Our privacy policy
We only use data needed for your order, your question, the security of the store, a newsletter you choose yourself and our own measurement of visits. That measurement recognises a visit only within the same day, by a visit hash, and rests on our legitimate interest. For measurement by Google, Meta and Microsoft Clarity we only use data if you say yes. We do not sell anything to third parties.
Last updated: 25 September 2026
Who We Are
- Data controller
- Miron Digital (trading as Studio Miron)
- Address
- Deken Darraslaan 5 bus 101, 8700 Tielt, Belgium
- Company number
- 0793239175
- VAT number
- BE0793239175
- hello@studiomiron.com
- Phone
- +32 (0)51 58 40 52
We are based in Belgium and work from our own studio there. We deliver throughout the European Union, the United Kingdom, the United States and Canada. What you order is designed, printed and packed by us, so your details do not go to an external print shop.
What Data We Collect
- Order details: your name, email address, billing and delivery address, phone number if you provide it, order number, chosen products, version and quantities.
- Customer account: your sign-in status and the profile, contact and address details you view or save in your account. Your account lives in the same secured store environment as your orders; our site itself only stores the strictly necessary cookies that keep you signed in.
- Personalisation details: the text you have printed on a card, game, invitation, poster or sign. Usually that is a name, a date or a short sentence. If you choose the personalised version, that text travels with your order exactly as you typed it. A note you add to your order is also stored with that order. Only enter details you want processed on the product and in your order.
- Payment details: we see whether a payment succeeded and with which method. Your full card or account details never reach us. The payment provider processes those.
- Communication: your name, email address and whatever you email us or send through the contact or cancellation form, including order number and return details when they are needed.
- Newsletter details: your email address, confirmation status and unsubscribe status.
- Technical data: IP address, time, browser and request data and limited server logs for security and troubleshooting. Your cart uses two necessary cookies and temporary session storage to restore focus. We also store in your browser your cookie choice and a list of the products you recently viewed; that list stays in your browser for at most 30 days and is not sent to us. If our server cannot confirm your choice at that moment, we remember that within this browser tab so your choice is not sent to us again on every page view; that flag is functional and not strictly necessary. If you dismiss the mix and match bar at the bottom of the screen, we remember within this browser tab that it should stay closed; that flag is strictly necessary for the dismissal you requested. See our Cookie Policy.
- Statistics data: page and product views totalled per hour, language, market and device category, plus store steps such as searching, adding to or removing from the cart and starting checkout. For an add we also count the product, Shopify variant and quantity. This hourly statistic stores no raw events, IP address, search text, cookie, or visitor, session, cart or order ID. In addition, our server, never your browser, calculates a visit hash for every event: a SHA-256 hash of a random secret that our own dashboard issues for each day, your IP address, your browser's user agent and the address of this website. The server uses your IP address and user agent only in memory for that calculation; they are never stored, logged or passed on. The secret changes every day (UTC), so the same browser gets a different hash the next day, visits cannot be linked across days, and the hash cannot be turned back into an IP address. Under that hash we store, for each visit, its steps and the origin it started with: the referring website (domain name only), the source, medium, campaign, content and term from the link, whether you arrived through an ad click from Google or Meta (only yes or no, never the click ID itself) and the first page of your visit. The measurement places nothing on your device, and we do not link a visit to your name, account or order. Separately, the origin of your visit (source, medium and campaign from the link, without an ID) stays in your browser until you close the tab and is attached to your cart and any order placed from it, so that we can see which campaigns lead to orders.
- Measurement and advertising data, only with your separate consent: Google Analytics measures how the site is used. Google and Meta can link a pseudonymous ad click and browser ID to store steps; Meta's pixel also receives the pages and products you view, what you add to your cart and when you start checkout, with the product IDs, value and currency. After your yes we also measure a purchase through our own server: with an order we pass Google and Meta the order number, the purchase value with currency and product lines, and the pseudonymous click and browser IDs from our attribution cookies, without name, email address, postal address or IP address, not even in hashed form. Without a yes, no purchase goes to Google Ads or Meta; Google Analytics then only receives the order itself, without a cookie or ID that points to you. Microsoft Clarity records, for session recordings and heatmaps, where you click, how far you scroll and how you move the mouse; what you type into fields and the text you have printed on a product are masked. All the details are in our Cookie Policy.
How We Use Your Data
- Processing your order, making and printing it in the studio, sending it and invoicing it. Legal basis: performance of the contract.
- Letting you sign in and showing and updating your profile, addresses and order details in the customer account. Legal basis: performance of the contract about the customer account that you conclude with us when you create the account.
- Answering your questions and complaints. Legal basis: performance of the contract or our legitimate interest.
- Meeting our legal obligations, such as the retention requirement for invoices. Legal basis: a legal obligation.
