This website is a set of static pages that stores nothing about you beyond the consent choice you make in its banner — plus an optional chat widget that loads only if you switch it on. The business behind it keeps a small amount of ordinary order data in ordinary tools. This page sets out what we protect and how, who else ever touches it, and — just as plainly — what we do not have.
Two things could hold information about you, and they are very different. The first is this website, which is a set of pages built ahead of time and handed to your browser as finished files. It holds nothing about you beyond the cookie-consent choice you make in its banner, and an optional chat widget that stays off unless you switch it on. The second is the business behind it — an email account, accounting records, the system that prints shipping labels — which holds a small amount of ordinary order information for as long as it is needed.
Almost everything below follows from that split. The website is not a place where your data lives, so most of the usual website security worries simply do not apply to it. The order records are real, and they are protected the way a small business protects paperwork: few people, few copies, sensible accounts, locked door.
This page is written to be checked rather than believed. Every claim about the site is something you can verify by loading it and reading the source, and every claim about the business is something you can hold us to on the phone.
fixedgearstraps.com is served over HTTPS. Everything between your browser and the site travels encrypted with TLS, so nobody sitting on the network in between can read a page or alter it on the way to you. What that protects is the delivery of a public page. You never type a secret into this site, so there is no secret of yours in transit to lose.
The pages are statically rendered. They are built once, in advance, and served as files. There is no database attached to the site. There is no API route, no backend of ours running code when you visit, no admin panel, no content management login and no user accounts. There is nothing to sign in to, so there is no password of yours for us to store or lose.
Our own code sets no cookies and writes nothing to local storage, session storage or IndexedDB. It runs no analytics. It makes no requests of its own to any server we control, because there is no server we control for it to talk to. Two third-party tools are the declared exception: the consent manager, which stores the choice you make in its banner, and the chat widget, which the consent manager blocks — no script, no connection, no storage — until you opt in to its category. Nothing else about you is stored by the site.
A breach needs something worth taking. An attacker who got all the way in would find HTML, a price list that is already public, and a spinning cog. That is not clever security. It is an absence of anything worth securing, chosen on purpose rather than arrived at by accident. Every feature we did not build is a feature that cannot be broken into.
In plain EnglishNone of section 2 requires trusting us. Open the developer tools in your browser and look.
The estimator at /quote runs entirely in your browser. It checks the fields, works out an estimate from the same price list published on the site, generates a reference shaped GH-Q-XXXX-### and draws a summary panel. Then it stops. Nothing is transmitted and nothing is saved. Close the tab and the entry is gone, including from our side, because it was never on our side.
From a security point of view that means three things. There is no submission endpoint to attack, spam or overload. There is no queue of quote requests sitting on a server waiting to be read by the wrong person. There is no store of buyer names, shop names and order volumes to leak, which is the part a competitor would actually want. It is a calculator, not an inbox.
To send a real quote request, email quotes@fixedgearstraps.com or call +1 (762) 760-1179 during workshop hours. From that moment your message is an ordinary email in our email account, and 6.0 covers what happens to it.
In plain EnglishCard numbers are not typed on this website. Online checkout is planned, not live. When it opens, the card goes to Stripe on a page Stripe hosts.
There is no cart and no checkout on fixedgearstraps.com today. The quote estimator is a calculator in your browser. The arrowed quote links on the tiles take you there and do nothing else — they do not start a payment, because payment is not available on this origin.
The intended architecture, once a Stripe account is connected and live mode is signed off, is a full-page Checkout page hosted by Stripe after a written quotation is approved. A server we control would create that Checkout Session from the approved amount in USD and send you only to the Stripe-hosted URL. Every card-entry field on that page comes from Stripe. No primary account number, CVC, PIN or track data is meant to pass through this website, a Cloudflare Worker, our mailbox, the chat widget, analytics or a log.
Do not send a full card number, security code, PIN, password or bank credential through the quote notes, email, a phone message, chat, SMS or social media. We will not ask for one that way. If one arrives anyway we delete it without using it and point you at the hosted page once it exists.
