Privacy
Privacy policy
We put the dose on the label. This is the same idea applied to your data: the actual list of what we collect, the actual names of the companies that receive it, and what you can do about either. No "we value your privacy" throat-clearing.
Updated 18 Aug 2026 The Meta Pixel is now switched on. Until today it was present in the page but not configured, so nothing was actually reaching Meta. It is now live, which means Meta receives the data described under Who else receives your data. Nothing else about this policy changed. You can switch it off, along with Google Analytics, in Your choices below.
The short version. We collect what we need to ship you a bottle and to see whether the website is working. We do not sell your data for money. We use Google Analytics and the Meta Pixel — both of which count as "sharing" your data under California law, and you can switch both off further down this page. Payment card numbers never reach us at all; Stripe handles those.
What we collect
Things you type in. These only exist because you chose to give them to us:
- Order details — your name, email address, shipping address, and what you bought. Entered on Stripe's checkout page, not ours. We see the result so we can ship the order.
- Email address, if you enter it in the signup box after ordering.
- Wholesale enquiries — business name, your name, email, phone if you give it, website or handle, and whatever you write in the message box. The wholesale form does not submit to a server. It opens a pre-filled draft in your own email program, which you then send to us yourself. Nothing reaches us until you press send, and you can see and edit every word before you do.
- Emails you send us, including anything you choose to put in them.
Things collected automatically. These happen when the page loads, before you click anything:
- Your IP address, which is roughly a location — usually to the city, not the street.
- Your device and browser — type, version, screen size, operating system, and the language your browser asks for.
- What you did on the site — pages viewed, how long, what you clicked, where you arrived from (a search, an ad, a link, or direct).
- Cookies and similar identifiers set by the analytics and advertising tools named in the next section. These are how a return visit gets recognised as a return visit.
What we never collect. Your card number, CVC, and expiry date are entered on Stripe's own checkout page and are never sent to this website or to any system we control. We can see the last four digits and the card brand on a receipt, and that is all. We also do not ask for, want, or store any health or medical information — please do not send us any. Cuprum Labs sells cosmetics; nothing here is a medical service and we are not set up to hold medical records.
Who else receives your data
Running a shop means other companies touch your data. Here is every one of them, what they get, and why. This list is exhaustive as of the date at the bottom of this page — if we add a tool, we add it here.
- Stripe — payment processing. Gets your name, email, billing and shipping address, card details, and what you ordered. Stripe is the merchant of record for the payment itself and processes it under its own terms. Their policy: stripe.com/privacy
- Google Analytics 4 (Google LLC) — tells us how many people visit, which pages they read, and where they came from. Gets your IP address, device and browser details, and your activity on the site, tied to a cookie identifier. We use it to decide what to write and what to fix. This is running today. Their policy: policies.google.com/privacy — and you can switch it off in the next section.
- Meta (Facebook, Instagram) — advertising measurement via the Meta Pixel. Gets your IP address, browser details, the pages you viewed on this site, and whether you bought something, matched against your Facebook or Instagram account if you have one. This is how an ad gets attributed to a sale, and how you end up seeing our ads again after visiting. Their policy: facebook.com/privacy/policy — and you can switch it off in the next section.
- Vercel — hosting. Every request for every page passes through Vercel's servers, so it sees your IP address, the page requested, and your browser's user-agent string, in ordinary server logs. Their policy: vercel.com/legal/privacy-policy
- Google Fonts — the typefaces on this site are served from Google's servers, which means your IP address reaches Google on every page load, whether or not you interact with anything. We are listing this because it is true and most sites quietly omit it. We intend to self-host these files so this stops happening. Until we do, it is disclosed rather than hidden.
- Google (Gmail) — our email runs on Gmail, so any email you send us is stored there. Their policy: policies.google.com/privacy
- Shipping carriers — whoever carries the parcel gets your name, address and a contact detail, because otherwise the parcel does not arrive.