- Sending you a newsletter, but only if you consent yourself. Legal basis: your consent. You first confirm through a link and a button. After that you can unsubscribe with one click.
- Limiting form abuse, duplicate submissions and technical attacks and fixing outages. Legal basis: our legitimate interest in keeping the store and mail service secure and available.
- Understanding which channels bring visits and orders and which pages and products help visitors, and improving the store with that knowledge, through our own cookieless visitor statistics with a visit hash that changes every day. Legal basis: our legitimate interest under Article 6(1)(f) GDPR; the measurement applies to every visitor, with or without a yes in the cookie banner, sets no cookie and does not go to Google or Meta, and we do not link a visit to your name, account or order; only the origin of your visit (source, medium and campaign from the link, without an ID) stays in your browser until you close the tab and is attached to your cart and any order placed from it. You have the right to object to this processing; questions or objections: email us.
- Measuring how the site is used and whether ads through Google or Meta bring visitors and paid orders, so we can pay for advertising by its results. Legal basis: your separate consent, through the cookie banner. A purchase only goes to Google Ads and Meta when the order carries a valid consent marker; without a yes, Google Analytics only receives the order itself, without a cookie or ID that points to you. You can withdraw this choice at any time with the Cookie settings button.
- Seeing where visitors get stuck, with session recordings and heatmaps from Microsoft Clarity, so we can improve the site. Legal basis: your separate consent, through the same single question in the cookie banner. What you type into fields and the text you have printed on a product are masked, we never load Clarity in your customer account, and you can withdraw this choice at any time with the Cookie settings button too.
We do not use your data to build profiles, and we do not sell your personal data to third parties.
Who Has Access to Your Data
- Shopify, the platform behind our store: that is where your customer account, the cart, checkout, payment and order management run. Shopify receives your profile, address, order and contact details and, for a personalised product, the text that goes on it, so your order can be made.
- Payment providers at checkout: process the data needed for the payment method you choose. Which provider that is depends on the method and is shown at checkout. We never receive a full card or account number.
- The carrier: receives your name, delivery address and the necessary delivery details.
- Vercel, the company that hosts our site: this means technical data is processed, such as your IP address, the time and browser data. What you enter in a form or your cart also passes through those servers.
- SEO Overview and Supabase, our own visitor statistics: our internal dashboard sends only the limited statistics fields above to our Supabase database in the selected EU region. There we store hourly and daily totals and, for each visit, the visit hash with the steps and origin of that visit. Your IP address and user agent are not sent there, and visits cannot be linked across days. No cookies are set and nothing is stored on your device for this.
- OpenFreeMap, the service behind the map images: only on the map poster page. As soon as the map appears, your browser loads the map images and their fonts straight from OpenFreeMap, based on OpenStreetMap data. This happens automatically while the map loads, so it happens even if you never search for anything yourself. OpenFreeMap sees your IP address, your browser details and which part of the map you request. We add no name and no account to that, and we do not record which crop you are looking at; only what you order in the end ends up in your order.
- Photon (Komoot), the place search: only when you look up a place on the map poster page or the star map page. That search does not leave your browser directly but goes through our own server, which passes on the search term and nothing else. Photon therefore sees the IP address of our server and not yours, and receives no name, no account and no other browser details. We do not keep the search term.
- Microsoft (Clarity, session recordings), only with your separate consent: receives through Clarity how this site is used (where you click, how far you scroll and how you move the mouse), plus technical data such as your IP address, browser and device type, for session recordings and heatmaps. What you type into fields and the text you have printed on a product are masked in those recordings, and we do not load Clarity on the pages of your customer account. Microsoft processes this for us as our processor. Without your yes, Clarity does not load and nothing is recorded.
- Google and Meta (site and ad measurement), only with your separate consent: Google receives through its measurement code how our site is used and, after your consent, can measure which ad brought you to our site, which store steps followed and whether a purchase came of it. Google is independently responsible for that and acts according to its own privacy policy. After your yes, Meta receives through its pixel which pages and products you view, what you add to your cart and when you start checkout, with the product IDs, value and currency. A paid order also goes server-side to Google and Meta, with the order number, the purchase data listed above and the pseudonymous click and browser IDs, without name, email address, postal address or IP address, not even in hashed form. As long as you have not said yes, we load nothing from Google or Meta: there is no code from them on the page, so they receive no signal from your browser and no purchase goes to Google Ads or Meta; Google Analytics only receives the order itself, without a cookie or ID that points to you. If you withdraw a yes you gave earlier, the code loaded at that moment immediately receives a denial signal, and after that nothing loads anymore.
- Judge.me, our review platform: manages the reviews customers write about our products and our store, and requests them by email after an order. If a review includes a photo, that photo loads directly from the Judge.me servers; at that moment Judge.me receives your IP address and browser data. The review texts themselves we collect when building the site, not from your browser, and of each review we only show the display name its author chose.
