Privacy Policy

Last Updated: July 24, 2026

Table of Contents

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Sharing Your Information
  5. Children's Privacy
  6. Data Retention
  7. Security
  8. Your Rights & Choices
  9. California Privacy Rights (CCPA/CPRA)
  10. International Transfers
  11. Changes to This Policy
  12. Contact Us

1. Introduction

This Privacy Policy describes how Lampstand Digital LLC ("Company," "we," "us," or "our"), doing business as Artos, collects, uses, and discloses your information when you use our website and marketplace platform (the "Service").

We are based in New Hampshire, USA. This Privacy Policy is a notice about our practices, not a request for blanket consent. Where consent is required, we ask separately through the relevant setting or workflow. Other processing may rely on performing a contract, legal obligations, legitimate interests, or another lawful basis available under applicable law.


2. Information We Collect

We collect information necessary to operate a safe, community-focused marketplace. This includes data you provide directly, data collected automatically, and data from third-party sources.

A. Information You Provide

  • Account Registration: When you sign up, we collect your name, email address, and username. Authentication is handled securely on our servers; we do not store raw passwords, only secure hashes.
  • Guild Membership Verification (Sensitive Data): To evaluate and maintain eligibility for the Artos Vendor Guild, applicants, members, and entity representatives must attest to the Eastern Orthodox affiliation required by the Guild Bylaws. We collect the relevant Parish and Priest information for this purpose.

This information is collected only for Guild and seller eligibility. Buyers are not required to provide religious affiliation to shop on Artos.

Note: This is considered sensitive personal data. We verify this manually or via limited audit and do not use it for marketing.

B. Religious Affiliation Data (Special Category)

Under data protection laws, information about your religious beliefs is classified as "special category data" requiring explicit consent under GDPR Article 9. We collect this information to:

  • Evaluate and maintain your eligibility for Guild membership
  • Maintain the integrity of the Guild and marketplace community
  • Contact your priest for verification if needed

What data we collect: Parish name, priest's name, and any supporting verification statement or correspondence provided during the Guild membership application or a later membership review

Legal basis: Explicit consent under GDPR Article 9

Purpose: Evaluating Guild membership eligibility and maintaining Guild and marketplace integrity

Retention: Retained while a membership application, Guild membership, or related seller status remains active. If membership or seller status ends, or an application is rejected, we delete or anonymize this verification data within 90 days unless it must be kept longer for an active dispute, fraud review, or legal hold.

Sharing: Accessible only to authorized verification staff and disclosed only to the parish or priest you provide, and only as needed for verification

Your rights: You may withdraw consent at any time by contacting support. If you withdraw consent, seller privileges will be suspended pending Steward review, and your seller account or Guild membership may be suspended or terminated if verification can no longer be maintained.

