01
The short version
- We collect what an order needs and almost nothing else: your name, email, phone, delivery address and what you bought.
- We run no analytics and no advertising trackers. There is no Google Analytics, no Meta pixel and no session recorder on this site, and nothing here follows you around the web. The only cookie we set keeps you signed in; the only other one you will meet is Razorpay’s, during payment, and clause 5 covers both. Nobody is building a profile of you here.
- We never see your payment details. Card numbers, UPI IDs and bank credentials go straight to Razorpay and never touch our servers.
- Your address goes to the people who make and deliver the piece, because that is the only way it can reach you.
- You can have your account and your personal data deleted by writing to adonai.reserve@gmail.com.
02
What we collect, and why
- Account
- Your name, email address and phone number, and a password you set. The password is stored only as a bcrypt hash, a one-way scramble. We cannot read it, recover it or tell you what it is, and neither can anyone who obtains the database.
- Addresses
- The billing and delivery addresses you save or enter at checkout: name, street, city, state, postcode, country and phone. Needed to quote shipping and to get the parcel to you.
- Orders
- What you bought, in which size, what it cost, which delivery service you chose, the delivery address for that order, its status, and any tracking number and carrier. Kept as the record of the sale.
- Payment references
- The identifiers Razorpay gives an order and a payment, whether it succeeded, and when. These are references to a transaction, not a means of making one.
- Inner Circle
- Only if you join from the footer: your email address, when you joined, and when you left. Used for Inner Circle mail and nothing else. Every message carries a link to leave, and leaving takes effect at once.
- Sessions
- For each device you sign in on: the IP address and browser user-agent at sign-in, when it was created, when it was last used and when it expires. This is what expires a stale sign-in on its own, what lets changing your password sign out every other device, and what makes a stolen session detectable.
That is the whole of it. We do not ask for a date of birth, a gender, an occupation or any of the other fields a shop collects because a form template had a slot for them.
03
What we do not collect
No card details, ever
We also do not run behavioural analytics, advertising pixels, heat-mapping or session replay, and we do not buy, sell, rent or enrich customer data. This site sets no third-party cookie of any kind.
04
Who else receives it
Three companies are involved in getting a piece to you, and each receives the part of your data its job requires. They are named rather than described as “trusted partners”, because you are entitled to know who holds your home address:
- Printify
- Recipient name, delivery address, phone number, and the items ordered. Printify passes these to the print provider that makes the piece and to the carrier that delivers it.Printify privacy policy ↗
- Razorpay
- Billing name, email address, phone number, and the order amount. Card, UPI and bank details are entered on Razorpay's own hosted form and are never transmitted to or stored by us.Razorpay privacy policy ↗
- Render
- Everything stored by the shop, as the infrastructure it runs on. Account records, order records and session records sit in a managed database operated by Render.Render privacy policy ↗
- Your email address and the emails we send you: order confirmations, and Inner Circle mail if you joined it. Sent through Google's Gmail service.Google privacy policy ↗
Beyond these, we disclose data only where the law requires it (a court order, a tax authority, or a lawful request we are obliged to answer) and to professional advisers bound by confidentiality. If the business is ever sold or transferred, customer records may pass to the buyer, who would be bound by this policy.
05
Cookies
This site uses cookies for one purpose: keeping you signed in. There is no cookie banner because there is nothing here that a banner would need to ask you about. No tracking, no profiling, no advertising.
- adonai_rt
- The sign-in cookie. It holds a refresh token that lets your browser get a new access token without making you log in again on every visit. It is HTTP-only, so no script on the page can read it, and it is marked Secure in production so it only travels over HTTPS. It lasts 30 days, and signing out deletes it.
- Razorpay's cookies
- Set by Razorpay’s payment form during checkout, under their own domain and their own policy, for fraud prevention and to keep the payment session working. We cannot read them. Razorpay privacy policy ↗
Your browser can block or clear either. Blocking the sign-in cookie means you cannot stay signed in, and so cannot check out.
06
Where your data is held
The shop’s database and servers are operated by Render. Our production partner and our payment provider process data in their own locations, and the business itself is established in India.
In practice this means that if you order from the United States, your delivery details cross borders: to the business in India, and to whichever print facility and carrier is closest to you. That is inherent in buying from abroad, and we mention it because a policy that quietly omits it is hiding the obvious.
07
How long it is kept
- Account data
- For as long as your account exists. Ask us to delete it and it goes, subject to the order records below.
- Order records
- Kept after an account is deleted, for as long as tax and accounting law requires a seller to be able to evidence a sale. These are the record of a transaction that happened; they are not something either of us can simply erase.
- Inner Circle
- Kept while you are in it. When you leave, the address stays only as a record that you left, so you are never mailed again. Ask and we will delete it outright.
- Sessions
- Expire on their own, and are removed when they do or when you sign out or revoke the device.
08
Your rights
Wherever you live, and whatever framework applies to you, we will honour the following. Write to adonai.reserve@gmail.com from the email address on the account and we will answer within 2 business days.
- See it. A copy of everything held about you.
- Correct it. Most of it you can edit yourself in your profile; anything you cannot, we will.
- Delete it. Your account and its personal data, except the order records clause 7 explains we must keep.
- Take it with you. Your data in a machine-readable file.
- Object. Tell us to stop processing it, or to stop sending you anything you signed up for. Note that this does not stop the order confirmation we send when you pay, or the despatch notification our production partner sends when a parcel you have ordered is handed to the carrier. Those are part of fulfilling the order, not marketing: they are the record of what you bought and where your parcel is.
California residents: we do not sell or share personal information as those terms are defined under the CCPA, and we do not offer financial incentives in exchange for personal information. The rights above cover the access and deletion rights that statute provides.
09
Security
Concretely, and only what is actually true of this system:
- Everything moves over HTTPS. There is no unencrypted route into the shop.
- Passwords are stored as bcrypt hashes at a deliberately slow cost factor, never as text and never reversibly encrypted.
- Sign-in uses short-lived access tokens with rotating refresh tokens, so a token captured once cannot be replayed indefinitely, and reuse of an old one is detectable.
- The sign-in cookie is HTTP-only and, in production, Secure. It cannot be read by a script and will not travel over plain HTTP.
- No payment credential is stored, because none is ever received.
No system is perfect, and a policy that claimed otherwise would be the least trustworthy sentence on this page. If we ever discover a breach affecting your data, we will tell you and the relevant authority as the law requires.
10
Children
This shop is not directed at children. We do not knowingly collect data from anyone under 16, and an account may only be created by someone 18 or over. If you believe a child has given us data, write to adonai.reserve@gmail.com and we will delete it.
11
Changes, and how to reach us
If this policy changes, the revised version appears here with a new effective date at the top of the page. The date is what tells you whether it has moved since you last read it, which is why it is set by hand rather than by the build. It marks a change in the text, not a deploy.
Questions, requests and complaints about privacy all go to the same place: adonai.reserve@gmail.com. Full contact details are on the Contact Us page.