Global Privacy Policy & Data Protection Protocol
Operating Entity: Mountain49 LLC • Effective Date: January 1, 2026 • Standard: GDPR & CCPA
1. DATA CONTROLLER IDENTIFICATION & PRINCIPLES
This Privacy Policy ("Policy") explains how Mountain49 LLC ("Company," "we," "us," or "our"), as the designated Data Controller, collects, processes, stores, and protects personal data obtained through the WaypointKit electronic commerce store.
Mountain49 LLC is incorporated under the laws of Wyoming, United States, and maintains active data compliance measures aligned with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and the California Consumer Privacy Act ("CCPA").
We adhere strictly to the principle of Data Minimization: We collect only the precise informational elements required to process your transaction in Euro (€), deliver your digital download tokens, fulfill tax reporting obligations, and prevent fraudulent payment activity. We never sell, monetize, rent, or lease traveler data to third-party marketing brokers.
2. CATEGORIES OF PERSONAL DATA COLLECTED
When you interact with the WaypointKit store or execute an order, we may collect and process the following categories of information:
A. Identification & Contact Information
Customer Full Name, Billing Email Address, and Phone Number provided during the Stripe Checkout sequence.
B. Billing & Fiscal Address Information
Country of residence, postal code, street address, and province used to determine applicable European VAT / digital services tax rates.
C. Transactional & Order Telemetry
Order identification strings, transaction timestamps, items purchased, gross sums in Euro (€), and fulfillment download logs.
D. Device & Connectivity Metadata
IP address, approximate geographic country location, browser user-agent string, and interface language preferences (EN/FR).
3. FINANCIAL PAYMENT DATA & PCI-DSS COMPLIANCE
All financial payments executed on WaypointKit are handled through Stripe, Inc. and its PCI-DSS Level 1 certified infrastructure.
Mountain49 LLC NEVER collects, views, processes, or stores your full credit card number, CVV/CVC security codes, or bank account PINs on our servers. When entering payment details, your card data is encrypted and transmitted directly from your client browser to Stripe via 256-bit TLS/SSL encryption.
Mountain49 LLC only receives an encrypted token, the card brand (e.g. Visa, Mastercard), the last four digits of the payment card, and transaction authorization verification.
4. LAWFUL BASES FOR DATA PROCESSING (GDPR ARTICLE 6)
We process your personal data under the following legal justifications recognized under European data privacy legislation:
- Contractual Performance (Art. 6(1)(b) GDPR): To generate your unique digital kit download keys, deliver your purchased field systems, and provide technical support.
- Legal & Fiscal Obligation (Art. 6(1)(c) GDPR): To comply with mandatory European cross-border tax rules, digital VAT accounting, and corporate recordkeeping.
- Legitimate Interests (Art. 6(1)(f) GDPR): To detect and mitigate fraudulent transaction attempts, maintain store availability, and safeguard our intellectual property.
- Consent (Art. 6(1)(a) GDPR): When you voluntarily submit an inquiry through our Customer Support form or opt in to receive seasonal packing updates.
5. SUB-PROCESSORS & THIRD-PARTY DISCLOSURES
Mountain49 LLC does not sell, trade, or distribute your personal data. We share information only with contracted service providers essential to store operations:
• Stripe, Inc.: Payment processing, fraud detection (Radar), and electronic receipt transmission.
• Cloudflare & Infrastructure CDNs: Encrypted content delivery, DDoS prevention, and asset caching.
• Governmental Tax Authorities: Disclosed only where mandatory for statutory VAT and digital excise reporting.
6. TRANS-BORDER DATA TRANSFERS & SAFEGUARDS
Because Mountain49 LLC is an entity organized in the United States, your personal data collected during checkout may be transferred to, stored, and processed in the United States.
To ensure adequate protection for transfers originating from the European Economic Area (EEA) and the United Kingdom, Mountain49 LLC and its processing partners utilize European Commission Standard Contractual Clauses (SCCs) and adherence to the EU-U.S. Data Privacy Framework where applicable.
7. DATA RETENTION PROTOCOLS
We retain personal information only for the duration necessary to satisfy the commercial purposes outlined in this Policy:
- Order and transaction records: Retained for 7 years to comply with statutory corporate tax and fiscal auditing obligations.
- Customer support communications: Retained for 24 months following resolution of the support ticket.
- Transient web access logs: Retained for up to 90 days for network security and intrusion analysis before automated erasure.
8. YOUR RIGHTS UNDER GDPR & CCPA
Depending on your geographic location, you enjoy comprehensive legal rights regarding your personal information:
To exercise any of these rights, transmit a verified request to support@mountain49.com. We respond to all verified statutory privacy petitions within 30 calendar days without charge.
9. TECHNICAL & ORGANIZATIONAL SECURITY MEASURES
Mountain49 LLC implements defense-in-depth technical safeguards to shield personal data against unauthorized disclosure, alteration, destruction, or interception. These safeguards include 256-bit TLS data transmission encryption, restricted role-based internal access controls, regular vulnerability auditing, and automated brute-force protection.
10. DATA PROTECTION INQUIRIES & DPO DISPATCH
Direct all privacy compliance inquiries, erasure petitions, or regulatory filings to:
Mountain49 LLC — Data Privacy Office
Division: WaypointKit Operational Security
Corporate Headquarters: Sheridan, Wyoming, USA
Direct Compliance Email: support@mountain49.com
Supervisory Jurisdiction: State of Wyoming / EU Representative Framework