  • Shop & Seller Information: If you are a Seller, we collect your Shop Name, Description, Logo, Return Policy, and applicable Business or Return Address for shipping and marketplace operations.
  • Orders, Guest Checkout, and Saved Addresses: When you place or receive an order, we process the buyer's name, email address, phone number where provided, billing and shipping addresses, order contents, customizations, delivery instructions, discounts, taxes, payment and refund status, shipment and tracking information, and related support or dispute records. A guest purchase is linked to a temporary guest and cart-session record rather than a registered buyer profile. Signed-in buyers may choose to save addresses to their account.
  • Recurring Shop Subscriptions: If you buy or administer a recurring shop subscription, we process the selected offering and billing interval, subscription and Stripe identifiers, billing and cancellation status, current billing period, delivery address, payment or failure status, delivery credits, monthly cycle records, and subscription-generated orders. We do not store the full payment-card number.
  • Artos-Assisted Seller Setup: If you authorize us to help set up your seller account, shop, or listings, we may collect or enter information you provide to us, authorize us to prepare, or make publicly available from sources you identify, including seller name, email address, shop profile details, product listings, product images or image URLs, descriptions, categories, variants, prices, inventory, shipping profiles, return policy, source URLs, and related setup notes. Guild eligibility verification and religious-data consent must still be completed directly by the applicant or authorized representative while signed in.
  • Shop Sync Imports, Exports, and Order Routing: Shop Sync lets Sellers upload seller-exported Shopify or Etsy CSV files, create platform-formatted CSV exports, manage inventory across warehouses or other locations, and route Artos fulfillment information to ShipStation or a Seller-chosen HTTPS webhook. Depending on what the Seller uploads or enables, we may process product listings, variants, SKUs, prices, inventory by location, warehouse names and addresses, external order identifiers, order contents, buyer names, email addresses, phone numbers, shipping addresses, fulfillment status, tracking data, file and row metadata, import/export history, webhook destinations, delivery attempts, and related errors. Artos does not receive a Seller's Shopify or Etsy account password through these CSV workflows. Shopify and Etsy are not affiliated with, endorsed by, or responsible for Artos.
  • Print-on-Demand Production: For Artos print-on-demand listings, we process Seller production files, file names, checksums, print areas, page counts, provider product identifiers, production attributes, preview and rights attestations, supplier quotes and charges, and production status. For an order, we also process the recipient name, email, phone number where provided, shipping address, order contents, delivery method, provider order identifiers, shipment and tracking data, and support or defect evidence.
  • Seller Media Library: We store media uploaded by Sellers and authorized collection managers, including the file, original and display names, alt text, tags, storage and processing metadata, usage locations, lifecycle status, and related audit records. Media may contain personal data chosen by the uploader and may become public when used in a published shop, product, campaign, profile, or collection.
  • Marketplace Programs, Referrals, and Curated Collections: If you apply for or participate as an Ambassador, Parish Partner, Seller referrer, or curated-collection manager, we may collect profile and application details, public biography and social links, parish or organization contact details, invitation email addresses, referral codes, attribution and conversion records, collection content, access history, commission and payout status, and Stripe Connect identifiers. Sellers participating in Vendor Referrals can see the referred shop's name, attribution date, qualifying-sale count, and reward status, but not the referred shop's buyer identities through that dashboard.
  • Reviews, Wishlists, and Other Content: We collect content you submit, publish, or share through the Service, such as reviews, public wishlists, Ambassador Picks, curated collections, shop pages, support requests, reports, roadmap suggestions, and related moderation records. Content you mark public is visible to other users and may be indexed by search engines.
  • Charitable Impact Records: When Artos allocates part of its retained marketplace revenue to an active charitable campaign, we associate the order with the campaign, buyer or guest record, shop, currency, retained-revenue amount, allocated amount, refunds or chargeback adjustments, and monthly totals. Sellers receive only aggregated shop impact; buyer identities are not included in that view. These records do not treat the buyer as the donor.
  • Billing and Transaction Data:
    • Buyers: We collect your order, contact, billing, and shipping information to process purchases and fulfill orders. We never store your full credit card number; marketplace payment data is processed directly by Stripe.
    • Sellers: To receive marketplace payouts, you must provide banking and tax information directly to Stripe via Stripe Connect. We do not see or store your full bank account details.
    • Seller Add-on Subscribers: Seller add-on subscriptions, including Shop Sync, custom storefront domains, and email marketing, are processed through Stripe Checkout. Stripe shares limited subscription metadata with Artos, such as customer and subscription identifiers, feature or price, currency, trial dates, billing status, renewal or cancellation state, and payment-method status. We use this metadata to activate, administer, support, and audit the feature.
  • Communications: We store messages sent through our "Contact Seller" feature and chats with our support team.
  • One-Time Shop Launch Notifications: If you ask to be notified when an empty shop posts its first active product, we collect your email address, the relevant shop, your consent timestamp and the consent text shown to you, notification and cancellation status, and related delivery metadata. If you are signed in, we may associate the request with your account. For guests, we store a one-way hash of a browser removal token so the notification can be cancelled from the same browser. The launch-alert request does not itself add you to a marketing list.
  • Artos Marketing Opt-Ins: If you separately choose to receive Artos news and promotions, we send your email address to our email provider for the Artos shopper audience and retain the provider's subscription, unsubscribe, and delivery records. This platform-wide choice is separate from the one-time launch alert and from any Seller's marketing list.
  • Seller Email Marketing Opt-Ins: If you choose to receive marketing emails from a specific shop, we store your email address, optional name, consent source, consent timestamp, unsubscribe status, and related delivery metadata for that shop's email list.
  • Audit, Authorization, and Acknowledgment Records: We keep records of certain admin actions, Artos-assisted setup authorization requests and responses, email-token approvals, seller product-edit authorization requests and responses, access to sensitive verification data, approval decisions, enforcement reasons, and other compliance or support activity.

