Privacy Policy
Last updated August 20, 2026
Pete's Clam Stop (petesclamstop.com) and Williams Candy (williamscandy.com) are two neighboring, family-run Coney Island shops — Pete's at 1320 Surf Avenue, Williams at 1318 Surf Avenue, Brooklyn, NY 11224 — both operated by the same company, The Clam Stop Inc. They share one staff system and one customer database, so this single Privacy Policy covers both websites and both shops' online ordering. Where something works differently between the two — for example, Pete's loyalty club is called "The First Dozen," Williams' is "The 1941 Club" — we say so; everything else applies equally to both.
This policy covers the two websites and everything you can send us through them — an order, a loyalty-club signup, a review, or a party, catering, or wholesale enquiry. It does not cover an in-person cash or card transaction at either counter — we don't collect or store anything about those beyond what any register receipt shows, and neither site's payment step exists at all, because there isn't one (see "Payment" below).
The tap-to-order window on each site — the one that builds a cart and sends a ticket to the kitchen or the counter — opens only when you scan a QR code printed at the shop. You can't place that kind of order by browsing to an open web address. Other things on these sites are not gated that way, and are reachable from an ordinary page with no QR code at all: each site's loyalty-club signup; our party-tray, catering, and wholesale enquiry forms — one such form on Pete's site, and two on Williams' (a catering form on its homepage and a wholesale/large-order form on its wholesale page); and each site's review card, which is a place to tell us how we did rather than a way to order or enquire. All of them are described below, and all of them collect information, so we are naming them here rather than letting the QR sentence imply that nothing on these sites is open to the web.
Neither shop ships, and neither shop runs its own delivery — every order placed through our own sites is picked up in person. You may also find one or both shops listed on a third-party delivery app: Pete's is listed on Uber Eats, and Williams is listed on both DoorDash and Uber Eats. That arrangement is between you and that app, and what that company does with your information is governed by its privacy policy, not this one.
What we collect, and when
We only collect information you type in yourself. There is no customer account, no login, and no customer profile.
When you place an order
- Your name — required, so we can call your ticket.
- Your phone number and/or email — optional. You can leave both blank and still order.
- A free-text note, if you write one.
- A zip code — optional, and only on Pete's order screen, which asks so we can see which neighborhoods to aim specials at. Williams' order screen does not ask for one.
- Your items, your order/ticket number, the tip you picked if the order screen offered one (Pete's does; Williams' does not), and the date and time.
- The IP address the order came from.
When you join the loyalty club
The First Dozen at Pete's, The 1941 Club at Williams: a phone number and/or email, plus your name if you'd like to give one — the name field is optional on both signup forms. Joining requires checking a marketing-consent box.
When you leave us a review or comment
Both sites have a short "how did we do?" card. Leaving one records:
- your star rating, or none if you didn't pick one;
- your name, if you give one — it is optional;
- the comment you write;
- which page you were on when you left it;
- the IP address it came from; and
- your browser's user-agent string — the short line of text every browser sends identifying itself and the operating system it's running on.
The IP address and the user-agent are erased from the record automatically after 30 days. They are kept that long for one reason: so we can tell nine hostile comments from one person apart from nine unhappy customers. The rating, the optional name, and the comment itself are kept longer — see "Data retention" below, which says plainly how long.
When you ask about a party tray or a large order
Pete's homepage carries a party and large-order enquiry form. Williams has two: a catering enquiry form on its homepage, and a wholesale and large-order form on its wholesale page. These are open-web forms — no QR code is involved — and they are an enquiry, not an order: nothing is charged, and nothing is confirmed until we've spoken to you. Sending one records your name (required), your phone number (required) — it's how we call you back with a price — your email (optional), the date you need it, the kind of event if you pick one from the list, the free-text description of what you want, whether you ticked the marketing box, and the IP address the enquiry came from.
When you give marketing consent
We keep a record of the consent event itself — the date and time, the exact wording you were shown, which page you were on, and the submitting IP address — so we can show you later exactly what you agreed to.
