How we handle your information

Privacy Policy

You send us a photograph of something you care about, along with your name and your address. This says exactly what happens to all of it — including the parts most policies leave out.

Effective Controller Contact

Privacy at a glance

As of

A summary of the policy below, in the style of an app-store privacy label. It is a summary — where it and the full policy differ, the full policy governs.

What we collect

◆ Your photographs The picture you upload, and the print file we make from it. Including the hidden data your camera wrote into the file — see section 3.
◆ Name & email To confirm your order, send it, and answer you if something goes wrong.
◆ Shipping address Collected by Stripe at checkout and passed to us and to the carrier.
◆ Your editing notes Free text you write us about the order. Please do not put anything sensitive in there.
◆ Order & payment record What you bought and that it was paid for. Card number handled by Stripe — we never see it.
◆ Basic technical logs IP address, browser, timestamps. Security and fraud prevention only.

What we never do

✕ Sell your data We do not sell or share personal information, and never have. No advertising networks.
✕ Train AI on your photos Your photograph is not training data for us or for anyone we send it to.
✕ Face recognition We extract no faceprint, no biometric identifier, and run no face matching. Ever.
✕ Advertising trackers No analytics pixel, no ad cookie, no third-party tracker on this site.
✕ Market with your photo Not without a separate opt-in that starts unticked.
Photos kept after your order ships
If you don't order then deleted
Leaves the US? No processors are US-based
Delete on request Any time free, within 45 days

Who we are, and what this covers

, , is the controller of the personal information described here — meaning we are the ones who decide what is collected and why, and the ones you can hold responsible for it.

This policy covers , the design tool, and everything we do to fulfil an order. It does not cover any other company's website, including ones we link to.

The card at the top of this page is a summary. It is accurate, but it is short. Where it and this policy differ, this policy governs.

Questions, or any request under this policy, go to .

What we collect

WhatWhere it comes from Why we have it
Photographs you upload You, through the design tool To generate the preview and to make your Pillow
Files derived from them Generated by us: the cut-out, the print artwork, the approved preview image To manufacture, and to record what you approved
Editing notes You, at checkout To make the change you asked for
Name and email You, and Stripe at checkout To confirm, send, and support your order
Shipping address Collected by Stripe, passed to us To deliver the Pillow
Payment confirmation Stripe To know the order was paid. We never receive your full card number — see 4.3
Order records Generated by us Fulfilment, support, returns, tax and accounting
Technical and log data Automatically, when you use the site Security, fraud prevention, abuse limits, keeping the site up

We do not ask for and do not want your government ID number, your date of birth, your precise location, your health information, your religion, your politics, your race, your union membership, or your sexual orientation. Please do not put any of that in an editing note — that box is free text and goes into our order record and to the people who make your Pillow.

There is no account to create, so there is no password for us to hold. Your cart lives in your own browser and is never uploaded until you check out.

The hidden data inside your photograph

A photograph is not only an image. Cameras and phones write a block of technical data into the file itself, called EXIF, and most people have never looked at it.

It commonly includes the exact GPS coordinates where the picture was taken, the date and time to the second, the camera or phone model, its serial number, and the settings used.

For a photograph of your own vehicle, the coordinates are usually your driveway. We would rather tell you that than let you find out later.

We currently pass your original file on unchanged — EXIF included — to the people who print and sew your Pillow, because the production team works from the untouched original as well as from the print file. It is not published anywhere, it is not attached to the Pillow, and it goes only to the suppliers listed in section 5, who are bound by contract to use it solely to make your order.

If you would rather it did not, you have three options. Any of them works, and none of them affects your order:

  • Ask us. Say so in your editing notes, or email with your order number, and we will strip the location data before the file goes anywhere.
  • Turn it off before you shoot. On iPhone: Settings → Privacy & Security → Location Services → Camera → Never. On Android: open Camera, Settings, turn off location tags.
  • Strip it from the copy you send. Most photo apps offer this when sharing or exporting.

We do not read, index, or do anything with the EXIF block beyond one thing: the pipeline reads the orientation tag so that a photograph taken in portrait is not printed on its side. Nothing looks at the location.

Who else handles it

We use other companies to run this business. Each is a processor: they act on our instructions, they are bound by a written contract, and none of them is permitted to use your information for their own purposes, to sell it, or to train models on it.

