Policies

Privacy

What this shop stores about you, why, and for how long.

This document is not finished. The gaps marked below are facts only the operator of the shop can supply, and it must not be published until they are filled in.

This notice describes what actually happens in the software, not what a template says usually happens. Where it says the shop does not do something, the shop does not do it.

Who is responsible

The controller for this data is  . Contact:  .

What is stored, and why

Your account
Email address, an optional name, and your password — hashed with scrypt, never stored in a form we can read. Needed to give you an account at all.
Sessions
A random token, hashed, plus the browser and IP the session was started from. Needed to keep you signed in and to let you see where you are signed in.
Orders
What you ordered, what it cost, the delivery address, and the design each pack turned out to contain. Needed to fulfil the order, and kept afterwards because tax law requires it.
Addresses
The addresses you save for next time. Yours to add, edit and delete at any point.
Cart
What is in your cart, against a random token in a cookie. Deleted automatically once it has been abandoned for thirty days.
Email we send you
The messages the shop has sent you, stored as they were sent so support can see exactly what you received.
Rate limiting
A counter against your IP address and, on sign-in, your email address. Needed to stop somebody guessing passwords. Cleared automatically.
Waiting list
Your email address and the language you signed up in — only once you have confirmed it by clicking the link we send.

Cookies

Two, both strictly necessary, both containing nothing but a random token: one for your session and one for your cart. There is no analytics, no advertising, no tracking pixel and no third-party script anywhere on this site, which is why you are not being asked to consent to any.

Who else sees it

Nobody, beyond the people who have to:   hosts the shop, and the carrier gets the delivery address so it can deliver. There is no advertising network, no data broker and no sale of anything to anybody.

How long it is kept

  • Orders and invoices: as long as tax law requires, then deleted.
  • Account, addresses and saved details: until you delete them or close the account.
  • Sessions: until they expire, or until you sign out.
  • Carts: thirty days after they are abandoned.
  • Rate-limit counters: a day.

What you can ask for

A copy of everything held about you; correction of anything wrong; deletion, except where an order has to be kept for tax; a machine-readable export; an objection to processing; and a complaint to your data protection authority. Ask by email and we will answer.

Security

Passwords are hashed with scrypt at parameters chosen to be slow on purpose. Session and reset tokens are stored only as hashes, so a copy of the database hands nobody a way in. Every form that changes something checks where the request came from. Sign-in and password reset are rate limited by address and by account.

Fill in the controller, the contact address, the hosting provider and — if you appoint one — the data protection officer. Add the carrier by name once it is chosen.