Privacy policy
Last updated: 2026-09-11
vyra.bio collects the minimum data needed to take payment and deliver an order. This page describes exactly what is stored, how, and for how long.
WHAT WE COLLECT
- · Order data: the items ordered, the shipping name and address, and the email address you enter at checkout.
- · Payment data: the coin chosen, the gateway invoice and payment address, the amount, and the transaction IDs the payment gateway reports. We never see or hold your wallet keys.
- · Disclaimer acceptance: the terms version you accepted and when, recorded per order.
- · Request metadata: the connecting IP address and the user-agent string, used for rate limiting and for the order audit trail. The IP is held in two forms — see below.
HOW IT IS STORED
- · Personal fields (name, address, email) are encrypted at rest with AES-256-GCM in our database; the key is held outside the database.
- · IP addresses are stored in two forms. On the order and staff-session records they are kept only as a salted hash, which cannot be reversed to the original address. The audit log, which records checkouts and administrative actions, stores the IP address itself, unhashed.
- · The site is served behind Cloudflare, which terminates TLS and sees connection metadata under its own privacy policy. Cloudflare does not receive order contents beyond what is needed to proxy the request.
- · Staff access to order data requires a password and, where enrolled, a one-time code. Actions that change data — order status, refunds, settings — are written to the audit log. We do not currently log staff reading order data, so there is no record of who viewed or decrypted a given order.
WHAT WE DO NOT DO
- · No third-party analytics, advertising pixels, or tracking scripts run on this site.
- · No marketing email. Email is sent only for order events: payment received, shipped, delivered, refunded, or cancelled.
- · No sale or sharing of personal data, other than passing the shipping address to the carrier and the invoice to the payment gateway.
COOKIES AND BROWSER STORAGE
- · pl_dg — records that you accepted the research-use disclaimer (one year).
- · vyra_theme — your light/dark preference.
- · vyra_admin_session — the staff login session; set only for administrators, never for customers.
- · Your cart is not a cookie. It is held in your browser's local storage under the key vyra_cart_v1 and stays on your device until you submit a checkout; clearing site data for vyra.bio empties it.
None of these are used for tracking across sites.
RETENTION
Order records are retained for as long as needed to fulfil the order, handle claims, and meet record-keeping obligations. In practice nothing is deleted automatically: we run no purge job, so completed orders, abandoned and expired checkouts, and their audit-log entries are all retained indefinitely. We would rather state that plainly than quote a retention period nothing enforces.
YOUR RIGHTS
You may ask for a copy of the data held against an order, or for its deletion once the order is complete and no claim is open. Contact us via the email on the Contact section of the About page, quoting the order ID. We will verify the request against the email on the order. Both are handled by hand; there is no self-service export or deletion.
DRAFT — this text has not been reviewed by legal counsel and is subject to revision.