The short version
BrickWorks is a small shop that builds LEGO® dioramas. This website has no shopping cart, no accounts, no forms, and no payment processing. It sells nothing directly — buying happens on Etsy or eBay, under their privacy policies, not ours.
It does run its own analytics, built to work without a cookie: page views, product views, outbound clicks to Etsy and eBay, and a few technical signals like page errors and load speed. Nothing is stored in your browser to make that possible — no cookie, no localStorage, no sessionStorage. The one cookie on this whole site is the one that keeps the shop owner logged into the private dashboard, and it carries none of your data. The sections below say exactly what gets recorded, how it’s built to avoid identifying you, and where its honest limits are.
Who we are
BrickWorks is a sole proprietorship based in the United States, operating the shop BrickWorksUS on Etsy and eBay and the website shopbrickworks.us. You can reach us at brickworksteam@gmail.com.
Review scans from packaging inserts
Every package we ship includes a printed insert with a QR code. That code points at a /review address on this site, which immediately forwards you to the review page for the shop you bought from. When that forward happens, we append one row to a private spreadsheet with exactly these seven fields, and nothing else:
- timestamp — when the scan happened, in UTC.
- path — the address that was scanned, such as
/review/etsy. - channel — which shop the insert was printed for, such as “etsy” or “ebay”.
- target — the page we forwarded you to.
- known — whether we recognized the channel, or had to fall back to our homepage.
- device — one coarse bucket: bot, mobile-ios, mobile-android, mobile-other, desktop, or unknown.
- referrer — the page that linked you here, if your browser sent one. A scan from a printed code usually sends nothing at all.
We read this to answer one question: did anyone actually scan the insert? Nothing in a row identifies a person, and no row is linked to an order or a buyer.
Site analytics
Separately, this site records its own traffic and usage, so we can see whether a page works without handing that job to a third-party analytics vendor. Every event we record is one of these types:
page_view— you loaded a page.product_view— you loaded a product page.outbound_click— you clicked through to Etsy or eBay, including a buy-now button and the/etsycheckoutlink. This is our best signal for whether the site is actually sending anyone to buy something.social_click— you clicked a link to our Instagram, Facebook, TikTok, or Pinterest.nav_click— you clicked a link in the site navigation.scroll_depth— you scrolled a quarter, half, three-quarters, or all the way down a page, most useful on the build-sequence pages.js_error— a script on the page broke, so we can fix it.web_vital— a browser-reported speed measurement (load time, responsiveness, layout stability), the same metrics Google uses for page-experience ranking.not_found— you landed on a broken link, so we know to fix it.crawler_hit— a search or AI crawler (Googlebot, Bingbot, GPTBot, ClaudeBot, and others) fetched a page. This tells us which crawlers are reading the site, not who you are.
Every event, whatever its type, is stored as one row with these fields:
- ts — when it happened, in UTC.
- env — which deployment wrote the row (our live site, our staging copy, or an automated test), never anything about you.
- type — one of the event types listed above.
- path — the page you were on. Anything in it that looks like an email address, an order number, a token, or an id is blanked out before it’s ever written down.
- visitor_hash — a one-way hash that stands in for “the same visitor,” not your identity. How it works is its own section below, because it’s the part worth reading closely.
- device — the same coarse bucket as the scan log: bot, mobile-ios, mobile-android, mobile-other, desktop, or unknown.
- country and city — coarse location, read from our host’s edge network. Never a coordinate, never anything more precise than a city name.
- is_bot and bot_name — whether the request looked automated, and which crawler we think it was.
- referrer_class and referrer — how you arrived (organic search, social, direct, referral, or a link from elsewhere on this site), and the referring page itself if your browser sent one, redacted the same way as the path.
- utm_source, utm_medium, and utm_campaign — campaign tags from the link you followed, if it had any, redacted the same way.
- props_json — a few extra details specific to the event type: which product, which outbound destination, which button, which error message. Never anything that could identify you on its own — no email, no order number, no name.
How we count visitors without a cookie
To tell “one visitor looked at three pages” from “three visitors looked at one page each,” every event needs some stand-in for “the same visitor,” and we build that stand-in without ever writing anything to your browser. When a request reaches our server, we read your IP address and your browser’s User-Agent string, in memory, and run them through a one-way hash together with the day’s date and a secret key we control. The result is 16 characters of hex. The IP address and the User-Agent are never written to a log, a database row, or anywhere else — they exist only for the moment it takes to compute that hash, and then they’re gone.
That hash changes every day at midnight UTC. Practically, that means rows from the same visitor on the same day carry a matching visitor_hash and can be counted as one visit, while rows from tomorrow cannot be tied back to today’s. We are not going to tell you this makes every row unlinkable from every other row forever — it does not, on purpose, for exactly one day at a time, because that is what “count today’s unique visitors” requires.
This is honestly imperfect in both directions. Several people on the same office or carrier connection can hash to the same value, undercounting. A phone that rotates its IP address mid-visit, or a visit that happens to straddle midnight UTC, can hash to two different values, overcounting. We trust the trend this produces, not the exact number.
Said plainly, because it matters more than the mechanics: this hash is pseudonymised data, not anonymous data. It is derived from information that could, in principle, be linked back to a person, even though we never store the information itself and never try to make that link. We are not claiming this setup complies with any specific data protection law — we are telling you exactly what it does, so you can judge that for yourself.
