Privacy Policy
Last updated: September 18, 2026
4 things typed by you, 3 traces the site logs on its own, 5 companies that handle a piece each, 0 advertising pixels, and 1 email to see, correct or delete any of it. Read that twice and you have the policy. It was written by looking at what the site does, 1 request at a time, and writing that down: where a number is given, it is the number the software uses, and where a company is named, it is a company that really receives something.
You are covered by this policy when you visit or order
Who is responsible. KENNETH COLBAUGH LLC, Decatur, Tennessee, the operator of the site, for anyone who loads a page on ainekay.com, opens an account or places an order.
Where the data goes. The United States, with 2 exceptions: order emails leave through Brevo, whose servers are in the European Union, and the request that fetches a page passes through the nearest server of Cloudflare's worldwide network. Payments run through Stripe and PayPal, both of which you will recognize from other shops. Ainekay is a US business selling to US addresses, and the map of where your data goes is as short as that sentence. 2 routes. No more.
You give us 4 things at checkout
At checkout, and this is the notice at collection. A name, a delivery address and an email address; a phone number is optional. Everything below is typed by you. On purpose.
- If you open an account you add a password, and a birthday if you fill in the optional field.
- If you write to us we hold whatever you put in the email or the form, and any photo you attach.
- If you post a review we hold the text, the star rating and the name you sign it with.
- If you use the chat bubble we hold the text you type into it.
Your card number? Never. It goes to Stripe or PayPal and not to us, typed into a frame that belongs to the processor, and our server sees a payment reference and the last 4 digits at most. The birthday field exists so that an account holder who ticked the marketing box can get a birthday email; leave it blank and nothing happens.
You leave 3 traces the site logs on its own, and 1 counter we keep
3 traces, then 1 counter. Nothing else.
- Trace 1 is the server log: your IP address, browser type, the page requested and the time, written by the web server for every request.
- Trace 2 is the referrer cookie, named sf_src, set only when you arrive through a link that carries a campaign or click identifier; it records that source and your landing page for 30 days.
- Trace 3 is the pair of processor cookies, __stripe_mid plus __stripe_sid, placed on the account and checkout pages for fraud screening.
- The counter is ours: while a tab is open, the page reports to our own server every 10 seconds which page it is showing, with a random session number, the page title and the referrer. That feeds a visitors-right-now count in our dashboard.
The counter is first-party: it talks to ainekay.com and to no advertising network. No Google Analytics tag runs on this site, no Meta pixel, no TikTok pixel and no Microsoft tag, because the settings page that would enable them is switched off, and if that ever changes this section is rewritten first. 0 pixels.
You get emails about your order, and marketing only if you ticked the box
Always sent. The order confirmation, a shipping email with the USPS number, a refund email when money moves, and replies to anything you write. These cannot be switched off while an order is open, because they carry the tracking number and the refund notice, and they are not marketing.
Sent only with the box ticked. News about the list and occasional offers, to the address on your account or order. The box is the newsletter form on the home page, the account sign-up form, and the "Email me with news and offers" line at checkout, unticked by default. No box, no marketing.
To stop. The unsubscribe link at the foot of every marketing email, the switch on your account page, or 1 email to us; honored within 10 business days, usually the same day. Beyond that, your details are used to fill the order, keep the tax record, answer your message, and let Stripe or PayPal screen the payment.
Cookies
5 cookies can appear. None is for advertising.
- cookie_consent is set by the site's consent module, which records a choice even though the cookie banner is switched off on this store; it holds a yes-or-no value and nothing about you.
- A login cookie is set only after you sign in to an account, so that the next page still knows you; the cart itself is held by your browser, not by a cookie.
- sf_src is the referrer cookie described above: 30 days, only after a tagged link.
- __stripe_mid and __stripe_sid are Stripe's cookies on the account and checkout pages, kept for 1 year and 30 minutes respectively and set by Stripe.
The banner is switched off on purpose, because there is no analytics or advertising script for it to control; if such a script is ever installed, we turn the banner on again that same day and rewrite this cookie list before the script runs. Any of these can be deleted from your browser whenever you like. Clearing site data empties your cart, and deleting the cookies signs you out and changes nothing else you would notice.
You are known to 5 companies that handle your data
Each of the 5 gets the piece it needs for its job and nothing more.
- Stripe handles card payments and Apple Pay or Google Pay, and receives the card details and the billing name.
- PayPal handles PayPal payments and receives what you enter on PayPal's own pages.
- USPS delivers, and receives the name and shipping address on the label.
- Brevo sends the order and account emails, and receives your email address and the contents of those emails.
- Cloudflare serves the pages and shields the server, and sees your IP address as any web host would.
Beyond the 5, the distribution partner that packs the order sees the name and address on the packing slip, and the hosting company that runs the server holds the database under contract. None of them buys the data. None sells it on. None is allowed to use it for anything but the job. If a court or a law forces us to hand data over, we do what the order says and no more. Links on this site to publishers' or carriers' own sites take you to pages with their own privacy rules.
You are kept on file for as long as the tax code says, then deleted
7 years. Order records stay 7 years from the order, because business records have to be kept for tax and accounting. Then they go.
Until you say so. An account stays until you delete it from the account page or ask us to; messages stay in the site's message log so that a later question about the same order can be answered, and are deleted when you ask; the marketing list keeps your address until you unsubscribe, and the address then stays on a suppression list so we do not write again.
As long as the software keeps it. The server log lives only for as long as the hosting software keeps it. We copy it nowhere. Deleting an account removes the login, the saved address and the birthday; the orders behind it stay for the 7 years, with the name on them, because that is what a tax record is.
You are protected by the same locks on every page
In transit, every page runs on HTTPS, the admin side included. Card data is never on our server; the processor's frame handles it. The order system is opened only by the people who run the desk, with individual logins, and if something goes wrong, every affected customer gets an email, along with the notices state law requires. No system is beyond a breach, and we will not write that ours is. What we can write is that the most valuable thing a thief could want, the card number, is not in our building. That is deliberate.
Your rights
Every request goes to [email protected] and is acknowledged within 1 business day.
- See what we hold: email us and a copy comes back within 45 days.
- Correct it, on the account page or with 1 email.
- Delete it the same way, though order records stay the 7 years.
- Take it with you, as a copy of your orders in a readable file, on request.
- Stop marketing by any of the 3 routes above.
The list ends there. We may ask for a reply sent from the address on the account. That is how we know the request is yours.
California residents
The California Consumer Privacy Act gives you 4 rights here. You can know what is held, have it deleted or corrected, and refuse any sale or sharing, with equal service afterwards. Ainekay sells no personal information and shares none for advertising. The full statement, the 15-day and 45-day clocks and the address for requests are on the page Do Not Sell or Share My Personal Information.
Children
The site is for adults buying books. Nothing is aimed at anyone under 13, and an account or order that turns out to belong to a child is deleted when we learn of it. A parent who thinks that has happened can write to the desk below. We act the same day. The "Last updated" line moves whenever the wording does; the wording in force is whatever was live when you ordered.
The bookseller
Ainekay is the trading name of KENNETH COLBAUGH LLC, a limited liability company formed in Tennessee.
Employer ID: 99-4178666
Registered office: 1015 Sneed Rd, Decatur, TN 37322, United States
Email address: [email protected]
Telephone: +1 (615) 809-1356
Message form: ainekay.com/pages/contact
Open: Monday to Friday, 8:00 AM to 4:30 PM Central Time
You hear back: within 1 business day, from a person
