Privacy Policy
We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we handle your data.
What data do we collect?
We collect and store the personal data you enter during the checkout process, including:
- Your name
- Email address
- Shipping address
- Payment information
How do we use your data?
We only use your data to fulfill your orders. We do not share your data with unnecessary third parties or use it for marketing purposes.
Shipping and Logistics: We use EasyPost as our shipping infrastructure provider. When you check out, your name, shipping address, and order dimensions are securely passed to EasyPost solely to calculate shipping rates and generate delivery labels with our partner carriers (such as USPS or UPS). EasyPost and its partner carriers only use this data to fulfill your delivery, in accordance with the EasyPost Privacy Policy.
Payments: We use Stripe as our payment processor. We do not store your credit card or financial information on our servers. When you pay for an order, your payment information, name, and billing details are passed directly to Stripe. Stripe uses this data to process your transaction, prevent fraudulent transactions, and comply with financial regulations. You can view how Stripe manages your data in the Stripe Privacy Policy.
How long do we keep your data?
We keep order history and sales receipts for tax/accounting purposes for a minimum of 7 years as required by law. If you request deletion before this time, we will remove your contact information from our database but we will retain anonymized financial records to meet our tax reporting obligations.
Your rights
You have the following rights regarding your personal data:
- Right to be Informed: You have the right to know what data we collect and how we use it (see above)
- Right of Access: You can ask us for a copy of the personal data we hold about you
- Right to Rectification: If we have your address or name misspelled, you can tell us to fix it
- Right to Erasure (Right To Be Forgotten/RTBF): You can ask us to delete your data, except where we are required by law to retain it
- Right to Restrict Processing: You can ask us to stop using your data for certain things while we resolve a dispute
- Right to Data Portability: You can request a digital copy of the data you gave us so you can take it elsewhere
- Right to Object: You can object to us processing your data based on our legitimate business interests
You may contact us at [email protected] to request deletion of your data and we will handle it within 30 days (unless we are legally required to retain it, e.g. for tax purposes).