This policy explains what personal data stampit.store ("STAMP", "we") collects when you use the Service, why we collect it, who we share it with, and what rights you have over it. We try to keep this readable rather than legalese-heavy. Questions? Reach out through our contact form.
| Category | What it is | Why |
|---|---|---|
| Account | Email address, hashed password, sign-up timestamp, sign-up IP, browser fingerprint hash. | Authenticate you, prevent fraud / multi-account abuse. |
| Designs | Prompts you type, logos / images you upload, the AI-generated artwork, product + variant choices, design previews. | Generate the artwork, ship the order, let you re-open past designs from your gallery. |
| Orders & payments | Shipping address, contact email, contact phone (if provided), order line items, order status, payment-provider order ID. | Process the payment, manufacture and deliver the product, communicate about your order. |
| Usage analytics | Pages visited, time on page, referrer, device + browser type, anonymised IP. | Understand which features are used, improve the product. Only collected if you accept the cookie banner. |
| Communications | Emails you send us, support tickets. | Help you with what you wrote in. |
We do not store full payment-card numbers, CVVs or bank details. Card data is handled directly by our payment processor; we never see the card number.
We share your data only with carefully selected third-party processors that help us deliver the Service. We don't list each individual provider by name — we may swap or add providers from time to time as we improve the platform — but the categories below cover every external party that may receive your data:
Each processor we work with is bound by a data-processing agreement that limits how they may use your data. We do not sell your data, share it with advertisers, or use it to train any AI model of our own.
We use a small set of cookies and equivalents:
Your account, designs and order history live for as long as your account does. If you ask us to delete your account, we erase your account record and orphan your designs from any personal identifiers within 30 days, except where we're required to keep certain data (e.g. paid invoices for tax law, typically 5–10 years depending on jurisdiction).
Your account, design and order data is hosted on infrastructure located in the EU or the US, depending on the data-residency setting of the relevant processor. Payment data is processed on the global infrastructure of our payment provider. AI generation requests transit our AI provider's API endpoints. We don't transfer your data outside the processors covered by Section 2.
Depending on where you live (GDPR for EU/UK, KVKK for Turkey, CCPA for California, etc.), you have the right to:
To exercise any of these, send a request via our contact form using the email address on your account. We respond within 30 days.
The Service is for adults. If you believe a child has created an account, contact us and we will remove it.
We take reasonable technical measures to protect your data: HTTPS everywhere, password hashing (handled by Supabase Auth), least-privilege access to the database, and limited audit logs. No system is 100% secure though — if you suspect a breach, please tell us immediately.
If we change this policy materially we will notify you by email and update the "Last updated" date above. The version that applies to your account is the one in force when you most recently used the Service.
Reach out through our contact form.