Your Expedition Cart

Official Stripe Checkout • Euro (€)

Subtotal 0,00 €
Instant Download
Stripe 256-Bit SSL
Apple Pay Google Pay Mastercard Visa
🌸 PRIVACY PROTOCOL // GDPR & CCPA COMPLIANT

Global Privacy Policy & Data Protection Protocol

Operating Entity: Mountain49 LLC • Effective Date: January 1, 2026 • Standard: GDPR & CCPA

1. DATA CONTROLLER IDENTIFICATION & PRINCIPLES

This Privacy Policy ("Policy") explains how Mountain49 LLC ("Company," "we," "us," or "our"), as the designated Data Controller, collects, processes, stores, and protects personal data obtained through the WaypointKit electronic commerce store.

Mountain49 LLC is incorporated under the laws of Wyoming, United States, and maintains active data compliance measures aligned with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and the California Consumer Privacy Act ("CCPA").

We adhere strictly to the principle of Data Minimization: We collect only the precise informational elements required to process your transaction in Euro (€), deliver your digital download tokens, fulfill tax reporting obligations, and prevent fraudulent payment activity. We never sell, monetize, rent, or lease traveler data to third-party marketing brokers.

2. CATEGORIES OF PERSONAL DATA COLLECTED

When you interact with the WaypointKit store or execute an order, we may collect and process the following categories of information:

A. Identification & Contact Information

Customer Full Name, Billing Email Address, and Phone Number provided during the Stripe Checkout sequence.

B. Billing & Fiscal Address Information

Country of residence, postal code, street address, and province used to determine applicable European VAT / digital services tax rates.

C. Transactional & Order Telemetry

Order identification strings, transaction timestamps, items purchased, gross sums in Euro (€), and fulfillment download logs.

D. Device & Connectivity Metadata

IP address, approximate geographic country location, browser user-agent string, and interface language preferences (EN/FR).

3. FINANCIAL PAYMENT DATA & PCI-DSS COMPLIANCE

All financial payments executed on WaypointKit are handled through Stripe, Inc. and its PCI-DSS Level 1 certified infrastructure.

Mountain49 LLC NEVER collects, views, processes, or stores your full credit card number, CVV/CVC security codes, or bank account PINs on our servers. When entering payment details, your card data is encrypted and transmitted directly from your client browser to Stripe via 256-bit TLS/SSL encryption.

Mountain49 LLC only receives an encrypted token, the card brand (e.g. Visa, Mastercard), the last four digits of the payment card, and transaction authorization verification.

4. LAWFUL BASES FOR DATA PROCESSING (GDPR ARTICLE 6)

We process your personal data under the following legal justifications recognized under European data privacy legislation:

  • Contractual Performance (Art. 6(1)(b) GDPR): To generate your unique digital kit download keys, deliver your purchased field systems, and provide technical support.
  • Legal & Fiscal Obligation (Art. 6(1)(c) GDPR): To comply with mandatory European cross-border tax rules, digital VAT accounting, and corporate recordkeeping.
  • Legitimate Interests (Art. 6(1)(f) GDPR): To detect and mitigate fraudulent transaction attempts, maintain store availability, and safeguard our intellectual property.
  • Consent (Art. 6(1)(a) GDPR): When you voluntarily submit an inquiry through our Customer Support form or opt in to receive seasonal packing updates.

5. SUB-PROCESSORS & THIRD-PARTY DISCLOSURES

Mountain49 LLC does not sell, trade, or distribute your personal data. We share information only with contracted service providers essential to store operations:

• Stripe, Inc.: Payment processing, fraud detection (Radar), and electronic receipt transmission.

• Cloudflare & Infrastructure CDNs: Encrypted content delivery, DDoS prevention, and asset caching.

• Governmental Tax Authorities: Disclosed only where mandatory for statutory VAT and digital excise reporting.

6. TRANS-BORDER DATA TRANSFERS & SAFEGUARDS

Because Mountain49 LLC is an entity organized in the United States, your personal data collected during checkout may be transferred to, stored, and processed in the United States.

To ensure adequate protection for transfers originating from the European Economic Area (EEA) and the United Kingdom, Mountain49 LLC and its processing partners utilize European Commission Standard Contractual Clauses (SCCs) and adherence to the EU-U.S. Data Privacy Framework where applicable.

7. DATA RETENTION PROTOCOLS

We retain personal information only for the duration necessary to satisfy the commercial purposes outlined in this Policy:

  • Order and transaction records: Retained for 7 years to comply with statutory corporate tax and fiscal auditing obligations.
  • Customer support communications: Retained for 24 months following resolution of the support ticket.
  • Transient web access logs: Retained for up to 90 days for network security and intrusion analysis before automated erasure.

8. YOUR RIGHTS UNDER GDPR & CCPA

Depending on your geographic location, you enjoy comprehensive legal rights regarding your personal information:

Right of Access: Request a copy of all personal records maintained by Mountain49 LLC.
Right to Rectification: Request prompt correction of incomplete or outdated billing data.
Right to Erasure: Request permanent deletion ("Right to be Forgotten") subject to statutory tax rules.
Right to Restriction: Limit the scope of data processing during formal disputes.
Right to Data Portability: Receive your data in a structured, machine-readable JSON format.
Right to Lodge a Complaint: File a grievance with your national data protection supervisory authority.

To exercise any of these rights, transmit a verified request to support@mountain49.com. We respond to all verified statutory privacy petitions within 30 calendar days without charge.

9. TECHNICAL & ORGANIZATIONAL SECURITY MEASURES

Mountain49 LLC implements defense-in-depth technical safeguards to shield personal data against unauthorized disclosure, alteration, destruction, or interception. These safeguards include 256-bit TLS data transmission encryption, restricted role-based internal access controls, regular vulnerability auditing, and automated brute-force protection.

10. DATA PROTECTION INQUIRIES & DPO DISPATCH

Direct all privacy compliance inquiries, erasure petitions, or regulatory filings to:

Mountain49 LLC — Data Privacy Office

Division: WaypointKit Operational Security

Corporate Headquarters: Sheridan, Wyoming, USA

Direct Compliance Email: support@mountain49.com

Supervisory Jurisdiction: State of Wyoming / EU Representative Framework

Encrypted Stripe Checkout in Euro (€):
Apple Pay Google Pay Mastercard Visa