Legal

Privacy Policy

What we collect, why we need it, and who else sees it. Written plainly, because a policy you cannot read is not consent.

Who this covers

This policy applies to Veyra and to everything you do on this site โ€” browsing the encyclopedia, building a design in the studio, and placing an order. It was last reviewed on 9 August 2026.

What we collect

Only what an order needs to reach you. When you check out we store:

  • Your name and delivery address โ€” street, optional second line, city, state or region, postcode and country.
  • Your phone number โ€” carriers ask for one on cross-border parcels.
  • Your email address โ€” where the order confirmation and the tracking link go.
  • Any note you add to the order, if you write one.
  • Your design โ€” the stones you picked, their order, the bead sizes and your wrist measurement. This is the instruction sheet the bracelet is strung from, so we keep it with the order.

Two other things create a record, and neither is part of checkout:

  • If you write to us through the contact form, we keep the name, email address, order number and message you typed, so we can answer you and find the thread again later.
  • If you save or share a design, the stones and wrist size behind that link are stored on their own. That record holds no name, address or email โ€” anyone with the link sees only the bracelet.
  • If you choose to keep your designs by linking an email address, we store that address and the list of designs you link to it. There is no password: signing in means clicking a one-time link we email you, and we keep only a one-way hash of that link, never the link itself. An account is entirely optional โ€” designing, saving and ordering all work without one.

We never see or store your card number or PayPal password. Card or PayPal account details are handled by the payment provider and never touch our server โ€” see Who else sees your data.

Why we need it

Each field above exists because a specific step fails without it: we cannot string a bracelet without the design, cannot ship it without the address, cannot confirm it without the email, and cannot pass a customs form without a contact number. We do not collect anything speculatively in case it becomes useful later.

The legal basis, where that framing applies to you, is performance of the contract you enter when you place the order โ€” plus our legitimate interest in keeping records of completed sales for accounting and dispute handling.

Cookies and conversion measurement

One cookie holds your session so that the design you are building survives a page reload and so your basket is still there when you come back from payment. It expires seven days after your last visit and cannot be read by JavaScript.

We also use two random identifiers stored in your browser to understand where people leave the design and checkout flow. They are not your name, email, address, phone number, design details or payment data. We retain these anonymous event records for 90 days and use them only to improve this site.

There is no Google Analytics, Meta Pixel, TikTok Pixel, advertising retargeting or sale of visitor data on this site. Payment success is confirmed by Stripe or PayPal on our server, not by tracking your payment details.

Who else sees your data

Three companies, each for one job, and neither gets more than that job needs.

  • Stripe โ€” takes card payments. Stripe receives your email address, the amount, and an internal order reference. Your shipping address is not sent to Stripe. Your card details go directly to Stripe and are governed by their privacy policy.
  • PayPal โ€” takes PayPal payments. PayPal receives the order amount, order reference and the shipping details needed to process and deliver a physical-goods order. Your PayPal password and funding details are handled by PayPal and never touch our server. PayPal's own privacy policy applies to that processing.
  • DeepSeek โ€” writes the optional crystal readings. For a bracelet energy reading it receives the stone names and their traditional associations. For the Lucky Stone tool it receives the name you enter (if any), your birthday month and day, your zodiac sign, and the suggested stones. It receives no address, email, phone number, payment data or order number. The name and birthday used by Lucky Stone are not written to our order database. If the service is unavailable, the reading is written by our own code instead.

Our site and database are hosted on Render, which stores the data on our behalf but does not use it. Beyond these, we do not sell, rent, trade or share your personal data with anyone. There is no data broker in this chain.

Where your data goes

This is a cross-border business, so your data crosses borders: our hosting, our payment processor and our fulfilment are not all in your country. Where your local law requires safeguards for that transfer, we rely on our providers' standard contractual terms. If you would rather not have your data leave your region, the honest answer is that we cannot ship to you without it.

How long we keep it

Session data, including an unfinished design that never reached checkout, expires seven days after your last visit and carries no contact details. Order records we keep for as long as accounting, tax and dispute windows require โ€” a paid order is a financial record, and deleting it the moment it ships would leave us unable to honour a return or answer a chargeback.

Unpaid test and abandoned orders may be removed from our order records.

Sign-in links expire 30 minutes after we send them and are single-use. A linked email address is kept until you ask us to remove it; deleting it does not delete your designs, it only unlinks them from you.

Your rights

Wherever you are, you can ask us to:

  • Show you the data we hold on you.
  • Correct it โ€” a mistyped address is worth fixing fast, before the parcel leaves.
  • Delete it, once no order is still open and no accounting or dispute window still applies to it.
  • Export it in a portable form.
  • Object to a particular use of it.

If you are in the UK, EU, or another region with equivalent law, these are statutory rights and you also have the right to complain to your local data protection authority. We would rather you came to us first.

Ask through the contact form or by email at veyrabeads.support@gmail.com. Include your order number if you have one โ€” it is how we find you without asking for more personal data than we already hold.

How it is protected

The whole site runs over HTTPS, so what you type reaches us encrypted. Your order page requires its private token; if needed, you can recover it through Track Order using the order number and checkout email. These pages are excluded from search engines. Card data never reaches our server, which means it cannot be exposed from it.

No system is beyond reach. If a breach ever affected your data, we would tell you rather than wait for you to find out.

Children

This site is not intended for children under 13, and we do not knowingly collect their data. If a child's details have been submitted, contact us and we will delete them.

Changes to this policy

If our data practices change โ€” a new processor, a new field at checkout โ€” this page changes with them and the review date at the top moves. We will not quietly widen what we collect and leave the old policy standing.

Anything here that is not clear enough: ask us. Related reading: Terms of Service and Shipping & Returns.