Privacy Policy
Last updated: October 1, 2026
This Privacy Policy explains what information Digital Shelf Lab (operated by Codigo Bro LLC) collects, how we use it, and the choices you have. We keep data collection minimal and only process what is necessary to run a digital products business.
1. Information we collect
We collect only the information needed to process an order and support you:
- Your name and email address
- Order and delivery details (product purchased, date, download status)
- Payment records generated by our payment providers (we do not see or store card numbers)
- The content of any support or consultation messages you send us
2. How we collect it
Information is collected when you place an order through our payment providers, contact us by email, or otherwise communicate with us directly.
3. Payments are handled by third parties
Card payments are processed by PCI-DSS compliant providers such as Stripe, Shopify Payments, and dLocal Go. Codigo Bro LLC never receives, stores, or processes your full payment credentials. Payment data is subject to the privacy policies of those providers.
4. How we use your information
We use collected information to:
- Process and deliver your orders
- Send delivery emails and product download links
- Provide customer support
- Prevent fraud and comply with legal obligations
5. Sharing of information
We do not sell, rent, or trade your personal information. We only share data with service providers that help us operate (such as payment processors and email delivery services) and with authorities when required by law.
6. Cookies & analytics
BORRADOR — revisar con el dueño/contador. Draft written on 2026-10-02 from how this store's platform works; not yet approved. It replaces the previous text of this section, which said that no advertising or tracking cookies are used.
This store is advertised on Meta (Facebook and Instagram). To measure that advertising and to count visits, we use the following.
Meta Pixel (in your browser). When you view the page or the checkout, the Meta Pixel reports to Meta events such as a page view, a content view, the start of checkout, adding an offer to your order, submitting payment information, and a purchase.
Meta Conversions API (from our servers). We send the same kind of events from our servers, including your purchases. These can include your email address, name, phone number (only if the checkout asks for it), city, state, postal code and country, which are hashed (SHA-256) before they are sent, together with your IP address, your browser's user agent, and the Meta cookie values _fbp and _fbc, which are not hashed. We use the same event identifier in the Pixel and in the Conversions API so Meta does not count one event twice.
Cookies.
_fbpand_fbc— Meta cookies. If you arrive from a Meta ad with a click identifier (fbclid) and there is no_fbccookie yet, our server creates it so the ad can be matched to your order.dsl_attr— our own first-party cookie. It stores the campaign parameters (UTM) and click identifier you arrived with, for the first and the last visit. It lasts 30 days.visitor_id— our own first-party cookie that identifies your browser so we can count visitors. It lasts 1 year.
When you open our pages inside the Instagram or Facebook in-app browser, we may recover the campaign parameters from the page that referred you and keep them for 7 days; only campaign parameters (UTM), never click identifiers.
Visit counts. For each page load we record the store, the offer, the market, your country, the type of device, the ad identifier and your visitor_id. This record does not include your IP address or your email.
Payments. Card payments are processed by Stripe, as described in section 3.
We use this information to attribute orders to the ad that brought you, to measure the results of our advertising, and to let Meta match purchases to ads. Meta handles the data it receives under its own privacy policy. You can block or delete cookies in your browser settings.
7. Data retention & security
We retain order records — including the time of purchase, the IP address and device information used at checkout, and a log of downloads of your products — for at least 24 months after purchase, to deliver your products, provide support, prevent fraud, and respond to payment disputes. We also keep information as required by accounting and tax law. We apply reasonable technical and organizational measures to protect your information.
8. Your rights
Depending on your jurisdiction, you may have the right to access, correct, or request deletion of your personal information. To make such a request, contact us at support@digitalshelflab.com and we will respond within a reasonable time.
9. Children
The Site and our products are not directed to children under 13, and we do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy periodically. Significant changes will be reflected here with an updated "Last updated" date.
11. Contact
For privacy questions or requests, contact us at:
Email: support@digitalshelflab.com
© 2026 Heirloom Hook. All rights reserved. Heirloom Hook is operated by Codigo Bro LLC (EIN: 42-3185729), registered in Wyoming, USA.