Legal
What we collect, why we need it, and who else sees it. Written plainly, because a policy you cannot read is not consent.
This policy applies to Veyra and to everything you do on this site โ browsing the encyclopedia, building a design in the studio, and placing an order. It was last reviewed on 9 August 2026.
Only what an order needs to reach you. When you check out we store:
Two other things create a record, and neither is part of checkout:
We never see or store your card number or PayPal password. Card or PayPal account details are handled by the payment provider and never touch our server โ see Who else sees your data.
Each field above exists because a specific step fails without it: we cannot string a bracelet without the design, cannot ship it without the address, cannot confirm it without the email, and cannot pass a customs form without a contact number. We do not collect anything speculatively in case it becomes useful later.
The legal basis, where that framing applies to you, is performance of the contract you enter when you place the order โ plus our legitimate interest in keeping records of completed sales for accounting and dispute handling.
One cookie holds your session so that the design you are building survives a page reload and so your basket is still there when you come back from payment. It expires seven days after your last visit and cannot be read by JavaScript.
We also use two random identifiers stored in your browser to understand where people leave the design and checkout flow. They are not your name, email, address, phone number, design details or payment data. We retain these anonymous event records for 90 days and use them only to improve this site.
There is no Google Analytics, Meta Pixel, TikTok Pixel, advertising retargeting or sale of visitor data on this site. Payment success is confirmed by Stripe or PayPal on our server, not by tracking your payment details.
Three companies, each for one job, and neither gets more than that job needs.
Our site and database are hosted on Render, which stores the data on our behalf but does not use it. Beyond these, we do not sell, rent, trade or share your personal data with anyone. There is no data broker in this chain.
This is a cross-border business, so your data crosses borders: our hosting, our payment processor and our fulfilment are not all in your country. Where your local law requires safeguards for that transfer, we rely on our providers' standard contractual terms. If you would rather not have your data leave your region, the honest answer is that we cannot ship to you without it.
Session data, including an unfinished design that never reached checkout, expires seven days after your last visit and carries no contact details. Order records we keep for as long as accounting, tax and dispute windows require โ a paid order is a financial record, and deleting it the moment it ships would leave us unable to honour a return or answer a chargeback.
Unpaid test and abandoned orders may be removed from our order records.
Sign-in links expire 30 minutes after we send them and are single-use. A linked email address is kept until you ask us to remove it; deleting it does not delete your designs, it only unlinks them from you.
Wherever you are, you can ask us to:
If you are in the UK, EU, or another region with equivalent law, these are statutory rights and you also have the right to complain to your local data protection authority. We would rather you came to us first.
Ask through the contact form or by email at veyrabeads.support@gmail.com. Include your order number if you have one โ it is how we find you without asking for more personal data than we already hold.
The whole site runs over HTTPS, so what you type reaches us encrypted. Your order page requires its private token; if needed, you can recover it through Track Order using the order number and checkout email. These pages are excluded from search engines. Card data never reaches our server, which means it cannot be exposed from it.
No system is beyond reach. If a breach ever affected your data, we would tell you rather than wait for you to find out.
This site is not intended for children under 13, and we do not knowingly collect their data. If a child's details have been submitted, contact us and we will delete them.
If our data practices change โ a new processor, a new field at checkout โ this page changes with them and the review date at the top moves. We will not quietly widen what we collect and leave the old policy standing.
Anything here that is not clear enough: ask us. Related reading: Terms of Service and Shipping & Returns.