Skip to content

STORE PRIVACY / REVIEW DRAFT

Privacy without the fog.

What the Store knows, why it needs it, and how to ask us to stop.

THE SHORT VERSION

Only what the Store needs

We use the minimum data needed to remember a cart, run an account or order, answer a message, and send a service alert you requested. General marketing requires a separate choice.

01 / THE DATA

What the Store may know

While you browse, the Store may use an essential cart or session identifier, your selected Store country or region, product choices, and limited technical or security logs needed to keep the service working.

If you create an account, contact us, request an availability alert, or place an order when sales are enabled, the Store may process your email and the details needed for that action. Depending on what you choose to do, those details can include a name, delivery address, phone number, product and size, message content, and order, payment, delivery, or refund references. Password credentials are handled by the authentication service; we do not ask you to send a password by email.

02 / THE PURPOSE

Why we use it

The data is used to keep your cart, provide account access, process the exact request or order you make, send related service emails, deliver support, prevent duplicate actions, and protect the Store from abuse.

An account, order, contact message, or availability-alert email does not by itself enrol you in a general newsletter. Any future marketing subscription must be a separate, clear choice. Selling personal data is not part of the current Store design.

03 / THE SERVICES

Who helps run the Store

Vercel serves the Storefront. Railway runs the self-hosted Medusa service and database. Resend is planned to deliver service emails through the Store's existing SMTP notification provider. Cloudflare R2 may deliver product or brand media.

A payment or delivery provider will be identified where that service is actually offered. Final provider contracts, regions, technical-log fields, transfer safeguards, and retention settings remain a launch gate for this review draft.

04 / THE CLOCK

How long it stays

We do not intend to keep every record forever. Each Store feature needs an approved retention rule. An availability alert is planned to expire after 120 days. After notification, cancellation, expiry, or permanent delivery failure, its email, email hash, and cancellation-token data enter a 30-day retention period and are removed by the next scheduled cleanup.

Final schedules for accounts, carts, orders, support messages, security logs, provider logs, and backups must be approved and stated here before this notice becomes effective. Records that must be kept for tax, accounting, disputes, or legal obligations may follow a longer applicable period.

05 / YOUR CONTROL

See it, change it, end it

Account details can be reviewed or changed through the Store where that control is available. Availability alerts include a direct cancellation route. You can also ask about access, correction, deletion, or another right available in your market through the contact below.

Before activation, the controller identity, applicable laws and markets, request-verification process, response timing, deletion workflow, and complaint route must be approved. Until then, this page remains a noindex review draft.

PRIVACY CONTACT

A human route, before launch

The public contact below must be verified as monitored before this notice becomes effective. Do not send passwords or payment-card details by email.

Email hello@ihatemyex.help