PRIVACY POLICY 

BAH SUPA. COM LLC 

 

Effective Date: ______4-25-2025_______________ 

Jurisdiction: State of Ohio, United States of America 

PREAMBLE 

This Privacy Policy (“Policy”) constitutes a legally binding agreement between you (“User,” “you,” or “Data Subject”) and Bah Supa. Com LLC, a limited liability company organized under the laws of the State of Ohio, with its principal place of business located at 850 Euclid Ave, Suite 819 #5476, Cleveland, OH 44114 (hereinafter, the “Company,” “we,” “us,” or “our”), governing the collection, use, protection, and disclosure of personal and non-personal information through our digital platform, www.bahsupa.com (the “Website” or “Platform”), and associated services. 

This Policy is adopted pursuant to the provisions of applicable U.S. federal and state privacy laws, including but not limited to: 

  • Federal Trade Commission Act, 15 U.S.C. § 41 et seq.; 
  • Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506; 
  • Ohio Consumer Sales Practices Act, Ohio Rev. Code § 1345.01 et seq.; 
  • Electronic Communications Privacy Act, 18 U.S.C. §§ 2510–2523; 
  • Relevant interpretations and guidance issued by the Ohio Attorney General’s Office and the U.S. Department of Commerce. 

ARTICLE I – DEFINITIONS 

1.1 “Personal Information” shall mean any information that identifies, relates to, describes, or is reasonably capable of being associated with an individual person, as construed under Ohio Rev. Code § 1345.01(D) and applicable federal standards. 

1.2 “Non-Personal Information” refers to anonymized or aggregated data that cannot reasonably be linked to any identifiable natural person. 

1.3 “Processing” shall mean any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, including but not limited to collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, dissemination, erasure, or destruction. 

1.4 “User” or “Data Subject” refers to any individual who accesses the Website, transacts with the Company, or otherwise provides information to us. 

1.5 “Data Controller” means the Company, which determines the purposes and means of the processing of personal data. 

1.6 “Third Party” means any natural or legal person, public authority, agency, or body other than the User, the Company, or an authorized data processor acting under our direct control. 

1.7 “Stripe” means Stripe, Inc., a Delaware corporation and authorized payment processor, whose services are integrated for the purpose of executing secure financial transactions on the Website. 

1.8 “Applicable Law” means all relevant federal and state statutes, rules, and regulations governing consumer data, privacy rights, and online commercial practices. 

ARTICLE II – SCOPE AND CONSENT 

2.1 This Policy applies to all data collected by the Company in connection with its online operations and services, including but not limited to purchases, communications, and user activity on the Website. 

2.2 By accessing the Website, submitting information, or utilizing services, the User hereby provides informed, voluntary, and affirmative consent to the collection, use, and disclosure of their data as outlined herein, consistent with 15 U.S.C. § 6502 and Ohio Rev. Code § 1345.02(A). 

2.3 If the User does not agree to be bound by this Policy, they must immediately discontinue use of the Website. 

ARTICLE III – CATEGORIES OF INFORMATION COLLECTED 

3.1 Personal Information collected may include but is not limited to: 

  • Full legal name 
  • Email address 
  • Billing and shipping address 
  • Payment data (processed via Stripe; we do not store full card data) 
  • IP address and geolocation 
  • Device identifiers, browser type, and operating system 
  • Usage behavior, referring links, and pages visited 

3.2 Automated Collection Mechanisms may include: 

  • Cookies and session tracking (pursuant to 16 C.F.R. § 312.2) 
  • Log files 
  • Web beacons 
  • Analytical tools such as Google Analytics 

ARTICLE IV – LEGAL BASIS FOR PROCESSING 

4.1 The Company shall process personal data only under the following lawful bases, pursuant to the principles of U.S. commercial law and the Restatement (Second) of Contracts: 

  • The performance of a contract or transaction initiated by the User; 
  • The consent of the User, freely given and specific; 
  • Compliance with a legal obligation; 
  • Legitimate interest, provided such interest is not overridden by the User’s rights and freedoms. 

