Privacy Policy
Last updated April 27, 2026
Who We Are
Amor Aeternus LLC ("we," "us," "our") operates the website amoraeternus.studio. We create hand-engraved antique and vintage objects and sell them through monthly drops and commissions.
When you interact with this website — signing up for drop notifications, submitting a commission inquiry, or making a purchase — you share personal information with us. This Privacy Policy explains what we collect, why we collect it, who we share it with, and the rights you hold over your data under applicable law.
Contact: hello@amoraeternus.studio
Information We Collect
We collect information you provide directly and information collected automatically:
Information you provide
- Email notification sign-up: your email address, first name, and last name.
- Commission inquiry form: your name, email address, and any details you include about your request.
- Purchase: your name, email address, shipping address, and payment details. Payment card data is processed directly by Stripe — we never see or store your card number.
Information collected automatically
- Google Analytics: IP address (anonymised), browser type, device type, referring URL, pages visited, and session duration. This data is associated with a randomly assigned Analytics ID, not your name.
- Google Fonts: when the page loads, your browser connects to Google's servers to download our fonts; Google logs your IP address as part of that request. See Google's Privacy Policy.
- Server logs: standard hosting logs including IP address, HTTP request, and timestamp, retained for security purposes.
How We Use Your Information
- Email marketing: to send you drop announcements and updates you signed up for. We use Klaviyo to manage and deliver these emails. Your consent is obtained at sign-up; you may withdraw it at any time by clicking "Unsubscribe" in any email.
- Order fulfillment: to process your purchase, arrange shipping, and communicate about your order.
- Commission: to respond to and fulfil your commission request.
- Analytics: to understand how visitors use the site and improve it. Aggregate data only — we do not build individual profiles for advertising.
- Security & fraud prevention: to detect and prevent unauthorised access or fraudulent transactions.
- Legal compliance: to meet our obligations under applicable law, including tax and financial record-keeping.
We do not sell, rent, or trade your personal information. We do not use your data for targeted advertising or retargeting across other websites. We do not use social login or share data with social platforms.
Lawful Basis for Processing
For visitors in the European Economic Area, United Kingdom, or other jurisdictions governed by GDPR or equivalent law, we process personal data on the following lawful bases:
| Processing Activity | Lawful Basis |
|---|---|
| Email marketing (drop notifications) | Consent — you opt in at sign-up. You may withdraw consent at any time. |
| Order processing & fulfillment | Performance of a contract — necessary to complete your purchase. |
| Commission inquiry & delivery | Performance of a contract — necessary to respond to and fulfil your request. |
| Website analytics (Google Analytics) | Legitimate interests — improving the website. Analytics are anonymised and aggregated. |
| Security & fraud prevention | Legitimate interests — protecting our customers and business from harm. |
| Financial record-keeping | Legal obligation — required by tax and accounting law. |
Email Marketing & Klaviyo
We use Klaviyo to manage our email list and send marketing communications. Klaviyo acts as a data processor under our instructions; Amor Aeternus LLC is the data controller for all subscriber information.
By signing up for drop notifications, you consent to receive marketing emails from us. Every marketing email we send includes:
- A one-click unsubscribe link — clicking it removes you from our list within 10 business days
- Our business address (as required by the CAN-SPAM Act)
- Clear identification that the message is from Amor Aeternus
You may also unsubscribe at any time by emailing hello@amoraeternus.studio. Unsubscribing from marketing emails does not affect transactional messages related to an order you have placed.
For information on how Klaviyo handles data, see the Klaviyo Privacy Policy.
Google Analytics
We use Google Analytics to understand how visitors use the site. Google Analytics collects anonymised data including your IP address (truncated), browser, device, and pages visited. This information is sent to Google servers.
Google Analytics does not enable us to identify you personally. We do not share this data with third parties for advertising.
You may opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on, or by using a browser extension that blocks analytics scripts.
For more information, see Google's Privacy Policy.
Payment Processing — Stripe
All payment transactions are processed by Stripe. When you check out, your payment card information is entered directly into Stripe's secure form and transmitted encrypted to Stripe's servers. We never receive, process, or store your full card number, CVV, or bank account details.
Stripe may retain transaction data (amount, date, last four digits, billing name and address) as required to process refunds, resolve disputes, and comply with financial regulations. Stripe is an independent data controller for the data it collects about you during payment.
For information on how Stripe handles your data, see the Stripe Privacy Policy.
Cookies
This site uses cookies in two categories:
- Functional cookies: necessary for the site to operate (e.g., session management, cart state). These cannot be turned off without breaking site functionality.
- Analytics cookies: set by Google Analytics to collect anonymised usage statistics. These are not used for advertising.
We do not use advertising cookies, tracking pixels, social media cookies, or retargeting cookies.
You may control cookies through your browser settings. Blocking all cookies may affect site functionality.
