Privacy Policy

Privacy Policy for Three Springs Farm

Effective Date: April 23, 2026

Last Updated: April 23, 2026

Introduction

Three Springs Farm (“we,” “our,” or “us”) is committed to protecting your privacy and being transparent about how we collect, use, and protect your personal information.

This Privacy Policy applies to:

  • Our website at www.threespringsfarm.com (the “Site”)
  • The Three Springs CSA Member App (the “App”)
  • Any related services we offer to our CSA members and customers, including SMS notifications

By using the Site or the App, you agree to the collection and use of information in accordance with this policy.

Information We Collect

1. Personal Information You Provide

When you contact us, subscribe, create an account, place an order, or otherwise interact with the Site or App, we may collect:

  • Name: Your first and last name
  • Email Address: Used for account creation, login, order confirmations, and communications
  • Password: Encrypted and stored securely for account access
  • Phone Number: Used for account recovery, order coordination, and, if you opt in, SMS notifications
  • Mailing / Pickup Address: For deliveries or pickup coordination
  • Profile and Preference Information: Any additional information you choose to provide

2. Membership & Order Information

To provide our CSA services, we collect:

  • Membership Details: Your CSA membership type, status, and preferences
  • Product Selections: Your weekly or seasonal product choices
  • Pickup Information: Your preferred pickup location and schedule
  • Order History: Records of your past orders and selections
  • Special Requests: Dietary preferences, allergens, or special instructions

3. Payment Information

When you make payments through the Site or App:

  • Payment Card Information: Processed securely through Stripe (our payment processor)
  • Billing Address: For payment processing
  • Transaction History: Records of payments and invoices

Important: We do not store your complete credit card information on our servers. All payment data is processed and stored securely by Stripe, our PCI-DSS compliant payment processor.

4. Website Usage Information

When you visit our Site, we may automatically collect:

  • Log Data: IP address, browser type, referring pages, and timestamps
  • Cookies and Similar Technologies: Used by WordPress and certain plugins to remember preferences, maintain sessions, and measure site usage
  • Analytics Data: Aggregate information about how visitors use the Site, which we use to improve it

5. Camera Access (App only)

  • QR Code Scanning: We request camera access solely to scan QR codes for quick check-ins at pickup locations
  • No Photos Stored: We do not capture, store, or transmit photos or videos

6. Device Information (App only)

We automatically collect certain information about your device:

  • Device Type: iOS version, device model
  • Unique Identifiers: Device ID for app functionality and push notifications
  • App Usage Data: Features used, screens viewed, and interaction patterns
  • Network Information: To ensure the app functions properly

7. Location Information (App only)

  • General Location: We may collect approximate location data to provide location-specific features (such as nearby pickup locations)
  • We do not track precise GPS location

8. Push & SMS Notifications

  • Device Tokens: To send you push notifications about your orders, pickup reminders, and farm updates
  • Mobile Phone Number: If you opt in, to send you SMS notifications (see the Communications section below)
  • You can disable notifications in your device settings or reply STOP to any SMS at any time

How We Use Your Information

Site & App Functionality

  • Create and manage your member account
  • Process your product orders and selections
  • Manage your pickup or delivery schedule
  • Provide customer support
  • Send order confirmations and receipts

Communications

  • Send important notifications about your membership and orders
  • Provide pickup reminders
  • Share farm updates, seasonal information, and news
  • Respond to your questions and requests
  • Send promotional offers (only with your consent)

Service Improvement

  • Analyze Site and App usage to improve features and user experience
  • Identify and fix technical issues
  • Develop new features based on member needs

Legal & Safety

  • Comply with legal obligations
  • Protect against fraud and abuse
  • Enforce our terms of service

How We Share Your Information

We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. We may share your Personal Data, including your SMS opt-in or consent status, with third parties
that help us provide our messaging services, including but not limited to platform providers, phone companies, and any other vendors who assist us in the delivery of text messages.

We do not sell your personal information. We only share information with the service providers listed below for the purposes of operating our Site, App, and CSA services.

Communications & SMS Opt-Out

SMS Notifications. By providing your phone number and opting in, you agree to receive SMS notifications from Three Springs Farm. These messages are transactional and related to your CSA membership, including pickup and delivery reminders, payment confirmations, membership status updates, account notifications, and important farm updates relevant to your membership.

Message frequency may vary. Standard Message and Data Rates may apply.

