1. Purpose and Scope
This Law Enforcement and Government Requests Policy explains how Storefront Labs, LLC (“Storefront”) receives, evaluates, and responds to subpoenas, search warrants, court orders, administrative demands, regulatory requests, preservation requests, emergency requests, and other legal process seeking customer, user, account, device, message, recording, location, integration, or operational information.
This policy is intended for law-enforcement agencies, regulators, courts, governmental authorities, customers, and other parties seeking information from Storefront.
2. Guiding Principles
Storefront’s response process is guided by the following principles:
- require valid legal authority before disclosing customer or user information;
- review requests for facial validity, jurisdiction, scope, specificity, and legal sufficiency;
- disclose only information reasonably responsive to a valid request;
- notify affected customers where legally permitted and appropriate;
- challenge or seek clarification of requests that are overbroad, unlawful, vague, or inconsistent with applicable law;
- protect privacy, security, confidentiality, and the rights of customers and users; and
- preserve the integrity of investigations and comply with lawful nondisclosure obligations.
3. Service of Legal Process
Legal process directed to Storefront should be addressed to:
Storefront Labs, LLC
Attn: Legal Process
1642 Burgos Dr
Sarasota, FL 34238
United States
Email copies may be sent to hello@storefrontworks.com. Email alone does not constitute valid service unless Storefront expressly agrees in writing or applicable law permits electronic service.
Storefront may require formal service through a registered agent, court-approved method, certified mail, personal service, or another legally valid channel.
4. Request Requirements
Requests should include:
- the requesting agency, authority, officer, attorney, or representative;
- contact information and official credentials;
- the legal authority relied upon;
- the Storefront account, customer, user, device, location, email address, phone number, identifier, or other target information;
- the specific categories of information sought;
- the relevant date range;
- the jurisdiction and matter number;
- the required response date;
- any nondisclosure requirement and its legal basis; and
- a certification that the request is complete, accurate, and lawfully issued.
Requests should be narrowly tailored. Broad requests for “all data,” unspecified future data, unrelated accounts, or information outside Storefront’s possession, custody, or control may be rejected or require clarification.
5. Review and Validation
Storefront may verify the identity and authority of the requester and may consult legal counsel before responding.
Storefront may reject, challenge, narrow, delay, or seek clarification of requests that:
- are not properly served;
- lack jurisdiction over Storefront or the requested data;
- do not identify the target with reasonable specificity;
- seek information beyond the scope of the cited authority;
- conflict with applicable privacy, communications, surveillance, or data-protection law;
- are technically impossible, unduly burdensome, or disproportionate;
- seek privileged, confidential, or protected information; or
- appear fraudulent, abusive, or unauthorized.
6. Scope Limitation and Data Minimization
Where disclosure is legally required, Storefront will use reasonable efforts to produce only information responsive to the valid request.
Storefront may redact unrelated information, withhold privileged material, separate customer-controlled data from Storefront business records, and use technical or legal means to narrow disclosure.
Storefront is not obligated to create new records, reconstruct deleted data, develop custom software, decrypt information it cannot decrypt, or provide information outside its possession, custody, or control unless applicable law requires otherwise.
7. Customer Notice
Storefront’s policy is to notify the affected customer before disclosure where legally permitted and reasonably practicable so the customer may seek protective relief or respond directly.
Notice may be delayed or withheld when:
- prohibited by law, court order, or binding nondisclosure requirement;
- Storefront reasonably believes notice would create an imminent risk of death, serious physical harm, destruction of evidence, flight, or material interference with an investigation;
- the request concerns Storefront’s own systems, employees, fraud prevention, security, or legal compliance;
- the customer is the subject of the investigation and notice is legally restricted; or
- providing notice is not reasonably possible.
When a nondisclosure restriction expires or is withdrawn, Storefront may provide delayed notice where lawful and appropriate.
8. Emergency Requests
Storefront may voluntarily disclose limited information where permitted by law and where Storefront reasonably believes an emergency involving imminent danger of death or serious physical injury requires immediate disclosure.
Emergency requests should include:
- the nature of the emergency;
- the person or persons at risk;
- the specific information requested;
- why the information is necessary to address the emergency;
- why ordinary legal process cannot be obtained in time;
- the requesting official’s identity, agency, and contact information; and
- a certification of accuracy and lawful authority.
9. Preservation Requests
Storefront may preserve existing records in response to a valid preservation request while the requester obtains appropriate legal process.
Preservation requests must identify the target, categories of data, relevant time period, legal authority, requesting agency, and duration of preservation.
Preservation does not guarantee that requested information exists, is complete, can be restored, or will be disclosed without valid legal process.
10. International Requests
Requests from authorities outside the United States must comply with applicable international legal processes, treaties, mutual legal assistance procedures, letters rogatory, executive agreements, or other legally recognized mechanisms.
Storefront may require foreign authorities to work through United States authorities or another competent jurisdiction before producing data.
Storefront will consider applicable international privacy, data-protection, transfer, secrecy, communications, and human-rights obligations.
11. Cost Reimbursement
Storefront may seek reimbursement of reasonable costs associated with locating, reviewing, preserving, processing, redacting, authenticating, and producing records, to the extent permitted by law.
Unusually burdensome, technically complex, expedited, or repeated requests may require advance agreement on scope, timing, format, and cost.
12. Prohibited or Unsupported Requests
Storefront does not support requests for:
- prospective or continuous surveillance without lawful authority;
- direct government access to Storefront systems;
- encryption keys or credentials not possessed or controlled by Storefront;
- data from independent third-party platforms not controlled by Storefront;
- customer devices or local systems outside Storefront’s control;
- information beyond Storefront’s retention period or technical ability to recover;
- content moderation or account action based solely on informal government preference; or
- requests that would require Storefront to violate applicable law.
13. Transparency
Storefront may publish aggregate transparency information concerning government requests, legal demands, disclosures, or challenges, subject to legal restrictions, operational feasibility, and the need to protect investigations, customers, users, and security.
Storefront may also publish general guidelines, update this policy, or disclose material legal positions where appropriate.
14. Customer Responsibilities
Customers remain responsible for responding to legal requests directed to them and for determining whether they must preserve or disclose information under their control.
Storefront may refer a requester to the customer where the customer is the appropriate data controller, business, records custodian, or recipient of process.
Customers should preserve their own records when litigation, investigation, legal hold, or regulatory obligations apply.
15. Retention and Availability
Storefront retains information in accordance with its Data Retention and Deletion Policy, customer configuration, operational needs, applicable agreements, and law.
Storefront cannot produce information that has been deleted, overwritten, never collected, not retained, or is outside Storefront’s possession, custody, or control.
Messages, recordings, logs, device data, location data, and other records may have different retention periods and may not be available indefinitely.
16. Secure Production
Storefront may require secure transmission methods, encryption, authenticated portals, password-protected files, chain-of-custody procedures, or other safeguards for sensitive productions.
Requesters are responsible for protecting information after receipt and for complying with applicable confidentiality, evidence, privacy, and security requirements.
17. Changes to This Policy
Storefront may update this policy to reflect changes in law, legal process, technology, products, security practices, and operational requirements. The current version will be identified by its effective date.
18. Contact Information
Storefront Labs, LLC
Attn: Legal Process
1642 Burgos Dr
Sarasota, FL 34238
United States
Email: hello@storefrontworks.com
Website: www.storefrontworks.com
This policy does not constitute legal advice, consent to jurisdiction, waiver of service requirements, or an agreement to accept legal process by email.