What we collect, why we collect it, who we share it with.
EFFECTIVE · 2026-07-27
This Privacy Policy explains how VivyVeil LLC ("VivyVeil", "we", "us") collects, uses, shares, and protects personal data when you visit vivyveil.com, place an order, or contact us. It applies to all visitors and customers globally. Where the laws of your jurisdiction grant you specific rights, those are described in §8.
VivyVeil LLC is the operator of vivyveil.com and is responsible (as data controller, under GDPR / UK GDPR) for personal data processed in connection with the Site. The legal entity is registered in Wyoming, USA with its registered office at 30 N Gould St Ste N, Sheridan, WY 82801, USA.
Where this Policy refers to "you", it means any visitor or customer whose personal data we process. Where it refers to "we", "us", or "VivyVeil", it means VivyVeil LLC.
We collect personal data in three ways: information you provide, information we receive about your transactions, and information that is collected automatically.
Information you provide. Account name, email address, shipping addresses, phone number, locale preference, any notes or photos you submit as part of a sourcing request or customer-update reply, and the content of any message you send to support.
We do not collect or store a password. Sign-in is by emailed magic link only — there is no password field on the Site, so there is no password of yours for us to lose.
Transaction information. Order numbers, item details, payment status, refund history, the breakdown of fees per item, customs acknowledgment timestamp, and any in-product notes you attach to a cart line. Payment-card details are not stored by us; they are handled by Stripe, our card-payment processor. What we keep against an order is a tokenised payment reference issued by Stripe and nothing else — we do not store the card number, the expiry date, the security code, or the last four digits. For PayPal payments we receive only your PayPal payer email and payer id; we never see your PayPal account password or any underlying funding-instrument number. Magic-link sign-in tokens are stored briefly and destroyed at use.
Automatically collected information. Device and browser metadata (user-agent, IP address, language, time zone), basic logs of the requests you make (URL, status code, latency), and the values of essential cookies described in §9. We do not run third-party advertising trackers or build behavioural profiles for marketing.
We process personal data to:
We do not currently send marketing email at all. Every email we send you is transactional: it relates to an order, a sourcing request, or a message you sent us. There is therefore no marketing list to join or leave, and no marketing-preference control in your account settings. If we ever start sending marketing email, it will be opt-in, we will ask you before the first one, every message will carry a one-click unsubscribe, and we will add the preference control to your account settings and say so here.
Where the EU General Data Protection Regulation or the UK GDPR applies, we rely on the following legal bases:
For each activity relying on Art. 6(1)(f), we conduct and document a Legitimate Interests Assessment. A written summary of the LIA for any specific activity is available on request.
We rely on a small list of established processors. Each only receives the minimum data required to perform its function.
| Processor | Purpose | Data shared |
|---|---|---|
| Stripe, Inc. (US) | Payment processing (card, Apple Pay, Google Pay) | Order ID, amount, currency, billing email, card data entered directly by you on Stripe's hosted element. |
| PayPal, Inc. (US) / PayPal (Europe) S.à r.l. et Cie, S.C.A. (EU) | Payment processing (PayPal balance, linked card or bank) | Order ID, amount, currency, your PayPal payer email and payer id returned to us on capture, and the shipping address we passed to the PayPal order to support PayPal's seller-protection program. |
| Cloudflare Workers (US) | Edge compute, request routing | Request payloads in transit only; no at-rest storage in this layer. |
| Cloudflare D1 (US) | Primary database | Account record, orders, products, addresses, refund history. |
| Cloudflare R2 (US) | Object storage | Uploaded product photographs and customer-update images. |
| Cloudflare Images (US) | Image transcoding & CDN delivery | The same image objects, served via a delivery URL. |
| Cloudflare KV (US) | Short-term key-value storage | Session tokens, edge cache of computed pages. |
| Cloudflare Turnstile (US) | Bot-protection challenge | Challenge metadata, IP address, browser signal — no order or account content. |
| Cloudflare network (CDN, TLS, DDoS) (US) | Network delivery and security | TLS termination, request metadata (URL, status, IP); flows through Cloudflare for delivery only. |
| Resend, Inc. (US) | Transactional email delivery | Recipient email, subject, body, attachments. |
| International carriers (DHL Express, SF Express, and the equivalent tracked carriers listed in the Shipping & Customs Policy §1) | Carriage and customs clearance of your parcel | Recipient name, shipping address, phone number, parcel weight, and the declared customs value for the piece. Shared only for the parcel actually being shipped, at the point the label is created. |
| Ingestion point (mainland China) | Receiving parcels from the original seller, inspection, photography, dispatch | Shipping name, address, phone; order-specific notes. Transfer covered by EU SCCs 2021/914 (Module 2: controller-to-processor) supplemented by a written Transfer Impact Assessment — see §6. |
We do not sell personal data and we do not share it with third parties for their independent marketing.
We are based in the United States. Our ingestion point is in mainland China. Personal data transferred to either for the purposes in §3 is covered by a written data-processing agreement with each processor.
Where the GDPR or UK GDPR applies, we rely on the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 (Module 1 controller-to-controller, or Module 2 controller-to-processor, as appropriate). For UK data we apply the UK International Data Transfer Addendum. For US processors that have self-certified, we also rely on the EU-US Data Privacy Framework and its UK and Swiss extensions.
