Privacy
Effective October 4, 2026
Information you provide
Handfair stores your email address, account type and session records, profile details, uploaded photos, listings, saved items, collections, follows, commission requests, support cases, private maker conversations, uploaded digital deliverables and instructions, account privacy requests, and product reviews. When purchases are available, we also store order details, shipping addresses, tracking, messages, and payment references. You choose the content you add.
Photos are resized and compressed before upload. We store the compressed version, not your original file. Image metadata is removed during compression.
How it is used
We use this information to sign you in, save your work, display published content, connect buyers and sellers, fulfill orders, provide support, and prevent abuse. Email sign-in uses a one-time code; we do not store account passwords. Where email delivery is configured and activated, marketplace messages and purchase updates follow your notification settings. Delivery records distinguish sent, failed, and uncertain attempts; runtime configuration alone does not prove receipt.
Publishing a product, profile, or collection makes its shared content available to visitors, including people with its link. Private drafts are not published automatically. Handle changes appear immediately on an already public profile; other draft edits stay private until you publish again. A claimed handle stays reserved while your profile is private.
A posted review displays its rating, text, date, and the profile name used when it was posted. Review photos you attach also become public with the review while the review and its public placement remain visible. Reviews can remain public after a refund. Removing a photo from your review ends that public attachment; copies already saved by visitors may remain.
Who receives it
Cloudflare provides hosting, database, photo storage, security, and account and marketplace email delivery. When payments are enabled, Stripe processes payment and seller onboarding information under its own privacy policy. Card details are entered on Stripe’s hosted checkout and are not stored by Handfair.
A commission’s brief, reference image, quote, and participant names are visible to its buyer and seller. Personalization reference photos at checkout remain private to their buyer and become available to the order’s maker after confirmed payment. Maker conversations and their attachments are limited to their participants; support cases and submitted evidence are available to their participants and authorized support staff. Digital PDF/ZIP deliverables and instructions are available to their owner and entitled paid buyers, with purchase versions frozen when ordered. Refunds can end download access; unresolved payment disputes or holds suspend it until the payment is eligible again. Made-to-order digital listings disclose public processing terms and promised formats. Each purchase retains its original terms and private buyer text brief; those private order records are available to the participants. These purchases have no initial file bundle. Makers explicitly record private file delivery for that order, and the selected files, instructions, notes and delivery history are retained under the same purchase access rules. Sellers receive the buyer and shipping information needed for their orders. They must use it only to fulfill the order and provide related support. We do not sell your personal information or share it for third-party targeted advertising.
Public image links and links to other websites may contact those providers when opened. Their privacy practices apply on their services. We may also disclose information when required by law or necessary to investigate misuse and protect users.
Staff receive separate support, moderation, and finance permissions. Moderators can review listing drafts, published content, and account information for moderation; support staff can handle assigned and authorized case, recovery, and privacy queues. Financial records and actions require finance permissions. Founder verification, strong account-removal and recovery decisions, and staff permissions remain restricted to the owner administrator. Moderation actions and their reasons are recorded in an access-restricted activity log. Hidden content is retained so decisions can be reviewed and reversed. Scoped staff investigations retain linked records, evidence notes and human decisions. Candidate flags do not automatically determine guilt, restrict accounts or move money. Public shop activity indicators show aggregated response and shipment-recording evidence only after at least five samples from five distinct customers; private buyer contacts and investigation notes are not part of those indicators.
Cookies and basic reporting
Essential first-party cookies keep your browser workspace, sign-in session, and verification request connected. Fully verified sessions expire after 30 days. When you enable an authenticator, a new email-code session has ten minutes to complete the second factor and cannot open your saved workspace before verification. Authenticator secrets are encrypted at rest, recovery codes are stored as one-use hashes, and session names you enter are labels rather than verified device identities. Your appearance preference is stored on your device. We do not use third-party advertising trackers.
Creatives can see sales, refunds, order activity, and stock information for their own shop. Customer emails and shipping addresses are not included in sales analytics.
Optional marketplace analytics is off until you allow it on your device. It honors Do Not Track and Global Privacy Control. Consented piece and shop activity, search terms, referral domains, and source, medium, and campaign labels use temporary browser sessions and daily pseudonymous hashes. Reports do not attach your account email or shipping address, and do not store full referral URLs or raw IPs. Avoid personal details in search terms or campaign labels. Sensitive search terms are removed; search and referral groups below three observed sessions are withheld. Raw activity and optional order attribution are removed after 90 days. Turn optional reporting off in its privacy control to stop future activity collection and clear the device session.
Promotions use aggregate views and clicks, with daily hashes and rate limits to reduce repeated counts. Existing site cookies or a coarse IP/browser grouping may be used to calculate those hashes. Raw IP addresses are not stored in promotion reporting. Cloudflare may process request and network information to operate and protect the service.
Retention and your choices
Saved work stays with your account or browser workspace until removed or handled through an account request. Sign-in codes expire after 10 minutes; expired verification and session records are cleaned up periodically. Submitted commission requests and their reference photos remain available to their participants, including after a request is closed. Order, payment, and security records may need to be retained for accounting, disputes, fraud prevention, or legal obligations.
You can edit your profile, remove private content, revoke shared links, and turn off release updates in the site. Previously completed order records and copies already made by other users may remain. Signed-in account settings let you list and revoke sessions, enable an authenticator, verify an email-address change with both addresses, and submit tracked export, correction, and removal requests. Exports contain your own structured JSON, uploaded-file metadata, order-linked financial observations, your payout records, and financial sync or expense receipts you submitted. They exclude raw payment-provider bodies and bank details; uploaded file bytes are not bundled into the JSON. Account removal requires verified ownership and staff review of outstanding orders, returns, parcels, refunds, payment disputes and holds, cases, commissions, and promotions. A paid made-to-order digital purchase awaiting maker files remains an outstanding obligation until files are recorded or a full refund is verified. It ends sign-in, removes the public profile and saved workspace/address data, and removes unused uploaded files through tracked cleanup. Completed purchase and participant-message records, shop transaction settings, payment/security histories, and files required by paid purchases remain retained. Cleanup failures remain visible for retry, and provider-held information requires separate fulfillment. If you lose the account email, account recovery verifies an accessible contact address and opens a staff request; independent ownership review is required before an identity transfer. You may also contact support@creativescreative.com. We verify ownership before acting.
Moderation notices and appeals
New visibility restrictions and restorations include a private explanation for the affected account. Your account settings show these notices and whether a current restriction can be appealed. Linked appeals keep your submitted text, evidence links, support conversation and recorded outcome together. Historical internal staff reasons are not copied into your notices.
Notices, read receipts and appeal decisions remain retained moderation and support history. Your own structured export includes your notice explanations and linked appeal outcomes; it excludes internal staff reasons and staff identities from those records. Automatic visibility notices and appeal decisions appear in the site. Human support replies follow the existing support notification settings.
Contact and changes
Accounts are for people 18 or older. If you believe a child has provided information, contact us so we can investigate. We update this notice when the service changes and show the effective date above.
Privacy questions: support@creativescreative.com.