Do Not Sell or Share My Personal Information
California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) compliance summary for goldenhour.
What we do
We do notsell personal information to third parties in the CCPA sense. We do not engage in cross-context behavioral advertising (the CPRA “sharing” definition).
We use processors strictly for service delivery: Stripe for payments, Twilio for SMS, Resend for transactional email, PostHog (when you opt in) for product analytics, Sentry for error reporting, and Cloudflare R2 for photo hosting. These are not sales under the CCPA.
How to opt out anyway
We honor your browser's Global Privacy Control (GPC) signal as the authoritative opt-out. When GPC is enabled, your browser sends the Sec-GPC: 1 header on every request. Our servers read that header and:
- Set a
gh_gpc_honoredcookie so downstream analytics surfaces no-op. - Drop your request from PostHog event capture, even after consent is given (GPC takes precedence).
- Render an “Opt-Out Honored” indicator in the footer of every page so you can verify the signal is being respected.
See /help/gpc for browser-specific instructions on enabling GPC.
Other ways to reach us
For any other privacy request (access, deletion, correction, portability), email privacy@goldenhourhq.com. We respond within the CCPA-mandated 45-day window.
Last updated: 2026-05-20.