Who this policy covers
Night Sky Studio (the “Shop”) operates the website at https://nightskystitch.com. This policy covers information the Shop processes when you browse the site, use the bag, pay, or request a download link.
The legal entity that operates the Shop is Night Sky Studio, LLC. The contact for this policy is help@nightskystitch.com.
Information kept in your browser
The bag is stored in this browser under the local-storage key night-sky-studio:bag:v1. The record contains a version number and a list of product identifiers with quantities. It does not contain your name, email address, or payment card. The Shop’s servers do not receive the bag until you start checkout, and then only as the product identifiers needed to open Stripe Checkout. Removing the items, or clearing the site data for this browser, removes the bag.
Your analytics choice, if you make one, is stored in this browser under the local-storage key night-sky-studio:consent:v1. That record is described under “Optional analytics.” It is not a cookie.
Purchases and transactional email
Payment, when checkout is enabled, is Stripe Checkout on Stripe’s pages. The Shop does not receive or store your card number.
When Stripe reports a payment as paid, the Shop stores the email address from Checkout, the Stripe customer id, the Checkout Session id, the payment intent id, the currency, the amounts Stripe reports (including a tax amount if Stripe sends one), the patterns on the order, and the pattern version for each pattern.
The Shop sends transactional email through a third-party service "Resend". Our sending address is patterns@nightskystitch.com. The Shop records the destination address, the message type, and whether the send succeeded. The message types the Shop records are purchase and purchase recovery. Purchase and recovery messages are not a newsletter signup. Newsletter is a separate subscription, described under “Support and the newsletter.”
Download links
A purchase link is created for 72 hours. A recovery link is created for 24 hours. The Shop stores a hash of the link token, not the token itself, with the expiry and the customer or order it belongs to.
A download record stores the entitlement, the pattern version, and the time. The request-detail field on that record is left empty. The Shop does not write your network address into the download record.
Recovery requests are rate-limited. For that limit the Shop stores a hash derived from the network address and a hash derived from the email address. It does not store the network address in the clear in that limit record.
Optional analytics
Analytics is opt-in only. The Shop utilizes Google Analytics 4, measurement id. It does not load until you accept analytics. That id is in the public page code. The Shop does not load the Google tag, and does not set analytics cookies, unless every one of the following is true: you choose Accept analytics; that choice is saved in local storage and has not expired; and the browser’s HTTPS origin matches the site origin configured for the Shop. If any condition fails, analytics stays off. Declining analytics means the Google tag is not loaded.
The saved choice lasts 180 days. If local storage cannot be read or written, the choice is not saved and analytics stays off. When the 180 days end, analytics stops until you choose again. If you reject analytics after the tag has loaded, the page will disable analytics. Cookie settings in the footer reopens the choice when those controls are enabled. The controls are not shown when analytics is not eligible to run.
The Shop does not use analytics for advertising. The Shop does not sell personal information.
Cookies
The Shop does not set analytics cookies unless you accept analytics and the conditions in “Optional analytics” are met. Those cookies, when Google’s tag sets them, are named _ga and _ga_0BMHESPWS0. Declining analytics means the Shop does not load GA4. The Shop does not set advertising cookies.
Service providers
- Stripe is used as our payment processor. - Resend sends purchase and recovery email, and can send studio notes after a newsletter signup as described under “Support and the newsletter.” - Cloudflare hosts the site and may process ordinary request data under Cloudflare’s own terms. - Google receives analytics data only after you accept analytics, and only when the tag is allowed to load, as described above.
These providers may process information in countries where they operate. [international transfers] The Shop does not, on this page, name a transfer mechanism, a retention period at a provider, or a subprocessors list beyond the providers named here.
Support and the newsletter
The support form at /support emails the Shop at help@nightskystitch.com with the name, email address, topic, and message you type, after Cloudflare Turnstile confirms the form. The Shop does not keep a copy of that note. The address you enter is the reply-to. The newsletter form stores your email address as a subscription only after you check the consent box. That list is for studio notes and stays separate from purchase email. When the Turnstile check is configured, it confirms the form before the address is saved, and the address can be sent through Resend only after that check succeeds. If that check is not configured, the address stays on the Shop’s list and is not sent to Resend. Unsubscribe removes the address from the Shop’s list and, when it was sent, from Resend.
Retention and requests
The Shop retains data indefinitely. There is no customer account and no self-service tool to export or delete information. To ask about information the Shop holds, email help@nightskystitch.com. The law that governs that request is [governing privacy law]. The Shop does not promise a response time on this page.
Changes
The Shop may replace this page by publishing a new version at this URL. The date in the introduction is the date of the version you are reading.
Need a little more context? Visit the FAQ or support page.