Effective 2026-07-16 Current as of August 29, 2026
KomiArts operates KomiArts. For privacy requests, use hello@komiarts.shop. We publish only approved business-facing details and do not expose a private owner email, phone number, personal legal name, or residential address.
We use data to provide the cart and account, validate and fulfill purchases, prevent duplicate or fraudulent activity, send requested account/order messages, maintain suppression choices, provide support, reconcile payments/refunds, meet legal/accounting obligations, and improve site reliability and usability. Optional browser measurement can be turned off below.
Cloudflare hosts the Worker and images; Upstash stores application records; Stripe hosts payment Checkout and processes payments/tax configuration; Printify produces and ships paid orders; Resend delivers account, order, and consented marketing email; Auth.js coordinates authentication. Each receives only the data needed for its role and applies its own terms and privacy practices.
We count store interactions and coarse performance measurements so we can understand traffic, product demand, searches, cart behavior, conversion, sales, refunds, and whether pages and Checkout are working well. Each accepted browser event is folded immediately into a UTC daily aggregate. Counts describe events, not unique people.
Daily aggregates can include a coarse page category, a coarse source such as direct, Google, Instagram, Etsy, or other referral, product and variant identifiers, list names, normalized search phrases with result counts, quantities, values, and Core Web Vitals. Paid orders add item quantities, merchandise, discount, shipping, tax, tip, total, shipping-country, and refund-reason totals server-side. We do not retain an event-level analytics record, analytics identity, full URL or query string, full referrer URL, advertising click identifier, visitor journey, campaign profile, or order reference in analytics.
These aggregate business records and opaque payment/refund deduplication bits are kept until the store owner chooses to delete them. Because a browser contribution is combined immediately with other totals and has no analytics identity, it cannot later be isolated as one person's record.
Optional browser analytics
Checking your saved preference…
Turning this off prevents future optional browser measurements from this browser. It cannot remove a contribution already combined into a daily total, and it does not alter aggregate payment/refund accounting or security rate limits.
Automated order-PII redaction remains fail-closed until a qualified reviewer approves the accounting, tax, chargeback, legal-hold, and backup period. Account access can still be deleted immediately; a tombstone prevents older backups from resurrecting access.
Checkout and security capabilities expire and are not extended on restore. Encrypted primary-data backups preserve original absolute expiries, use a separate destination/key identifier, apply deletion tombstones first, and are restore-tested in an isolated database once external backup configuration is enabled.
Aggregate store analytics have no automatic expiration and remain until the store owner explicitly deletes all or a selected date range.
Signed-in users can download a JSON export, manage newsletter consent, and delete account access. A verified-email account can also surface guest orders made with that email. For another guest request, contact us; we will verify control of the order email before disclosing or changing personal data.
The analytics control above provides a simple, free objection to future optional browser measurement. The same control remains linked from every page footer.
Every marketing email includes one-click and page-confirmed unsubscribe controls. Minimal suppression information remains so an old backup or future signup does not silently undo a complaint, bounce, or opt-out.
Hosted Checkout keeps card details out of this application. Webhooks are signature-verified, passwords require verified email ownership and versioned PBKDF2 parameters, request bodies are bounded, and sensitive return details require a nonce or matching account. No system is risk-free; contact us if you believe an account or order is exposed.
The store is not directed to children under 13, and we do not knowingly ask a child under 13 to create an account or join marketing. A parent or guardian can contact us about removal.
We update the effective date when this policy changes materially. Contact hello@komiarts.shop or use the contact page.
“I want to share some cute stickers with everyone!”
You’re browsing as a guest
Sign in to view orders associated with your verified email. You can always buy as a guest.
Sign inNew here? Create an account
30% off everything. 5% off 3+ eligible stickers. Free U.S. shipping at $40.00. Mystery Boxes Are Here. Secure checkout by Stripe