C. Information Collected Automatically

  • Log & Performance Data: We use logging services to collect error reports and monitor performance. This may include your IP address, browser type, operating system, and details about crashes or bugs you experience.
  • Analytics & Usage: We analyze how users interact with our platform to improve user experience and features.
  • Cookies: We use essential cookies for session management (keeping you logged in) and functional cookies to remember your preferences (like "Dark Mode").

3. How We Use Your Information

We use your data for the following specific purposes:

  1. Service Operation: To create accounts, support Artos-assisted shop setup, process guest and account purchases, calculate shipping rates, arrange print-on-demand production and white-label fulfillment, provide shipment tracking, operate media and content tools, and deliver digital downloads.
  2. Billing and Subscription Administration: To activate paid features, verify trial or subscription status, process marketplace payments and payouts, administer recurring buyer subscriptions and Seller add-on subscriptions, allocate subscription delivery credits, handle cancellation and payment failures, provide support, and maintain billing audit records.
  3. Shop Sync Operations: To validate and apply Seller-provided CSV imports, create Seller-requested CSV exports, maintain inventory by warehouse or location, route orders and shipment updates to ShipStation or Seller-chosen webhook recipients, retry failed deliveries, provide audit history, and troubleshoot errors. Imported customer/order data is used for marketplace operations, fulfillment, support, fraud prevention, debugging, and legal compliance, not unrelated marketing.
  4. Community Integrity: To evaluate and maintain Guild membership eligibility and administer the membership requirements in the Guild Bylaws.
  5. Programs, Referrals, and Public Content: To administer Ambassador and Parish Partner programs, Seller referrals and fee rewards, attribution, commissions and payouts, curated-collection invitations and permissions, reviews, wishlists, campaigns, and published marketplace content.
  6. Charitable Impact: To calculate, adjust, and display how eligible purchases helped Artos allocate retained marketplace revenue to active charitable campaigns. Buyer-facing history is account-specific; Seller-facing history is aggregated and excludes buyer identity.
  7. Support & Communication: To send transactional emails such as order confirmations, subscription and billing notices, collection invitations, shipping updates, review reminders, and password resets, and to respond to support inquiries.
  8. One-Time Shop Launch Notifications: To send the one-time notice you requested when a shop posts its first active product, manage cancellation and delivery, and tell the relevant Seller that someone is waiting for the shop to launch. The Seller receives only a partially masked version of your email address as an interest signal and may turn off these signup alerts. Your launch-alert request does not itself enroll you in marketing or give the Seller permission to contact you.
  9. Artos Marketing: To send Artos news and promotions when you make a separate, optional marketing choice. Artos marketing emails include an unsubscribe path, and cancelling a one-time shop launch alert does not change this separate preference.
  10. Seller Email Marketing: To allow Sellers to email contacts who explicitly opted in to that Seller's updates through checkout, shop signup forms, product waitlists, or consent-confirmed imports. Seller marketing emails are optional and include an unsubscribe path. Customer/order data imported through Shop Sync is not added to marketing contact lists unless the buyer separately opted in.
  11. Platform Stability: To monitor system health, debug errors, and prevent fraud.
  12. Legal Compliance: To comply with tax laws, legal processes, maintain audit records, resolve disputes, prevent fraud, and enforce our Terms of Service.

