly

We collect personal information you voluntarily provide when you:

  • Create an account: name, email address, username, password

  • Place an order: billing name, shipping address, email address, phone number, payment information (processed through third-party payment processors; we do not store full card numbers)

  • Subscribe to recurring deliveries: payment method, delivery frequency preferences, subscription management details

  • Apply for the Heroes Program (military, law enforcement, first responders, educators): full name, email, branch of service or employer, verification documentation submitted through GovX (our third-party verification partner)

  • Contact us: name, email, phone, message content

  • Join our team or creator program: name, email, social media handles, portfolio information

  • Participate in surveys, contests, or promotions: responses, contact details

  • Sign up for email or SMS marketing: email address or mobile phone number

2.2 Information Collected Automatically

When you visit our Site, we and our third-party service providers automatically collect certain technical and usage information, including:

  • Device and browser information: IP address, browser type and version, operating system, device type and identifiers

  • Usage data: pages viewed, links clicked, search queries, referral URLs, time spent on pages, session duration

  • Location data: approximate geographic location inferred from IP address (we do not collect precise GPS location without consent)

  • Shopping behavior: products viewed, items added to cart, abandoned cart data, purchase history

  • Log files: server logs, error logs, access timestamps

  • Cookies and similar tracking technologies: see Section 7 for details

2.3 Information from Third Parties

We may receive information about you from:

  • GovX: eligibility verification status (pass/fail) for the Heroes Program discount; we receive confirmation of eligibility but not the underlying verification documents

  • Payment processors (e.g., Shopify Payments, Stripe, PayPal): transaction confirmation, fraud signals, partial payment details

  • Social media platforms: if you connect a social account or interact with our social media pages (Facebook, Instagram, YouTube, TikTok, LinkedIn), we may receive profile information you have made public

  • Analytics providers: aggregated and de-identified behavioral data

  • Marketing partners and advertising networks: interest-based audience segments

  • Retail partners and wholesale distributors: contact information for business inquiries


3. How We Use Your Information

We use the personal information we collect for the following purposes:

3.1 Fulfillment and Service Delivery

  • Processing and fulfilling your orders, including subscription deliveries

  • Sending order confirmations, shipping notifications, and delivery updates

  • Managing your customer account and purchase history

  • Processing returns, exchanges, and refunds

  • Providing customer support and responding to inquiries

3.2 Heroes Program Administration

  • Verifying military, law enforcement, first responder, or educator eligibility through GovX

  • Applying applicable discounts to qualifying purchases

  • Communicating program updates, terms, or eligibility changes

3.3 Subscription Management

  • Processing recurring billing for subscription orders

  • Sending subscription management notifications (upcoming charges, renewal reminders, payment failures)

  • Honoring pause, modify, or cancellation requests

3.4 Marketing and Communications

  • Sending promotional emails about new products, flavors, offers, and events (with opt-out option)

  • Sending SMS marketing messages (only with express prior written consent)

  • Personalizing marketing content based on your purchase history and browsing behavior

  • Running targeted advertising on third-party platforms (Facebook, Instagram, Google, TikTok)

  • Conducting A/B testing and improving campaign effectiveness

3.5 Site Improvement and Analytics

  • Understanding how users interact with the Site to improve usability and content

  • Diagnosing technical issues and monitoring Site performance

  • Conducting market research and product development analysis

3.6 Legal and Security

  • Detecting, preventing, and investigating fraud, unauthorized transactions, and security incidents

  • Complying with applicable laws, regulations, and legal processes

  • Enforcing our Terms of Service and other agreements

  • Protecting the rights, property, and safety of the Company, our users, and others


4. Legal Bases for Processing (EEA and UK Users)

If you are located in the European Economic Area or United Kingdom, we process your personal data under the following legal bases:

  • Contract performance: processing necessary to fulfill your orders, manage your account, and deliver our Services

  • Legitimate interests: fraud prevention, Site analytics, improving our products and services, direct marketing to existing customers (where balanced against your rights)

  • Legal obligation: compliance with applicable laws and regulations

  • Consent: email and SMS marketing communications; use of non-essential cookies; processing for certain profiling activities (you may withdraw consent at any time)


5. How We Share Your Information

We do not sell your personal information to third parties. We may share your information in the following circumstances:

5.1 Service Providers

We share information with vendors and service providers that perform services on our behalf, including:

  • E-commerce platform: Shopify (hosting, checkout, payment processing infrastructure)

  • Payment processors: Shopify Payments, Stripe, PayPal, and similar providers

  • Fulfillment and logistics: shipping carriers (UPS, FedEx, USPS) and third-party fulfillment centers

  • Discount verification: GovX (Heroes Program eligibility verification)

  • Email marketing: Klaviyo, Mailchimp, or similar email service providers

  • SMS marketing: platforms such as Attentive, Postscript, or similar

  • Analytics: Google Analytics, Meta Pixel, and similar tools

  • Advertising networks: Google Ads, Meta (Facebook/Instagram), TikTok Ads, and similar platforms

  • Customer support: help desk and chat software providers

  • Fraud prevention: identity verification and fraud detection services

These service providers are contractually obligated to use your information only for the purposes of providing services to us and to maintain appropriate data security practices.

