HowdyDrop

Privacy Policy

Effective Date: May 15, 2026

Tam Labs LLC ("HowdyDrop," "we," "us," or "our") provides a curated live shopping experience, including howdydrop.com (the "Site"), our live shows on Whatnot, and related communications and features (collectively, the "Services"). HowdyDrop is powered by Shopify, which enables us to provide the Services to you. This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase through the Services or otherwise communicate with us. If there is a conflict between this Privacy Policy and our Terms of Service, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.

By using the Services, you acknowledge that you have read and understood this Privacy Policy.

Personal information we collect

When we use the term "personal information," we mean information that identifies, relates to, or can reasonably be linked to you. Personal information does not include information that has been anonymized or de-identified so that it cannot reasonably be linked to you.

Depending on how you interact with the Services, we may collect or process the following categories of personal information, including inferences drawn from it:

  • Contact details — name, billing address, shipping address, phone number, email address.
  • Financial information — payment-card details, financial-account information, transaction details, form of payment, payment confirmation and other payment-related data. Full card numbers are processed by Shopify Payments and are not stored on our servers.
  • Account information — username, password (stored hashed), preferences, settings, and saved selections.
  • Transaction information — items you view, add to cart, wishlist, purchase, return, exchange, or cancel; live-show RSVPs and win history; order history.
  • Communications with us — the content of emails, support tickets, social-media messages, and other correspondence.
  • Device and connection information — device identifiers, browser type and version, operating system, language settings, IP address, and approximate location derived from IP.
  • Usage information — pages and listings viewed, time spent, clicks and scroll behavior, referring URLs, and similar interaction data.

Sources of personal information

We may collect personal information from:

  • You directly — when you create an account, place an order, RSVP for a show, subscribe to emails, write to us, or otherwise interact with the Services.
  • Automatically — from your device when you use the Services, including through cookies, pixels, SDKs, and similar technologies.
  • Service providers — vendors that operate components of the Services on our behalf.
  • Partners and third parties — including Whatnot, Meta, Google, TikTok, and other platforms, in accordance with their settings and your privacy choices on those platforms.

How we use personal information

Depending on your interactions with the Services, we use personal information to:

  • Provide and improve the Services — process and fulfill orders, arrange shipping, support live-show participation, manage your account, remember preferences, personalize recommendations, develop new features, and operate the Site.
  • Marketing and advertising — send marketing communications (show reminders, recap emails, founder notes) where you have consented or where permitted by law, and serve interest-based advertising across Meta, Google, TikTok, and other platforms based on activity on the Services.
  • Security and fraud prevention — authenticate your account, detect and investigate suspicious or fraudulent activity, protect against abuse, and secure the Services.
  • Customer support and relationship management — respond to inquiries, resolve issues, and maintain our relationship with you.
  • Legal and compliance — comply with applicable law, respond to lawful requests from law enforcement or other authorities, enforce our terms and policies, and exercise or defend legal claims.

How we disclose personal information

We disclose personal information in the following circumstances:

  • Service providers and processors — vendors that help us operate the Services, including Shopify (commerce platform, hosting, payment processing), Klaviyo (email marketing), Whatnot (live shopping), shipping carriers (USPS, UPS, DHL, others), analytics providers, customer-support tools, and cloud storage. Each processor is contractually bound to use information only as needed to provide its service.
  • Advertising and analytics partners — for measurement, attribution, and interest-based advertising. See "Pixels and tracking" below.
  • At your direction — when you ask us to share information with a third party (for example, via social-media widgets or login integrations) or otherwise consent to disclosure.
  • Affiliates — within our corporate group, subject to this Privacy Policy.
  • Legal and business transactions — to comply with legal obligations, respond to subpoenas or other lawful process, enforce our terms, protect the rights, safety, or property of HowdyDrop, our users, or others, and in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.

We do not sell personal information for money.

Relationship with Shopify

The Services are hosted by Shopify, which processes personal information about your use of the Services to provide and improve them. Information you submit to the Services is transmitted to and shared with Shopify and certain third parties that may be located outside your country of residence. We also use Shopify enhanced features that incorporate data about your interactions with our Store, other merchants, and Shopify. In those circumstances, Shopify is responsible for the processing of your personal information, including for responding to your requests to exercise your rights with respect to those uses. To learn more about how Shopify uses your personal information, see the Shopify Consumer Privacy Policy and the Shopify Privacy Portal.

Pixels and tracking

The Services use cookies, pixels, tags, and similar technologies, including the Meta Conversions API (CAPI), Google Analytics 4 (GA4), and the TikTok Pixel. These tools help us measure performance, understand which shows and pieces resonate, and serve advertising to people who have interacted with us. Marketing-attribution cookies typically persist for up to 90 days. You can manage these via your browser settings, the Network Advertising Initiative opt-out (optout.networkadvertising.org), the Digital Advertising Alliance opt-out (optout.aboutads.info), or platform-level settings on Meta, Google, and TikTok.