4. Sharing Your Information

We do not sell your personal data. We share information only as follows:

A. Between Users

  • Buyers to Sellers: When a Buyer places an order or starts a recurring shop subscription, the relevant Seller receives the Buyer's name, shipping address, order contents, customizations, and contact or delivery information reasonably needed for fulfillment, customer service, returns, safety notices, and disputes. Sellers may not use this information for unrelated marketing without separate consent.
  • Shop Launch Interest: When someone requests a one-time shop launch notification, the relevant Seller may receive a signup alert containing a partially masked version of the subscriber's email address. The Seller receives the masked address only as an interest signal and is not permitted to use it to identify, contact, or market to the subscriber.
  • Sellers to Buyers: A Seller's shop name, legal or business name when applicable, and return address may be visible on shipping labels or other order documents.
  • Public and Program Information: Information you choose to publish in a shop, public wishlist, review, Ambassador profile or Pick, curated collection, or similar public surface is shared with visitors. Authorized admins and collection managers may see the names or account emails of other managers and invitation recipients as needed to administer access. Referral participants may receive limited shop-level attribution, conversion, commission, payout, or reward information, but not unrelated buyer personal data.

B. Third-Party Service Providers (Sub-Processors)

We share data with specific service providers who perform services on our behalf or support a transaction you request. They must handle data under their applicable contracts, terms, privacy obligations, and law:

  • Payment Processing and Billing: Stripe processes marketplace and recurring-subscription payments, payouts, refunds, disputes, Seller add-on subscriptions, and connected-account onboarding for Sellers, Ambassadors, and Parish Partners. Stripe shares related customer, payment, billing, payout, and subscription metadata with Artos.
  • Hosting & Infrastructure: Vercel hosts our web application, Convex powers our application database and backend, and Cloudflare R2 stores user-uploaded media and related files.
  • Communications: Resend sends transactional emails, curated-collection invitations, one-time shop launch notifications and related Seller signup alerts, Artos marketing emails, and Seller marketing emails. Resend may hold related delivery metadata, sender-domain records, audience/contact records, unsubscribe status, and suppression records.
  • Shipping and Tracking: Sellers, carriers, and shipping-technology providers such as Shippo may receive order identifiers, carrier and tracking numbers, shipment status, destination details, and other fulfillment information needed to provide rates, register or reconcile tracking, deliver orders, and investigate shipping problems. A Seller may separately use its own shipping provider under that Seller's account and privacy terms.
  • Print Production and Fulfillment: Prodigi receives the production files, print specifications, order reference, recipient name and shipping address, email and phone number where provided, delivery method, and related order metadata needed to quote, print, package, ship, track, cancel, update, or investigate an Artos print-on-demand order. For this fulfillment data, Artos acts as controller and Prodigi generally acts as our processor under its Data Processing Addendum. Prodigi may act as a separate controller for its account administration, billing, security, fraud prevention, support, legal-compliance, and corporate processing. Prodigi may use production labs and carriers in different countries according to the product and destination; some carriers and other recipients may act as independent controllers for their own delivery or legal purposes.
  • Internal Operational Alerts: Slack receives minimized order-alert metadata for authorized Artos operations staff, limited to the shop, an opaque Artos order identifier, aggregate quantity, order total, timestamps, order/payment status, sales channel, Artos fee rates and source, platform commission, platform-managed tax, Stripe processing fee, and seller net amount. Buyer names, email addresses, phone numbers, shipping addresses, product details, customizations, discount details, and payment-provider references are excluded from new Slack alerts.
  • Analytics, Advertising Measurement, and Performance: PostHog, Sentry, and Axiom help us understand product usage, monitor system stability, measure performance, and investigate errors. Where configured, Google's tag and advertising-measurement services process consent signals and, when the required analytics or marketing permission is active, may receive ad-click identifiers and purchase events containing an Artos transaction identifier, value, currency, shipping and tax totals, product identifiers and names, variants, quantities, prices, and shop affiliation. We do not send the buyer's name, email address, phone number, or shipping address in that purchase event. Google storage is denied by default until the relevant choice permits it, and GPC keeps analytics and advertising storage denied.
  • Seller-Chosen Commerce and Fulfillment Tools: Shopify and Etsy data reaches Artos only when a Seller exports and uploads a CSV. When a Seller downloads a platform-formatted CSV, the file is created in the Seller's browser for the Seller to upload or use. If a Seller enables ShipStation or a custom webhook, Artos sends the selected order, customer, shipping, inventory, product, fulfillment, or tracking fields to that Seller-chosen recipient. Those recipients process the data under the Seller's account and their own terms and privacy practices.
  • Charitable Campaigns: Artos may publish campaign names, links, images, and aggregate allocated amounts. Artos does not share a buyer's identity with the campaign organizer merely because a purchase generated an impact allocation. If you follow an external campaign link or donate directly, the destination's own privacy practices apply.

