DYSTOWNED sells garments. We do not sell, rent, or trade information about you — not to advertisers, not to data brokers, not to anyone. We collect what we need to make pieces, deliver them, support the people who own them, and improve the store — and this page lists all of it. If something is not listed here, we do not collect it.
Account. When you create an account we store your email address, the name you give us, and a cryptographic hash of your password. We never see or store the password itself.
Orders. When you place an order we store what you bought, the price paid, and the shipping address you provide, so we can deliver your pieces and honor returns, exchanges, and the records tied to a DUID.
Payment. Payments are processed by Stripe. Your card number goes directly from your browser to Stripe and never touches our servers. We keep only Stripe's reference to the transaction.
Your dysto and manifest. The contents of your dysto live in your own browser. If you are signed in, they sync to your account so they follow you between devices. Your manifest is stored with your account.
DUID registration. When you register a piece, we store the link between the DUID and your account so ownership can be verified.
Newsletter. If you subscribe, we store your email address and when you subscribed. Unsubscribing is honored permanently.
Messages. If you write to us through the contact form, we keep the message and the details you include so we can reply.
Product analytics. On the live site we record how the store is used — pages opened, products viewed, what goes in and out of your dysto, checkout progress, and session recordings of how the page was used. This is described in full in the next section.
We use PostHog for product analytics and session replay. It records page views and page-leave events, product and checkout activity (what you view, add to your dysto, and buy), and session recordings — a replay of clicks, scrolling, and typing on the page. Passwords are always masked in recordings, and card details are entered inside Stripe's own frame, which recordings cannot see. Analytics runs only on the live site — never in development — and its requests are proxied through dystowned.com/ingest rather than being sent to a third-party domain from your browser.
A personal profile is created when you sign in or complete an order. It links your activity to your email address so we can support you, honor the records tied to your pieces, and understand what to make next. If you browse without signing in and never order, your activity stays under an anonymous identifier.
You can turn all of this off with one click: the Privacy Choices control in the Legal Area. We also honor the Global Privacy Control signal automatically — if your browser sends it, analytics is off without you doing anything. Visitors in the European Union, the United Kingdom, and the wider European Economic Area are not tracked at all: for those regions, analytics is never loaded in the first place.
What we do not run: no advertising trackers, no ad cookies, no third-party tracking pixels, no fingerprinting scripts, and no data broker enrichment. We do not profile you for advertising, and we do not buy data about you from anyone.
If this ever changes, this page will say so plainly before it takes effect.
We set a session cookie when you sign in — it is what keeps you signed in, and nothing else reads it. Your dysto is kept in your browser's local storage. PostHog sets its own cookie so a repeat visit is not counted as a new one. We set a dysto_country cookie holding only your country code, which is how we know not to load analytics for visitors in regions that require opt-in consent, and a dysto_tracking cookie holding your Privacy Choices setting — a cookie rather than local storage so our servers honor your opt-out too, not just your browser. That is the full list.
We rely on a small set of processors, each only for its narrow job: Stripe (payments), Vercel (hosting), MongoDB (our database), Cloudflare (image and media delivery), Resend (transactional email such as order confirmations and password resets), and PostHog (the product analytics described above). Each receives only what its job requires.
One optional feature is worth naming precisely: the shipping estimate in the dysto sidebar has a "use my location" control. If — and only if — you tap it, your browser sends your coordinates to BigDataCloud to look up a postal code. We never see or store the coordinates, and nothing happens unless you ask for it.
Beyond processors, we disclose information only if the law compels us to, and only the minimum compelled.
Order records are kept as long as tax and accounting law requires. Newsletter addresses are kept until you unsubscribe. Contact messages are kept until resolved, then removed on request. Accounts are kept until you ask us to delete yours — then we delete it, keeping only what order law obliges us to retain.
You can ask us what we hold about you, ask us to correct it, or ask us to delete it — whoever you are, wherever you live. Write to us and we will act on it. Residents of California and the European Union have additional statutory rights, described on our CCPA and GDPR pages.
Passwords are hashed, transport is encrypted, payment data never reaches our infrastructure, and administrative access to customer data is restricted by role. No system is perfect; if a breach ever affects your data, we will tell you directly and quickly.
This site is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has given us information, contact us and we will delete it.
When this policy changes, the date at the top changes with it, and material changes will be announced on the site before they take effect. The current version always lives at this address.
Email: contact@dystowned.com