Global Privacy Control. If you visit the Site with the Global Privacy Control ("GPC") signal enabled, we will treat it as a request to opt out of the "sale" or "sharing" of personal information for targeted advertising for the device and browser you are using, and — where we can reasonably link the signal to a Shopify account — for that account as well. Learn more at globalprivacycontrol.org. Other than GPC, we do not currently respond to other "Do Not Track" signals.

Marketing consent and opt-out

By subscribing to our email list, you consent to receive marketing emails. You may opt out at any time by clicking unsubscribe in any marketing email or by writing to hello@howdydrop.com. Transactional messages (order, shipping, account notices) will continue regardless. If we launch SMS marketing, opt-in will be explicit and separate from email consent, and you will be able to opt out by replying STOP to any marketing text.

Your rights and choices

Depending on where you live, you may have some or all of the following rights with respect to your personal information. These rights are not absolute, apply only in certain circumstances, and in some cases we may decline a request as permitted by law.

  • Right to access / know — request access to the personal information we hold about you.
  • Right to delete — request that we delete personal information we maintain about you.
  • Right to correct — request correction of inaccurate personal information.
  • Right to portability — request a copy of personal information we hold about you, or that we transfer it to a third party, in certain circumstances and with certain exceptions.
  • Right to opt out of sale or sharing for targeted advertising — opt out of the "sale" or "share" of personal information, or out of processing for "targeted advertising," as defined by applicable law. To exercise this right, email hello@howdydrop.com or use the Do Not Sell or Share My Personal Information link in the Site footer. The GPC signal described above is also honored.
  • Right to manage communications — opt out of marketing emails via unsubscribe in any email; you may still receive non-promotional service messages such as order confirmations.

If you reside in the United Kingdom or the European Economic Area, you may also have, subject to local-law exceptions:

  • Right to object to or restrict processing of personal information for certain purposes.
  • Right to withdraw consent, where we rely on consent to process personal information. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

To exercise any of these rights, write to hello@howdydrop.com. We may need to verify your identity before fulfilling a request. You may designate an authorized agent to make a request on your behalf; before acting on the request, we may require the agent to provide proof of your authorization and may need to verify your identity directly with us. We will respond within the timeframes required by applicable law. We will not discriminate against you for exercising any of these rights.

Complaints and appeals

If you have a complaint about how we process your personal information, please contact us at hello@howdydrop.com so we can try to resolve it. Depending on where you live, you may have the right to appeal our decision by contacting us at the same address, or to lodge a complaint with your local data protection authority. For the European Economic Area, you can find the relevant supervisory authorities through the European Data Protection Board.

California residents — Do Not Sell or Share

We do not sell personal information for money. We may share certain identifiers and browsing information with advertising partners (Meta, Google, TikTok) for targeted advertising, which may be considered a "sale" or "share" under the California Consumer Privacy Act. To opt out, email hello@howdydrop.com, use our Do Not Sell or Share My Personal Information link in the Site footer, or enable the Global Privacy Control signal in your browser.

Cookies

We use first-party and third-party cookies for site functionality, analytics, and advertising. Our default attribution window for marketing cookies is 90 days. You can manage cookies via your browser settings; disabling certain cookies may affect site functionality.

International transfers

We may transfer, store, and process personal information outside the country where you live, including in the United States. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on recognized transfer mechanisms such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent safeguards.

Children

The Services are not directed to children, and we do not knowingly collect personal information from anyone under 13 (or the age of majority in your jurisdiction, where higher). If you believe a child has provided us information, write to hello@howdydrop.com and we will delete it promptly. As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we "share" or "sell" (as those terms are defined under applicable law) the personal information of individuals under 16.

Security and retention

We use reasonable administrative, technical, and physical safeguards to protect personal information. No security measure is perfect or impenetrable, and information you transmit may not be fully secure in transit; please do not use unsecure channels to send sensitive information. You are responsible for keeping your account credentials confidential.

We retain personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Order records are typically retained for at least seven years for tax and accounting purposes.

Third-party websites and links

The Services may link to third-party websites or platforms. We do not control those sites and are not responsible for their privacy or security practices. Information you share on third-party platforms (including social-media platforms) may be visible to others without restriction. Inclusion of a link does not imply endorsement.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on the Site with a revised Effective Date and, where required, provide additional notice.

Contact

Questions, requests, or concerns: hello@howdydrop.com. For purposes of applicable data protection laws, HowdyDrop is the data controller of your personal information.