We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation, protect and defend the rights or property of Lampstand Digital LLC, or protect the personal safety of users of the Service.


5. Children's Privacy

The Service is intended for users at least 18 years of age or older.

  • Buyers: Must be 18 or older to use the Service
  • Sellers: Must be 18 or older to enter into binding contracts

We do not knowingly collect data from children under 13. If discovered, we will investigate and delete it promptly, subject to any legal obligation to preserve a limited record.


6. Data Retention

We retain personal data only as long as necessary:

  • Account Data: Retained while your account is active.
  • Transaction Records: Retained for at least 7 years to comply with tax and accounting laws (IRS requirements).
  • Recurring Shop Subscriptions: Subscription enrollment, billing, delivery-credit, cycle, cancellation, payment, refund, and subscription-generated order records are retained while the subscription is active and afterward with the related transaction, tax, accounting, fraud, dispute, support, and legal-hold records. Transaction-linked records may be retained for at least 7 years.
  • Verification Data: Guild membership verification data is retained while a membership application, Guild membership, or related seller status remains active. If membership or seller status ends, or an application is rejected, this data is deleted or anonymized within 90 days unless it must be retained longer for an active dispute, fraud review, or legal hold.
  • One-Time Shop Launch Notifications: A pending notification is retained until the shop posts its first active product, you cancel the request, or the notification is otherwise no longer needed. After a notification is sent or cancelled, its waitlist record is scheduled for deletion within 90 days, unless we must retain a limited record for security, abuse prevention, a legal claim, or a legal obligation. These requests are not retained as Seller marketing contacts.
  • Artos-Assisted Setup, Authorization, and Audit Records: Artos-assisted setup authorization records, seller product-edit authorization records, source references, and governance/audit logs are retained as long as needed for marketplace integrity, support, dispute handling, fraud prevention, legal claims, and legal compliance. If tied to marketplace transactions, disputes, listings, or financial records, they may be retained with the related marketplace records.
  • Shop Sync Records: Uploaded CSV files and staged row payloads are retained for up to 30 days, then removed by an automated cleanup process. Customer-inclusive webhook delivery payloads are retained for up to 30 days; delivery records without customer details are retained for up to 90 days. Import/export audit metadata, warehouse settings, catalog links, destination settings, and applied operational records are retained while the Seller uses the feature or as needed for support, security, disputes, fraud prevention, legal compliance, and enforcement. Pausing a destination stops new sharing through it. Account deletion removes Shop Sync files, staging records, destinations, and non-transactional integration data, subject to the marketplace transaction, tax, dispute, fraud, legal-hold, and other exceptions described below.
  • Print-on-Demand Records and Files: Active production files remain while used by a listing and may be retained with order, provider, accounting, support, defect, dispute, fraud, or legal-hold records. Provider order, quote, charge, shipment, and event records follow the related marketplace transaction retention period. Retiring a listing stops new use of its files but does not remove copies needed to complete or document an existing order. Prodigi uses purpose-based retention for production and quality control, reprints, support, disputes, chargebacks, warranties, accounting, tax, security, fraud prevention, audit, and legal compliance; backups are removed through its standard overwrite cycles.
  • Programs, Referrals, and Invitations: Program applications, public profiles and content, referral and commission records, payout history, Seller referral progress and rewards, collection-manager invitations, membership history, and access events are retained while the program or collection remains active and afterward as needed for payment reconciliation, fraud prevention, access control, moderation, disputes, legal obligations, and audit history. Expired or revoked invitation secrets are not usable, but limited invitation and access history may remain for security and accountability.
  • Charitable Impact: Order-level impact entries and refund or chargeback adjustments follow the retention period for the related order. Buyer, Seller, campaign, and monthly totals may remain as derived accounting and reporting records, subject to deletion or anonymization where applicable.
  • Seller Media: Active or archived media and metadata remain while used by the Seller or related content. Unused assets moved to trash are ordinarily scheduled for deletion after 30 days. Copies embedded in retained orders, disputes, audit records, cached delivery systems, or legal holds may remain longer where necessary.
  • Referral and Attribution Data: First-party referral and Share & Save attribution records generally expire after 30 days unless converted into an order-linked commission, reward, fraud, or accounting record that requires longer retention.
  • Deletion: You may request account deletion from your account settings or by contacting support. Note that we must retain certain marketplace messages and financial transaction records even after account deletion.

