Back

Privacy Policy

We respect your privacy. This policy explains the information NoirCraft collects, why we collect it, and the choices you can make about your personal data.

Last updated: January 10, 2026

Data Controller

NoirCraft is the data controller responsible for your personal data. For privacy-related inquiries, contact us at support@noircraft.com.

Information we collect

Information you provide

  • Account information: Name, email address, and password when you create an account.
  • Order information: Shipping address, billing address, phone number, and payment details (processed securely by Stripe).
  • Communications: Messages you send through our support forms, emails, or chat.
  • Newsletter: Email address when you subscribe to marketing communications.

Information collected automatically

  • Device information: IP address, browser type, operating system, and device identifiers.
  • Usage data: Pages visited, time spent on pages, links clicked, and referral sources.
  • Location data: Approximate location based on IP address for fraud prevention and localization.

How we use your information

  • Order fulfillment: Processing orders, coordinating production with manufacturing partners, and arranging shipping.
  • Customer service: Responding to inquiries, resolving issues, and providing support.
  • Transactional communications: Sending order confirmations, shipping updates, and receipts.
  • Marketing: Sending newsletters and promotional offers (only with your consent).
  • Personalization: Providing product recommendations based on your browsing and purchase history.
  • Security: Detecting and preventing fraud, abuse, and unauthorized access.
  • Legal compliance: Meeting tax, accounting, and regulatory requirements.
  • Analytics: Understanding how visitors use our site to improve the experience.

Third-party sharing

We share the minimum necessary data with trusted third parties to operate our business. We do not sell your personal information.

  • Payment processing: Stripe processes payments securely. We never store your full card details.
  • Fulfillment partners: Print-on-demand partners (e.g., Printify) receive shipping details to produce and ship orders.
  • Shipping carriers: Couriers receive delivery addresses to complete shipments.
  • Analytics: Google Analytics helps us understand site usage (with anonymized IP addresses when possible).
  • Email services: Email providers send transactional and marketing communications on our behalf.
  • Hosting: Cloud infrastructure providers (Vercel, MongoDB) store and process data.

International data transfers

Your data may be transferred to and processed in countries outside your residence, including the United States. When transferring data from the EU/EEA/UK, we use:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Data Processing Agreements with all service providers.
  • Providers certified under recognized frameworks where applicable.

Cookies

We use cookies and similar technologies to operate our website and improve your experience. You can manage your cookie preferences at any time using the cookie settings button in the bottom-left corner of the page.

Necessary cookies

Required for core functionality: shopping cart, checkout, session management. Cannot be disabled.

Duration: Session to 1 year

Analytics cookies

Help us understand how visitors interact with our site using Google Analytics. Only enabled with your consent.

Duration: Up to 2 years

Marketing cookies

Used for advertising and retargeting to show relevant ads. Only enabled with your consent.

Duration: Up to 2 years

Preference cookies

Remember your preferences and provide personalized recommendations. Only enabled with your consent.

Duration: Up to 1 year

Data retention

  • Order records: Retained for 7 years for tax and accounting purposes.
  • Account data: Retained while your account is active; deleted within 30 days of account closure upon request.
  • Support communications: Retained for 3 years to help with follow-up inquiries.
  • Marketing preferences: Retained until you unsubscribe or request deletion.
  • Analytics data: Aggregated and anonymized data may be retained indefinitely.

Security

We implement appropriate technical and organizational measures to protect your data:

  • All data transmitted via HTTPS/TLS encryption.
  • Payment data processed through PCI-DSS compliant Stripe.
  • Regular security assessments and monitoring.
  • Access controls limiting data access to authorized personnel.
  • Secure cloud infrastructure with industry-standard protections.

While we strive to protect your data, no method of transmission over the Internet is 100% secure.

Your rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data.
  • Rectification: Update or correct inaccurate information.
  • Erasure: Request deletion of your data when no longer needed.
  • Restriction: Limit how we process your data in certain circumstances.
  • Portability: Receive your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw consent at any time for consent-based processing.
  • Opt-out: Unsubscribe from marketing using the link in every email.

To exercise these rights, contact us at support@noircraft.com. We will respond within 30 days (or as required by applicable law).

For EU/EEA/UK residents (GDPR)

If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under the General Data Protection Regulation:

  • Right to lodge a complaint with your local Data Protection Authority.
  • Right to know the legal basis for processing your data.
  • Right to data portability in a commonly used format.
  • Right not to be subject to automated decision-making, including profiling.

UK Information Commissioner's Office: ico.org.uk

EU Data Protection Authorities: edpb.europa.eu

For California residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

  • Right to know: Request disclosure of personal information collected, used, and shared.
  • Right to delete: Request deletion of your personal information.
  • Right to correct: Request correction of inaccurate personal information.
  • Right to opt-out: Opt out of the sale or sharing of personal information.
  • Right to limit: Limit the use of sensitive personal information.
  • Non-discrimination: We will not discriminate against you for exercising your rights.

We do not sell your personal information.

NoirCraft does not sell personal information to third parties for monetary consideration. We may share data with service providers as described above, but this is not considered a "sale" under CCPA.

To submit a CCPA request, email support@noircraft.com with the subject line "CCPA Request." We may verify your identity before processing.

Children's privacy

Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately at support@noircraft.com, and we will delete the information promptly.

Changes to this policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or a prominent notice on our website. Your continued use of our services after changes take effect constitutes acceptance of the updated policy.

Contact us

For privacy-related questions or to exercise your rights:

We aim to respond to all privacy requests within 30 days.