Data Protection

Privacy Notice

This notice explains how Daily Progress handles personal data collected through the website.

Last updated: July 13, 2026

Who Is Responsible

Daily Progress operates this website and acts as the controller of the personal data described here. Privacy requests can be submitted through our contact page. Commercial legal-entity and trading-address details will be published before sales open.

Data We Collect

  • Newsletter: email address, signup source, page reference, basic device/request metadata, and confirmation-email status.
  • Checkout reservations: title, first name, last name, email, selected product, size, quantity, reservation ID, page reference, basic device/request metadata, and confirmation-email status.
  • Contact requests: title, first name, last name, email, message, page reference, basic device/request metadata, and notification status.
  • Contact history on this device: a copy of successfully submitted contact details, including name, email, message, date, and time, is stored locally in your browser so that device can display it. This local copy is deleted automatically 30 days after submission.
  • Reservation history on this device: a local receipt containing the reservation ID, selected items, value, date, and time is stored in your browser and displayed in the authenticated account area. Reservation receipts have no automatic browser-expiry period.
  • Cart: product, size, and quantity stored locally in your browser so the cart remains available between visits.
  • Accounts: email, authentication provider, profile metadata, session records, and password-security data handled by Supabase Auth.
  • Paid orders: order ID, account ID, products, sizes, quantities, totals, payment status and provider references, name, phone, shipping address, fulfilment status, and timestamps.

Daily Progress does not receive or store complete payment-card details. Stripe collects and processes payment credentials on its hosted page. Supabase Auth processes passwords; the storefront does not store plain-text passwords.

Why We Use It

  • to send product updates when you join the newsletter;
  • to record and confirm hoodie reservations at your request;
  • to answer messages and provide requested support;
  • to protect forms, prevent abuse, and maintain site security;
  • to plan launch demand using limited operational records.
  • to authenticate accounts, take payment, prevent overselling, fulfil orders, and provide order support;

Depending on the interaction, processing is based on your consent, steps taken at your request, and our legitimate interests in operating and securing the website. You may withdraw newsletter consent at any time through the contact page.

Service Providers And Transfers

We use Vercel for website hosting, Supabase for protected database storage and authentication, Stripe for payment processing, and Resend for transactional and product email delivery. These providers process limited data on our behalf and may process it in countries outside your own. Where required, transfers must use an applicable legal safeguard.

We do not sell personal data. We may disclose limited information when required by law, to protect rights and security, or during a lawful business reorganisation.

Retention And Security

Newsletter data is retained until you withdraw, the list is closed, or it is no longer needed for product communication. Reservation records are retained while the first-drop process remains active and for a reasonable support or record-keeping period afterward. Contact messages are retained until resolved and for a reasonable support period. Account and order records are retained for account operation, fulfilment, fraud prevention, support, and applicable tax or legal record-keeping periods. Security metadata follows the retention of the associated record unless it is needed longer for abuse prevention or legal claims.

Access is restricted to server-side systems and authorised operators. No online system can guarantee absolute security, but we use access controls, validation, rate limiting, and encrypted network connections.

Your Choices And Rights

Depending on the law that applies to you, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may withdraw consent without affecting earlier lawful processing and may complain to the relevant data-protection authority.

Submit a request through the contact page using the same email address associated with your data. We may need to verify identity before acting.

Browser Storage And Children

The site uses essential authentication cookies for secure account sessions and local browser storage for cart continuity, contact-message history, reservation receipts on the current device, and to remember when the privacy notice has been dismissed. Contact-message copies are removed after 30 days. Reservation receipts remain until you remove them. Local copies can also be removed through the relevant Clear button or your browser controls. Removing a local copy does not by itself delete the corresponding operational record held by Daily Progress; submit a request through the contact page for that. We do not currently run advertising pixels or behavioural advertising cookies. The site is not directed to children, and we do not knowingly collect personal data from children who cannot lawfully provide it.

Updates

We will update this notice when analytics or DP Club features are introduced or when providers and processing materially change. Changes will be identified by a new date at the top of this page.