Privacy Policy
La Sobremesa Foods LLC (“La Sobremesa,” “we,” “us,” or “our”) respects your privacy. This policy explains how we handle personal information through our websites, accounts, shop, communications, events, and business forms.
Effective: August 29, 2026
Sites Covered by This Policy
This policy applies to La Sobremesa services presented on:
- www.lasobremesafoods.com (our primary company website) and its redirecting address, lasobremesafoods.com;
- gatorojodrink.com and www.gatorojodrink.com (our GATO ROJO product website); and
- auth.lasobremesafoods.com, the sign-in host used by both sites.
These domains are parts of one website operated by La Sobremesa Foods LLC and share one La Sobremesa account. GATO ROJO is a product brand of La Sobremesa Foods LLC, not a separate business or DBA. The sites use the same application and move you to the authentication host to sign in. A short-lived, single-use session-transfer record lets you return signed in to the site where you started. Authentication cookies are scoped within the applicable lasobremesafoods.com or gatorojodrink.comdomain family; browsers do not permit one cookie to span both families. Shopify-hosted checkout and any linked third-party site are governed by that provider’s privacy notice in addition to this policy.
Notice at Collection for California Residents
The table below describes the categories of personal information we collect, the reasons we use them, and the parties to which we disclose them for business purposes. Some information can fall into more than one California statutory category.
| Category and examples | Purposes | Processors and recipients |
|---|---|---|
| Identifiers and contact information: name, email, optional phone number, account ID, shipping and billing contact details, company and job information, invite code, IP address or a keyed hash of it, and device/session identifiers. | Create and secure accounts; communicate; fulfill purchases; manage newsletters, events, press and trade inquiries; prevent abuse; and comply with law. | Supabase; Shopify; Brevo; Vercel and related hosting infrastructure; Google when you choose Google sign-in; and professional or legal advisers when necessary. |
| Customer records and commercial information: account profile and saved address, cart contents and Shopify cart ID, products ordered, quantities, prices, order number, payment and fulfillment status, newsletter status, event RSVP, guest information, and trade or press requests. | Provide the requested service; maintain carts and order records; support customers; manage inventory, events, sales leads and subscriptions; and keep business and compliance records. | Supabase; Shopify; Brevo for subscriptions and email; and our email recipients responsible for events, press, sales, or support. |
| Internet or other electronic activity: request time, browser/user-agent, referral or source label, coarse state inferred from request headers, cookie and consent choices, sign-in and passkey events, and security or delivery logs. | Route and operate the sites; remember choices; authenticate users; enforce age and shipping rules; detect abuse; troubleshoot; and measure email delivery or engagement. | Supabase; Shopify; Brevo; Google for Google sign-in; and Vercel/hosting infrastructure. |
| Protected characteristics and sensitive personal information: date of birth and the resulting 21-or-older eligibility status; account login credentials and passkey credential data. | Confirm legal purchase eligibility and protect access to an account. Date of birth is encrypted before it is stored. Passkeys store a public key and credential metadata, not a fingerprint, face scan, or device PIN. | Supabase and the passkey software used by our application; your device/passkey provider participates when you choose a passkey. |
| Approximate location: state inferred from infrastructure request headers and the shipping state supplied at checkout. | Determine product availability, enforce shipping restrictions, prevent abuse, and document compliance. | Vercel/hosting infrastructure, Supabase, and Shopify. |
We collect these categories directly from you, automatically from your browser and hosting request headers, from Google when you choose Google authentication, and from Shopify through order webhooks. We do not use or disclose sensitive personal information to infer characteristics about you.
Accounts and Authentication
Account signup uses Supabase Authentication. We collect your email, first and last name, optional phone and address, newsletter choice, signup source, and date of birth. We use the date of birth to confirm that you are at least 21; the stored account profile contains the encrypted date, birth month, eligibility result, and verification time. Supabase maintains the account, verification and session records needed to sign you in.
Existing account holders can choose Google sign-in. Google and Supabase process the OAuth request, and we receive account information made available for sign-in, such as your email, name, profile image, provider identifier, and authentication tokens. Google sign-in is not used to create an account until the site’s age-verification signup has been completed.
You can register a passkey after authentication. We store your user ID, email, passkey credential ID, public key, signature counter, supported transports, and creation/update times in Supabase. Authentication challenges are short-lived and marked as used. Biometric checks remain with your device or passkey provider and are not received by La Sobremesa.
Shopping, Checkout, and Order Records
You can browse and add products to an anonymous cart without signing in. A random first-party cart-session cookie links the browser to cart contents and a Shopify cart ID stored in Supabase. The raw session value is kept in an HttpOnly cookie, and only a one-way hash is stored in our database. When you begin checkout, you must sign in and pass the account age and shipping-state checks. We then attach the anonymous cart to your account and send the verified account email and cart information to Shopify through its Storefront API. Checkout takes place on Shopify. Shopify collects and processes the contact, delivery, billing, payment, fraud-prevention, and transaction information needed to complete the purchase. La Sobremesa does not receive or store full payment-card numbers in this application.
Shopify sends us authenticated order, payment, cancellation, refund, and fulfillment-related events. We keep order number, items, quantities, prices, totals, currency, payment and fulfillment status, state and compliance information in Supabase for inventory, customer support, legal compliance, and order-history functionality.
Newsletter, Events, Invitations, and Business Communications
Newsletter signup sends your email, first and last name, and a properly formatted optional mobile number to Brevo. We also receive your affirmative marketing choice; the page may pass a signup-source label, but the current newsletter integration does not add that label or your IP address/user-agent to your Brevo contact. Brevo manages list membership, confirmation when configured, unsubscribe status, delivery, and email engagement. You can unsubscribe through any marketing email or contact us. Transactional or legally required messages may continue after a marketing opt-out.