Stripe publishes that a PCI-certified auditor evaluated Stripe and certified it to PCI Service Provider Level 1 — the most stringent level of certification available in the payments industry (docs.stripe.com/security/stripe, reviewed 21 Aug 2026). That is Stripe’s status as a service provider. It does not certify, endorse or guarantee Gearhold LLC. We hold no PCI-DSS attestation of our own. We have not selected an SAQ. We do not claim completed PCI validation. The correct SAQ, attestation of compliance, and any scan duty will be confirmed against the actual production architecture with Stripe, the acquirer or the applicable payment brand before live card acceptance.
The later integration is planned to keep amounts server-authoritative, to use HTTPS redirects only to Stripe-created hosted URLs, to verify webhooks on the unmodified raw body with an endpoint-specific signing secret, to keep secrets out of the browser bundle, to store the least metadata an order needs, and to patch, monitor and test before live mode. None of that is live today.
We keep no card numbers. After a real charge, what would come back is the ordinary merchant record: that a payment went through, for how much, on what date, and the name attached to it. That record would live with the accounting records described below.
An order leaves a trail in four places. That trail is the only personal information the business holds about you, and none of it is on the website.
| Where | What is in it | Who can reach it |
|---|---|---|
| Our email account | Your message and our replies: name, email address, shipping address, what you ordered, and anything you chose to write to us. | The people who run the business, each signed in with their own account. |
| Accounting records | Invoices and payment records: name, billing details, amounts, dates, and the totals a tax return needs. | The people who run the business, plus the tax authorities if they ask for what the law entitles them to. |
| The shipping label system | What the carrier needs to deliver a parcel: name, delivery address, a contact detail for delivery, weight and tracking number. | The people who run the business. The carrier receives the label data. |
| Paper at the bench | Order slips and repair notes: a name, an address, and what is being made or restitched. | Whoever is at the bench that day. |
| The chat widget, if you used it | The transcript of what was typed, held by tawk.to rather than by us. | The people who run the business, through the chat dashboard. The widget itself only loads for visitors who opt in to it. |
Email deserves an honest note, because it is where nearly all of this starts. Mail normally travels encrypted between mail servers, but the hops in between are not ours and we cannot promise it for every message. After it arrives, a copy sits in your sent folder as well as in our inbox. Send us what an order needs — a name, an address, what you want made. Nothing that would hurt you if the wrong person read it.
Access is limited to the people who run Gearhold. That is a short list and it does not include contractors, marketers, agencies or anyone who bought a lead list. Accounts are individual rather than shared, they are protected with strong unique passwords and with two-step verification wherever the provider offers it, and access is removed when someone stops working with us.
There is no permission matrix here and it would be dishonest to draw one. The controls that exist are the ones that fit a workshop: a small number of named accounts, no shared logins, and no reason for anyone else to be in the inbox. How long each record is kept, and why, is set out at /legal/privacy.
The workshop is a room with a bench, a wall of webbing, Ruth the 1978 bar-tack machine, and a clipboard. It is locked when nobody is in it. The computer used for the business is password-locked and is not left signed in where someone could walk up to it.
Paper matters more here than it does in most security policies, because paper is where a live order note actually sits. Order slips stay in the workshop. They are not carried around, not left face-up on the counter, and not photographed for the internet. Once the order is closed and the accounting record is made, the slip is shredded.
What is not here is worth saying too. There is no badge reader, no camera wall, no alarmed server room and no visitor log, because there is no server here to guard and no data center to sign into. There is a lock, a bench, and a habit of putting paper away.
