Privacy policy

Privacy Policy

Last Updated: March 25, 2026

This Privacy Policy is designed to comply with applicable U.S. federal and state privacy laws, including the California Consumer Privacy Act (CCPA/CPRA), the Maryland Online Data Privacy Act (MODPA), and consumer privacy laws in Colorado, Connecticut, Virginia, Texas, Oregon, Florida, Montana, Nebraska, New Hampshire, New Jersey, Delaware, Iowa, Minnesota, Indiana, Kentucky, Rhode Island, and other states that have enacted consumer data protection legislation.

Who We Are

SBRP LLC ("we," "us," or "our") operates hiscoxcases.us, an online retailer of instrument cases based in Glen Arm, Maryland. We act as the "controller" or "business" with respect to personal data collected through this website.

Data Minimization

In accordance with applicable privacy laws, including the Maryland Online Data Privacy Act, we limit our collection and processing of personal data to what is strictly necessary to provide you with the products and services you request. We do not collect personal data speculatively or for purposes beyond those described in this Policy.

Information We Collect

We collect the following categories of personal information:

  • Identifiers: name, email address, shipping and billing address, phone number — collected when you place an order or contact us
  • Commercial information: products purchased, order history, transaction amounts — collected to process and fulfill your order
  • Internet or electronic network activity: pages visited, session duration, device type, browser type, and referring URL — collected automatically by Shopify's platform analytics in aggregate, non-identifiable form
  • Communications data: content of emails or messages you send to our customer service

We do not collect sensitive personal information as defined under applicable state laws (such as health data, biometric identifiers, precise geolocation, racial or ethnic origin, religious beliefs, sexual orientation, or immigration status) unless strictly necessary to fulfill a specific service you have requested.

How We Use Your Information

We use your personal information solely for the following purposes:

  • Processing, fulfilling, and shipping your orders
  • Sending order confirmations, shipping notifications, and customer service communications
  • Responding to your inquiries and support requests
  • Improving website functionality and the customer experience using aggregated, anonymized analytics data
  • Detecting and preventing fraud and maintaining website security
  • Complying with legal obligations, including tax, accounting, and recordkeeping requirements

We do not use your personal information for targeted advertising, cross-context behavioral advertising, or profiling that produces legal or similarly significant effects on you.

Sharing and Disclosure of Information

We do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising purposes. We may share your information only in the following limited circumstances:

  • Service providers: We share data with Shopify (e-commerce platform), shipping carriers (UPS, FedEx, USPS), and payment processors (Stripe), solely to fulfill orders and operate our business. These providers are contractually prohibited from using your data for any purpose other than providing services to us.
  • Legal requirements: We may disclose information when required by law, court order, or government authority, or to protect our legal rights and those of our customers.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will notify you of any such change in control.

Categories of third parties to which we have disclosed personal data: shipping and logistics providers, payment processors, e-commerce platform providers.

Data Retention

We retain personal information only as long as necessary to fulfill the purposes described in this Policy:

  • Transaction records (name, address, order details, payment method type): 7 years, as required for tax and accounting compliance under federal and Maryland state law
  • Customer service communications: up to 3 years from the date of the interaction
  • Website analytics data: retained in aggregate, anonymized form indefinitely; individual session data is not retained beyond 26 months
  • Marketing communications preferences: until you opt out or withdraw consent

Your Privacy Rights

Depending on your state of residence, you may have the following rights regarding your personal information. We will respond to verified requests within 45 days (extendable by an additional 45 days with notice).

Rights Available to All Consumers

  • Right to Know: the categories and specific pieces of personal information we have collected about you
  • Right to Access: a portable copy of the personal information we hold about you
  • Right to Correct: inaccurate personal information we have about you
  • Right to Delete: your personal information, subject to certain legal exceptions
  • Right to Non-Discrimination: we will not discriminate against you for exercising your privacy rights

Additional Rights for California Residents (CCPA/CPRA)

California residents have the right to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising. California residents may also submit requests through an authorized agent.

Additional Rights for Maryland Residents (MODPA)

Maryland residents have the right to obtain a list of the categories of third parties to which we have disclosed their personal information, the right to appeal any denial of a privacy rights request (see Section 2.9), and the right to opt out of any future sale of personal data (we do not currently sell personal data).

Rights in Colorado, Connecticut, Virginia, Texas, Oregon, Nebraska, and Other States

Residents of states with enacted consumer privacy laws have rights to access, correct, delete, and obtain a portable copy of their personal data, as well as the right to opt out of targeted advertising and profiling (neither of which we engage in). State-specific rights will be honored in accordance with applicable law.

2.8 How to Submit a Privacy Rights Request

To exercise any of your privacy rights, please contact us at: info@hiscoxcases.com. Please include your full name, the state in which you reside, and a description of your request. We will verify your identity before processing your request. We do not charge a fee for processing requests unless they are manifestly unfounded or excessive.

Right to Appeal

If we deny your privacy rights request, we will provide you with a written explanation of our reasoning. You may appeal our decision by submitting a written appeal to info@hiscoxcases.com with the subject line "Privacy Rights Appeal." We will respond to your appeal within 60 days. If your appeal is denied, you may contact your state's Attorney General office to submit a complaint.

Universal Opt-Out — Global Privacy Control

We honor the Global Privacy Control (GPC) signal, a browser-based preference that instructs websites not to sell or share your personal data. If your browser or browser extension sends a GPC signal when you visit hiscoxcases.us, we will treat this as an opt-out request from the sale or sharing of your personal data (noting that we do not currently engage in such activities). For more information on enabling GPC, visit globalprivacycontrol.org.

Data Security

We implement commercially reasonable administrative, technical, and physical safeguards to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These include SSL/TLS encryption for all data transmitted to and from our website and access controls for systems storing personal data. In the event of a data breach that triggers applicable state notification obligations, we will notify affected individuals and relevant authorities as required by law. All 50 states have enacted data breach notification laws.

Children's Privacy — COPPA

Our website is not directed to individuals under the age of 13, and we do not knowingly collect personal information from children under 13 in accordance with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506. We do not sell the personal data of any consumer under the age of 18. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at info@hiscoxcases.com and we will delete such information promptly.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will post the updated Policy on our website with a revised effective date. For material changes, we will provide additional notice, such as a prominent website notice or email notification to recent customers.

Contact Us

For any privacy-related questions, requests, or concerns: SBRP LLC | 5200 Glen Arm Rd, STE D, Glen Arm, MD 21057 | info@hiscoxcases.com