Automatically, from anyone browsing either site
Page views, QR-code scans, and order-funnel activity, collected through an analytics beacon we wrote and run ourselves. It is not Google Analytics, Meta/Facebook Pixel, or any third-party analytics or advertising tool, and neither site runs one.
One detail is worth stating plainly rather than glossing over. Because one company runs both shops, there is one analytics system, and it lives on our own petesclamstop.com server. On Pete's site, that beacon request stays on the same domain you're already browsing. On Williams' site, the request goes from williamscandy.com to petesclamstop.com — so it is technically a request to a different domain, but it is still a server we operate, for our own two shops. No outside analytics company receives it either way.
What that analytics system does not keep is your raw IP address: a daily unique visitor is counted as a one-way hash — a scrambled value that is not designed to be turned back into an address, and that we never attempt to turn back into one. We would rather be precise than overclaim here: a hash of this kind is a real practical barrier, not a mathematical impossibility, so we treat these values as reduced-risk data rather than as fully anonymous. The rate-limit counters that slow down spam and abuse mostly key on a salted one-way hash of the address too; a small number of short-lived counters, pruned daily, key on the address itself. And some records genuinely do hold a real IP address — we say so at each place it happens: order records, marketing-consent records, party, catering and wholesale enquiries, and review submissions, all described above.
From two third-party services embedded on our pages
Google Fonts (used to render the sites' typefaces) and a Google Maps embed (used to show each shop's location) — described fully under "Cookies and tracking technologies" below. Loading either sends your device's IP address to Google as part of how those services work; we do not control what Google does with that beyond what Google's own privacy policy describes.
Payment
How we use your information
- Your name: to prepare and call your order.
- Your phone or email: so we can reach you if something's wrong with your order — an item's out, we can't read your note, you stepped away before it was called.
- Marketing consent: only to send you the specials, seasonal-hours, and club updates you opted into. If you didn't check the box, we don't send you anything.
- Analytics: to see how busy each shop's ordering flow is, whether the QR codes are working, and where visitors get stuck.
We do not build advertising profiles from any of this, and we do not use it to track you across other websites.
Cookies and tracking technologies
We use a few different, narrow mechanisms — not a general tracking or advertising setup:
- Session and security cookies (first-party, functional only). When you scan
a QR code to order, the ordering flow sets small,
HttpOnlycookies to authenticate that QR station and to protect the order form against forgery (a CSRF token). The party, catering, and wholesale enquiry forms each set oneHttpOnlycookie of the same kind — a one-hour anti-forgery token, no QR code involved. These carry no advertising payload and are not read by any third party. - Browser storage for your cart. Your basket while you're actively ordering is kept in your browser's local storage, not a cookie, so the order page remembers what you've added as you move through it.
- Google Fonts. Both sites load typefaces from
fonts.googleapis.comandfonts.gstatic.com. Requesting a font file from Google's servers sends your IP address to Google as a normal part of how the request works. Google's documented font-serving infrastructure does not set cookies or use this for ad targeting, but the request itself is real and worth disclosing plainly. - Google Maps embed. Each site's homepage embeds a Google Maps view of the shop's location. Because that embed loads content directly from Google inside the page, Google may set its own cookies in that embedded frame, governed by Google's own privacy policy — not ours.
- What we don't use: third-party advertising cookies, retargeting or remarketing pixels, ad networks, cross-site tracking scripts, or data brokers. Neither site currently runs Google Analytics, Meta/Facebook Pixel, or any comparable third-party analytics or ad-tech tool.
Do Not Track signals
Some browsers offer a "Do Not Track" (DNT) setting. Because neither site performs cross-site tracking of any kind — no ad pixels, no third-party analytics, no cross-site cookies — our sites' behavior does not change based on whether your browser sends a DNT signal: with or without it, we are not tracking you across other websites either way. We will update this section if that ever changes.