To opt out: Reply STOP to any message at any time. You will receive one final confirmation message and no further SMS messages unless you opt back in.

For help: Reply HELP to any message, or contact us at farmers@threespringsfarm.com or 918-868-7675.

We will not share mobile information with third parties for promotional or marketing purposes.

For full SMS program terms, see our SMS Notification Terms and Conditions.

Third-Party Services

We use the following third-party services to operate our Site, App, and messaging. Each has its own privacy policy governing how it handles data.

Ionos (Website Hosting)

Purpose: Hosting the WordPress-based Site.

Data Collected: Standard web server logs (IP address, browser type, pages visited).

Privacy Policy: Ionos Privacy Policy

Firebase (Google)

Services Used:

  • Firebase Authentication: Account creation and login management
  • Firebase Realtime Database: Storing your membership and order data
  • Firebase Cloud Messaging: Delivering push notifications

Privacy Policy: Google Privacy Policy

Google Sign-In

Purpose: Optional alternative login method

Data Shared: Name, email address, profile picture (if you choose to sign in with Google)

Privacy Policy: Google Privacy Policy

Stripe

Purpose: Payment processing

Data Shared: Payment card information, billing address, transaction details

Security: PCI-DSS Level 1 certified (highest security standard)

Privacy Policy: Stripe Privacy Policy

Expo

Purpose: App development and over-the-air updates

Data Collected: Minimal device and usage data for app functionality

Privacy Policy: Expo Privacy Policy

Twilio / Pingram (SMS Delivery)

Purpose: Delivering SMS notifications you have opted in to receive.

Data Shared: Mobile phone number, message content, delivery status.

Privacy Policies: Twilio Privacy Policy

Data Security

We take the security of your information seriously and implement industry-standard measures:

  • Encryption: All data transmitted between your device and our servers is encrypted using SSL/TLS
  • Secure Storage: Your password is encrypted and never stored in plain text
  • Access Controls: Limited access to personal data, only for authorized personnel
  • Payment Security: All payment information is handled by Stripe, not stored on our servers
  • Regular Updates: We keep our security measures up to date

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

Data Retention

We retain your personal information for as long as:

  • Your account is active
  • Needed to provide you services
  • Required by law or for legitimate business purposes

If you request account deletion, we will delete or anonymize your personal information within 30 days, except for data we’re required to retain for legal, accounting, or security purposes.

Your Privacy Rights

You have the following rights regarding your personal information:

Access & Portability

  • Request a copy of the personal data we hold about you
  • Request data in a portable format

Correction

  • Update or correct inaccurate information through your account settings
  • Contact us for assistance with corrections

Deletion

  • Request deletion of your account and associated data
  • Note: Some information may be retained for legal obligations

Opt-Out

  • Unsubscribe from promotional emails (using the unsubscribe link)
  • Reply STOP to any SMS message to stop receiving text messages
  • Disable push notifications in your device settings
  • Opt out of analytics (contact us for assistance)

Restrict Processing

  • Request limitation on how we use your data

To exercise any of these rights, please contact us at the email address below.

Children’s Privacy

Our Site and App are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us
immediately, and we will delete such information.

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws different from your country. By using our Site or App, you consent to the transfer of your
information to the United States and other countries where we operate.

California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to Know: What personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the “sale” of personal information (Note: We do not sell personal information)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

To exercise these rights, contact us using the information below.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of significant changes by:

  • Updating the “Last Updated” date at the top of this policy
  • Sending you a notification through the Site or App, or via email
  • Posting a notice on the Site

We encourage you to review this Privacy Policy periodically.

Cookie Policy

Our Site uses cookies and similar technologies as part of WordPress and any plugins we have installed (for example, to maintain login sessions or measure site usage). Our App does not use cookies. Third-party services integrated into the Site or App (such as Firebase and Stripe) may use cookies or similar technologies in accordance with their own privacy policies.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact us:

Three Springs Farm
1367 South Highway 82A, Oaks, OK 74359
Email: farmers@threespringsfarm.com
Phone: 918-868-7675

For privacy-specific inquiries, please use the subject line “Privacy Policy Inquiry.”

Consent

By using the Three Springs Farm website or CSA Member App, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.


Questions or Concerns?
Your privacy is important to us. If you have any questions about this policy or how we handle your data, please don’t hesitate to reach out.

Thank you for being a member of Three Springs CSA!