Privacy
Privacy
The service is designed to collect only what a purchase, enquiry, return or seller assessment needs, keep private evidence out of public systems, and preserve a reviewable record of access and deletion.
In your browser
The basket is stored in local storage. A checkout status token may be kept in session storage so the confirmation page can show that order; closing the browser session removes it. The token is long, random and reveals only minimum order state. This site does not set an advertising or behavioural-tracking cookie.
Purchases
We store the purchaser's name, email, phone, delivery address, order lines, the disclosure version bought, approved shipping route, price, payment state, provider references, fulfilment, shipment, return and refund records. These are needed to reserve a one-of-one stone, take payment, deliver it, support the buyer and keep required commercial records.
Stripe hosts card entry. Card numbers and security codes do not enter this site's database. Stripe receives payment and contact details under its own privacy terms. Signed provider events are stored as a checksum and a deliberately limited operational summary, not as a duplicate of the full event payload.
Enquiries and privacy requests
We store the name, contact route, category and message before trying to send an internal notification. This means an email-provider outage does not lose the enquiry. Where configured, a salted one-way network address hash is used for abuse limits; the raw address is not stored in the enquiry row.
Seller and acquisition evidence
A secure seller submission can include contact details, location, language, claimed species and origin, weight, requested price, ownership or extraction account, licence information and private photographs or video. The seller's exact words are kept separately from translations, extracted claims, photographic observations, risk signals and the named operator's decision.
Original files use random private object keys and checksums and begin in quarantine. They are not placed in Git or a public bucket and are not sent to an AI model. Identity documents are not accepted through the first-contact form.
Processors and recipients
Cloudflare provides the public pages, edge API, bot protection and private object storage. A managed PostgreSQL provider stores governed records. Stripe processes cards. The configured email relay sends enquiry notifications. An approved carrier receives only the details needed to deliver a fulfilled order. Protected Studio and Desk access is identity-based and role-limited.
No analytics service is represented here as active unless it is actually configured and added to this notice and data inventory.
Retention and deletion
The implementation baseline is two years for enquiries that do not become orders and seven years for order and purchase records. Those periods are provisional pending the legal, tax, second-hand-dealer and AML/CTF schedule. Automated jobs first produce a dry-run report, honour legal holds, require approval for sensitive batches, cover primary and derived copies, and leave a non-identifying deletion receipt. Backups and search/export copies have their own expiry and verification steps.
Your request
You may ask for access, correction or deletion where retention is not legally required, or raise a privacy concern. A request is recorded as a durable enquiry and handled through the approved identity-check and response procedure.
No monitored privacy address is published yet. The contact page records this as a launch gate. Preview status cannot be removed until a real address and accountable response owner are in place.