Legal
Privacy Policy
Last updated 26 August 2026
What we collect, why, who sees it, how long we keep it, and how to make us delete it. We do not sell personal information or share it for targeted advertising.
Rack n' Stack, Inc. ("Rack n' Stack", "we", "us") operates https://www.racknstack.com. This policy covers personal information we collect through the website, quote and contact forms, email, and phone, and what we do with it. It serves as our notice at collection.
We are a business-to-business infrastructure firm. Almost everything we hold is business contact and project information: who you are at work, what you are deploying, and where the site is.
1. What we collect
Identifiers and business contact details: name, employer, job title, work email, phone, and site and billing addresses.
Commercial and project information: quote requests, part numbers and quantities, scopes of work, site details you share for an engagement, order and invoice history, and correspondence with our team.
Technical and usage information collected automatically: IP address, browser and device type, referring URL, pages viewed, and interaction events, with an approximate city-level location derived from IP.
We do not seek sensitive personal information as defined by California law. Do not send it to us; if it reaches us inside a document you supply, we use it only to complete the engagement it relates to.
This site is not directed at children. We do not knowingly collect information from anyone under 18.
2. Why we use it
To quote, schedule, and deliver hardware and services: sourcing, staging, dispatching crews, invoicing, and handling warranty and RMA claims.
To run the customer relationship, meet legal obligations including tax records and export screening, and to operate, secure, and improve the website.
To send operational email where you asked for it or where it relates to business you have already done with us. Every such message carries an unsubscribe link.
We do not use your personal information to train machine-learning models, and we do not use automated decision-making technology to make significant decisions about you. Credit and compliance decisions are made by people.
3. Legal bases (EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we process personal data to perform a contract with you or take steps at your request before entering one; for our legitimate interests in operating, securing, and developing a B2B infrastructure business, balanced against your rights; to comply with legal obligations; and, where required, on consent, which you may withdraw at any time.
4. Who we share it with
Service providers acting on our instructions and bound to confidentiality: website and database hosting, product analytics, email delivery, freight carriers and customs brokers, and our accounting, insurance, and IT providers.
Where the law requires or permits: regulators, law enforcement, and courts under a valid legal process; our professional advisers; and, in a merger, acquisition, or sale of assets, the counterparty under confidentiality.
We have not sold personal information or shared it for cross-context behavioral advertising in the preceding twelve months, and we do not do so now. We do not disclose personal information to data brokers.
5. Cookies, analytics, and opt-out signals
The site sets strictly necessary cookies so it functions, and uses PostHog product analytics, hosted in the United States, to understand aggregate usage. Details are in our Cookie Notice.
We do not run advertising pixels, cross-site retargeting, or ad-network tags on this site.
In the EEA, the UK, and Switzerland analytics stay off until you accept them in the cookie banner. Everywhere else they run unless you decline. Where the law recognizes a universal opt-out mechanism such as Global Privacy Control, we treat it as a valid opt-out for that browser. Browser Do Not Track signals have no agreed standard and we do not respond to them.
6. How long we keep it
Quote and inquiry records where no order followed: up to three years from last contact.
Order, invoice, warranty, project, and export-compliance records: a minimum of five years from the transaction, and longer where tax, customs, or export-control law requires it or where a claim is open.
Marketing contact records: until you unsubscribe, plus a permanent suppression entry holding only what is needed to keep you unsubscribed.
Website analytics: event-level data up to two years, aggregate reporting indefinitely. When a retention period ends we delete the record or de-identify it.
7. Where it goes and how it is protected
We are based in the United States and our systems and providers are principally US-hosted. If you contact us from outside the US, your information is transferred to and processed in the US. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's standard contractual clauses with the UK addendum where applicable, or a recipient's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions.
We use TLS in transit, encryption at rest with our hosting providers, role-based access control, and multi-factor authentication on administrative accounts. No system is perfectly secure; if a breach affects your personal information we will notify you and the relevant regulator within the timeframes the applicable law requires.
8. Your rights
Depending on where you live you may have the right to know what we hold and why, get a copy in a portable format, correct it, delete it, opt out of sale, sharing, targeted advertising, or profiling with legal effects, limit the use of sensitive personal information, and not be treated worse for exercising any of it.
These rights are recognized in the United States under the comprehensive privacy laws of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, and outside it under the GDPR and UK GDPR. Which of them you get depends on your residence.
To exercise a right, email contact@racknstack.com with “Privacy request” in the subject line, or call 702-362-7659. We verify identity before acting, usually by a reply from the work email on file, and we respond within 45 days, extendable once by a further 45 days with notice. An authorized agent may act for you with written permission we can verify.
If we refuse a request you may appeal by replying to our decision or emailing contact@racknstack.com with “Privacy appeal” in the subject line. We will answer in writing within 45 days (60 where the law allows). If we deny the appeal we will tell you how to complain to your state attorney general, the California Privacy Protection Agency, or your supervisory authority.
9. Changes and contact
We update this policy when our practices or the law change, and the date at the top changes with it. Material changes are flagged on the website before they take effect.
Rack n' Stack, Inc., 6442 Windy Rd, Las Vegas, NV 89119, USA. contact@racknstack.com · 702-362-7659.