In plain EnglishThese are the outside companies involved in serving this site and running the business, and the most any of them ever sees.
| Who | What it is for | What it gets |
|---|---|---|
| Our hosting provider | Storing and serving the website files. | Whatever request logs a web host keeps by default: IP address, user-agent, the file requested, a timestamp. We add no logging of our own, and we never read or analyze theirs. |
| Our email provider | Sending and receiving business mail. | The content of your emails to us and our replies, and the addresses on them. |
| Stripe (planned, not live) | Intended processor for a future full-page Stripe-hosted Checkout after a written quote is approved. | Nothing from this origin today. When checkout is switched on: card numbers and billing details on Stripe’s hosted page. They never reach this website. |
| The carrier | Getting the parcel to you. | Name, delivery address, a contact detail for delivery, parcel weight, tracking. |
| Our accounting tools | Invoices, tax filings and the records the law requires a business to keep. | Name, billing details, amounts and dates. |
| Google Fonts (fonts.googleapis.com, fonts.gstatic.com) | Serving the Archivo and Space Mono typefaces used across the site. | Your IP address, user-agent string and the referring page, sent when the font loads. No cookies are set on this site. |
| Termly (app.termly.io) | Running the cookie-consent banner and remembering what you answered. | Your consent choice, and a consent record with a timestamp and the page you were on, sent to Termly’s consent service when you save a choice. The script loads on every page. |
| tawk.to (embed.tawk.to) | The live-chat widget, for visitors who switch it on. | Blocked until you opt in, so by default: nothing. While active: chat messages and details you submit, IP address, browser and device data, pages and session activity, approximate location, timestamps. |
| Fontshare, operated by Indian Type Foundry (api.fontshare.com) | Serving the Clash Display typeface used for headings. | Your IP address, user-agent string and the referring page, sent when the font loads. No cookies are set on this site. |
Beyond the host handing you this page, the two font providers and the consent manager are the only outside servers your browser talks to while you read it — plus tawk.to if you have switched the chat on. Loading a font is a real network request, so it sends your IP address, your user-agent string and the page you are viewing to servers operated by Google in the United States and by Indian Type Foundry in India. If you are reading from anywhere else, that information leaves your country. A webfont is small, but it is not nothing, and we would rather write it down than let you find it in the network tab.
Everything else in that table sits behind the scenes. None of it sees anything unless you write to us, call us or place an order.
The 3D cog on the home page is drawn with three.js, which is bundled into the site itself rather than pulled from a content delivery network. It costs you no third-party request and it reports nothing to anyone.
The full cookie inventory, with the browser panels to check it in, is at /legal/cookies. What the business holds off the website is at /legal/privacy, and how to ask for a copy of it or its deletion is at /legal/your-data.
In plain EnglishWe hold no security certifications. Here is the full list of what is missing, why, and what to do if your procurement rules need it.
A row of badges is easy to imply and hard to back. So here is the list, without apology.
The reason is scale, not indifference. Audit programs like SOC 2 and ISO 27001 are built for organizations that hold large amounts of other people’s data in systems they run themselves. We run no systems. The website holds nothing, and the business holds a modest set of order records inside ordinary business tools that carry their own compliance. An audit of that would buy a logo for this page, not a safer strap or a safer address book.
If your purchasing rules require a SOC 2 report, a security questionnaire backed by an audit, a signed data processing agreement listing named sub-processors, or a supplier carrying cyber insurance, we will not clear that bar. We would rather tell you in the first email than waste a month of your time. Buy through a distributor who can meet it, or buy from us on a purchase order where the only data that changes hands is a name, a shipping address and an invoice — which, for a box of pedal straps, is usually the honest amount.
In plain EnglishIf order information ever got out, we would tell the people affected quickly and in plain words, and tell the regulators the law says we must.
The website has no store to breach, so the realistic incident is a business one: our email account is compromised, an accounting login is phished, a laptop walks off, or a paper order slip goes missing.
The first move would be to contain it — change credentials, end active sessions, revoke access, stop the leak. The second would be to work out exactly what was exposed and whose information it was. We would write that down as we went, because a clear record is what makes the notice afterwards worth reading.
