PoliciesPrivacy

Privacy

This page describes how the site works today with data you provide. Full legal terms, retention schedules, and a published contact for privacy requests will be confirmed before full launch — nothing below invents those details.

Cart on your device

Your shopping cart and any promo code you apply are stored in your browser's localStorage so the bag persists between visits. That data stays on your device until you clear site data or empty the cart. At checkout, line items are re-priced on the server so totals match current catalog prices.

Orders & payments

When payment processing is configured, checkout runs through Stripe. Card numbers and payment credentials are handled by Stripe — Dew Theory does not store full card data on this site. Order records keep what is needed to fulfill and support the purchase (items, totals, shipping address you provide, and status). Without Stripe keys, checkout can still run in a local mock mode for development; that is not a live payment path.

Booking & virtual consultation

Appointment requests and virtual-consultation intake collect the information you submit so Emily can prepare and follow up. Consultation photos are stored privately — there are no public image URLs. Access is limited to authorized admin views and the secure intake session tied to your consultation. Intake and plan links use private tokens; treat them as personal and do not share them publicly.

Admin sessions

Studio staff sign in through a separate admin area. Sessions use an httpOnly cookie so credentials are not exposed to page scripts. That gate is for operators only — it is not part of the customer account experience.

Email (when configured)

Transactional messages (order or consultation-related) may be sent through Resend when an API key and verified from-address are set. Until then, messages are logged for development rather than delivered. Contact form submissions are handled by the site's contact API for Emily to reply.

What this page does not claim yet

We do not invent third-party analytics vendors, ad networks, or a privacy-officer name. Cookie banners, formal retention periods, and GDPR/CCPA request procedures will be published when Emily confirms the full policy. First-party funnel events may be recorded to understand storefront flow; any additional analytics provider will be named here only after it is actually in use.