Privacy Policy
Last updated: May 5, 2026
1. Overview
Holy Smokes Engraving (“we”, “us”, or “our”) is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data when you use our website or make a purchase.
2. Information We Collect
We collect the following categories of information:
- Account information: Name and email address when you register for an account.
- Order information: Name, email address, and shipping address when you place an order.
- Payment information: Payment is processed by Stripe. We never see or store your full card number, CVV, or bank details. Stripe may collect and store payment data subject to their own Privacy Policy.
- Usage data: We may collect anonymized analytics such as pages visited and actions taken to improve the site experience. No personally identifiable information is included in this data.
3. How We Use Your Information
We use your information solely to:
- Process and fulfill your orders
- Send order confirmation and shipping notification emails
- Maintain your account and order history
- Respond to your questions or support requests
- Comply with legal obligations
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Cookies & Session Data
We use a single authentication cookie (auth-token) to keep you signed in to your account. This cookie is HTTP-only, meaning it cannot be accessed by JavaScript, and expires after 7 days. We do not use third-party tracking cookies or advertising cookies.
5. Third-Party Services
We use the following third-party services that may process your data as part of delivering our service:
- Stripe — payment processing. Stripe Privacy Policy
- Resend — transactional email delivery (order confirmations, shipping notifications). Resend Privacy Policy
- Cloudinary — product image hosting. Images uploaded to our store are stored on Cloudinary servers. Cloudinary Privacy Policy
6. Data Retention
We retain your order data for as long as necessary to fulfill legal, accounting, and business obligations — typically a minimum of 7 years in accordance with US tax law. If you delete your account, your personal profile information will be removed, but order records will be retained in anonymized form.
7. Data Security
We take reasonable technical and organizational measures to protect your personal information, including HTTPS encryption, HTTP-only authentication tokens, and hashed passwords. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Opt out of any future marketing communications
To exercise any of these rights, email us at dwight@holysmokesengraving.com. We will respond within 30 days.
9. Children's Privacy
Our site is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. Continued use of the site after changes are posted constitutes your acceptance of the revised policy.
11. Contact
Questions about this policy? Email us at dwight@holysmokesengraving.com.