Directory Privacy
Privacy Notice
This notice describes what the ChristmasContractor.com Contractor Network collects, why, where it is stored, and which outside services can receive information. It describes the behaviour of this application only.
Effective date: August 28, 2026 · Version 1.2
1. Who is responsible
The data controller for the personal information described in this notice is Kingdom Christmas Lights, LLC, doing business as ChristmasContractor.com.
Business address: 15462 Highway 105 East, Plantersville, Texas 77363, United States.
Privacy contact: info@christmascontractor.com.
This notice is effective August 28, 2026, and is version 1.2.
2. Cookies this site sets
These are the cookies this application sets. It does not set advertising or cross-site tracking cookies.
- Signed-in session (
cc_directory_session) — created when you sign in. It contains your email address, a role derived from that address, the time it was issued, and, where available, an account identifier. It is signed with HMAC-SHA-256, marked HttpOnly and SameSite=Lax, marked Secure in production, and expires 30 days after it is issued. Your permissions are re-checked on the server on each request; the cookie alone does not grant access. - Sign-in hand-off (
cc_shopify_auth_state,cc_shopify_auth_verifier,cc_shopify_auth_nonce) — short-lived values used only to complete a single sign-in and protect it against interception and replay. They are cleared once authorisation finishes. - Sign-out reference (
cc_shopify_id_hint) — an identity-provider reference held so that signing out of the directory can also end the upstream session. It is encrypted with AES-256-GCM, bound to that single purpose, and cleared at logout. - Pre-launch access (
cc_prelaunch_bypass) — set only where a pre-launch gate is enabled, to remember that access was granted. - Get Listed / claim hand-off (
cc_acquisition_intent) — set when you start a Get Listed or claim request, so your in-progress request survives the next step. It is encrypted with AES-256-GCM, marked HttpOnly and SameSite=Lax, and expires 45 minutes after it is set; both the cookie and its sealed contents carry that expiry independently. - Operational-analytics opt-out (
cc_operational_analytics_opt_out_v1) — records an analytics opt-out for up to one year so the browser and server apply the same preference. This is not a marketing or advertising preference, and it does not change Shopify’s separate customer-privacy controls.
3. Signing in
Contractor account sign-in is not yet enabled on the public site: browsing the directory, searching, and reading profiles need no account, and public listing and claim requests run through the Get Listed process without one.
When account sign-in is enabled, it is handled by Shopify Customer Account authentication (OpenID Connect). You authenticate with Shopify; this directory receives confirmation of your identity, not your password. The session cookie described above is then issued by this application.
4. Listings, claims, and drafts
When a business is added to the directory or an existing profile is claimed, the request records the business details supplied, the identity and stated role of the person making the request, its binding to a signed-in account, the request status, and review metadata.
Drafts and claim requests are private while under review. Publication is a separate, manual decision. Contact details become publicly visible only where each one has been separately approved for public display; an owner’s email address is not published by default.
While a Get Listed or claim request is in progress, the request details you have entered are carried in the short-lived encrypted cc_acquisition_intent cookie described in section 2 until the request is submitted or the cookie expires.
5. Information you type into forms
Depending on which form you use, the directory may collect:
- your name and the company you represent;
- contact details you provide, such as email address and telephone number;
- the service area, property address, or project location relevant to your request;
- the message or project description you write;
- your consent or attestation where the form asks for one;
- a résumé or work history, where you apply through a hiring form.
Provide only what a request needs. Do not include information you would not want a reviewer to read.
6. Interaction events
First-party operational analytics.Where the collection policy permits it and the owner’s Production gate is on, the site measures usage, SEO and campaign attribution, Directory activity, Design Studio activity, hiring and contractor-acquisition funnels, Product Help outcomes, commerce hand-offs, and product or site improvement. Eligible United States traffic may be measured by default without a universal analytics prompt. A visitor opt-out, a blocked or unknown region, an internal route, or automated traffic prevents the restricted event from being stored.
The allowlisted event record can contain an event name, route template, limited device class, short-lived pseudonymous session identifier, first- and current-session campaign/source labels, referring hostname, a non-personal entity identifier, and small event-specific properties. It rejects names, email addresses, telephone numbers, street addresses, IP addresses, raw user-agent strings, full referring URLs, raw search or Product Help question text, messages, Shopify customer/order contents, and arbitrary form contents.
Policy-eligible events are stored in the United States in the protected first-party Supabase/PostgreSQL analytics store. Raw access is limited to the owner and explicitly designated analytics administrators; dashboard reporting uses de-identified daily aggregates. The server-side gate can stop collection before a request body is read. While that gate is off, no new first-party operational analytics event is written.
This first-party store is not used for retargeting, ad personalization, cross-company profiling, advertising audience construction, or sale of personal data. Marketing and advertising consent remains separate. Product Help’s operational learning system is also separate: its question content is not copied into the general analytics event store.
7. Where information is stored
On the server. In development and in the current MVP configuration, records are written to local JSON files on the server. Where durable storage is configured, records are written instead to a Supabase/PostgreSQL database.
In your own browser.This application stores a substantial amount of working data in your browser’s localStorage. This is not limited to interface preferences. Depending on which tools you use, it can include:
- Saved client contact profiles — first and last name, company name, job title, email address, telephone number, and property address, together with an email-verification status.
- Approved estimate packages — the approved scope, pricing and planning detail for an estimate.
- An approved-job queue — jobs carried forward from approved estimates.
- Customer intake details, request and response drafts, contractor pricing and labour profiles, job-cost planning, service libraries, and inventory assignment plans.
- Design and layout selections and interface preferences.
