Privacy Policy

La Sobremesa Foods LLC (“La Sobremesa,” “we,” “us,” or “our”) respects your privacy. This policy explains how we handle personal information through our websites, accounts, shop, communications, events, and business forms.

Effective: August 29, 2026


Sites Covered by This Policy

This policy applies to La Sobremesa services presented on:

These domains are parts of one website operated by La Sobremesa Foods LLC and share one La Sobremesa account. GATO ROJO is a product brand of La Sobremesa Foods LLC, not a separate business or DBA. The sites use the same application and move you to the authentication host to sign in. A short-lived, single-use session-transfer record lets you return signed in to the site where you started. Authentication cookies are scoped within the applicable lasobremesafoods.com or gatorojodrink.comdomain family; browsers do not permit one cookie to span both families. Shopify-hosted checkout and any linked third-party site are governed by that provider’s privacy notice in addition to this policy.

Notice at Collection for California Residents

The table below describes the categories of personal information we collect, the reasons we use them, and the parties to which we disclose them for business purposes. Some information can fall into more than one California statutory category.

Category and examplesPurposesProcessors and recipients
Identifiers and contact information: name, email, optional phone number, account ID, shipping and billing contact details, company and job information, invite code, IP address or a keyed hash of it, and device/session identifiers.Create and secure accounts; communicate; fulfill purchases; manage newsletters, events, press and trade inquiries; prevent abuse; and comply with law.Supabase; Shopify; Brevo; Vercel and related hosting infrastructure; Google when you choose Google sign-in; and professional or legal advisers when necessary.
Customer records and commercial information: account profile and saved address, cart contents and Shopify cart ID, products ordered, quantities, prices, order number, payment and fulfillment status, newsletter status, event RSVP, guest information, and trade or press requests.Provide the requested service; maintain carts and order records; support customers; manage inventory, events, sales leads and subscriptions; and keep business and compliance records.Supabase; Shopify; Brevo for subscriptions and email; and our email recipients responsible for events, press, sales, or support.
Internet or other electronic activity: request time, browser/user-agent, referral or source label, coarse state inferred from request headers, cookie and consent choices, sign-in and passkey events, and security or delivery logs.Route and operate the sites; remember choices; authenticate users; enforce age and shipping rules; detect abuse; troubleshoot; and measure email delivery or engagement.Supabase; Shopify; Brevo; Google for Google sign-in; and Vercel/hosting infrastructure.
Protected characteristics and sensitive personal information: date of birth and the resulting 21-or-older eligibility status; account login credentials and passkey credential data.Confirm legal purchase eligibility and protect access to an account. Date of birth is encrypted before it is stored. Passkeys store a public key and credential metadata, not a fingerprint, face scan, or device PIN.Supabase and the passkey software used by our application; your device/passkey provider participates when you choose a passkey.
Approximate location: state inferred from infrastructure request headers and the shipping state supplied at checkout.Determine product availability, enforce shipping restrictions, prevent abuse, and document compliance.Vercel/hosting infrastructure, Supabase, and Shopify.

We collect these categories directly from you, automatically from your browser and hosting request headers, from Google when you choose Google authentication, and from Shopify through order webhooks. We do not use or disclose sensitive personal information to infer characteristics about you.

Accounts and Authentication

Account signup uses Supabase Authentication. We collect your email, first and last name, optional phone and address, newsletter choice, signup source, and date of birth. We use the date of birth to confirm that you are at least 21; the stored account profile contains the encrypted date, birth month, eligibility result, and verification time. Supabase maintains the account, verification and session records needed to sign you in.

Existing account holders can choose Google sign-in. Google and Supabase process the OAuth request, and we receive account information made available for sign-in, such as your email, name, profile image, provider identifier, and authentication tokens. Google sign-in is not used to create an account until the site’s age-verification signup has been completed.

You can register a passkey after authentication. We store your user ID, email, passkey credential ID, public key, signature counter, supported transports, and creation/update times in Supabase. Authentication challenges are short-lived and marked as used. Biometric checks remain with your device or passkey provider and are not received by La Sobremesa.

Shopping, Checkout, and Order Records

You can browse and add products to an anonymous cart without signing in. A random first-party cart-session cookie links the browser to cart contents and a Shopify cart ID stored in Supabase. The raw session value is kept in an HttpOnly cookie, and only a one-way hash is stored in our database. When you begin checkout, you must sign in and pass the account age and shipping-state checks. We then attach the anonymous cart to your account and send the verified account email and cart information to Shopify through its Storefront API. Checkout takes place on Shopify. Shopify collects and processes the contact, delivery, billing, payment, fraud-prevention, and transaction information needed to complete the purchase. La Sobremesa does not receive or store full payment-card numbers in this application.