How we share your information
- Our staff, through the shared staff portal, to run orders and manage the club list at either shop.
- Our web host, Hostinger, which stores the sites and the database as part of hosting them.
- Google, only as described above (Fonts and Maps) — we do not send your order or contact information to Google; the IP-address exposure there happens because your browser requests content directly from Google's servers, not because we hand data to Google ourselves.
- Nobody else. We do not sell your information, and we do not rent, trade, or share it with anyone else for their own marketing. The only other circumstance would be a legal requirement — for example, a valid court order.
Data retention
- Order records: kept three calendar years, then deleted by scheduled maintenance.
- Club and marketing contacts: unsubscribing marks your record as opted out, and that is what stops the marketing — but it does not delete the record, and nothing in our system deletes contacts on a schedule today. So the row itself — your name, your phone number, your email — is currently kept indefinitely unless you ask us to delete it. We would rather say that than let this list imply a deletion schedule that doesn't exist. Setting one is on our list.
- Consent records: the record of what you agreed to — the date and time, the exact wording you were shown, which page you were on, and the submitting IP address — is stored on that same contact record rather than separately, so it lasts exactly as long as that record does: currently indefinitely, unless you ask us to delete it. That record is the proof we had permission to contact you in the first place, which is why we would keep it at least as long as we keep the contact details themselves.
- Identifiable analytics and security records (IP addresses or hashed visitor identifiers in security, audit, or rate-limit data): no more than 90 days; some short-lived rate-limit data is deleted sooner.
- De-identified aggregate analytics (daily counts of page views, QR scans, and site actions, with no IP address, visitor hash, account, or customer identifier attached): may be kept up to five calendar years for seasonal comparisons.
- Party-tray, catering, wholesale, and large-order enquiries: currently kept indefinitely. We have not set a deletion period for these yet, and we would rather say so than let the list above imply a schedule that doesn't exist. Setting one is on our list.
- Reviews and comments: the IP address and the browser user-agent are erased automatically after 30 days, as described above. The rating, the optional name, and the comment itself are currently kept indefinitely — same honest caveat as the line above.
Anything on this list marked "indefinitely" you can have deleted on request, at any time, whatever the default is — see "Contact us" below. "Indefinitely" describes what our automatic cleanup does on its own today; it is not a refusal to delete something when you ask.
If you ask us to delete your order history, we may still need to keep a minimal record for tax and accounting purposes.
Data security
New York's SHIELD Act (Gen. Bus. Law §§ 899-aa, 899-bb) requires businesses handling New Yorkers' data to maintain reasonable administrative, technical, and physical safeguards. We maintain such safeguards for the information described in this policy — including our web host's account security, restricted staff-portal access, and the salted-hash and scheduled-deletion practices described above — and we hold our hosting provider to the same standard for anything they touch on our behalf.
If a data breach affecting your personal information ever occurs, we will notify affected individuals as required by law.
Your privacy rights
Regardless of where you live, you can always ask us to tell you what we have about you, correct something that's wrong, delete what we have, or stop sending you marketing. See "Contact us" below for how to reach us, and note the limits above (we hold no payment data to give you, and some records are kept briefly for tax purposes even after a deletion request).
If you are a California resident
Two different California laws are relevant, and they don't lead to the same answer:
- The California Consumer Privacy Act (CCPA/CPRA) does not apply to either business. That law only covers businesses that meet at least one of three thresholds: over $26,625,000 in annual gross revenue (the current inflation-adjusted figure under Cal. Civ. Code § 1798.140(d)(1)(A), adjusted under § 1798.199.95(d)), or buying/selling/sharing the personal information of 100,000 or more California consumers or households a year, or getting 50% or more of revenue from selling or sharing personal information. Two small, seasonal, walk-up Brooklyn shops meet none of these, by a wide margin. We are not claiming CCPA rights (like a "Do Not Sell or Share My Personal Information" link) here because they would not reflect any real legal obligation — and we don't sell or share your information for cross-context advertising in any case.
