Privacy Policy

What we collect, why, and who we share it with

ALFA Manufacturing Group · Last updated 2026-09-10

This policy explains how ALFA Manufacturing Group (“ALFA MFG”, “we”) handles personal information in ALFA OS — the staff workspace, the client portal at start.alfamfg.com, the public project wizard, and the landing pages we run for our brands. It applies to customers, prospective customers, and our own team. We are a Florida contract manufacturer of cosmetics and personal-care products; we collect information to quote, make and ship products and to run the company — not to sell or advertise to you.

1. What we collect

What you give us. When you fill in the project wizard we ask for your name, email, phone, company and details about your project. When you accept a portal invitation we collect your name, email and a password. In the portal you may upload purchase orders, artwork, briefs and messages. If you text or call us, we keep the message and the number it came from. If you speak or type to one of our assistants, we keep that conversation.

What we collect automatically. When you use ALFA OS we record the IP address, browser and device type, the pages and features you use, and the time — the ordinary server logs any web application keeps. When you accept our terms or opt in to text messages we record the date, time, IP address and browser as proof of consent. Anonymous step-by-step events in the project wizard tell us where people get stuck; they never include what you typed.

Sign-in and biometrics.Two-step sign-in can use a text-message code, an authenticator app, or the face or fingerprint unlock already on your phone or computer. That last option works through the WebAuthn standard: the biometric check happens on your own device and your device only sends us a cryptographic “yes”. Your face, fingerprint or any other biometric data never leaves your device, and ALFA MFG never receives, stores or has access to it.

What we do not collect. We do not use advertising or tracking cookies, we do not buy data about you, and we do not collect payment card numbers — Stripe handles those.

2. Why we use it

We use your information to answer your inquiry and quote your project; to create and secure your login; to make, track, invoice and ship your orders and show you their status in the portal; to send you the order updates, sign-in codes and customer-service messages you asked for; to run our accounting, planning and quality records; to keep the service secure and find out what went wrong when something breaks; and to meet legal and tax obligations. If you have opted in, we may also email you about our products and services — every such email has an unsubscribe link.

The legal bases for this, where a law asks for one, are performing our contract with you, our legitimate interest in running a manufacturing business securely, your consent (for texts and marketing email, which you can withdraw), and compliance with law.

3. Who we share it with

We do not sell personal information, and we do not share it with anyone for their own marketing. We share it with service providers that process it on our instructions so the application works — each is bound by contract to protect it — and with our own staff who need it to do their jobs. Those providers are:

  • Supabasesign-in (authentication) and our database, hosted in the United States.
  • Vercelhosts the application and serves its pages.
  • Stripeinvoicing and payments — when you pay an invoice, your card or bank details go to Stripe, not to us.
  • Plaidconnects our own company bank accounts to our books. Plaid never sees customer data; it is listed because it processes our staff’s bank-connection credentials.
  • Twiliosends and receives text messages and phone calls, including sign-in codes.
  • Fishbowlour manufacturing and inventory system (ERP), where orders, parts and shipments live.
  • Shopifyour online store and product catalogue.
  • Klaviyoemail marketing to people who have opted in.
  • Microsoft 365company email, calendar, files and meetings.
  • Anthropic, OpenAI and ElevenLabsAI model providers that process the text you type or the audio you speak to an assistant (see the AI Assistants page).

We may also share information when the law requires it, to protect our rights or someone’s safety, with professional advisers (our accountants and lawyers) under confidentiality, or as part of a sale or reorganisation of the business, in which case the new owner is bound by this policy.

Plaid.Our books connect to our company bank accounts through Plaid. Plaid’s handling of the data it receives is governed by Plaid’s End User Privacy Policy at plaid.com/legal/#end-user-privacy-policy. By connecting a bank account through ALFA OS you agree that your information may be processed by Plaid as described there. Stripe. Payments are processed by Stripe, whose privacy policy is at stripe.com/privacy.

4. Cookies

ALFA OSsets only the cookies it needs to work: a session cookie that keeps you signed in and a few preference cookies (for example your portal language). There are no advertising, analytics or third-party tracking cookies, so there is nothing to opt out of; blocking cookies entirely will simply stop you signing in. The client portal may load a customer’s chosen brand font from Google Fonts, which receives your IP address to deliver the font file.

5. How long we keep it

We keep customer, order, invoice and accounting records for as long as we do business with you and for seven years afterwards, because tax law and our quality system require it. Portal login details are kept while the account is active and removed within 90 days of it closing. Project-wizard inquiries that never become a customer are kept for up to two years so a specialist can follow up. Consent records (terms acceptance, text-message opt-in) are kept for as long as the consent is relied on plus four years. Server logs and assistant conversations are kept for up to 12 months. We keep information longer only where a legal hold or dispute requires it.

6. Your choices and rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it, ask us to delete it (we will, unless a record must be kept by law), or ask us to stop using it for a particular purpose. You can stop text messages by replying STOP, stop marketing email with the unsubscribe link, and close your portal login by asking us. To make any request, write to info@alfamfg.com; we will verify it is you before we act, we will not treat you differently for asking, and we answer within 45 days. You may authorise someone to make a request for you.

7. State-specific notices

California.California residents have the rights described above under the CCPA/CPRA. We do not sell or “share” personal information for cross-context behavioural advertising, and we have not done so in the past 12 months. The categories we collect are identifiers (name, email, phone, IP), commercial information (orders, quotes), professional information (company, title), internet activity (usage logs) and the contents of messages you send us. Under California’s Shine the Light law we do not disclose personal information to third parties for their direct marketing. Other states. Residents of Colorado, Connecticut, Virginia, Texas, Oregon, Utah and other states with privacy laws have similar rights of access, correction, deletion and portability, and may appeal a refusal by writing to info@alfamfg.com with “appeal” in the subject. Illinois, Texas and Washington. As stated above, we do not collect, capture, store or receive biometric identifiers or biometric information; device biometrics used for sign-in stay on your device.

8. Children

ALFA OS is a business tool. We do not knowingly collect information from anyone under 18, and the service is not directed to children. If you believe a minor has given us information, tell us at info@alfamfg.com and we will delete it.

9. Where the data lives, and security

Our systems are hosted in the United States. If you use them from elsewhere, your information is transferred to and processed in the United States. We protect it with encryption in transit and at rest, two-step sign-in, role-based access, idle sign-out and an audit trail — the Digital Security page explains this in more detail. No system is perfectly secure; if a breach affects you we will notify you as the law requires.

10. Changes

When we change this policy the “Last updated” date changes, and we tell portal users about material changes by email or a notice in the portal. Earlier versions are available on request.

Questions or requests

Write to ALFA Manufacturing Group, 17401 NW 2nd Ave, Ste 7, Miami Gardens, FL 33169, or email info@alfamfg.com. We answer within a reasonable time and never charge for a request about your own information.