Data Retention
| Data Category | Retention Period |
|---|---|
| Email marketing list (name & email) | Until you unsubscribe or request deletion |
| Order records (name, address, transaction) | 7 years — required by U.S. tax and accounting law |
| Commission correspondence | Until completion + 3 years |
| Google Analytics data | 26 months (Google's default retention), anonymised and aggregated |
| Server security logs | 90 days |
After the applicable retention period, we will securely delete or anonymise your data. You may request earlier deletion by contacting us (see Your Rights below).
Data Security
We take reasonable technical and organisational measures to protect your personal data, including:
- HTTPS encryption for all data transmitted to and from this website
- Selecting third-party service providers (Klaviyo, Stripe, our hosting provider) that maintain strong security certifications and data processing agreements
- Limiting access to personal data to those who need it to fulfil their role
No system is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals and relevant authorities as required by applicable law.
Children Under 13
This website is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at hello@amoraeternus.studio and we will delete it promptly.
This notice is provided in compliance with the Children's Online Privacy Protection Act (COPPA).
Do Not Track & CalOPPA
The California Online Privacy Protection Act (CalOPPA) requires us to disclose how we respond to "Do Not Track" browser signals.
Do Not Track: This site does not currently respond to Do Not Track (DNT) signals, as there is no universally accepted standard for how websites should respond to DNT requests.
Third-party tracking: Google Analytics collects anonymised analytics data when you visit this site. Stripe may set cookies related to payment processing. No third-party advertising networks have access to your data through this site.
California residents may also review the CCPA/CPRA section below for additional rights and disclosures.
California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you specific rights regarding your personal information.
Categories of personal information we collect
- Identifiers: name, email address
- Commercial information: order history, transaction records
- Internet activity: anonymised analytics data (Google Analytics)
- Geolocation data: shipping address (provided by you at checkout)
Purposes of collection
Email marketing communications; order processing and fulfillment; website analytics; security and fraud prevention; legal compliance.
Sale or sharing of personal information
We do not sell your personal information. We do not share your personal information with third parties for cross-context behavioural advertising. In the past 12 months, we have not sold or shared personal information as those terms are defined by the CCPA/CPRA.
Sensitive personal information
We do not collect, use, or disclose sensitive personal information (as defined by CPRA) beyond what is necessary to fulfil your order or send you communications you have consented to receive.
Your California privacy rights
- Right to Know: request disclosure of the categories and specific pieces of personal information we have collected about you, the purposes of collection, and the categories of third parties we disclose it to.
- Right to Delete: request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: as noted above, we do not sell or share personal information for behavioural advertising.
- Right to Limit Use of Sensitive Personal Information: we do not use or disclose sensitive personal information for purposes beyond those listed above.
- Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights.
Shine the Light (California Civil Code § 1798.83)
California residents may request, once per year, a list of the categories of personal information disclosed to third parties for their direct marketing purposes and the names and addresses of those third parties. As noted above, we do not disclose personal information to third parties for their own direct marketing purposes.
How to exercise your California rights
Submit a request by emailing hello@amoraeternus.studio with the subject line "California Privacy Request." We will respond within 45 days. If we need additional time (up to 90 days total), we will notify you in writing.
You may designate an authorised agent to submit requests on your behalf. We may require verification of your identity and confirmation of the agent's authorisation before processing the request.
EEA & UK Residents
If you are in the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR grants you the following rights regarding your personal data:
- Right of access: obtain a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your data ("right to be forgotten"), subject to legal retention obligations.
- Right to restriction: request that we limit processing of your data in certain circumstances.
- Right to data portability: receive your data in a machine-readable format, where technically feasible.
- Right to object: object to processing based on legitimate interests or for direct marketing at any time.
- Right to withdraw consent: where processing is based on consent (e.g., email marketing), withdraw at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email hello@amoraeternus.studio. We will respond within 30 days.
Right to lodge a complaint
If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with your national data protection authority:
- EU residents: contact your national supervisory authority (find your authority here).
- UK residents: contact the Information Commissioner's Office (ico.org.uk).
International data transfers
Your personal data is processed in the United States. When we transfer data from the EEA or UK to the US, we rely on our service providers' data transfer mechanisms (Standard Contractual Clauses, adequacy decisions, or equivalent safeguards) to ensure your data is protected to GDPR standards. Klaviyo and Stripe both maintain EU-US data transfer compliance — see their respective privacy policies for details.
Third-Party Links
This website may contain links to third-party websites (e.g., Instagram, TikTok). These sites have their own privacy policies, which we do not control. We encourage you to review the privacy policies of any site you visit. We are not responsible for the content or privacy practices of third-party sites.
Changes to This Policy
We may update this Privacy Policy as our practices change, as new services are introduced, or as required by law. Material changes will be noted at the top of this page with a new effective date. Where we have your email address, we may notify you of significant changes. Continued use of the site after a policy update constitutes acceptance of the revised policy.
Contact & Rights Requests
This policy is written to be read, not just filed. If anything is unclear, or to exercise any right described in this policy, please contact us:
We aim to respond within 30 days (45 days for California privacy requests), usually much sooner.
Amor Aeternus LLC
Michigan, United States