We would notify the people affected without undue delay. Where the GDPR or the UK GDPR applies, we would notify the relevant supervisory authority within 72 hours of becoming aware of the breach. We have no establishment in the EU and no lead authority, so that means the authority for the people affected rather than one regulator standing in for the rest. Where a US state breach-notification law applies we would follow it, including the Georgia notification law for Georgia residents. We would not sit on the news until the picture was perfect.
A notice from us would tell you, in plain English:
It would not be dressed up as a routine security update.
If you find a genuine security problem with fixedgearstraps.com, email hello@fixedgearstraps.com with SECURITY in the subject line, or call +1 (762) 760-1179 during workshop hours. There is no security@ address. There is one inbox, and the people who run the business read it.
Tell us what you found, how to reproduce it, and what someone could actually do with it. A short clear write-up beats a scanner export every time.
If you report a genuine issue in good faith, do not access anyone else’s information, and do not degrade the service for other people, we will not pursue you and we will not report you. We will thank you and we will fix it. We cannot pay a bounty, and pretending otherwise would waste your afternoon.
What we ask you to avoid:
We aim to acknowledge a report within five working days. Someone is at the bench Tue–Sat 10–18 ET, so a Sunday report waits until Tuesday. That is an aim we think we can keep, not a contractual response time, and we are not going to promise you an hour.
What we can actually fix is this website and the way the business handles your order. Our host, Stripe (when checkout is connected) and the two font providers run their own systems and their own reporting routes, so a fault inside one of those is theirs to fix. Tell us anyway if it reaches you through us. Reports about missing security headers on a page that stores nothing are welcome too, and are likely to be answered with a thank-you and a link back to this page.
In plain EnglishThe restitch guarantee has no time limit, but it does depend on the workshop still existing. That is worth knowing before you treat it as insurance.
The lifetime restitch guarantee, set out in full at /legal/guarantee, has no time limit, needs no receipt, and follows the strap to a second owner. It also depends on there being a bench, a machine and someone to sit at it.
Gearhold is one workshop. If it closed, the guarantee would close with it. There is no parent company standing behind it, no escrow arrangement, and no third party contracted to honor repairs in our place. Anyone who tells you a lifetime guarantee from a small maker is stronger than the maker is selling you something.
What we can tell you is what a bad week looks like in practice. Ruth is a 1978 bar-tack machine, and machines that old are repairable — the parts exist and so do the people who know them. Webbing and hardware come from more than one supplier. Order records, invoices and the price list live in ordinary business tools that keep their own backups, so a dead laptop is an inconvenience rather than an ending. If a run slips, you get the new date from us rather than silence.
If we ever had to wind the business down, we would say so on this website and email anyone with an order in progress, finish or refund the work in hand, and give reasonable notice for guarantee claims instead of closing the door overnight.
The records would go the way /legal/privacy describes: kept while the law still wants them, then destroyed. A customer list is not an asset we would sell, and there is nothing else in there to sell. If the business were ever sold rather than closed, the order records and the guarantee would travel with it under the assignment clause at /legal/terms, and this page would say so before it happened.
In plain EnglishEvery claim here is checkable today. If one stops being true, the page changes before the thing does.
This page describes how the site and the workshop work now. Some of it would stop being true the day we added a form that posts somewhere, a cart, live Stripe checkout, an analytics tag or a chat widget.
That day came for the chat widget on 20 Aug 2026, when the consent manager and the opt-in chat went live, and this page, /legal/cookies and /legal/privacy changed in the same release — before either one ran, not after somebody with the network tab open caught us. The promise stands for whatever is next: the pages are corrected before the code ships, and the effective date at the top moves with them.
We cannot email you about a change, because there is no mailing list to email. The date at the top is the honest signal. We keep the previous wording, so if you want to know what this page said on the day you ordered, ask and we will tell you.
Security questions, a vulnerability report, or a procurement questionnaire you would like answered honestly rather than optimistically — same address, same phone, same people.
If you think anything on this page overstates what we do, tell us and we will change it. If we ever disagree, let’s start with a phone call.