This browser-held data stays on the device you are using. It is not a copy held on our servers, it is not synchronised between your devices, and anyone else who uses that browser profile can read it. Each of these stores has a corresponding clear action in the tool that created it, and clearing your browser’s site data removes all of them.
sessionStorage is used for short-lived state that is discarded when the browser tab closes.
Regions. This application is hosted in the United States, and its database is located in the United States.
Application integrations. Of the conditional application services listed in section 8, Supabase is enabled in production for required database and protected analytics storage. Resend, Twilio, Google Sheets, OpenAI and Google Gemini are not enabled: at launch this application sends no email, sends no SMS, synchronises nothing to Google Sheets, and sends nothing to OpenAI or Google Gemini. If any of these is enabled later, this notice will be updated first.
8. Outside services
These services can receive information, each only in the situation described:
- Shopify — when you sign in or sign out.
- Supabase — when durable database storage is configured, as the store of record.
- Google Analytics 4 (GA4), Search Console, Merchant Center, and Shopify Analytics — separate Google and Shopify systems report site/store engagement, search performance, product visibility, and commerce activity under their own controls. The first-party event store does not copy raw Shopify customer or order records, Product Help question text, or Search Console query rows into its raw event table.
- OpenStreetMap— map tiles load from OpenStreetMap servers on pages that display a map, so your browser’s request reaches them directly.
- Nominatim (OpenStreetMap) — where a location field offers look-up, the text you type into that field is sent from your browser to Nominatim to resolve it to a place.
- unpkg — the Leaflet mapping library loads from unpkg.com on pages that display a map.
- Resend — where email notification is configured, to send directory email.
- Twilio and Resend — for administrator-initiated invitations, where the owner has authorised them.
- Google Sheets — only where an operator has explicitly enabled a sheet sync.
- OpenAI and Google Gemini — this application carries optional AI-assisted profile drafting and lead-analysis support. Where an operator enables one of these providers and supplies its API key, the business or lead text being drafted or analysed is sent to that provider. Neither is enabled by default, and this notice does not assert that either is live in production; see item 4.
9. How long information is kept
Session cookies expire as described in section 2. Stored records are kept as follows:
- Leads — 24 months after the most recent meaningful activity, unless continued retention is reasonably necessary for an active business relationship, a legal obligation, fraud prevention, or a dispute.
- Claims — 36 months after approval, rejection, withdrawal, or other final resolution. The minimum information required to document an ownership decision, prevent duplicate or fraudulent claims, or resolve a dispute may be retained longer where reasonably necessary.
- Listing drafts — 12 months after the most recent activity; a draft that has not been submitted or completed by then is deleted.
- Hiring submissions — 2 years after submission or the final hiring decision.
- First-party operational analytics — raw policy-eligible United States events are retained for 90 days and de-identified daily aggregates for 25 months when collection is authorised and enabled. No event is retained for traffic blocked by the regional, opt-out, bot, internal-route, or Production-gate policy. The retention job is controlled as part of the separately authorised analytics activation.
Request logs. This application does not create its own request log of IP addresses or browser user-agent strings. Hosting, security, content-delivery, database and other infrastructure providers may temporarily process operational and security logs under their own configurations and contractual retention practices. Where a privacy request is made, only the minimum record reasonably necessary to document the request, its authentication, the response, and any appeal is retained.
10. Your choices and requests
You can decline to submit any form. You can sign out, which clears the session cookie described in section 2. You can clear cookies and local storage in your browser at any time. The footer’s unobtrusive Privacy choices control lets you opt out of future first-party operational analytics or later remove that opt-out. Opting out clears first-touch, session-touch, and pseudonymous-session analytics state; it does not affect site functionality and does not change the separate marketing or advertising preference.
Making a privacy request. To request access to, correction of, or deletion of personal information, email info@christmascontractor.com. Identity is verified by matching your email address and the business, listing, claim, application, or submission information already associated with the relevant record; we ask only for the additional information reasonably necessary to authenticate you or confirm your authority to act for a business or another person, and we do not require government identification unless it is genuinely necessary for a specific high-risk request and no less intrusive method is reasonably available.
Timing. We respond within 45 days of receiving an authenticated request. Where reasonably necessary, we may take one additional 45-day extension and will tell you why within the initial 45-day period.
Appeals. If you disagree with a decision, reply to it or email info@christmascontractor.com with the subject line “Privacy Appeal”. We provide a written response within 60 days of receiving an appeal. If an appeal is denied, we explain why and provide information about submitting a complaint to the appropriate state regulator or attorney general.
Applicable law. These processes are operated under the Texas Data Privacy and Security Act and other applicable United States federal and state privacy laws.
What we do not do. We do not sell personal information. We do not share personal information for cross-context behavioural advertising. We do not use personal information for targeted advertising. We do not carry out profiling that produces legal or similarly significant effects.
Children and minors.ChristmasContractor.com is a general-audience business directory and industry platform; it is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The minimum age for submitting information through this platform is 18: people under 18 may not submit business listings, ownership claims, hiring applications, contact forms, account requests, or other personal information, and no parent-or-guardian submission workflow for minors is enabled. If we learn that personal information was submitted by a child or minor contrary to this policy, we delete it unless retention is legally required. A verified parent or legal guardian may request access to or deletion of a child’s information at info@christmascontractor.com.
11. Contact
For questions about the directory itself, see the support details in the site footer. Privacy requests go to info@christmascontractor.com as described in section 10.


Official ChristmasContractor.com Store
Featured Vendor
Shop Contractor-Grade Christmas Light Supplies
Bulbs, wire, clips, timers, décor, permanent lighting, and installation essentials from the official ChristmasContractor.com store.
Shop Supplies