Privacy Policy
Last updated: 01 April 2026
1. Who we are
DecalStars ("we", "us", "our") operates the website at https://decalstars.com. We are a UK-based business selling and producing custom vinyl decals. For questions about this policy contact us at our contact page.
2. What data we collect
- Account data: name, email address, password (hashed).
- Order data: shipping name, address, order contents, payment status.
- Payment data: payments are processed by Stripe. We never store full card numbers. We store Stripe payment intent and charge IDs for order management.
- Design data: SVG files, preview images, and metadata for designs you create or purchase.
- Usage data: server logs, IP addresses, browser type — collected automatically for security and performance.
3. How we use your data
- To process and fulfil orders.
- To manage your account and store.
- To process payments and pay out creator commissions via Stripe Connect.
- To send order confirmation and shipping notifications.
- To comply with legal obligations (financial records, fraud prevention).
We do not sell your data to third parties. We do not use your data for advertising.
4. Legal basis (UK GDPR)
We process your data under the following legal bases: contract (to fulfil your order), legitimate interests (security, fraud prevention), and legal obligation (financial record-keeping).
5. Stripe
Payments are handled by Stripe, Inc. When you make a purchase, you interact with Stripe's secure payment system. Creator payouts are made via Stripe Connect. Stripe's privacy policy applies to data processed by their systems: stripe.com/gb/privacy.
6. Data retention
We retain order data for 7 years to comply with UK financial regulations. Account data is retained while your account is active. You may request deletion of your account at any time — we will delete your personal data unless we are legally required to retain it.
7. Your rights
Under UK GDPR you have the right to: access your data, correct inaccurate data, request deletion, restrict processing, and data portability. To exercise any right, contact us via the contact page.
8. Cookies
We use essential session cookies required for the site to function (login, cart, CSRF protection). We do not use tracking or advertising cookies.
9. Changes to this policy
We may update this policy from time to time. We'll update the date at the top of this page. Continued use of the site constitutes acceptance of the updated policy.