Privacy Policy
Last updated: 4 October 2026
We collect as little as we can get away with, because a store that keeps less data cannot leak much.
1. What we collect
- Order data. What you bought, the price, and the email address PayPal gives us for the transaction.
- Your cart. Stored in your own browser under a local storage key. It never leaves your device until you check out.
- Server logs. Standard request logs kept by our host, including IP address and user agent.
We do not ask for, want, or store payment card numbers. Card details never touch our servers; PayPal handles them.
2. Why we use it
To take payment, deliver your order, answer your support messages, and meet our tax and accounting obligations. That is the whole list.
3. Who we share it with
PayPal, for payment processing. Meta Platforms Ireland Limited, only if you accept optional advertising measurement - see section 5. Sentry, for server error monitoring when configured and browser diagnostics when you accept. Our hosting provider, to run the site. And public authorities, if the law compels it.
We do not sell your data. If you accept optional advertising measurement, the event details listed in section 5 are shared with Meta so that our advertising can be measured. Declining means no Meta Pixel or Conversions API event is sent.
4. How long we keep it
Order records are kept as long as needed to fulfill orders, handle disputes and meet applicable accounting and legal requirements. The exact retention period depends on the rules that apply to the transaction. Cart data in your browser is kept until you clear it. Hosting and security logs follow the retention settings of the hosting provider.
5. Cookies and advertising measurement
Your cart lives in local storage, readable only by this site. PayPal's own buttons set cookies when they load to keep you from being charged twice; their privacy notice covers those.
Meta Pixel and Conversions API, only if you accept
A consent banner is shown before any Meta tracking loads. If you accept, the Meta
Pixel is loaded and may set first-party cookies such as _fbp and
_fbc. If server-side Conversions API tracking is configured, successful
purchases are also sent from our server. That event may include the purchase value,
currency, product identifiers, browser identifier, IP address and browser user-agent.
If PayPal provides the buyer's email, the server normalizes and SHA-256 hashes it
before sending it to Meta; the raw email is not sent to the browser for tracking.
These events are used to measure advertising performance.
If you decline or close the banner without choosing, the Meta script is not loaded and no event is sent to Meta. Your choice is stored in your browser so the banner does not reappear on each visit. You can change it at any time using the Cookie choices link in the footer; withdrawing consent prevents future events and expires the first-party Pixel cookies.
Sentry error monitoring
When configured, Sentry receives server-side application errors so we can detect failed requests and checkout problems. Server reports are scrubbed to exclude user identity, cookies, request bodies, headers, query values and payment details. Browser error reports are sent only after you accept this banner and are stopped for future events when you withdraw consent.
What is shared when you accept:
- That a page was viewed, plus the page and referrer.
- That a product was viewed: its id, name and category.
- That a product was added to the cart, with its price.
- That checkout was opened, with the cart contents and total.
- That an order was purchased, with the order reference, total and product ids.
The browser Pixel does not receive your name, email address or card details. When server-side tracking is enabled, Meta may receive the normalized, hashed PayPal email as described above. Card details never touch our server. Meta may match events against its own records about you, which is what makes the measurement possible. To have your data deleted, or to object to this processing, use the support contact listed in this section.
6. Your rights
You can ask us what personal data we hold about you, ask us to correct it, or ask us to delete it where we are not required to keep it. If you accepted analytics cookies you can also object to that processing, and you can withdraw consent at any time using Cookie choices in the footer. We answer within 30 days. Email support@accvault.run.place.
7. Security
The production storefront must be served over HTTPS; local development uses HTTP. Payment card details are handled by PayPal and are not stored by this storefront.
8. Changes
If we change this policy we will update the date at the top of this page. Material changes will be announced on the site before they take effect.