privacy

Privacy Policy

Last updated

Who we are

Chismis Archive ("we", "us", "our") is the controller of personal data you provide through this website. Contact: [email protected].

What we collect

  • Account data: email, display name, marketing preferences.
  • Order data: shipping/billing addresses, phone (optional), order history.
  • Payment data: processed by our hosted checkout — we never see card numbers.
  • Technical data: IP address, browser, anonymous usage analytics (Plausible — no cookies).

Why we use it

  • To process and ship your orders (legal basis: contract).
  • To send transactional emails — order confirmation, shipping (legal basis: contract).
  • To send marketing emails, only if you opt in (legal basis: consent — withdrawable any time).
  • To detect fraud and protect our service (legal basis: legitimate interest).
  • To meet tax and accounting obligations (legal basis: legal obligation).

Who sees your data

A short list of sub-processors:

  • Our commerce platform — order processing, payments, customer accounts.
  • Postmark — transactional email.
  • Cloudflare — CDN, WAF, R2 storage.
  • Fly.io — application hosting (London region).
  • Sentry — error monitoring (request bodies are scrubbed).

Your rights

You can:

  • Download your data (we email a ZIP, link valid 24h).
  • Delete your account (anonymised after a 30-day grace period; order rows retained for tax compliance).
  • Toggle marketing emails on or off at any time on your profile.
  • Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).

How long we keep it

Account data: until you request deletion. Order data: 7 years (UK tax requirement), but anonymised once your account is deleted.