Privacy policy
Last updated June 2026.
Short version: we collect the minimum needed to ship your order and answer your messages, we never sell it, and your card number never touches our servers.
What we collect
- Orders: your name, email, shipping address and order details — to process payment, ship the order, and provide support.
- Email list: your email address, only if you choose to join. Every email has a one-click unsubscribe.
- Messages: anything you send us through the contact form, so we can reply.
- Usage: standard, mostly-anonymous analytics (pages viewed, device type, referrer) to understand what's working. We don't build advertising profiles.
How we use it
Only to take and fulfill your order, provide support, send you email you asked for, prevent fraud, meet legal/accounting obligations, and improve the site. Nothing else.
Who we share it with
We use a small set of trusted processors, and share only what each one needs:
- Stripe — payment processing (a PCI-DSS Level 1 processor).
- Our fulfillment partner — your name and shipping address, to deliver the order.
- Resend — to send order confirmations and any email you opted into.
- Analytics & hosting providers — to run and measure the site.
We do not sell or rent your personal data, and we don't share it for others' advertising.
Cookies
We use the essential cookies needed to run the cart and checkout, and basic analytics. You can block cookies in your browser; the store will still work, though some conveniences may not.
How long we keep it
Order records are kept as long as needed for support, warranty and legal/tax requirements; email-list data until you unsubscribe; contact messages until the matter is resolved.
Security
Payments run entirely through Stripe — we never see or store full card numbers. We limit access to personal data to what's needed to run the store.
Your rights
You can ask us to access, correct, export or delete your data, or to stop emailing you. Reach us through the contact page and we'll respond within 30 days. Where the GDPR or CCPA/CPRA applies, you have those rights too — including the right not to be discriminated against for exercising them — and we honor them.
Children
The store isn't directed to children under 16, and we don't knowingly collect their data.
Changes & contact
If this policy changes, the “last updated” date above will change. Questions about your data? Reach KARST through the contact page.