Store policies

Privacy policy

Effective date: October 9, 2026

What this policy covers

This page describes information flows visible in the VibeCrate storefront code as of the effective date. Some features depend on platform configuration. The policy is not legal advice and has not been reviewed by a lawyer.

Information you enter or create

  • Gift finder: The recipient, style, and budget choices are held in the page while the recommendation is calculated in your browser. The code does not submit a separate quiz response to the storefront database. PostHog autocapture, when analytics is configured, may record interactions with page controls, so we cannot promise that quiz interactions are never included in analytics data.
  • Shopping cart: Cart items are saved in your browser's local storage so the cart can persist between visits on that browser.
  • Account: If you choose to create an account, the sign-up form asks for your name, email address, and password. Account sign-in is handled through the site's Convex Auth integration.
  • Email contact: The site has no contact-submission form or newsletter signup feature in the code reviewed. If you email us, your email provider will handle that message and its contents.
  • Orders: Checkout is hosted by MadeThis rather than by a card-entry form on this storefront. When an order is sent back to the storefront for fulfillment, its backend is written to receive and store the order reference, customer email and optional name, purchased items and quantities, order amounts, shipping amount, payment status, and an order-status access token. The storefront code reviewed does not receive card numbers in that fulfillment message.

Analytics and browser storage

PostHog analytics is initialized only when the storefront analytics key is configured. In that case, the code enables page-view tracking, autocapture, and exception reporting; it uses browser local storage and cookies for persistence and disables session recording. The analytics host is configured by an environment setting, with a PostHog US host as the code fallback. We cannot confirm from storefront code alone whether analytics is currently configured or what retention settings apply to the analytics project.

When available, the cart's checkout link can also carry a PostHog distinct identifier, session identifier, and saved UTM campaign parameters to MadeThis for order-source attribution. Incoming UTM source, medium, and campaign values are kept in session storage. Analytics avoids starting on pages with order-status link tokens and redacts those tokens from captured strings.

Store and platform services

The storefront uses Convex for its store backend, including catalog data, accounts, and order records. MadeThis provides the hosted checkout and sends order details to the store's fulfillment endpoint. PostHog may receive analytics events if it is configured. The code reviewed does not establish each provider's complete privacy practices, data locations, retention periods, or subprocessors; refer to their applicable privacy information for those details.

Your questions

For a privacy question or a request about information associated with you, email team@vibeparcel-bhs.madethis.app. We have not verified a specific data-retention schedule or an automated deletion process, so this page does not promise one.