5.2 Business Transfers

In the event of a merger, acquisition, sale of assets, financing, or other corporate transaction, your personal information may be transferred as part of the transaction. We will provide notice and choice where required by applicable law.

5.3 Legal Requirements

We may disclose your information if required to do so by law, subpoena, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5.4 With Your Consent

We may share your information for any other purpose with your prior consent.


6. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Our general retention practices include:

  • Account information: retained while your account is active and for up to 7 years after account closure to satisfy legal and accounting obligations

  • Order and transaction records: retained for a minimum of 7 years to comply with tax and financial recordkeeping requirements

  • Marketing preferences and communications history: retained until you unsubscribe or for 3 years after your last interaction, whichever is later

  • Heroes Program verification records: eligibility confirmation retained for the duration of your program participation plus 3 years

  • Website analytics data: retained for up to 26 months in aggregate or de-identified form

  • Customer support records: retained for 3 years after resolution

When we no longer need your personal information for the purposes it was collected, we will securely delete, destroy, or anonymize it.


7. Cookies and Tracking Technologies

7.1 What We Use

We and our third-party partners use cookies, web beacons, pixel tags, and similar tracking technologies on our Site. These technologies help us operate the Site, remember your preferences, analyze usage, and deliver targeted advertising.

  • Strictly Necessary Cookies: required for the Site to function (e.g., maintaining your shopping cart and session login). These cannot be disabled.

  • Performance and Analytics Cookies: help us understand how visitors interact with the Site (e.g., Google Analytics)

  • Functionality Cookies: remember your preferences (e.g., language, region)

  • Targeting and Advertising Cookies: used to deliver relevant ads and track ad campaign effectiveness (e.g., Meta Pixel, TikTok Pixel, Google Ads Tag)

7.2 Managing Cookies

You can control cookies through:

  • Your browser settings: most browsers allow you to block or delete cookies

  • Our cookie consent tool (if available on the Site)

  • Opt-out tools provided by analytics and advertising partners, including the Google Analytics Opt-out Browser Add-on, the Network Advertising Initiative (NAI) opt-out, and the Digital Advertising Alliance (DAA) opt-out

Please note that disabling certain cookies may impact the functionality of our Site and Services.

7.3 Do Not Track

Our Site does not currently respond to browser-based "Do Not Track" signals. However, we honor Global Privacy Control (GPC) signals where required by applicable law (see Section 10 for California).


8. Data Security

We implement reasonable and industry-standard technical and organizational security measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures include:

  • SSL/TLS encryption for data transmitted between your browser and our Site

  • Encryption of stored payment data (we do not store full credit card numbers; payment data is tokenized by our payment processors)

  • Access controls limiting employee access to personal information on a need-to-know basis

  • Regular security assessments and monitoring

  • Vendor security requirements for third-party service providers

Despite our efforts, no security system is impenetrable. In the event of a data breach that requires notification under applicable law, we will notify affected individuals and authorities as required. If you believe your account security has been compromised, please contact us immediately at the address provided in Section 13.


9. Children's Privacy

Our Site and Services are intended for adults aged 18 and over. We do not knowingly collect personal information from children under the age of 13 (or under 16 in jurisdictions requiring a higher age threshold). If we become aware that we have inadvertently collected personal information from a child under the applicable age threshold without verifiable parental consent, we will take steps to delete such information promptly. If you believe we may have collected information from a child, please contact us immediately.


10. Your Privacy Rights

10.1 California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collection, and the categories of third parties with whom we share it

  • Right to Delete: the right to request deletion of personal information we have collected, subject to certain exceptions

  • Right to Correct: the right to request correction of inaccurate personal information

  • Right to Opt Out of Sale or Sharing: we do not sell personal information. However, we may "share" information (as defined under CPRA) for cross-context behavioral advertising. You may opt out by visiting our Site and using the cookie management tool or contacting us. We also honor Global Privacy Control (GPC) signals as an opt-out

  • Right to Limit Use of Sensitive Personal Information: we do not process sensitive personal information beyond what is permitted without the right to limit

  • Right to Non-Discrimination: we will not discriminate against you for exercising your privacy rights

To exercise your rights, submit a verifiable consumer request through the contact information in Section 13. We will respond within 45 days (extendable by another 45 days with notice). You may designate an authorized agent to make a request on your behalf with proper written authorization.

