This policy explains what personal information Saigon Crafter collects, why we collect it, who else sees it, how long we keep it, and what you can make us do about it. It is written to be read. Where a term of art is unavoidable we say what it means.
1. Who is responsible
Saigon Crafter, Houston, Texas, United States, is the controller of the personal information described here. That means we decide what is collected and why, and we are the party you hold responsible.
Contact for any privacy matter: [email protected]. We do not have a statutory data protection officer, because we are not large enough to be required to appoint one. The email above reaches the person who actually decides these things.
2. What we collect and why
| Category | What it is | Why we have it |
|---|---|---|
| Order and delivery details | Name, email address, delivery address, billing address, phone number if you give one | To accept your order, make the item, get it to you, and answer you if something goes wrong |
| Order history | What you bought, when, at what price, and the status of each order | To support the order, to handle returns, and to meet tax and accounting obligations |
| Payment information | The last four digits and card brand, plus the outcome of the charge. Not the full card number | To reconcile payments and process refunds |
| Personalization content | Photographs, names, dates and any other material you send for a made to order item | To make the item you ordered, and for nothing else |
| Account details | Email address and a hashed password, if you choose to create an account | To let you sign in and see your own orders |
| Technical logs | IP address, browser user agent, pages requested, timestamps and error traces | Security, fraud prevention and diagnosing faults |
| Correspondence | The emails you send us and our replies | To handle the matter and to keep a record of what was agreed |
We collect this from you directly, except technical logs, which the server records automatically, and payment outcomes, which come back from Stripe.
3. What we deliberately do not do
We do not sell, rent, trade or share your personal information for money or for anything of value. We have never done so and this policy commits us not to start without telling you first.
We run no advertising trackers and, at the time of writing, no third party analytics of any kind. There is no advertising pixel on this site. We build no behavioural profile of you and we do not use your data to train any model.
We never see your full card number. Card details are entered into fields hosted by our payment processor and are transmitted directly to it. They do not pass through, and are not stored on, our servers.
4. Our legal basis for using it
If you are in the European Union, the United Kingdom or another place with equivalent law, this is the basis on which we rely for each purpose.
- Performance of a contract. Order details, delivery details and personalization content. Without them we cannot make or send what you bought.
- Legal obligation. Invoice and tax records, retained for the period the law requires.
- Legitimate interests. Security logs, fraud prevention and defending legal claims. We have weighed these against your interests and consider them proportionate, because the data involved is minimal and is not used to profile you.
- Consent. Marketing email, and any use of your photograph beyond making your item. Consent can be withdrawn at any time and withdrawal does not affect what was lawful before it.
5. Who else sees it
A small number of companies help us complete an order. Each receives only what it needs for its part, may use it only on our instructions, and may not use it for its own purposes.
| Who | What they get | What for |
|---|---|---|
| Stripe, Inc. | Payment and billing details | Taking the payment and detecting fraud |
| Shipping carriers | Name, delivery address, phone number where the carrier requires one | Delivering the parcel |
| Production partners | What is needed to make and label the item, including your address and, for personalized items, your photograph | Making and dispatching your order |
| Our hosting provider | Whatever is stored on the server, at rest | Running the site and the database |
| Customs authorities | Name, address and a description and value of the contents | Clearing an international parcel, where the law requires it |
We will also disclose information where we are legally compelled to, or where disclosure is necessary to establish, exercise or defend a legal claim. If we are ever compelled to hand over your data and we are permitted to tell you, we will.
If the business were ever sold or transferred, order records would transfer with it, and you would be told before that happened.
6. Where your information goes
Our servers are located outside the United States and your data is processed in the United States and in the country of the hosting provider. Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, or the United Kingdom Addendum to them, with the receiving party.
An international order necessarily involves sending your address to a carrier and a customs authority in your own country. That is unavoidable if you want the parcel.
7. Photographs you send us
A photograph uploaded for a personalized item is used to produce that item and for nothing else.
We do not publish it. We do not put it in a portfolio, a listing photograph or an advertisement without asking you and getting a clear yes. Silence is not a yes.
We keep the file while the order is open and for thirty days after delivery, so that we can remake the item if something is wrong in transit. After that it is deleted. Ask us at any time and we will delete it sooner, and confirm when it is done.
8. How long we keep things
| What | Kept for |
|---|---|
| Order and invoice records | Seven years, as tax and accounting rules require |
| Personalization photographs and files | Thirty days after delivery, or sooner on request |
| Account details | Until you close the account |
| Customer correspondence | Two years from the last message in the thread |
| Server and security logs | Ninety days |
| Marketing consent records | Until you withdraw consent, plus two years to evidence that consent existed |
9. Your rights
Whoever and wherever you are, you may ask us to do any of the following, and we will.
- Tell you what personal information we hold about you, and give you a copy.
- Correct anything that is wrong.
- Delete what we hold, other than records we are legally required to keep.
- Give you your data in a portable, machine readable form, or send it to someone else.
- Stop using it for a particular purpose, or restrict how we use it while a dispute is resolved.
- Withdraw consent you previously gave.
Residents of the European Union and the United Kingdom hold these rights under the General Data Protection Regulation. Residents of California hold rights to know, delete, correct, and to opt out of sale or sharing under the California Consumer Privacy Act as amended; because we do not sell or share personal information, there is nothing to opt out of, and we will not discriminate against you for exercising any right. We extend the same rights to everyone else, because operating two standards is more trouble than it is worth.
To exercise a right, email [email protected]. We answer within thirty days. We may ask you to confirm your identity, which normally means replying from the email address on the order; we will not demand documents we do not need. You may use an authorised agent, and we may ask for proof of their authority.
Deleting your data does not delete records we must retain by law, such as invoices. In that case we will say exactly what is being kept and why.
10. Automated decisions
We do not make decisions about you by automated means that produce legal or similarly significant effects. Stripe applies automated fraud scoring to card payments; if a payment is declined on that basis you can email us and a person will look at it.
11. Security
The site is served over HTTPS throughout. Passwords are stored hashed, never in a readable form. Administrative access to order data is limited to the people who fulfil orders, and is protected by individual accounts rather than a shared login. Payment card data never reaches our systems.
No system is perfect. If a breach occurs that is likely to affect your rights, we will notify the relevant supervisory authority within seventy two hours where the law requires it, and we will tell you directly and promptly, in plain language, what happened and what you should do.
12. Children
This shop is not directed at children under thirteen and we do not knowingly collect their personal information. If you believe a child has given us information, email us and we will delete it.
13. Cookies
Cookies are covered separately in the Cookie Policy, which lists every cookie this site sets.
14. Changes to this policy
If this policy changes in a way that matters, the date at the foot of the page changes with it and the change is announced on this page. We will not quietly broaden what we do with data you gave us under an earlier version.
15. Complaints
Tell us first: [email protected]. If you are not satisfied, residents of the European Union may complain to the supervisory authority of their member state, and residents of the United Kingdom to the Information Commissioner's Office. Residents of California may contact the California Privacy Protection Agency or the Attorney General.
16. Contact
Saigon Crafter, Houston, Texas, United States. [email protected]
Last updated 30 August 2026.
