Legal

Privacy Policy

Last Updated: March 30, 2026 · Session Cards™ by Tommy Rush

1. Who We Are

Tommy Rush Enterprises ("we," "us," "our," or "Company") operates the website at session-cards.com and sells Session Cards™, a physical card product for songwriters and music producers. Our business address is Sherman Oaks, California, USA. Contact: support@session-cards.com.

2. What We Collect

We collect personal data in the following ways:

3. Legal Basis for Processing (GDPR / CCPA)

We process personal data based on the following legal grounds:

4. How We Use Your Data

5. Email Marketing & Consent

We add you to our marketing email list only if you explicitly consent via a checkbox on our website or at checkout. Every marketing email includes an unsubscribe link. You may withdraw consent at any time by clicking "Unsubscribe" or emailing support@session-cards.com.

We comply with the CAN-SPAM Act. All marketing emails include our physical mailing address and a working opt-out mechanism honored within 10 business days.

6. Third-Party Data Sharing

We do not sell your personal data. We share it only with the following service providers:

7. Cookies

session-cards.com uses the following cookies:

All visitors will see a cookie consent banner before any analytics or advertising cookies are set. You may withdraw consent at any time by clearing your cookies or using your browser's privacy settings.

8. Data Retention

We retain personal data for the following periods:

If you request deletion of your personal data, we will remove it within 30 days except where legal retention is required (e.g., tax records).

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

To exercise any of these rights, email support@session-cards.com with the subject line "Privacy Rights Request." We will respond within 30 days.

10. Your Privacy Choices — Do Not Sell or Share My Personal Information

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have the right to opt out of the "sharing" of your personal information for cross-context behavioral advertising. While we do not sell personal data for money, the use of analytics and advertising cookies (Google Analytics, Meta Pixel) may constitute "sharing" under CPRA.

To opt out:

We will honor your request within 15 business days. Opting out will not affect your ability to browse or purchase from this site.

11. California Residents — Additional Rights (CCPA / CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise California rights, email support@session-cards.com with "California Privacy Request" in the subject line.

12. International Data Transfers

Our services are operated in the United States. If you are located in the EU, UK, or any other jurisdiction with data transfer restrictions, your data may be transferred to and processed in the US. Such transfers are made pursuant to legal mechanisms compliant with GDPR and UK GDPR, including Standard Contractual Clauses where applicable (via Shopify and Google's data processing agreements).

13. Security

We implement industry-standard security measures including SSL/TLS encryption for all data in transit and secure payment processing via Shopify's PCI-DSS compliant infrastructure. However, no internet transmission is 100% secure. You are responsible for keeping your account credentials confidential.

In the event of a data breach that affects your personal data, we will notify you within 72 hours (or as required by applicable law) via the email address on file.

14. Children's Privacy

Session Cards™ is intended for adults (producers, songwriters, and music professionals). We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided personal data, we will delete it immediately. If you believe a child's data has been submitted to us, please email support@session-cards.com.

15. Changes to This Policy

We may update this Privacy Policy at any time. Material changes will be posted on this page with an updated "Last Updated" date and, for existing customers, communicated by email. Your continued use of the site after changes are posted constitutes your acceptance of the updated policy.

Summary: We collect only what we need to run this business. We don't sell your data. We use Google Analytics and Meta Pixel for performance measurement, and Klaviyo for email marketing. You can opt out of tracking via the cookie consent banner, unsubscribe from emails at any time, request deletion, or ask any questions at support@session-cards.com.

16. Contact Us

Questions about this Privacy Policy or your personal data?

Tommy Rush Enterprises
Sherman Oaks, California, USA
Email: support@session-cards.com
Website: session-cards.com