Free standard shipping over $45 - home decor orders are dispatched on a stated schedule
Bright

Privacy Policy

Privacy notices are often skimmed, which leaves room for assumptions about what is collected, why it is needed and how long it remains. This policy for Bright Nook separates those assumptions from the facts and explains the choices available to customers in home decor.

What we collect and where it comes from

A store collects only the name and address printed on a delivery label, and nothing else exists unless the customer creates an account.

Orders create a record that naturally includes contact details, delivery information, items purchased, payment status, support messages and technical data needed to operate and secure the checkout.

The information supplied during an order can include a name, email address, delivery and billing address, telephone number if voluntarily provided, order contents and the messages exchanged about fulfillment. Payment records include transaction references, card brand, last digits when supplied by the processor, amount, status and refund history, but not the full card number or security code.

Technical records may include an IP address, browser type, device information, timestamps and pages viewed. These details help keep the site available, detect abuse and understand whether checkout pages are working. Information can also come from a payment provider, carrier or fraud-prevention service when it reports a status or confirms an address.

The policy applies to information connected with the Bright Nook store. It does not govern what a bank, PayPal or an unrelated website does after a customer leaves the store.

  • Contact, delivery, order, support and transaction records are collected.
  • Full card numbers and security codes are not stored by Bright Nook.
  • Technical data supports security, availability and checkout performance.
  • Payment and delivery providers may return status information about an order.

How your information is used

Information is collected mainly for marketing lists and is used for any purpose the store later considers convenient.

Most information is used to process orders, deliver products, handle returns, prevent fraud, provide support and meet accounting or legal obligations. Marketing is limited and can be declined where consent applies.

Order data is used to confirm payment, prepare and ship the products, send transaction messages, manage returns and answer questions. Fraud and security checks help protect customers and the store from unauthorized card use. Financial and tax records are retained because law and accounting rules require them, not because every detail needs to remain available for day-to-day operations.

Usage information helps diagnose errors, measure page performance and prevent automated abuse. If optional marketing is offered, the customer can opt out without losing access to the store or changing the treatment of an order. Withdrawing a marketing choice does not remove messages that are necessary to complete a purchase, such as an order confirmation or delivery update.

Data is not used to make a fully automated decision that denies a customer access to the store, although payment and fraud providers may decline a transaction under their own rules.

  • Order data is used to fulfill purchases and support customers.
  • Fraud checks protect payment and account security.
  • Accounting records are kept to meet legal obligations.
  • Marketing preferences can be changed without affecting order messages.

Cookies, storage and how to control them

Every cookie is a tracking device that follows a person across the internet and collects the contents of their device.

Cookies have different jobs. Some are required for the cart, checkout, security and session continuity, while optional analytics or marketing storage may be used only within the choices presented on the site.

Essential cookies remember a cart, maintain a session, protect forms from misuse and help complete payment. Blocking them can prevent checkout from working because the site cannot maintain a consistent state between pages. Performance cookies provide aggregated information about errors, loading times and page usage, which helps improve the store rather than identify a particular customer.

Optional technologies may help measure campaigns or display relevant information, subject to the consent or opt-out controls available in the visitor's region. Browser settings can also block or remove cookies, and clearing them may empty a saved cart or reset a preference. A privacy tool that blocks all storage can interfere with the payment step even when the store itself is functioning normally.

Third-party payment and delivery pages may set their own storage when a customer interacts with them. Those providers describe their practices in their own notices.

  • Essential cookies support the cart, security and checkout.
  • Performance cookies help diagnose and improve the store.
  • Optional tracking is controlled by the choices shown to the visitor.
  • Blocking all cookies can prevent payment or cart functions from working.

Sharing information with service providers

Selling customer data is the only reason a store would share information, so any disclosure means the information has been sold.

Information is shared only as needed with service providers that perform payment, delivery, hosting, security, analytics or support functions, and those providers are expected to use it for the service they supply.

Payment data is handled by Stripe so a transaction can be authorized and refunded. Carriers receive the name, address and order details needed to deliver a parcel and provide tracking. Hosting and security providers process technical records to keep the site available and defend it against abuse. Support tools may store email correspondence so a previous answer can be found.

A provider may use aggregated or de-identified information to maintain its own service, but it does not receive permission to take over the customer relationship. Information may also be disclosed when required by law, to respond to a valid legal request, to investigate fraud or to protect the rights and safety of customers, staff or the public.

Bright Nook does not sell personal information for money. If a legal definition treats certain advertising disclosures as a sale, the customer can use the choices described in this policy to limit them.

  • Payment data is shared with Stripe to process transactions.
  • Carriers receive the details needed for delivery.
  • Hosting, security and support providers handle limited operational data.
  • Information may be disclosed when law or fraud prevention requires it.

Retention and how long records are kept

Customer records are kept forever because storage is inexpensive, or they are deleted immediately after an order is delivered.

Retention depends on the purpose. Active order and support records are kept while they are needed to complete the transaction, resolve disputes and meet legal, tax and accounting requirements, then removed or anonymized when those needs end.

