Last updated:
The short version:We're a neighborhood used bookstore, not an ad company. We only collect the information we need to run the shop and stay in touch — mostly an email address if you ask us to. We never sell your personal information, and you can ask us to access or delete your data at any time.
1. Who we are
This Privacy Policy explains how To Be Read (also known as the Clackamas Book Exchange, “we,” “us,” or “our”) handles personal information collected through our website at tobereadshop.com(the “Site”). We are a used bookstore located in Milwaukie, Oregon, USA, and we are the controller responsible for your personal information.
If you have any questions about this policy or how we handle your data, contact us using the details in Section 14 (Contact us).
2. Information we collect
Information you give us
- Newsletter sign-ups. When you subscribe, we collect your email address so we can send you store news and confirm your subscription.
- Accounts & wishlists.If you create a wishlist, we use a passwordless “magic link” sign-in, which collects your email address. We store the books you save and send you an email if a title on your wishlist arrives in the shop.
- Reviews. If you submit a review, we collect the name you provide, your star rating, and your review text. The name and review you submit are displayed publicly on the Site once approved.
- Messages. If you email or call us, we receive whatever information you choose to share.
Information collected automatically
- Privacy-friendly analytics. We use Plausible Analytics, which is cookieless and collects only aggregate, anonymized usage data (such as page views and referring sites). It does not track you across sites or build a profile of you, and does not collect personal data.
- Google Tag Manager. We use Google Tag Manager to manage measurement tags. These run only after you opt in through our cookie banner (see our Cookie Policy).
- Server logs & abuse prevention. Like most websites, our hosting provider records technical request data such as IP address and browser type. We also use your IP address transiently to rate-limit forms and prevent abuse. For reviews, we store only a salted, one-way hash of your IP address — never the raw address.
We do not knowingly collect payment card details on this Site. In-store purchases are handled at our point of sale, and online sales happen on third-party marketplaces (see Section 5).
3. How we use your information
- To operate the Site and provide features you request (wishlists, reviews, the trade-credit estimator, and the reading recommendation tool).
- To send you the newsletter and wishlist notifications you signed up for.
- To respond to your questions and provide customer service.
- To understand, in aggregate, how the Site is used so we can improve it.
- To protect the Site against spam, fraud, and abuse.
- To comply with our legal obligations.
4. Legal bases for processing (EU/UK visitors)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:
- Consent — for the newsletter, wishlist notifications, and optional analytics cookies. You can withdraw consent at any time.
- Legitimate interests — for running and securing the Site and understanding aggregate usage, balanced against your rights.
- Legal obligation — where we must retain or disclose information to comply with the law.
5. When we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only with service providers who process it on our behalf, and only as needed to run the Site:
- Netlify — website hosting.
- Neon — managed database that stores wishlists, accounts, and reviews.
- Resend — sends our transactional and newsletter emails.
- Plausible — cookieless, aggregate analytics.
- Google — Tag Manager (consent-gated), plus Maps, Books, and Places used to show our location, look up book details, and display reviews.
- Groq — powers the “Next Read” recommendation tool; the reading preferences you type are sent to generate a suggestion and are not stored by us.
- TikTok — embedded videos on some pages may load content from TikTok.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a sale or transfer of the business (with notice to you where required).
6. Cookies & tracking technologies
We use a small number of cookies and similar technologies. Optional analytics tags load only after you consent. For full details and to change your choice at any time, see our Cookie Policy.
7. How long we keep your information
We keep personal information only as long as needed for the purposes above. Newsletter and wishlist data is kept until you unsubscribe or ask us to delete it. Reviews are kept while published. Aggregate analytics data contains no personal information. We delete or anonymize data when it is no longer needed.
8. How we protect your information
We use reasonable administrative and technical safeguards, including encryption in transit (HTTPS), access controls, salted hashing for IP data, and reputable service providers. We also practice data minimization — we limit what we collect in the first place.
However, no method of transmission over the internet or electronic storage is completely secure, and we cannot and do not guarantee absolute security. You provide information to us at your own risk, and you are responsible for keeping any sign-in link or credentials confidential. To the fullest extent permitted by law, and except for obligations we cannot disclaim under applicable data-protection law, we are not liable for any unauthorized access to, alteration of, or loss of data that occurs despite reasonable safeguards, including events beyond our reasonable control or acts of third parties.
9. Your privacy rights
Oregon residents (Oregon Consumer Privacy Act)
You have the right to:
- Confirm whether we process your personal data and access it.
- Obtain a list of the categories of third parties to which we have disclosed personal data.
- Correct inaccuracies and request deletion of your personal data.
- Obtain a portable copy of data you provided to us.
- Opt out of the sale of personal data, targeted advertising, and certain profiling. (We do not sell data or use it for targeted advertising.)
California residents (CCPA/CPRA)
- The right to know what personal information we collect, use, and disclose.
- The right to delete and to correct your personal information.
- The right to opt out of the “sale” or “sharing” of personal information. (We do not sell or share it.)
- The right to limit the use of sensitive personal information. (We do not use sensitive personal information for these purposes.)
- The right not to receive discriminatory treatment for exercising your rights.
EU/UK residents (GDPR / UK GDPR)
- The rights of access, rectification, erasure, restriction, data portability, and to object to processing.
- The right to withdraw consent at any time, without affecting prior processing.
- The right to lodge a complaint with your local supervisory authority.
How to exercise your rights
Email us at TBR@tcpbusiness.com or use the contact details below. We will verify your request (and that of any authorized agent) and respond within the timeframes required by applicable law. You may appeal a decision by replying to our response; if we deny your appeal, you may contact the Oregon Department of Justice.
10. Your choices & the Global Privacy Control
- Email: unsubscribe from the newsletter at any time using the link or reply in any email we send you.
- Cookies: accept or decline optional cookies through our banner, and reopen “Cookie settings” from the footer to change your choice.
- Global Privacy Control (GPC): we honor recognized opt-out preference signals, such as GPC, as a valid request to opt out where applicable.
11. Children's privacy
Our Site is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
12. International visitors
We are based in the United States, and our service providers may process data in the U.S. and other countries. If you access the Site from outside the U.S., you understand your information will be transferred to and processed in the U.S., which may have different data protection laws than your country.
13. Third parties, limitations & your acknowledgment
We share information with the service providers described in Section 5 so they can perform services for us, and we require them to protect it. However, those providers and any other third party operate independently, and — except as required by applicable data-protection law — we are not responsible or liable for the independent acts, omissions, security practices, or privacy practices of any third party, including third-party sites or embeds you reach from the Site.
This Privacy Policy is provided for transparency and does not create any contractual right or warranty beyond what applicable law requires. Except for rights that cannot be waived or limited under applicable data-protection law, your use of the Site is also subject to the disclaimers, limitation of liability, indemnification, and dispute-resolution provisions in our Terms of Service, which are incorporated here by reference. By using the Site and providing information to us, you acknowledge and consent to the collection, use, and disclosure of information as described in this Policy.
14. Contact us
To exercise your rights or ask a privacy question, reach us at:
To Be Read · Clackamas Book Exchange7931 SE King Rd, Ste 1
Milwaukie, OR 97222, USA
Email: TBR@tcpbusiness.com
Phone: 503-659-2559
15. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Material changes will be highlighted on the Site. Please review it periodically.
