Privacy Policy
Last updated: March 2026
Your privacy matters. We collect only what we need to fulfill your orders and improve your experience. We never sell your personal data — period.
1. Who We Are
Snoutique ("we," "us," or "our") operates the website at snoutique.shop (the "Site"). This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit the Site, create an account, place an order, or interact with us in any way.
By using the Site, you agree to the practices described in this Privacy Policy. This policy is incorporated into our Terms of Service.
2. Information We Collect
Information You Provide Directly
- Account information: name, email address, and avatar URL (when you sign up via email or Google OAuth)
- Shipping information: full name, street address, city, state, ZIP code, and country (provided at checkout or saved to your account)
- Order details: product selections, customization choices (such as design, color, size, and personalization text), and quantities
- Newsletter subscription: email address (when you subscribe to our newsletter)
- Stock notifications: email address and product preferences (when you sign up for back-in-stock alerts)
- Support communications: any information you include when contacting us via email
Information Collected Automatically
- Usage data: anonymous page views, referral sources, and browsing patterns collected through Vercel Analytics (no personally identifiable information)
- IP address: used temporarily for rate limiting and fraud prevention; not stored long-term
- Error data: technical error information (browser type, device type, error messages) collected through Sentry for debugging purposes — this may include order IDs but does not intentionally capture personal information
Information We Do NOT Collect
- Payment information: credit card numbers, bank account details, and other financial data are processed exclusively by PayPal. We never see, store, or have access to your full payment details. We only receive a transaction ID and payment confirmation from PayPal.
3. How We Use Your Information
We use your personal information for the following purposes:
- Order fulfillment: processing your order, submitting it to our production partner, and arranging shipping
- Transactional communications: sending order confirmations, shipping notifications with tracking information, and delivery updates
- Customer support: responding to inquiries, processing returns and refund requests
- Account management: maintaining your account, saved addresses, and coupon assignments
- Marketing: sending promotional emails, new product announcements, and exclusive offers — only if you have subscribed to our newsletter (you can unsubscribe at any time)
- Stock alerts: notifying you when a product you requested is back in stock
- Site improvement: analyzing anonymous usage data to improve our website, products, and customer experience
- Security and fraud prevention: rate limiting, detecting suspicious activity, and protecting against unauthorized access
Legal Basis for Processing
We process your personal information on the following legal grounds:
- Contractual necessity: to fulfill orders you place and manage your account
- Consent: for marketing emails and newsletter subscriptions (which you can withdraw at any time)
- Legitimate interest: for fraud prevention, site security, analytics, and improving our services
- Legal obligation: for maintaining order and tax records as required by law
4. Data Sharing and Third-Party Services
We share your personal information only with third parties that are necessary for operating the Site and fulfilling your orders. We never sell, rent, or trade your personal information.
We may also disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Snoutique, our customers, or others.
5. Cookies and Local Storage
We use the following cookies and browser storage technologies:
- Shopping cart data stored in browser localStorage
- CSRF protection tokens for form security
- Supabase authentication session cookies (for logged-in users)
- Theme preference (light/dark mode)
- Vercel Analytics — collects anonymous, aggregated usage data (page views, referral sources). No cookies are set; no personally identifiable information is collected.
We do not use any third-party advertising, retargeting, or tracking cookies. No data is shared with advertising networks.
6. Data Security
We take the security of your personal information seriously and implement industry-standard measures to protect it, including:
- SSL/TLS encryption (256-bit) for all data transmitted between your browser and our servers
- Server-side input validation on all forms and API endpoints
- CSRF protection on all data-modifying requests
- Rate limiting on all API endpoints to prevent abuse
- Payment data handled exclusively by PayPal — we never process or store card details
- Secure authentication through Supabase with encrypted password storage
While we strive to protect your personal information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to implementing and maintaining reasonable safeguards.
7. Data Retention
- Order and transaction records: retained for 7 years to comply with U.S. tax and accounting regulations
- Account data: retained until you delete your account. Upon account deletion, personal data is removed and order records required for legal compliance are anonymized
- Newsletter subscriptions: retained until you unsubscribe
- Stock notification requests: retained until you are notified or the request is no longer relevant
- IP addresses (rate limiting): ephemeral; not stored beyond the rate-limiting window
- Error logs (Sentry): retained according to Sentry's default retention policies (typically 90 days)
8. Your Rights
Regardless of where you are located, you have the following rights regarding your personal data:
- Access: request a copy of the personal information we hold about you
- Correction: request that we update or correct inaccurate personal information
- Deletion: request deletion of your personal data (you can also delete your account directly from your account settings at any time)
- Opt out of marketing: unsubscribe from marketing emails at any time using the link in any email, or by contacting us
- Data portability: request your personal data in a structured, commonly used format
To exercise any of these rights, email us at support@snoutique.shop. We will respond to all requests within 30 days. We may need to verify your identity before processing your request.
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know: you may request details about the categories and specific pieces of personal information we have collected about you, the sources of collection, the purposes for collection, and the categories of third parties with whom we share your data
- Right to delete: you may request deletion of your personal information, subject to certain legal exceptions
- Right to opt out of sale: we do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising
- Right to non-discrimination: we will not discriminate against you for exercising any of your CCPA/CPRA rights. You will receive the same quality of service and pricing regardless of whether you exercise your rights
- Right to correct: you may request correction of inaccurate personal information
To exercise your California privacy rights, email us at support@snoutique.shop. We will verify your identity by confirming information associated with your account or order history. You may also designate an authorized agent to make a request on your behalf by providing written authorization. We will respond to verified requests within 45 days. If additional time is needed, we will notify you of the extension and the reason.
10. Do Not Track Signals
Some browsers offer a "Do Not Track" (DNT) setting. Because there is no accepted standard for how to respond to DNT signals, our Site does not currently respond to DNT browser signals. However, we do not engage in cross-site tracking, and we do not use third-party advertising or retargeting cookies.
11. International Data Transfers
Our Site is operated in the United States. If you access the Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate. By using the Site, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.
12. Children's Privacy
The Site is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@snoutique.shop and we will promptly delete that information. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete it as soon as possible.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes that materially affect how we handle your personal information, we will make reasonable efforts to notify registered users via email prior to the changes taking effect. Your continued use of the Site after any changes constitutes your acceptance of the updated policy.
14. Contact Us
For any privacy-related questions, concerns, or requests, contact us at:
Snoutique
Email: support@snoutique.shop
We aim to respond to all privacy inquiries within 24 hours on business days.