WhoWhat they receive What for
Stripe Your name, email, billing and shipping address, card details — direct from you, on Stripe's own page Taking payment. The card form is hosted by Stripe on Stripe's domain, so your card number never touches our website
remove.bg Your photograph Automatically separating the vehicle from its background. See the AI Transparency Statement
Cloudflare Your IP address and request data, in transit Serving the site, TLS, and blocking attacks
Our manufacturing partner
[NOT YET SELECTED]
Your name, shipping address, print artwork, approved preview, and original photograph Printing, sewing and dispatching your Pillow
Shipping carrier
[NOT YET SELECTED]
Your name, address, and contact details Delivering the parcel and telling you where it is
Google (Workspace) Anything you put in an email to us — your name, your email address, your message, and any attachment Receiving and storing mail sent to our published addresses. Writing to us is optional; this row exists because the contact form opens your own mail app, so what you send arrives in a mailbox Google hosts
Sending provider
[NOT YET SELECTED]
Your name and email address Order confirmations, proof requests, shipping notices

The unfilled rows above are not an oversight. We have not yet chosen a manufacturer, a carrier, or the provider that will send our order emails. This table will name them before we take a real order, and we will update this policy when we do.

Payment card data. Your card number, expiry and security code go directly from your browser to Stripe. They do not pass through our servers and we do not store them. We receive only confirmation that a payment succeeded, and the last four digits and card brand, so we can identify the transaction.

Beyond those processors, we disclose personal information only: to professional advisers under a duty of confidence; where we are legally required to, such as a valid court order or subpoena; to establish or defend a legal claim; to prevent fraud or harm; or to a buyer if the business is sold, in which case we will tell you before your information becomes subject to a different policy.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either. See section 11.

Why we are allowed to use it

Under US law we use your information for the purposes set out in this policy. If you are in the UK, the EU, or another place with equivalent law, we also have to name a lawful basis, and these are ours:

PurposeLawful basis
Making and delivering your Pillow Performance of our contract with you
Taking payment and preventing fraud Contract, and our legitimate interest in not being defrauded
Answering your questions and handling returns Contract, and legitimate interest in customer service
Keeping the site secure and available Legitimate interest in protecting our service and users
Tax, accounting and record-keeping Legal obligation
Using your photograph in marketing Consent — opt-in only, withdrawable at any time
Marketing emails Consent — opt-in only, withdrawable at any time

How long we keep it

WhatHow long Then
A photograph uploaded but never ordered Deleted, along with the cut-out made from it
Your original photograph, on an order after despatch Deleted
Print artwork and approved preview after despatch Deleted. Kept this long so we can reprint a faulty Pillow and show what you approved if there is a dispute
Order and payment records
no photographs
Required for tax and accounting
Technical logs Up to 12 months Deleted or anonymised
Marketing consent record Until you withdraw it, plus 3 years Kept to prove the consent existed

You can ask us to delete your photograph sooner, at any time, including before these periods expire. We will do it, unless we still need the file to finish an order you have placed — in which case we will delete it as soon as the order ships. Email . There is no charge.

Where we must keep a record for tax or legal reasons, we keep the record — what was bought, when, for how much — and delete the photograph. Those are separate things and we treat them separately.

Backups are deleted on their own rolling cycle, so a file may persist in a backup for a short period after deletion from live systems. It is not restored to live use once deleted.

Faces, and biometric information

We do not collect, capture, generate, store, use, or disclose any biometric identifier or biometric information. We do not create faceprints or scans of face geometry. We do not run facial recognition, face detection, face matching, age estimation, or emotion analysis on your photograph, and neither does any service we send it to on our behalf.

People do appear in these photographs — standing beside a truck, sitting on a bike. Nothing in our system looks at them. The automatic cut-out separates a foreground object from its background; it produces an outline, not an identity, and it has no concept of a person.

This statement is made for the purposes of the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, the Washington My Health My Data Act, and every equivalent law. If that ever changes, we will obtain the written consent those laws require before it changes, not after, and we will publish the retention and destruction schedule they require.

Separately: if a person is identifiable in a photograph you upload, you have promised us under section 5 of the Terms that you have their permission. That is a promise about their rights, and it is not affected by anything in this section.

Cookies and tracking

This site sets no advertising cookies, no analytics pixels, and no third-party trackers. There is no Google Analytics, no Meta pixel, no ad network, and nothing that follows you to another website.

We use two pieces of browser storage, both strictly necessary, both on your own device, and neither uploaded until you check out:

  • Local storage holds your cart, so it survives a page refresh.
  • IndexedDB holds the artwork for pillows in your cart, because a print file is far too large for local storage.

Clearing your browser data clears both, and empties your cart. Nothing is lost that we hold a copy of.