ARTICLE V – PURPOSES OF DATA USE 

5.1 The Company collects and uses information for the following enumerated purposes: 

  • To facilitate and process transactions and payments through Stripe; 
  • To provide support, fulfill orders, and manage customer accounts; 
  • To conduct internal research and statistical analysis to improve services; 
  • To communicate with Users regarding account status, system updates, promotions, and legal notices; 
  • To protect the Website, investigate fraudulent activity, and ensure lawful use of services; 
  • To comply with applicable statutes, administrative subpoenas, court orders, and regulatory obligations. 

ARTICLE VI – DISCLOSURE TO THIRD PARTIES 

6.1 Disclosure of data shall be limited, necessary, and proportionate, consistent with statutory requirements. 

6.2 We may disclose personal data: 

  • To Stripe for secure payment processing under contractual terms; 
  • To law enforcement agencies or regulatory bodies pursuant to valid legal process under 18 U.S.C. § 2703(d); 
  • To our legal, tax, or IT advisors bound by confidentiality; 
  • To successors, assigns, or purchasers in the event of a corporate transaction, subject to compliance with applicable consumer rights. 

6.3 We do not sell, lease, or share personal information to unaffiliated third parties for direct marketing purposes, consistent with 15 U.S.C. § 45. 

ARTICLE VII – DATA SECURITY MEASURES 

7.1 The Company implements reasonable and appropriate technical and organizational measures, including encryption, pseudonymization, access controls, and regular audit logging in line with NIST SP 800-53 and ISO/IEC 27001 standards. 

7.2 While no system can guarantee absolute security, we take diligent measures to minimize risk and shall notify affected parties in the event of a data breach consistent with Ohio Rev. Code § 1349.19. 

ARTICLE VIII – RETENTION AND DESTRUCTION 

8.1 Data shall be retained for the minimum period necessary to: 

  • Fulfill contractual obligations 
  • Comply with tax, audit, or legal requirements 
  • Resolve disputes or enforce rights 

8.2 Thereafter, all personal data shall be anonymized or securely destroyed using industry-accepted protocols, including overwrite, physical destruction, or cryptographic erasure. 

ARTICLE IX – USER RIGHTS AND REMEDIES 

9.1 Users shall have the following rights under applicable laws: 

  • The right to request access to personal data 
  • The right to rectify inaccurate or incomplete information 
  • The right to withdraw consent at any time without prejudice 
  • The right to request erasure (“right to be forgotten”), where appropriate 
  • The right to lodge a complaint with the Ohio Attorney General’s Consumer Protection Section or Federal Trade Commission

9.2 All requests must be submitted in writing to the contact information provided herein, and identity verification may be required to process requests. 

ARTICLE X – MINORS AND CHILDREN’S DATA 

10.1 This Website is not intended for individuals under the age of thirteen (13). We do not knowingly solicit or collect data from children, in compliance with COPPA, 15 U.S.C. §§ 6501–6506. 

10.2 If we become aware that personal information has been collected from a child without verified parental consent, we will delete such data promptly. 

ARTICLE XI – GOVERNING LAW AND JURISDICTION 

11.1 This Policy shall be governed, interpreted, and enforced in accordance with the laws of the State of Ohio, without regard to its conflict of laws principles. 

11.2 Any claim, dispute, or proceeding arising from this Policy shall be subject to the exclusive jurisdiction of the state and federal courts located in Montgomery County, Ohio, and all parties hereby submit to such venue. 

 

 

 

ARTICLE XII – POLICY MODIFICATIONS 

12.1 We reserve the right to modify this Policy at our sole discretion to reflect changes in law, technology, or business practices. Amendments shall become effective upon publication. 

12.2 Users will be deemed to have accepted the updated Policy through continued use of the Platform after notice. 

ARTICLE XIII – CONTACT INFORMATION 

All correspondence, data subject access requests, regulatory inquiries, or notices required under this Privacy Policy or applicable law shall be directed to: 

Bah Supa. Com LLC 

Attn: Data Privacy Compliance Officer 

850 Euclid Ave, Suite 819 #5476 

Cleveland, OH 44114 

Email: BahSupa@gmail.com

Phone:(937)430-0312