- Resend, our mail provider (United States): sends our email and processes recipient, sender, subject, message content and delivery metadata for that. This includes newsletter confirmations, contact and cancellation messages and the confirmation of receipt of a cancellation. Contact and cancellation emails also arrive in our own mailbox.
We may also share data when the law requires it, or with professional advisers bound to confidentiality. The visitor statistics set no cookie; only the origin of your visit stays, without an ID, in your browser until you close the tab; measurement by Google, Meta and Microsoft Clarity stays off until you switch it on through the cookie banner. Without your consent there are no advertising pixels or tracking cookies on our site.
International Transfers
We are based in the European Union. The United Kingdom recognises the European Economic Area as offering an adequate level of protection, so your data can be transferred to and processed in our systems in the EU. Shopify, the platform behind our store, is Canadian and may process data in Canada and other countries; for Canada, UK adequacy regulations apply where relevant. For other transfers we rely on the safeguards the UK GDPR allows, such as the International Data Transfer Agreement or the UK Addendum to the standard contractual clauses of the European Commission. Resend, our mail provider, processes data mainly in the United States and uses the Data Privacy Framework with its UK Extension alongside those contractual safeguards. Vercel, which hosts our site and internal dashboard, also uses appropriate safeguards for transfers outside the United Kingdom and the EEA. Our own visitor statistics, including the data per visit, are stored in our selected Supabase region in the EU. Judge.me, our review platform, may process data outside the United Kingdom and the EEA; if a review photo is shown, Judge.me receives your IP address. That transfer rests on appropriate safeguards. If you switch on the measurement, Google and Microsoft are certified under the Data Privacy Framework and its UK Extension, and Meta may process data in the United States under its applicable transfer safeguards. You can email us if you want more information or a copy of these safeguards.
Data Retention
- Invoices and accounting records: 10 years. That is the retention period Belgian VAT law prescribes for invoices and bookkeeping, and it applies to us because we are based in Belgium. Other order details, including the personalisation text belonging to your order, are only kept as long as they are needed for warranty, complaints and a possible dispute.
- Profile and address details in your customer account: as long as your account is active or as long as they are needed for the service. You can ask us to delete the account and this data. Data that is also part of an order or invoice is afterwards only kept as long as the legal retention requirement or an ongoing dispute demands.
- The print files we prepare in the studio for your order: no longer than needed for production, delivery, reprints and complaint handling.
- Email contact: 2 years after the last message.
- Newsletter: active until you unsubscribe. After that, our mail provider only keeps your email address and unsubscribe status on a suppression list, as long as needed to respect your unsubscribe. That data is not used to send newsletters.
- Technical logs: per the limited retention period configured at the company that hosts our site. We only keep them longer if needed to investigate a specific security incident.
- For form security we keep hashed keys for at most 24 hours and only inside the active server function. Your email address itself is not stored in that counter.
- Our own visitor statistics: data and steps per visit for 90 days, daily totals for 400 days. The secret for the visit hash exists at most until the end of the following day; we do not store your IP address or user agent for this at all.
- The cart cookies: 14 days.
- The cookies for measurement by Google, Meta and Microsoft Clarity, only after your yes: from one day to about two years, as listed for each cookie in our Cookie Policy. Our own attribution cookies: up to 90 days, or shorter if you withdraw your consent.
Your Rights
You have the right to access your data, have it corrected or deleted, have the processing restricted, object, and have your data transferred. If you gave consent, you can withdraw it at any time; that does not affect the lawfulness of the processing carried out on the basis of your consent before you withdrew it.
Email us at hello@studiomiron.com. We respond as soon as possible and at the latest one month after receiving your request. You can always lodge a complaint with a supervisory authority, without contacting us first: in the United Kingdom that is the Information Commissioner's Office (ico.org.uk), and you can also contact the Belgian data protection authority (Gegevensbeschermingsautoriteit, gegevensbeschermingsautoriteit.be), which supervises us because we are based in Belgium.
Children's Privacy
Our store is meant for adults ordering something for a baby shower, a birth, a wedding or another celebration. Our services are not directed at children under the age of 13 and we deliberately do not ask children for data. If you put your child's name or date of birth on a card, game or poster, we only use it to make and send that product.
Do you think we have still received data about a child that should not be with us? Email hello@studiomiron.com and we will delete it.
Data Security
The site runs entirely over an encrypted connection. Your cart lives in a cookie that JavaScript in your browser cannot read (httpOnly). Payment details go directly to the payment provider and never pass through our servers.
Access to order and customer data is limited to those who need it to make your order, send it or answer your question. If you still notice something that seems wrong, let us know through our contact page.
Questions?Happy to explain it in plain language.
Contact us