Transfer Impact Assessment — mainland China. Mainland China has no adequacy decision under Art. 45 GDPR. We have completed a written TIA for our ingestion point under EDPB Recommendations 01/2020. The data we transfer is limited to what is needed to receive and inspect a parcel (shipping name, address, phone, order-specific notes). We do not transfer payment data, credentials, sign-in tokens, browsing history, or device identifiers. The full TIA summary is available on written request.
We retain personal data only as long as needed for the purpose for which we collected it, plus any period required by applicable law.
| Data category | Retention |
|---|---|
| Account profile (name, email, address book, locale preference) | Active life of the account, plus eighteen months after account closure for fraud, dispute, and reactivation handling. |
| Order and payment records (order details, payment status, refund history, customs declaration) | Seven years from the order date, to meet US tax-record retention. |
| Support correspondence | Three years from last contact. |
| Marketing-email preferences | Not applicable — we send no marketing email and hold no marketing preference (see §3). |
| Magic-link sign-in tokens | Destroyed at first use or after fifteen minutes, whichever is earlier. |
| Server access logs containing IP addresses | Ninety days. |
After the applicable retention period, we delete the data or anonymise it irreversibly. Where one record category contains data needed for a longer category (for example the account profile is needed to reconcile a seven-year-old order), we retain only the minimum subset necessary, not the full account record.
All visitors. You may close your account, request access to your data, ask us to correct it, or contact us with a privacy question at support@vivyveil.com.
EU / UK consumers (GDPR). You have the right to access, rectify, erase, restrict processing of, and port your personal data, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You may also lodge a complaint with your supervisory authority.
California residents (CCPA / CPRA). You have the right to know what personal information we have collected, the right to delete and the right to correct personal information, the right to limit use of sensitive personal information, and the right to opt out of "sales" or "sharing" — though we do not sell or share for cross-context behavioural advertising. We do not discriminate against you for exercising any of these rights.
How to submit a request. Email support@vivyveil.com from the email address on your account with a one-line description of what you would like us to do (access, rectify, erase, port, restrict, or object). For guest orders, include a recent order number. Authorised agents must include written proof of authority and the data subject's own confirmation.
How we verify identity. We match the requesting email against the email on your account record. Where the match is ambiguous — for example, a closed account, a guest order, or a mismatched email — we will ask for an additional verification factor that is already known to both sides (typically a recent order number, the last four digits of the card used for an order, or a magic-link confirmation to the email on file). We never ask for new sensitive information solely for verification, and we never ask for a password or a full payment-card number.
We will respond to verifiable requests within thirty days, or within forty-five days where extended by law; for clearly unfounded or excessive requests (in particular, repetitive requests within a short window) we may charge a reasonable fee or refuse, as permitted by Art. 12(5) of the GDPR. We log the receipt time, the verification outcome, and the dispatch of our response for each request.
We use the smallest set of cookies and local-storage entries that the Site needs to work. We do not run third-party advertising trackers.
| Name | Type | Purpose |
|---|---|---|
| vivy.session_token (__Secure-vivy.session_token on HTTPS) | Strictly necessary | Sign-in state |
| vivy_cart | Strictly necessary | Your shopping bag itself, stored as base64-encoded JSON in an HttpOnly cookie (encoded, not encrypted) |
| vivy.locale | Functional | Language preference, written on first page view from an IP-derived country guess |
| Cloudflare Turnstile and Cloudflare network cookies | Strictly necessary | Bot protection and DDoS mitigation |
Strictly necessary and functional cookies do not require consent.
If we later add any analytics, advertising, or conversion-tracking technology (for example Google Analytics, Meta Pixel, TikTok Pixel, or remarketing tags), we will surface a consent banner before any such technology runs, update this Policy to disclose it, and update the cookie table above. Until then, no such technology is in use.
The Site is not directed to children, and we do not knowingly collect personal data from a child below the local digital-consent age. We apply a default minimum of sixteen years, with the following local overrides:
Where local law sets a stricter (higher) digital-consent age than sixteen, the stricter local age applies. If you believe a child below the applicable age has provided us with personal data, contact us at support@vivyveil.com and we will delete it within thirty days.
We use TLS in transit and encryption-at-rest for the payment tokens and magic-link tokens we store. There are no password hashes to protect, because the Site has no password sign-in (see §2). Access to production systems is limited to personnel who need it. No system is perfectly secure.
Breach notification. If we become aware of a personal-data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority (the lead authority where the GDPR or UK GDPR applies, and any other competent authority under local law) without undue delay and where feasible no later than seventy-two hours after becoming aware, in line with GDPR / UK GDPR Art. 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay under GDPR / UK GDPR Art. 34, with a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take. For US state-level breach-notification laws (notably the CCPA / CPRA and state-specific statutes) we comply with each state's notification timing and content requirements in parallel.
We may update this Policy from time to time. Material changes are posted on the Site and, where you have an account, emailed to you. The version applicable to a given visit is the version in force on that visit; historic versions are available on request.
VivyVeil LLC · Privacy
Registered office: 30 N Gould St Ste N, Sheridan, WY 82801, USA
Email: support@vivyveil.com
EU and UK representative (GDPR Art. 27). Designation is in progress. While it is pending, support@vivyveil.com is the primary point of contact for all GDPR and UK GDPR matters, including data-subject requests under Arts. 15-22 and any communication a supervisory authority would otherwise direct to the representative. We respond to EU and UK data-subject requests to the same timelines and standard set out in §8, and we do not condition any of your rights on the representative being in place.
You may also lodge a complaint directly with your supervisory authority (in the EU, the data-protection authority of your country of residence; in the UK, the Information Commissioner's Office).