California Shine the Light: California Civil Code Section 1798.83 permits California residents to request information about personal information disclosed to third parties for their direct marketing purposes. Contact us to make such a request.

10.2 Other U.S. State Residents

Residents of Colorado, Connecticut, Virginia, Texas, and other states with comprehensive consumer privacy laws may have similar rights, including rights to access, delete, correct, and opt out of certain processing. Contact us to exercise these rights. We will respond within the timeframes required by applicable state law.

10.3 EEA and UK Residents (GDPR/UK GDPR)

If you are located in the European Economic Area or United Kingdom, you have the following rights:

  • Right of access to your personal data

  • Right to rectification of inaccurate data

  • Right to erasure ("right to be forgotten") in certain circumstances

  • Right to restriction of processing

  • Right to data portability

  • Right to object to processing based on legitimate interests or for direct marketing

  • Right to withdraw consent at any time (without affecting the lawfulness of processing prior to withdrawal)

  • Right to lodge a complaint with your local supervisory authority

To exercise your rights, contact us using the details in Section 13. We will respond within 30 days.

10.4 Canadian Residents (PIPEDA/Provincial Laws)

Canadian residents have the right to access personal information we hold about them and to request correction of inaccurate information, subject to applicable exceptions. Contact us to exercise these rights.

10.5 Email and SMS Marketing Opt-Out

You may unsubscribe from marketing emails at any time by clicking the "Unsubscribe" link in any email or by contacting us. You may opt out of SMS marketing by replying STOP to any text message. Please note that transactional communications (order confirmations, shipping updates, subscription management) are not subject to opt-out.


11. Third-Party Links and Services

Our Site may contain links to third-party websites, social media platforms (Facebook, Instagram, YouTube, TikTok, LinkedIn), and external services (including GovX for the Heroes Program). This Privacy Policy does not apply to those third-party sites or services. We encourage you to review the privacy policies of any third-party sites you visit. We are not responsible for the privacy practices of third parties.


12. International Data Transfers

Brew Shockalaka is based in the United States. If you are located outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located and our central database is operated. Data protection laws in the United States may differ from those in your country.

For transfers of personal data from the EEA or United Kingdom to the United States, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission and the UK International Data Transfer Agreement (IDTA), as applicable. Contact us for more information about the safeguards in place.


13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:

Brew Shockalaka

Website: https://brewshock.com

Contact Page: https://brewshock.com/pages/contact

For EEA/UK data protection inquiries or to identify our EU/UK representative (if applicable), please use the same contact information.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this Policy and, where required by law, provide additional notice (such as a banner on our Site or an email notification to registered account holders).

We encourage you to review this Privacy Policy periodically. Your continued use of the Site and Services after any changes become effective constitutes your acceptance of the revised Policy.


15. Additional Disclosures and Definitions

15.1 Categories of Personal Information Collected (CCPA Disclosure)

In the past 12 months, we have collected the following categories of personal information:

  • Identifiers: name, email address, IP address, account login credentials, phone number

  • Commercial information: purchase history, subscription details, product preferences

  • Financial information: payment method details (tokenized; processed by third-party payment processors)

  • Internet or network activity: browsing history on our Site, search queries, interaction with ads

  • Geolocation data: approximate location inferred from IP address

  • Professional or employment-related information: military branch, employer (Heroes Program only)

  • Inferences: product preferences, purchasing likelihood, interest profiles derived from the above

15.2 Business Purposes for Collection

We collect the above categories for the business and commercial purposes described in Sections 3 and 5 of this Policy, including order fulfillment, account management, marketing, analytics, fraud prevention, and legal compliance.

15.3 Subscription Cancellation Policy Notice

Our Site offers subscription purchases. As disclosed at checkout, by placing a subscription order, you authorize recurring charges at the frequency selected. You may cancel, pause, or modify your subscription at any time through your account portal or by contacting us. We will process cancellations before the next billing cycle where technically feasible. Charges already processed are subject to our refund policy.

15.4 Heroes Program (GovX) Specific Disclosures

To access military, law enforcement, first responder, and educator discounts through the Heroes Program, you must verify your eligibility through GovX, a third-party identity and eligibility verification service. When you initiate verification, you will be directed to GovX's platform and your information will be subject to GovX's Privacy Policy in addition to this Policy. We receive only a verification result (eligible/not eligible) and your name and email to associate the discount with your account. We do not receive or store your underlying government-issued credentials or documentation.


© 2026 Brew Shockalaka. All rights reserved. | brewshock.com