Privacy Policy
Updated September 26, 2026
Patriarch Outfitters is a trade name of Hilachem Ventures LLC.
Who we are
In this policy, "we" and "us" mean Hilachem Ventures LLC, operating as Patriarch Outfitters.
About this policy
This policy describes, in plain language, how we actually handle your information.
What we collect
We collect information when you place an order. Our payment processor collects it on its checkout page and passes it to us:
- your name and email address
- your shipping address
- the items you ordered and the amount paid
We keep a record of each order so you can see its status. If you sign in to see your orders, we also keep your sign in sessions, whether you turned on two step sign in, the sizes you last bought, and your email preference. There is no password. Signing in sends a code to the email address you used at checkout, or uses your Google account if you choose that. We never store your Google password and only receive your email address from Google.
What we do not collect
We never see or store your card number. The payment processor handles it.
Your cart
Your cart is saved in your own browser using local storage so it survives a page reload. It is not sent to us until you start checkout, and you can clear it at any time by removing the items or clearing site data in your browser.
Information we collect automatically
We also collect some information automatically as you browse, separate from anything you type into a form.
Every visit sends us information about how the site works and how it is used:
- the pages you view, how fast each one loads, and how you arrived, meaning the website or search engine that linked to us and any campaign tags in that link
- your browser and its language and time zone, your screen size and sharpness, whether you use a touch screen or a mouse, your rough connection speed, and the text of any error our code runs into
- how you use the store: the collections and products you look at and for how long, how far you scroll, the buttons and links you press, the colors and sizes you choose, and what you add to or remove from your cart
- when you start checkout and when you reach the order confirmation page
- a random id for the browser tab you are using, and the order of the pages you view in that tab
We use this to find and fix problems and to learn which products and pages work, so we can improve the store. Our usage reports do not record what you type into forms, and this data is not designed to carry your name or email address.
Like every website, our servers see your internet address when your browser connects. We use it to turn away abusive traffic and to check whether you are in the EEA or the UK. When each report above arrives, we also use it to work out three things that we do store: the country the address is registered to, whether the visit looks automated (for example a search engine crawler, or an address that belongs to a cloud provider), and a scrambled code made from the address, your browser's description, and the date, using a secret key. The code stays the same for your visits on one day and changes the next day, so we can count returning traffic within a day. It cannot be turned back into your address. If our systems place you in the EEA or the UK, we make this code only after you accept the banner described below. We do not store the address itself.
Separately, we would like to recognize a returning visitor across visits, before you have an account, so we can understand what brings visitors back and what leads to an order, and eventually show more relevant products. Outside the European Economic Area and the United Kingdom, we do this by default: your browser gets a random id, held in its own local storage rather than a cookie, used to connect your visits and the activity described above. If our systems place you in the EEA or the UK, based on a location check we run ourselves rather than handing your connection to an outside company, we do not do this until you tell us it is fine. You will see a banner asking you to accept or decline. Accepting turns on the same random id. Declining is remembered, using that same local storage, so we do not ask again on your next visit, and the returning-visitor id described here is not created either way until you answer. The performance and error data described above is separate and is sent regardless of your answer, as explained below. The tab id in the list above is kept in your browser's session storage, which is cleared when you close the tab, only once you have the returning-visitor id. Until then it lasts for one page.
When you place an order, we attach this random id to the order so we can see which visits led to a purchase. Because an order carries your email address, this connects your browsing on this site to you. We do not use it to advertise to you on this site or anywhere else.
The reports in the list above are sent whether or not you accept the banner. If you have not accepted, or have declined, they carry no returning-visitor id and cannot be connected to an order or to you. Reports from the same page still share its tab id, and outside the EEA and the UK the daily code can connect reports from the same day.
You can clear this random id at any time by clearing your browser's site data for this site, the same way you would clear your cart.
Cookies
The site sets one cookie, and only when you sign in to see your orders. It holds nothing but a random id and keeps you signed in. It expires automatically after 30 days if you do not return, and in any case after 180 days, and signing out removes it right away. This is separate from the browser storage described above. We use no advertising or analytics cookies, and we do not allow other companies to place cookies or trackers on this site.
