Privacy policy

Strideworkz LLC

Personal Information Protection Standard

Effective Date: July 15, 2026    |    Version 1.0    |    Doing business as: Chris Ray

1. Purpose and Scope

This Personal Information Protection Standard ("Standard") establishes the policies and practices Strideworkz LLC ("Company"), operating the Chris Ray eyewear brand, follows to protect the personal information of customers, users, and business partners collected through its e-commerce and marketplace operations, including its Shopify storefront and TikTok Shop channel.

This Standard applies to all Company personnel, systems, and third-party service providers that collect, store, process, or transmit personal information on the Company's behalf.

2. Data We Collect

In the course of operating the Chris Ray storefront, the Company collects the categories of personal information described in its published Privacy Policy (available at chrisrayeyewear.com/policies/privacy-policy), including contact details, order and transaction information, device and usage information, and communications with customers. The Company does not collect personal information beyond what is reasonably necessary to fulfill orders, provide customer support, and operate its marketing and affiliate programs.

3. Data Classification

The Company classifies personal information it handles into the following tiers and applies handling controls proportionate to sensitivity:

  • Restricted: Payment card data. Not stored by the Company — all payment processing is handled exclusively by Shopify Payments and TikTok Shop's PCI-DSS compliant payment infrastructure.
  • Confidential: Customer contact and shipping information, order history. Access limited to authorized personnel on a need-to-know basis.
  • Internal: Aggregated sales, inventory, and marketing performance data. Restricted to Company personnel.
  • Public: Product listings, marketing content, published policies.

All Confidential and Restricted data is encrypted in transit (TLS/HTTPS) and at rest by the Company's infrastructure providers (Shopify and Google Workspace), consistent with those providers' respective security and compliance programs.

4. Access Control

Access to systems containing personal information is restricted to the Company's founders and designated authorized personnel on a least-privilege basis. Access to the Shopify admin, Google Workspace, and TikTok Shop Seller/Partner Center is limited to individuals whose role requires it.

  • Multi-factor authentication (MFA) is enforced on all core business accounts, including Google Workspace and Shopify admin.
  • Devices used to access Company systems are configured to auto-lock and require passcode or biometric authentication.
  • Account access is reviewed periodically and revoked promptly upon a personnel change.

5. Security Baseline

The Company maintains the following baseline security practices for all endpoints used to access Company systems:

  • OS-native anti-virus and endpoint protection enabled on all devices (e.g., Microsoft Defender, macOS XProtect).
  • Enforced screen-lock and passcode/biometric authentication on all devices.
  • Strong, unique passwords required for all business accounts, supplemented by MFA.
  • Software and operating systems kept current with vendor-issued security updates.

6. Vulnerability and Threat Management

The Company relies on the security patching, network monitoring, and vulnerability management programs maintained by its core infrastructure providers — Shopify and Google Workspace — both of which operate dedicated security teams and maintain industry security certifications. The Company does not operate independent on-premise infrastructure and therefore has no independent network perimeter requiring separate vulnerability management.

7. Incident Response and Breach Notification

In the event of a suspected or confirmed security incident involving personal information, the Company will:

  • Immediately investigate and, where necessary, contain the incident, including revoking compromised credentials and coordinating with Shopify/Google Workspace support as applicable.
  • Assess the scope and impact of the incident, including what personal information may have been affected.
  • Notify affected sellers, platform partners (including TikTok Shop), and any applicable regulatory authority without undue delay, and in any event within the timeframe required by applicable law.
  • Notify affected individuals directly where required by applicable law.
  • Document the incident and any remediation steps taken.

Incident response responsibilities are held directly by the Company's founders, Drew and Parker, given the Company's size.

8. Data Retention and Deletion

The Company retains personal information only as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements. Upon a valid request from a customer, user, or platform partner (including TikTok Shop), the Company will delete, update, or provide the requested personal information within a reasonable timeframe, consistent with its published Privacy Policy.

At the conclusion of any contractual relationship with TikTok Shop, the Company will delete all TikTok Shop customer data in its possession, except where retention is required by applicable law.

9. Third-Party and Vendor Management

The Company's core service providers — Shopify (e-commerce platform and payments) and Google Workspace (business email and productivity) — maintain their own industry-standard security and compliance programs, including encryption in transit and at rest. The Company does not share personal information with third parties beyond what is necessary to fulfill orders, process payments, provide customer support, and operate its affiliate marketing program, consistent with its published Privacy Policy.

10. Data Protection Responsibility

Given the Company's size, no dedicated Data Protection Officer has been appointed. Data protection responsibilities are held directly by the Company's founders. Questions regarding this Standard or the Company's data practices may be directed to strideworkz@gmail.com.

11. Policy Review

This Standard is reviewed and updated periodically to reflect changes in the Company's operations, applicable law, and industry practice. This version is effective as of the date listed above.

12. Contact

Strideworkz LLC

6014 Blue Circle Drive, Minnetonka, MN 55343, United States

Email: strideworkz@gmail.com

Phone: +1 952-855-2322