We do not sell your personal information for money. We never have. But California and several other states define "sale" and "sharing" broadly enough that letting an advertising platform set a cookie counts, even with no money involved. Under those definitions, our use of Google Analytics and the Meta Pixel is sharing, so we say so plainly rather than hiding behind the fact that no cash changes hands. Switch it off below and it stops.
Artificial intelligence
We do not put your personal information into any AI system. There is no chatbot on this site, no AI support agent, no automated decision-making about you, and no profiling engine deciding what you see or what you pay. Nothing you type here is used to train a model, ours or anyone else's.
To be complete about it: we use AI tools the way most small businesses now do — as a writing and coding assistant while building the site and drafting copy. That work happens with our own material. Customer data is not part of it.
If this ever changes — an AI support agent, personalised pricing, anything that processes your data by machine — this section gets rewritten before the feature ships, not after.
How long we keep it, and how to have it deleted
There is nowhere on this site to upload a file — no photo submissions, no document uploads, no user accounts holding your content. So there is no library of customer uploads sitting somewhere. What does accumulate is order records, emails, and analytics identifiers:
- Order and payment records — kept for 7 years. This one is not our choice; tax and accounting rules require it, and a refund or chargeback dispute can surface long after the sale.
- Marketing emails — kept until you unsubscribe, then removed from the sending list. Every marketing email has a working unsubscribe link.
- Wholesale enquiries — kept for 2 years from the last time we spoke, then deleted.
- Customer support emails — kept for 3 years, so we can look up what we told you.
- Google Analytics data — retained for 14 months, which is the maximum retention window we have configured, after which Google deletes the user-level records.
To have your data deleted, email gocuprum@gmail.com with the subject "Data deletion request". We will reply within 5 business days and complete it within 30 days. You do not have to explain why, and asking will not affect your guarantee or any order in flight.
The one thing we cannot delete on request is the order and payment record itself, for the 7-year window above — that is a legal retention obligation and it applies to us the same as to any other shop. Everything else goes.
Where it is stored, and how it is protected
This site is a set of static pages. It has no database, no user accounts, no login, no file storage bucket, and no server of ours holding customer records. That is not a security feature we built — it is a consequence of the site being small — but it is worth stating plainly, because it means there is no store of customer data here to be left publicly readable.
Your data lives in the vendor systems named above: order and payment records in Stripe, emails in Gmail, analytics in Google Analytics. Each is protected by that vendor's own security, plus our own account credentials.
What we can tell you about our side: every page is served over HTTPS, admin accounts have two-factor authentication switched on, and payment credentials are never handled by our code. What we will not tell you is that your data is "completely secure", because nobody can honestly promise that. If we ever have a breach that affects you, we will email you and tell you what happened.
Your choices
Turn off analytics and advertising tracking. This switch works on this browser, on this device, right now. It stops Google Analytics from loading and stops the Meta Pixel from initialising on every page of this site. It is stored in your browser, so clearing your browser data will reset it, and you will need to set it again on other devices.
We also honour Global Privacy Control. If your browser or an extension sends a GPC signal, we treat it as an opt-out automatically and you do not need to touch the switch above.
Your rights over your data. Depending on where you live — California, Colorado, Connecticut, Virginia and a growing list of other states — you have the right to know what we hold about you, get a copy of it, correct it, have it deleted, and opt out of your data being sold or shared for advertising. We extend all of these to every customer regardless of state, because operating two standards is more work than just doing it for everyone.
Email us and say what you want. We reply within 5 business days and finish the job within 30 days. We will not charge you, we will not make you create an account to ask, and we will not treat you differently afterwards. If we ever have to say no to a request we will tell you which exemption we are relying on and why.
Children
This site is not aimed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal information, email us and we will delete it.
If this policy changes
The "last updated" date at the bottom of this page is the real date this text last changed. If we make a change that materially affects what we do with your data — a new vendor receiving it, a new purpose, a longer retention window — we will say so at the top of this page for at least 30 days, and email anyone on our list.
Contact
One person reads this inbox and it is not a ticket queue.
Cuprum Labs