Our payment page is Stripe's, and Stripe sets its own cookies for fraud prevention. Cloudflare may set a cookie to distinguish a visitor from an attack. Both are strictly necessary; neither is advertising.

Global Privacy Control. We honour the GPC signal. Because we do not sell or share personal information there is nothing for it to switch off, but we treat it as a valid opt-out request and will continue to honour it if that ever changes.

If we ever add analytics, we will update this section before turning it on, and we will pick something that does not build a profile of you.

How we protect it

Everything travels over encrypted connections (TLS). Payment happens on Stripe's own hosted page, which keeps card data out of our systems entirely.

API keys and credentials are held server-side, never in the website's code, and can be rotated. Access to order files is restricted to the people who need it to fulfil orders.

Uploads are limited in size and rate, and orders are capped per day, to prevent one visitor exhausting or overwhelming the service.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal information we will notify you and the relevant regulator as the law requires, and we will tell you what was affected rather than issuing a vague statement.

Please do not email us photographs or documents you consider sensitive. Ordinary email is not encrypted end to end.

Your rights in California

If you live in California, the California Consumer Privacy Act as amended by the CPRA gives you the following rights. We will not discriminate against you for using any of them — no worse price, no slower service, no refused order.

  • Know — what we have collected about you, where it came from, why, and who we disclosed it to.
  • Access — get a copy, in a portable format.
  • Delete — have it erased, subject to the narrow exceptions in section 6.
  • Correct — have inaccurate information fixed.
  • Opt out of sale or sharing — we do not sell or share, so there is nothing to opt out of. We have included no "Do Not Sell or Share My Personal Information" link for that reason, and if that ever changes the link will appear before the practice does.
  • Limit use of sensitive personal information — we do not collect any, so there is nothing to limit.

Categories. In the 12 months before the date at the top of this page we collected: identifiers (name, email, address, IP); commercial information (what you ordered); internet activity (basic logs); geolocation only insofar as it is embedded in a photograph you chose to upload (section 4); and visual information (your photographs). Each was collected for the purposes in section 5 and disclosed only to the processors in section 4. We disclosed no personal information for any commercial purpose beyond those, and sold or shared none.

How to make a request. Email with your order number if you have one. We will confirm within 10 business days and respond within 45 days, extendable once by another 45 if we tell you why. It is free unless a request is manifestly unfounded or excessive.

Verification. To protect you, we will check that a request really comes from you — normally by matching the email address on the order. We will not ask for a government ID for an ordinary request. An authorised agent may act for you with written permission, and we may still verify with you directly.

Shine the Light. California Civil Code § 1798.83 lets residents ask about disclosures to third parties for their own direct marketing. We make no such disclosures.

Your rights in the UK, EU and elsewhere

If you are in the UK, the European Economic Area, or a jurisdiction with comparable law, you have the rights to: access your data; have it corrected; have it erased; restrict how we use it; object to processing based on legitimate interests; receive it in a portable format; and withdraw consent at any time, without that affecting what we did lawfully before you withdrew it.

Exercise any of them at . We respond within one month.

You can complain to a regulator. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EEA it is your national supervisory authority. You do not have to come to us first, though we would like the chance to fix it.

International transfers. We are based in the United States and all of our processors are US-based, so if you order from outside the US your information is transferred to the US. Where the law requires a transfer mechanism we rely on the European Commission's Standard Contractual Clauses, or the UK Addendum, together with the technical measures in section 9.

No automated decision-making. We make no decision about you by automated means that produces a legal or similarly significant effect. The automatic cut-out is a step in making a picture, not a decision about a person.

Children

This site is not directed to children, and we do not knowingly collect personal information from anyone under 13. You must be 18 to order.

If you are a parent or guardian and believe your child has uploaded a photograph or given us information, email . We will delete it promptly and will not require you to prove anything first.

Changes to this policy

We will update this policy when what we do changes — particularly when we name the manufacturer, the carrier and the sending provider still marked unfilled in section 5.

The effective date at the top always reflects the current version. For a material change — a new category of information, a new purpose, a new recipient — we will give notice on the website before it takes effect, and by email where we hold your address and the change affects you.

We will not apply a materially different use to information we already hold without asking you first. If we ever wanted to use existing photographs for a new purpose, we would ask for consent rather than announce it in an updated policy.

Contacting us

Privacy questions and any request under this policy:

Attn: Privacy Privacy requests · General ·

We answer privacy requests ourselves. There is no ticket system and no form to fill in — an email describing what you want is enough.