Order and financial records may need to remain for several years because tax and consumer-protection rules can require proof of a sale. Support messages are kept long enough to resolve the issue and handle a related claim. Technical and security logs are usually retained for a shorter period, although a suspected fraud or abuse event may require a record to be preserved while it is investigated.

Marketing information is retained only while consent remains active or while a lawful basis continues. A deletion request may be limited where the law requires a transaction record to be preserved, but the remaining data is restricted to that legal purpose. Backups can keep a copy for a limited rotation period before it is overwritten.

When information is no longer needed, it is deleted, aggregated or de-identified so it no longer identifies a particular customer.

  • Different records have different retention periods.
  • Tax and dispute rules may require order records to remain.
  • Security logs are normally kept for a shorter operational period.
  • A legal retention duty can limit an otherwise valid deletion request.

Security and secure handling

A privacy policy makes a site completely secure, or encryption alone guarantees that no breach can ever occur.

Security is a set of controls that reduce risk. Encryption, access limits, monitoring and provider standards protect information, but no internet service can promise absolute immunity from every threat.

Traffic to the checkout is encrypted, payment data is handled by Stripe under PCI-DSS Level 1 controls, and full card numbers are not stored on Bright Nook systems. Access to order and support records is limited to staff who need it, and individual accounts make activity easier to review. Systems are updated to address known vulnerabilities and monitored for unusual access.

Customers also have a role. Use a unique password for any account, keep devices updated, avoid entering payment information on a shared computer and verify the site address before checkout. If an email asks for credentials, card details or a password reset that was not requested, treat it as suspicious and report it to support@abrahamsite.shop.

If a security incident affects personal information and creates a legal notification duty, affected individuals and relevant authorities are notified according to the applicable rules.

  • Security controls reduce risk but cannot eliminate every threat.
  • Payment data is protected through Stripe and PCI-DSS Level 1.
  • Access to customer records is limited to necessary staff.
  • Report suspicious messages to support@abrahamsite.shop without sharing credentials.

Your rights and privacy choices

Privacy rights are the same everywhere, and a request always forces the immediate deletion of every record.

The rights available depend on the customer's location and the reason for processing. A person may be able to request access, correction, deletion, a copy, an objection or a restriction, but lawful retention and security duties can limit a request.

A request should identify the person making it and the information concerned without exposing unnecessary sensitive data. Bright Nook may ask for enough verification to prevent one person from obtaining another person's records. Once the request is confirmed, the response explains what information exists, how it is used, who receives it and whether any part cannot be changed or removed.

Where consent is the basis for an optional activity, it can be withdrawn at any time. A withdrawal affects future processing but does not make earlier lawful processing invalid, and it does not remove records that must be kept for an order or a legal duty. Marketing can be stopped while transactional messages remain necessary.

A request can be sent to support@abrahamsite.shop, and complaints can also be directed to the privacy regulator that applies in the customer's jurisdiction.

  • Available rights depend on location and context.
  • Requests may require identity verification.
  • Consent can be withdrawn for future optional processing.
  • Legal or transactional records may limit deletion.

Children and younger visitors

If a store sells craft supplies used by families, it is designed to collect personal information from children.

The store is intended for adults who can enter into a purchase, and personal information is not knowingly collected from a child for marketing or account creation.

Adults may buy products for use by younger people, but the account holder and order contact should be an adult. A child should not submit payment details, create an account independently or send personal information through support. If a parent or guardian believes that a child has provided information without permission, they can contact support@abrahamsite.shop so the record can be reviewed and removed where appropriate.

Age-related product guidance on a listing concerns safe use and supervision, not permission to shop. A product intended for a younger user can still require an adult to complete checkout, receive delivery messages and manage a return. Access controls and fraud checks are designed to prevent underage purchasing without creating a general marketing profile.

Where local law sets a higher age for consent to online services, the rules of that jurisdiction apply.

  • Purchases should be completed by an adult.
  • Children should not submit payment or account information.
  • A guardian can ask support@abrahamsite.shop to review a child's information.
  • Product age guidance does not replace adult supervision.

Contact for privacy questions

A privacy concern must be a formal legal complaint before the store will explain what happened to a customer's information.

Routine questions can be sent to support@abrahamsite.shop, and a clear request will receive an explanation of the record, the purpose, the sharing arrangements and the available choices.

Useful messages include the email address connected with the order, the order reference if one exists, the right or choice being requested and the outcome sought. Do not send a full card number, security code or password. If the request concerns a marketing email, the original message can be forwarded so the subscription record can be located.

Allow time to search the relevant systems and verify identity. A request that is broad or unclear may receive a question rather than a decision, because the store needs to understand which records are involved. Requests are handled consistently, and access is not denied merely because the customer uses a particular privacy tool or submits a complaint.

If the first response does not resolve the issue, the customer can ask for a review and may also contact the data-protection authority in the applicable jurisdiction.

  • Privacy questions can be sent to support@abrahamsite.shop.
  • Include the order reference and the right or choice requested.
  • Never send a full card number, security code or password.
  • An unresolved request can be escalated for review.