Privacy policy.
1. What we collect
- Account data — your name, email address and password (encrypted) when you create an account.
- Shop application data — if you apply as a shop: your shop's name, address, story, photos, and a government-issued ID used solely to verify that a real person stands behind the shop.
- Order data — when purchases launch: items bought, shipping address, and payment status. Card numbers are handled by our payment processor (Stripe) and never touch our servers.
2. What we never collect
- No behavioral tracking or browsing profiles.
- No third-party advertising cookies.
- No Google Analytics, Meta Pixel, or similar scripts.
- No location tracking.
- No data purchased from or sold to data brokers — ever.
3. Cookies
We use a single, strictly functional mechanism: an authentication session (stored locally in your browser) that keeps you signed in. It identifies your session, not your behavior. Because we use no tracking cookies, you won't see a cookie banner — there's nothing to consent to.
4. Identity documents
The ID submitted with a shop application is used once, by a human, to verify the shop owner's identity. It is stored encrypted in a private bucket, is never public, never shared with third parties, and is deleted upon request once verification is complete.
5. Who processes your data
- Supabase — our database and authentication provider (data stored in the United States).
- Vercel — our hosting provider.
- Stripe — payment processing, once purchases launch. Stripe has its own privacy obligations.
That's the complete list. No marketing platforms, no ad networks.
6. Your rights
You can request a copy of your data, correct it, or delete your account and everything attached to it at any time. Email us at hello@tongraal.com and a real person will handle it.
7. Changes
If this policy ever changes, we'll say so plainly on this page with a new date. The no-tracking principle is not up for revision.