Privacy policy
Last Updated:2025.2.15
Welcome to Chrystara (“we,” “us,” or “our”). This Privacy Policy explains how we collect, use, and protect your personal information when you visit www.chrystara.com (the “Site”) or purchase our crystal jewelry and wellness products (“Services”).
By using our Services, you agree to this policy. If you disagree, please refrain from using the Site.
1. Information We Collect
Directly Provided by You
- Contact & Account Details: Name, email, address, phone number, username, and password.
- Order Information: Billing/shipping addresses, payment details (processed securely via Stripe/PayPal), and purchase history.
- Communications: Customer service inquiries, product reviews, or survey responses.
Automatically Collected
- Usage Data: IP address, browser type, device information, and interactions with the Site (via cookies and analytics tools).
- Cookies: Essential for site functionality (e.g., shopping cart). Manage preferences through your browser settings.
From Third Parties
- Payment Processors: Confirmation of transactions (we do not store full credit card numbers).
- Social Media: If you interact with us on platforms like Instagram or Facebook.
2. How We Use Your Information
Purpose | Examples | Legal Basis |
---|---|---|
Order Fulfillment | Processing payments, shipping, returns | Contractual Necessity |
Customer Support | Responding to inquiries, account management | Legitimate Interest |
Marketing | Email newsletters (opt-out anytime) | Consent |
Security | Fraud prevention, system protection | Legal Obligation |
3. Information Sharing
We never sell your data. Limited sharing occurs with:
- Service Providers: Shopify (hosting), USPS/FedEx (shipping), and email marketing tools.
- Legal Compliance: If required by law (e.g., court orders).
- Business Transfers: During mergers or acquisitions.
Past 12 Months’ Disclosures:
Category | Shared With |
---|---|
Identifiers (email, address) | Payment processors, shipping carriers |
Commercial data (orders) | Fulfillment partners |
Usage data | Google Analytics |
4. Your Rights & Choices
All Users
- Access/Correct Data: Contact service@chrystara.com.com.
- Delete Account: Request via customer service.
- Marketing Opt-Out: Unsubscribe link in emails.
California Residents (CCPA)
- Right to know data collection categories and request disclosure.
- Right to opt out of “sales” (we do not sell data).
EU/UK Residents (GDPR)
- Right to data portability and restriction of processing.
- Data transfers protected by Standard Contractual Clauses (SCCs).
5. Key Policies
Cookies
Essential cookies cannot be disabled. Others (e.g., analytics) can be managed via browser settings. Details: WordPress Cookies
User-Generated Content
Product reviews are public. We are not responsible for third-party use of this content.
Children’s Privacy
Not intended for users under 13. Contact us to delete accidental collections.
Data Retention
- Orders: 7 years (tax compliance).
- Accounts: Until deletion request.
- Inactive accounts: Deleted after 3 years.
6. Contact Us
For questions or to exercise your rights:
- Email: service@chrystara.com.com
Policy Updates: Changes will be posted here with a revised “Last Updated” date.