Privacy Policy
Last updated: 23 February 2026
1. Introduction
Beaufart™ (“we”, “our”, “us”) respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our platform and store, in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
Account Information
- Email address and username
- Password (stored securely hashed)
Content You Upload
- Audio files (emissions)
- Titles, descriptions, and metadata
Store & Order Data
- Shipping addresses you provide at checkout
- Email address (for guest checkout and order communications)
- Order history, items purchased, and order status
- Payment transaction references (we do not store full card numbers — payment is handled entirely by Stripe)
Technical Data
- IP address, browser type, and device information
- Session cookies for authentication and cart persistence (see our Cookie Policy)
3. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Providing and maintaining the platform | Contract performance |
| Creating and managing your account | Contract performance |
| Fulfilling and shipping your orders | Contract performance |
| Processing payments via Stripe | Contract performance |
| Sending order confirmation and shipping emails | Contract performance |
| Calculating and collecting VAT/sales tax | Legal obligation |
| Displaying your emissions on the platform | Consent (by uploading) |
| Persisting your shopping cart across sessions | Legitimate interest |
| Preventing fraud and abuse | Legitimate interest |
4. Third-Party Data Sharing
We do not sell your personal data. We share data only where necessary to provide our services:
- Stripe — Payment processing. Stripe receives your payment card details directly. See Stripe’s Privacy Policy.
- Printful / Prodigi — Order fulfillment. Your name and shipping address are shared with the print-on-demand provider to manufacture and deliver your order.
- SendGrid — Transactional email delivery. Your email address is shared for sending order-related communications.
- Public content — Emissions you upload are visible to other users on the platform.
- Legal requirements — We may disclose data if required by law.
5. Data Retention
- Account data: Retained while your account is active. You can request deletion at any time.
- Order data: Retained for 7 years as required for tax and accounting records.
- Guest checkout data: Email and shipping address retained with order records for 7 years.
- Emissions: Retained until you delete them or your account is closed.
- Shopping cart: Guest carts expire after 30 days. Authenticated carts persist until checkout or manual clearing.
6. Data Security
- Encrypted data transmission (HTTPS/TLS)
- Hashed and salted password storage
- Payment processing handled entirely by PCI DSS-compliant Stripe
- Access controls and authentication on all administrative systems
7. International Transfers
Your shipping address may be shared with fulfillment providers in the US (Printful) or UK (Prodigi) depending on your delivery destination. Where data is transferred outside the UK, appropriate safeguards are in place.
8. Your Rights (UK GDPR)
Under UK data protection law, you have the right to:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your data (subject to legal retention requirements)
- Data portability — Receive your data in a structured, machine-readable format
- Object — Object to processing based on legitimate interest
- Withdraw consent — Where processing is based on consent, you may withdraw at any time
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
9. Cookies
We use essential cookies for authentication and shopping cart persistence. See our Cookie Policy for details.
10. Children
Our Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.
11. Changes to This Policy
We may update this privacy policy from time to time. Changes will be indicated by the “Last updated” date at the top of this page.
12. Contact & Complaints
For privacy-related enquiries: [email protected]
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
See also: Terms of Service • Returns Policy • Community Guidelines