What we deliberately do not collect
- No stored IP addresses. We read your IP address in memory, for the moment it takes to compute the visitor hash above, and never write it anywhere. An automated test fails the build if a raw IP address ever reaches a log row.
- No stored raw browser fingerprint. Your browser sends a detailed User-Agent string on every request. We read it the same way as the IP address, reduce it to a coarse device bucket and, for crawlers, a named bot, and throw the original away without storing it.
- No cookies, no localStorage, no sessionStorage on any page a visitor sees. The one exception, described next, is not a visitor-facing one.
- No third-party analytics, advertising, or tracking scripts. No Google Analytics, no Meta pixel, no Vercel Analytics. Every event described above is written by our own code to our own spreadsheet.
- No accounts, forms, or newsletter signups for visitors to this site.
- No payment or card data. Checkout never happens here.
The one cookie: our own login
The shop owner reads the analytics above on a private dashboard at /admin, behind a password. Logging in sets one cookie, and it is the only cookie this site ever sets, for anyone. It is first-party (set by shopbrickworks.us, read only by shopbrickworks.us), httpOnly (invisible to any script on the page), and expires after 12 hours. Its entire contents are a signed expiry timestamp — no name, no email, no password, no data about you, because the only fact it needs to carry is “the owner logged in before this time.” You will never receive this cookie unless you type the admin password yourself.
Other links that pass through this site
Besides the review QR codes, /etsycheckout forwards shoppers from Instagram and Facebook product tags to the matching Etsy listing, and buy-now buttons on product pages send you to Etsy or eBay directly. Both are recorded as an outbound_click event, described above. etsy.shopbrickworks.us, a shortcut address that sends anyone who visits it straight to our Etsy shop, is not currently instrumented and records nothing.
Who we share data with
- Google — scan rows and analytics rows are both appended to a private Google Sheet that only we can open, using a dedicated service account. Google stores it for us and does not use it for its own purposes.
- Vercel — our host. Like any web host, Vercel receives and briefly logs ordinary request information, including your IP address, in order to serve and protect the site. That is Vercel’s own infrastructure logging, kept for a short period, and it is separate from everything described above. We do not use Vercel Analytics or Speed Insights. See Vercel’s privacy policy at vercel.com.
- Etsy and eBay — they run the shops you buy from and hold your order under their own privacy policies. See the next section.
- Shipping carriers — the postal service or courier gets the name and address needed to deliver your parcel, because there is no other way to deliver a parcel.
- Nobody else. We do not sell, rent, or share this data, and we have no advertising or analytics partners.
If you buy from us
Orders are placed and paid for on Etsy or eBay, never on this site. Those marketplaces collect your payment and contact details under their own privacy policies and are responsible for them. We never see your card number.
Once a sale completes, the marketplace shows us the name, shipping address, and any note you sent, so we can build and post your order. We read that information in Etsy’s and eBay’s own systems and use it to pack, ship, and support the order. We do not copy it into a mailing list, a customer database, or a marketing tool, because we do not have any of those.
We do keep our own bookkeeping spreadsheet, and it is deliberately anonymous: one row per sale holding the date, product, quantity, amounts, fees, which marketplace, and the marketplace’s own receipt number. It records no buyer name, address, or email. The receipt number can be looked up inside Etsy or eBay by us, so it is a pointer into their records rather than a copy of them.
We will never message you off-platform to ask for a review or to sell you something. The QR code in your package is the only nudge we send, and it takes you to the marketplace’s own review page without telling us who you are.
How long we keep things
Neither the scan log nor the analytics log has an automatic expiry — rows stay in the private spreadsheet until we delete them by hand. We are telling you that plainly rather than implying a deletion schedule we do not run. Bookkeeping rows are kept as long as tax rules require, which in the United States generally means at least seven years — but those rows contain no buyer details, only amounts. The buyer details themselves live in Etsy’s and eBay’s systems, kept for as long as those companies keep them.
Do Not Track
We do not track visitors across other websites or over time, so a Do Not Track signal from your browser changes nothing about what we do — there is nothing here for it to switch off. We also allow no other party to collect information about your browsing through this site.
Children
This site is not directed at children under 13 and does not knowingly collect information from them. Nothing described on this page identifies a visitor by name, and we do not knowingly collect information that would.
Your rights
Depending on where you live, you may have the right to ask what personal information we hold about you, to correct it, to have it deleted, or to complain to your local data protection authority. For this website’s analytics and scan logs, the honest answer is that we hold a pseudonymised hash we cannot connect back to you ourselves, since we never stored the IP address or User-Agent it was built from. For an order, ask us and we will tell you exactly what we have and delete whatever we are not legally required to keep. Email brickworksteam@gmail.com and we will reply within 30 days. Requests about the data a marketplace holds should go to Etsy or eBay directly, since they hold it.
Changes to this policy
If we change what we collect, we will update this page and move the “last updated” date at the top. Material changes will be described here rather than made quietly.
Contact
Questions about any of this go to brickworksteam@gmail.com. A real person reads it.
LEGO® is a trademark of the LEGO Group, which does not sponsor, authorize, or endorse this site.