For an event or invitation, we process invite and RSVP status, attendee and plus-one names/contact details, guest count, response time, newsletter choice, and a hashed network identifier used to limit repeated updates. Brevo sends invitation and RSVP-confirmation emails. When an RSVP flow includes an affirmative newsletter choice, the site also submits eligible guest email addresses to the newsletter signup endpoint. Press and trade forms process the details shown in the form and send them through Brevo’s transactional email service to the appropriate La Sobremesa team mailbox. We use those details to respond and manage the relationship.
Cookies, Local Storage, and Privacy Preferences
- Authentication: Supabase session tokens and cross-domain session-transfer records keep you signed in and return you to the requested covered site.
- Age gate: a browser cookie remembers an adult-age response for 30 days; a separate preview-only bypass cookie lasts 10 minutes.
- Cookie preferences: a first-party cookie records essential, shopping-cart, analytics, and marketing choices for that browser origin. Essential security, age-gate, authentication, and preference storage stays active. The current application does not load an advertising or web-analytics SDK.
- Shopping cart: an HttpOnly first-party cookie uses a random value to reconnect this browser to an anonymous cart for up to 30 days. You can turn this category off after acknowledging that doing so clears the anonymous cart cookie and blocks cart actions until restored.
- Do Not Sell or Share: the
lsf_opt_out_sharingcookie records the choice for up to 24 months on the domain where it is set.
Because browser storage is origin- or domain-specific, set your cookie and sale/sharing preferences separately on each covered domain you use. Clearing browser data removes those saved choices. Blocking essential cookies may prevent account, age-gate, or preference features from working. If shopping-cart storage is disabled and you attempt a cart action, the site asks whether you want to restore it. Declining cancels the requested action.
Sale, Sharing, and Analytics
Our current application code does not load advertising pixels or a web-analytics service and does not disclose personal information to third parties for cross-context behavioral advertising. Email delivery and engagement measurement occurs through Brevo. We provide a sale/sharing opt-out because California law treats some data flows as a “sale” or “sharing” even when no money changes hands, and because our practices and vendor configurations can change. We will not sell or share the personal information of a consumer after receiving an applicable opt-out.
Use the Do Not Sell or Share My Personal Information control in the footer to set the opt-out cookie. We also process a browser-enabled Global Privacy Control as an opt-out where legally required. The current application does not otherwise use the cookie-consent selection to activate analytics or advertising.
Other Disclosures
We disclose information to the processors described above to provide their services to us. We may also disclose information when required by law; to protect users, our rights, property, or safety; to investigate misuse; or as part of a financing, merger, acquisition, reorganization, or sale of all or part of the business. Vercel hosts the application. Providers may process information in the United States and other countries under their own infrastructure arrangements.
Retention
We keep personal information only as long as reasonably necessary for the purpose collected, including:
- account, passkey, profile, saved cart, and order records while the account or transaction remains active and afterward as needed for support, fraud prevention, tax, accounting, alcohol-sales, dispute, and other legal obligations;
- marketing contacts until you unsubscribe or we remove the contact, while retaining suppression information needed to honor the opt-out;
- event, press, and trade information through the event or relationship and a reasonable follow-up and recordkeeping period;
- short-lived passkey challenges and session-transfer records until they expire or are used; and
- security, request, compliance, webhook, and email-delivery records for the period reasonably needed to secure, troubleshoot, document, and comply with obligations.
We consider the nature and sensitivity of the information, the service or relationship, legal limitation and recordkeeping periods, fraud and security needs, and whether information can be deleted or deidentified when setting retention periods. Backup copies may persist for a limited period after deletion.
Your California Privacy Rights
Subject to verification and legal exceptions, California residents may:
- Know and access the categories, sources, purposes, recipients, and specific pieces of personal information collected about them;
- Delete personal information;
- Correct inaccurate personal information;
- Opt out of sale or sharing of personal information;
- Limit certain uses and disclosures of sensitive personal information (we use sensitive information only for the permitted purposes described above); and
- Receive equal service and pricing without retaliation for exercising privacy rights.
To submit an access, correction, deletion, or limitation request, email hello [at] lasobremesafoods.com with the subject “Privacy Request.” Tell us the right you wish to exercise and the account, purchase, signup, or other interaction involved. We will verify your request using information already associated with you, such as by confirming control of your email. An authorized agent may submit a request, but we may request proof of the agent’s authority and direct verification from you where permitted.
For a no-JavaScript or alternate sale/sharing request, email hello [at] lasobremesafoods.com with the subject “Do Not Sell or Share.”
Security
We use administrative, technical, and organizational safeguards designed for the nature of the information, including encrypted transport, restricted service-role database access, row-level security, encrypted date-of-birth storage, keyed hashing for configured compliance logs, and verification of Shopify webhooks and passkey origins. No method of storage or transmission is completely secure.
Children and Age Restrictions
Our products and purchasing services are intended for adults age 21 and older. We do not knowingly collect personal information from children under 13. If you believe a child provided information, email hello [at] lasobremesafoods.com.
Changes and Contact
We may update this policy to reflect our practices or legal requirements. We will post the revised policy with a new effective date and provide additional notice when required. For questions or privacy requests, contact hello [at] lasobremesafoods.com.
Your Choices
- Marketing: use the unsubscribe link in a marketing email or email us for help.
- Authentication: choose email, Google (for an existing eligible account), or a registered passkey; you can sign out and request account deletion.
- Browser storage: reopen Cookie Preferences from the footer or clear/block storage in your browser.
- Sale/sharing: use the footer control, a supported Global Privacy Control signal, or the email method above.