Legal
Privacy Policy
What we collect, why we collect it, who else touches it, and what you can ask us to do with it.
Last updated: July 22, 2026
Who we are
DreamSilkyStudio ("we", "us") operates this online store, selling digital products and made-to-order physical goods. We are the data controller for the personal information described in this policy.
Questions about privacy or your data can go to hello@dreamsilkystudio.com. [[Add your registered legal entity name and business address here.]]
What we collect
We collect only what an order or an account actually requires. In practice that is:
- Order details — the items purchased, amounts, and your order history.
- Contact details — the email address you check out with, so we can send receipts and download links.
- Delivery details — name and postal address, collected only when an order contains a physical item.
- Account details — if you create an account, your email and an encrypted authentication record. We never see or store your password.
- Payment details — handled entirely by Stripe. Card numbers never reach our servers; we retain only a payment reference and the last four digits.
- Technical data — IP address and browser user-agent, recorded when a download link is used, to enforce download limits and detect abuse.
- Analytics data — only if analytics is enabled on this deployment; see the Analytics section.
Why we use it
Each piece of data maps to a specific purpose:
- To take payment and deliver what you bought — including sending files and passing shipping details to the print provider that makes your item.
- To provide customer support and answer questions about your order.
- To maintain your account, order history and download library.
- To protect the store — rate limiting, fraud prevention and enforcing download entitlements.
- To send marketing email, only if you explicitly opted in. Every message carries an unsubscribe link.
Who processes your data
We use a small number of service providers. Each receives only what it needs to do its job, and none of them are permitted to use your data for their own purposes.
- Stripe — payment processing. Receives your payment and billing details directly.
- Supabase — database, authentication and file storage for the store.
- Print-on-demand providers (Printify, Printful, Gelato, or another connected provider) — receive the name, address and item details needed to produce and ship a physical order. They receive nothing for digital-only orders.
- Resend — transactional email delivery (receipts, download links, order updates).
- Our hosting provider — serves the site and processes requests.
- Analytics providers — only those enabled on this deployment.
Cookies and analytics
The store itself uses a small number of strictly necessary cookies — keeping you signed in and holding your cart. These cannot be switched off without breaking the site.
Beyond that, this deployment may load analytics or advertising tags (Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, Microsoft Clarity). Each is optional and loads only when configured. Where they are active they set their own cookies and may build a profile of your visit.
[[If you sell into the EU or UK and enable any of these, you must obtain consent before they load, and list here exactly which ones you use.]]
How long we keep it
Order and payment records are retained for as long as tax and accounting law requires — commonly six to seven years. [[Confirm the exact period for your jurisdiction.]]
Account data is kept until you delete your account. Download entitlements expire on their own schedule but the purchase record remains part of your order history.
Marketing consent is kept until you withdraw it.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access — request a copy of what we hold about you.
- Correction — have inaccurate details fixed. Most can be edited yourself under Account settings.
- Deletion — ask us to erase your data, subject to records we are legally required to keep.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests, and opt out of marketing at any time.
How we protect it
Traffic is encrypted in transit over HTTPS. Database access is restricted by row-level security so customers can only reach their own records. Administrative access is limited to authorised accounts.
Payment credentials never touch our infrastructure. Third-party provider API keys are encrypted at rest using AES-256-GCM.
No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the relevant regulator as the law requires.
Children
This store is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
If this policy changes materially we will update the date at the top and, where the change affects how we use your data, tell you directly.
Questions? Write to hello@dreamsilkystudio.com.