$4.49 shipping anywhere in the 50 states and DC · free from $32 · every copy new

Privacy Policy

Last updated: September 3, 2026

Follow one order through froxeo.com and this policy has been read. It starts at checkout, passes through two payment companies, then a wholesaler, a warehouse and finally the Postal Service, and ends when the record is deleted. Lisa Pasco Funy LLC of Cheektowaga, New York, answers for each step. A practice not written here is a practice the site does not have.

Checkout takes four things and passes the fifth to someone else

Collected by Froxeo: a name, a shipping address and an email, plus an optional phone number used only when the warehouse or USPS has a delivery question.
Not collected by Froxeo: card or PayPal details, which are typed into Stripe's or PayPal's own field. The shop learns that the payment cleared, the cardholder's name, and the closing four digits of the card number.
An account: stores those same four things so the next checkout is shorter, and closes on request the same day.
An email to the shop: filed with the order it concerns.

The wholesaler learns the address, and so does the mail carrier

What travels: the name, the shipping address and the optional phone number, to the wholesaler and the warehouse partner that pack the book, and on the label to USPS.
What stays: the email address, the card details and the account, along with the rest of the order history. None of those companies sees any of it.

The server log holds three things and nobody's name

The server log: IP address, the browser and device in use, the pages requested. Kept to run the site and to notice an attack.
Attached to it: no name, no email, no order. It is a list of requests, not of people.

One counter belongs to the shop, and no outside tracker runs here

The visitor counter: built into the store software. For as long as a page stays open, it reports back to Froxeo's own server at short intervals: the page's address and title, the referring address, and a random session number. That shows how many readers the site has and which shelf holds them. No name. No email. Nobody outside Froxeo reads it.
Outside trackers: none. No Google Analytics, no advertising pixel, no session replay, no heat-mapping script. The page source was checked before this line was written.

Cookies

Cart and session: one cookie.
Signed-in account: one cookie.
Cookie preference: one cookie, written by the software itself, since no optional cookie exists for a visitor to rule on.
Arrival: one cookie, kept 30 days, noting the referring page, the first page opened and any campaign code in the link, so an order can be matched to the link that brought it. Read by Froxeo alone.
Stripe's fraud check: two cookies set by Stripe the moment the checkout page loads, one for the visit and one that lasts about a year, both under Stripe's own policy.
Advertising cookies: none.
Banner: none appears on arrival, and no consent panel sits in the corner either. Both were switched off deliberately, because none of the cookies above is one a visitor could refuse and still buy a book.
If an analytics or advertising script ever arrives: the panel comes back on the same day, and this section is rewritten before the script loads.
Cookies switched off in the browser: the cart forgets itself between visits; the rest of the site works.

Marketing email waits for a tick that is never pre-ticked

The box: one, at checkout, offering news and offers by email, and it loads unticked.
Left empty: the only mail from Froxeo is about the order: confirmation, dispatch note with tracking number, replies to what was written.
Ticked: word of new titles may follow, each message with an unsubscribe link. One email to contact@froxeo.com has the same effect at any time.

Five uses are the whole list

One: buying the book from the wholesaler and delivering it.
Two: handling a return, a refund or a question.
Three: stopping fraud and keeping the site standing.
Four: keeping the records that tax and consumer law oblige a business to keep.
Five: sending marketing email to the people who ticked the box.
Not on the list: selling personal information, sharing it for advertising, building a profile, or letting a machine decide anything about a customer.

Six companies, one job each

Stripe and PayPal: take payment, under their own policies.
The wholesaler and the warehouse partner: pick and pack.
USPS: delivers.
The hosting company: runs the store software and holds the order records on its servers as Froxeo's processor, with no right to use them for itself.
Anyone else: only a court or a law can compel a disclosure, and Froxeo would say so wherever the law allows. Data brokers and advertising networks appear nowhere in this list because they appear nowhere in the business.

Each record has a lifetime, and most can be cut short

Order record (name, address, titles): for the period US tax and bookkeeping rules make a business keep it, then deleted.
Support thread: until the matter is settled, plus a margin in case it comes back.
Account data: until the account closes.
Server log and visitor counter: overwrite themselves on a rolling basis.
A deletion request: clears everything except what the tax rules make the shop keep, and the reply says what that remainder is.

Your rights

What can be asked: what personal information is on file, a correction, a deletion, or a portable copy.
How: an email to contact@froxeo.com from the address on the order or on the account.
Timing: an acknowledgement within 1 business day; one question back, if needed, to make sure the request is genuine; an answer inside 45 days, or 45 more for an unusual request, with a heads-up before the first 45 expire.
Cost and consequence: none. Asking alters nothing about how Froxeo serves you.

California residents

The extra right: under the CCPA and its CPRA amendments, to direct a business to stop any selling or sharing of personal information.
At Froxeo: nothing is sold or shared, so there is no switch on the site, but a request is still recorded, within 15 business days, by the route on the page Do Not Sell or Share My Personal Information.
Know, correct and delete requests from California: the 45-day timing above, and nobody who asks is served any differently.

Children

Who the shop serves: adults. The site is not built for children.
Under 13: Froxeo does not knowingly keep any information about a child under 13. A message saying that a child has given some, and the record is removed.

HTTPS on every page, and two logins at the desk

In transit: every page loads over HTTPS, so what is typed is encrypted on its way to the shop.
Card data: never lands on Froxeo's systems at all.
Access: the order system opens to two people, the ones who ship and support orders, on two separate logins.

No perimeter is perfect, and word of a breach would come from Froxeo first

Where it stops: the shop does not call that perimeter unbreakable, because no perimeter is.
Should a breach ever reach a customer's information: the first word about it would come from Froxeo, without delay, naming what was touched and what to do.

Other sites keep their own rules

Links out: Stripe, PayPal, USPS tracking or any other site: each has privacy practices of its own, not covered here.

The date beneath the title moves when the words do

A change: moves the date beneath the title, and the new wording applies from that day.
A change to how personal information is used: posted on the site before it starts, never after.

Legal name: Lisa Pasco Funy LLC, doing business as Froxeo
Formed in: New York, United States, as a limited liability company
Tax ID (EIN): 99-4781769
Registered office, also the returns address: 229 Cleveland Dr, Cheektowaga, NY 14215, United States

Write to: contact@froxeo.com
Call: +1 (585) 543-4654
Form: froxeo.com/pages/contact
Desk hours: Monday to Friday, 9:00 AM to 5:00 PM Eastern Time
We answer: within 1 business day, and a person writes the answer