- California's Online Privacy Protection Act (CalOPPA) (Cal. Bus. & Prof. Code §§ 22575-22579) does apply, and this policy is written to satisfy it: it's conspicuously posted, states the categories of information we collect and why, describes how you can review or ask us to change your information, explains how we respond to Do Not Track signals (above), and states how we'll notify you of material changes (below).
If you live in another U.S. state with a comprehensive privacy law
Around twenty states now have one, and they do not all work the same way — so rather than assume a single "we're too small" sentence covers all of them, we checked the ones that are shaped differently. As of the date at the top of this policy:
- The volume-based laws — Virginia, Colorado, and most others — apply once a business handles the personal data of tens of thousands of that state's residents in a year (commonly 100,000, or 25,000 when combined with selling data). Contrary to a common misreading, these have no revenue threshold at all: the number of people is the whole test. Two walk-up Coney Island shops that sell in person and don't ship are nowhere near those numbers in any state.
- Connecticut changed materially on July 1, 2026 (SB 1295 / Public Act 25-113). Its main volume threshold dropped from 100,000 residents to 35,000, its old "25% of revenue from selling data" prong was removed outright, and it now applies with no volume threshold whatsoever to a business that processes sensitive data, or that offers personal data for sale. We are still outside it — and specifically because of that second half, not because of our size: we do not sell personal data at all, and we do not collect sensitive data as that law defines it (no health, biometric, precise-location, immigration, racial, religious, sexual-orientation, or citizenship data). What we hold is a name, a way to reach you, and what you ordered.
- Texas has no volume or revenue threshold either. Its law instead exempts small businesses as the U.S. Small Business Administration defines them, and that is what exempts us — with one carve-out that binds even an exempt small business: consent is required before selling a consumer's sensitive data. We don't sell data of any kind.
- Utah is one of the few states whose test includes a revenue floor at all ($25 million a year), on top of a volume test. We are far below both.
So this policy carries no separate state-by-state rights section. It does not need one to give you the rights themselves: the "Regardless of where you live" paragraph above is a standing offer to any customer in any state, and we will honor it. If either business ever starts shipping out of state at real volume, or ever starts selling or sharing personal data, this analysis changes, and we will redo it rather than leave this paragraph standing.
Children's privacy
We sell food and candy that kids love, and kids are always welcome in either shop. But these websites are meant for adults to use.
Under 13 — the federal rule (COPPA)
We do not knowingly collect personal information from children under 13. The order form and club signup are intended to be filled out by a parent, guardian, or other adult — please don't have a child enter their own name, phone number, or email. If you believe a child under 13 gave us information, contact us and we will delete it. If an adult enters their own contact details to order for a child who's with them, that's fine — that's the adult's information, not the child's.
Under 18 — New York's own rule (Child Data Protection Act)
New York has a minors law that reaches further than the federal one, and we'd rather name it than leave it out: the New York Child Data Protection Act (Gen. Bus. Law art. 39-FF, §§ 899-ee et seq.), in effect since June 20, 2025. Two things make it different from most privacy laws on this page. It covers everyone under 18, not just under 13. And it has no business-size threshold at all — a two-shop operation is as covered as a national platform, so "we're small" is not an answer to it. It reaches an operator who actually knows a given user is a minor, or whose service is primarily directed to minors, and it restricts processing a minor's data beyond what is strictly necessary to provide the service unless informed consent is obtained.
Our position, stated plainly: neither site is directed to minors. Yes, we sell food and candy that kids love — but these websites are ordering and information tools built for adults. There is no account, no profile, no advertising, no cross-site tracking, and nothing on either site that targets, personalizes, or nudges anything at a young person. We do not ask anyone's age, so we do not knowingly hold a minor's data. The fields we collect are the ones needed to prepare and call an order, which is the narrow "strictly necessary to provide the service" case that law describes. We ask that anyone under 18 not enter their own name, phone number, or email — have a parent or guardian do it. If you're a parent or guardian and believe your child under 18 gave us information, contact us and we will delete it, exactly as we do for under-13 requests.