Do-Not-Track signals
Some browsers let you send a Do-Not-Track signal. There is no common standard yet for how a site should respond to it, so we do not currently change our behavior based on it. The banner described above is how we actually ask visitors in the EEA and UK for a real answer, rather than relying on a passive signal.
Who receives your information
We share your information with the companies that help us run the store, and give each one only what it needs for its job:
- A payment processor takes your payment under its own privacy policy. We never see your card number. It also receives the random id described above, so we can match an order to the visit that led to it.
- A manufacturing and fulfillment service receives the name, shipping address, and order information necessary to make and deliver your order.
- Our hosting and database provider stores order and account records and runs the site's servers.
- A telemetry service, shared across the sites we operate, receives the browsing and activity data described above.
- Our email provider sends the messages described in this policy, such as sign in codes and order updates.
- If you sign in with Google, Google sends us a signed confirmation of your email address, along with technical fields (such as a one-time code and an expiry) we use only to confirm that confirmation is genuine and current. We do not receive your Google password, and we keep only the email address.
We do not sell your information
We do not sell your personal information, and we do not share it with other companies for their own advertising. The sharing described above is only what each partner needs to do its job for us.
How long we keep it
We keep order records until you ask us to delete them, except where the law requires us to keep them longer, such as for accounting and tax. When you request deletion, we delete or de-identify personal information that we are not required or reasonably permitted to retain. We may retain limited information when necessary for accounting, tax, fraud prevention, security, resolving an existing dispute, establishing or defending legal claims, or another purpose permitted by law. Information retained for one of these purposes will not be used for unrelated purposes. Sign in records expire on their own. If you delete your data from the Privacy page of your account, we remove your name, email address, shipping address, and the random id described above from every order record right away and keep only the items, the amounts, and the dates.
How we protect your information
We limit who and what can reach your data. A sign in code or link expires quickly, works once, and is stored as a scrambled version rather than the original value, the same way a password would be if this site used passwords. A sign in session is a random value tied to your browser and ends automatically. Traffic to this site is encrypted. Our internal logs are built to exclude your name, email address, and any sign in code or token, even when we are troubleshooting a problem. No system is perfectly secure, and we cannot guarantee against every possible breach, but this is how we design against one.
Your choices
You can download everything we hold about you and delete it yourself from the Privacy page after you sign in. You can also ask us what we hold about you, ask us to correct it, or ask us to delete it where the law allows. Email us at the address on the Contact page.
Your rights under state privacy laws
Depending on where you live, applicable state privacy law may give you additional rights concerning your personal information, generally including the right to know what we have collected, to correct it, to delete it, and to receive a copy of it. We provide the access, correction, deletion, and portability tools described above to all customers whether or not a particular state law requires us to do so, because building one honest process is simpler than building fifty. We do not sell personal information and do not use it for targeted advertising, so there is nothing to opt out of on that front. Where applicable law provides additional rights, including a right to appeal our response to a request, we will honor those rights. Email us and we will tell you how, or point you to your state attorney general's office.
Marketing email and text messages
We do not send marketing email today, though we plan to. Marketing email and text messages from us are both opt-in: we will not enroll you automatically, and buying something from us is never treated as enrollment. If you opt in to marketing email, every message will include a way to unsubscribe, and we will honor that request promptly. If you opt in to text messages, you can stop them at any time by replying STOP, and message and data rates may apply. An order-related message you already expect, such as a shipping notification, is not marketing and is not affected by this section.
Mobile opt-in information and consent — including your phone number and the fact that you agreed to receive text messages — are not shared with or sold to third parties or affiliates for marketing purposes under any circumstances.
Visitors outside the United States
We ship only to addresses in the United States today, but this site can be browsed from anywhere. If our systems place you in the European Economic Area or the United Kingdom, the browser tracking described above waits for your consent, as explained there. Wherever you are, the information in this policy is transferred to and processed in the United States. Depending on your location, you may have rights to access, correct, delete, or object to our processing of your information, and to complain to your local data protection authority. Reach us at the email address on the Contact page to exercise any of these.
Children
This site is not meant for children under 13, and we do not knowingly collect their information. This follows the US Children's Online Privacy Protection Act. If you believe a child under 13 has given us information, email us and we will delete it.
Changes
If we change this policy we will post the new version here and update the date below.