Privacy Policy
Effective date: May 18, 2026
This Privacy Policy explains how Surprise Flowers LLC ("we," "us," or "our") collects, uses, and shares information about you when you use surprise-flowers.com (the "Site") or our subscription gift service (the "Service"). By using the Service, you agree to the practices described here.
1. Information We Collect
We collect information directly from you, automatically as you use the Site, and from a small number of service providers who help us run the business.
From you, when you sign up
- Your name, email address, phone number, and billing address
- For each recipient: their name, delivery address, optional phone number, and any gift message you choose to include
- Account credentials (if we add account login in the future)
Automatically, as you use the Site
- Device and browser information (user agent, IP address, screen size)
- A small set of session cookies used to keep your checkout state working — we do not use third-party advertising or tracking cookies
- Standard server access logs
From service providers
- Stripe (our payment processor) shares limited transaction details with us, such as the last four digits of the card used, the brand, and a payment status. We never receive your full card number, expiration date, or security code.
2. How We Use Information
We use the information we collect to:
- Process and deliver your subscription, including handing recipient information to our florist network so flowers can be delivered.
- Send you transactional emails — such as your order receipt and a notification approximately 14 days before each scheduled delivery.
- Provide customer support.
- Detect, investigate, and prevent fraud or other harmful activity.
- Comply with legal obligations and enforce our Terms of Service.
We do not use your information to send marketing emails unless you have specifically opted in. We do not sell your personal information.
3. Who We Share Information With
We share personal information only with the service providers required to run the Service, and only the minimum needed for them to do their job.
| Provider | What we share | Why |
|---|---|---|
| Fulfillment partners | Recipient name, delivery address, phone, gift message; your name and email | Florist network that prepares and delivers each arrangement |
| Stripe (stripe.com) | Your payment details — collected directly by Stripe on their hosted checkout page | Payment processing |
| Authorize.net (authorize.net) | A short-lived payment token representing our merchant card | Payment processing for the merchant-side wholesale payment to our fulfillment partner |
| Email service provider (e.g., SendGrid) | Your name, email, and the contents of transactional messages | Sending receipts and delivery notifications |
| Hosting provider (e.g., Render) | Server logs and database content | Running the Site |
We may also share information when we believe in good faith it is required to: comply with a legal obligation; protect our rights, property, or safety, or that of our customers or others; or facilitate a business transfer (such as a merger or acquisition), in which case the recipient will be bound by privacy obligations at least as protective as these.
4. How Long We Keep Information
We retain personal information for as long as your subscription is active and for a reasonable period afterward to comply with tax, accounting, and legal obligations (typically up to seven years for transactional records). Recipient information is retained for the duration of the related subscription. You may request earlier deletion as described below; we will honor the request to the extent we are not legally required to retain the information.
5. How We Protect Information
We use industry-standard technical and organizational safeguards, including TLS encryption for all data in transit and access controls on our databases. No system is perfectly secure, however, and we cannot guarantee that information will never be accessed, altered, or destroyed by unauthorized parties.
6. Your Rights
Regardless of where you live, you may contact us at hello@surprise-flowers.com to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information (subject to retention obligations)
- Opt out of any marketing emails
California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act gives you additional rights, including the right to know what personal information we collect, the right to delete your personal information, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. To exercise any of these rights, email us at privacy@surprise-flowers.com. We will not discriminate against you for exercising your rights.
Other states
Several U.S. states (including Virginia, Colorado, Connecticut, and Utah) have enacted similar privacy laws. Where these laws apply to your residence, we will provide equivalent rights upon request.
7. Children's Privacy
The Service is not intended for use by anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
8. International Users
The Service is intended for users in the United States. If you access the Service from outside the United States, you understand that your information will be processed and stored in the United States, where data protection laws may differ from those in your country.
9. Cookies
The Site uses a single session cookie that keeps your checkout state working as you move through the form. We do not use cross-site advertising cookies or third-party analytics cookies that profile users across other websites. You may disable cookies in your browser settings; if you do, the Site will still load but the checkout flow may not work correctly.
10. Third-Party Links
The Site may contain links to third-party websites we don't control. We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies before providing them with information.
11. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the Site at least 30 days before the changes take effect. The "Effective date" at the top of this Policy will reflect the date of the most recent revision.
12. Contact
Questions about this Privacy Policy or how we handle your information? Email privacy@surprise-flowers.com or write to:
Surprise Flowers LLC
Attn: Privacy
212 W. Troy St., Ste B
Dothan, AL 36303