Text message (SMS) communications
Neither site sends text messages today. There is no carrier or messaging provider connected to either shop's system at all — the staff portal's "send a text" screen is an explicitly labeled simulation that delivers nothing — so no marketing or promotional text has ever been sent to anyone by either shop. If you gave a phone number and ticked the marketing box, we are holding that permission, not acting on it.
What the box you ticked actually says today. Every consent box on either site — the order screen, the loyalty-club signup, and the party, catering, and wholesale enquiry forms — is today a single combined box, worded along the lines of "text or email me." Ticking it is one permission covering both channels at once. There is not currently a separate text box and a separate email box, and we are not going to describe our forms as something they aren't.
What has to happen before any text is ever sent. We are treating that combined tick as permission to email you, not as finished consent to text you. Before text messaging is switched on at all, we will collect or re-confirm consent specifically for text messages, on a disclosure that states plainly that agreeing is never a condition of placing an order, that message frequency may vary, and that your carrier's message and data rates may apply — consistent with the Telephone Consumer Protection Act (TCPA). You'll be able to reply STOP to cancel and HELP for help, and we will honor any clear request to stop, however you word it — by text, by phone, by email, or in person. You do not have to guess a magic word, and you do not have to use a particular channel to be heard.
If the consent boxes themselves ever change — for example, if they're split into separate text and email checkboxes — this section changes with them, in the same pass.
Email communications
Ticking the marketing box gives us permission to email you about specials, seasonal hours, and club offers. As of the date at the top of this policy we have not built marketing email sending either — we are collecting consent so we can start later. (Transactional email about an order you actually placed — a confirmation, or a note that it's ready — is a different thing, and is not marketing.)
Any marketing email we do send will go only to people who opted in, will identify who it's from, won't use a misleading subject line, will carry The Clam Stop Inc., 1320 Surf Avenue, Brooklyn, NY 11224 as our valid physical postal address, and will include a clear way to opt out — as the CAN-SPAM Act requires (15 U.S.C. § 7704(a); the postal-address requirement is § 7704(a)(5)). That Act also allows a sender up to ten business days to stop sending after you opt out. We intend to act far faster than that, but ten business days is the legal outside limit and you're entitled to know it rather than be told "immediately" and then wait.
We also intend to include a one-click unsubscribe header in any bulk email we send. To be exact about what that is: one-click unsubscribe is not a CAN-SPAM requirement. It's a mailbox-provider expectation for bulk senders — the RFC 8058 List-Unsubscribe mechanism Gmail, Yahoo and others look for. We're naming it as a courtesy feature we plan to offer, not as a legal duty we're claiming to have discharged.
To opt out of anything, at any time: use the unsubscribe page or the link in any message we send, call the shop and ask to be taken off the list, or contact us below. Opting out of marketing doesn't affect an order you've already placed — we may still contact you about that specific order.
Third-party links and embedded content
Our sites link out to other websites — social media pages, review platforms, and the delivery-app listings named above (Uber Eats from both sites, DoorDash from Williams' site) — and embed a Google Maps view of each shop's location, also described above. We are not responsible for the privacy practices of any site we merely link to; once you leave our page, that company's policy governs, not ours. For the Google Maps embed specifically, Google's own privacy policy governs what happens once that content loads.
Changes to this policy
If we change how we collect, use, or share information, we will update this page and change the date at the top. We encourage you to check back occasionally, particularly before you place an order or join a loyalty club.
Contact us
Call (718) 372-0302 or come by either shop in person — the fastest way to reach us about anything on this page.
To write to us: The Clam Stop Inc., 1320 Surf Avenue, Brooklyn, NY 11224 (this is the company's notice address for both Pete's Clam Stop, 1320 Surf Avenue, and Williams Candy, 1318 Surf Avenue).
We may need to ask a question or two to confirm it's really you before we hand over or delete a record, and we'll respond within 30 days.