Shopify sends us authenticated order, payment, cancellation, refund, and fulfillment-related events. We keep order number, items, quantities, prices, totals, currency, payment and fulfillment status, state and compliance information in Supabase for inventory, customer support, legal compliance, and order-history functionality.

Newsletter, Events, Invitations, and Business Communications

Newsletter signup sends your email, first and last name, and a properly formatted optional mobile number to Brevo. We also receive your affirmative marketing choice; the page may pass a signup-source label, but the current newsletter integration does not add that label or your IP address/user-agent to your Brevo contact. Brevo manages list membership, confirmation when configured, unsubscribe status, delivery, and email engagement. You can unsubscribe through any marketing email or contact us. Transactional or legally required messages may continue after a marketing opt-out.

For an event or invitation, we process invite and RSVP status, attendee and plus-one names/contact details, guest count, response time, newsletter choice, and a hashed network identifier used to limit repeated updates. Brevo sends invitation and RSVP-confirmation emails. When an RSVP flow includes an affirmative newsletter choice, the site also submits eligible guest email addresses to the newsletter signup endpoint. Press and trade forms process the details shown in the form and send them through Brevo’s transactional email service to the appropriate La Sobremesa team mailbox. We use those details to respond and manage the relationship.

Cookies, Local Storage, and Privacy Preferences

Because browser storage is origin- or domain-specific, set your cookie and sale/sharing preferences separately on each covered domain you use. Clearing browser data removes those saved choices. Blocking essential cookies may prevent account, age-gate, or preference features from working. If shopping-cart storage is disabled and you attempt a cart action, the site asks whether you want to restore it. Declining cancels the requested action.

Sale, Sharing, and Analytics

Our current application code does not load advertising pixels or a web-analytics service and does not disclose personal information to third parties for cross-context behavioral advertising. Email delivery and engagement measurement occurs through Brevo. We provide a sale/sharing opt-out because California law treats some data flows as a “sale” or “sharing” even when no money changes hands, and because our practices and vendor configurations can change. We will not sell or share the personal information of a consumer after receiving an applicable opt-out.

Use the Do Not Sell or Share My Personal Information control in the footer to set the opt-out cookie. We also process a browser-enabled Global Privacy Control as an opt-out where legally required. The current application does not otherwise use the cookie-consent selection to activate analytics or advertising.

Other Disclosures

We disclose information to the processors described above to provide their services to us. We may also disclose information when required by law; to protect users, our rights, property, or safety; to investigate misuse; or as part of a financing, merger, acquisition, reorganization, or sale of all or part of the business. Vercel hosts the application. Providers may process information in the United States and other countries under their own infrastructure arrangements.

Retention

We keep personal information only as long as reasonably necessary for the purpose collected, including:

We consider the nature and sensitivity of the information, the service or relationship, legal limitation and recordkeeping periods, fraud and security needs, and whether information can be deleted or deidentified when setting retention periods. Backup copies may persist for a limited period after deletion.

Your California Privacy Rights

Subject to verification and legal exceptions, California residents may:

To submit an access, correction, deletion, or limitation request, email hello [at] lasobremesafoods.com with the subject “Privacy Request.” Tell us the right you wish to exercise and the account, purchase, signup, or other interaction involved. We will verify your request using information already associated with you, such as by confirming control of your email. An authorized agent may submit a request, but we may request proof of the agent’s authority and direct verification from you where permitted.

For a no-JavaScript or alternate sale/sharing request, email hello [at] lasobremesafoods.com with the subject “Do Not Sell or Share.”

Security

We use administrative, technical, and organizational safeguards designed for the nature of the information, including encrypted transport, restricted service-role database access, row-level security, encrypted date-of-birth storage, keyed hashing for configured compliance logs, and verification of Shopify webhooks and passkey origins. No method of storage or transmission is completely secure.

Children and Age Restrictions

Our products and purchasing services are intended for adults age 21 and older. We do not knowingly collect personal information from children under 13. If you believe a child provided information, email hello [at] lasobremesafoods.com.

Changes and Contact

We may update this policy to reflect our practices or legal requirements. We will post the revised policy with a new effective date and provide additional notice when required. For questions or privacy requests, contact hello [at] lasobremesafoods.com.

Your Choices