Grace Period: Account deletion requests have a 30-day grace period only for accounts without retained marketplace history. If your account has marketplace message history, order history, refunds, invoices, disputes, or related fraud-review records, deletion is fulfilled by anonymization instead of hard deletion. Authentication is removed and direct profile details are anonymized, but some personal data already embedded in retained marketplace records, such as order shipping details and related invoice, dispute, message, and fraud-review records, may remain available only as needed for platform integrity, fraud review, legal compliance, and claims handling.

Transactional and Fraud-Review Retention: Marketplace buyer/seller messages, orders, invoices, refunds, disputes, and related fraud-review records are retained for 7 years after creation or resolution, as applicable. These retained records may include transaction-linked personal data, such as shipping details, and may continue to reference an anonymized account after deletion.

Legal Holds: In cases of suspected fraud, abuse, or legal disputes, account deletion may be temporarily blocked pending investigation. This may occur when:

  • A message you sent has been reported and is under admin review
  • You have an open dispute that has not been resolved
  • You have recent high-value transaction activity (over $10,000 in the last 30 days)
  • An administrator has placed a manual hold on your account

Data Under Legal Hold: Messages and account data may be preserved beyond standard retention periods until the matter is resolved. Messages under legal hold will display "[Content under legal review]" to other users but will remain accessible to authorized administrators for investigation purposes.

Religious verification data subject to an active dispute, fraud review, or legal hold may also be preserved beyond the standard 90-day post-termination or post-rejection window until the matter is resolved.


7. Security

We employ industry-standard security measures:

  • Encryption: All data in transit is encrypted via SSL/TLS.
  • Access Control: Sensitive data (like verification details) is accessible only to authorized administrators.
  • Admin Audit Trails: Artos-assisted setup, seller product-edit authorization activity, enforcement edits, and sensitive-data access are logged so we can review who took certain actions and why.
  • Integration Logging Controls: Shop Sync limits customer details in custom webhooks by default, signs webhook requests, stores integration credentials as encrypted secrets or one-way hashes, and keeps purpose-limited delivery and error records. Sellers must expressly confirm before enabling customer-inclusive custom webhooks or ShipStation routing.
  • Payment Security: We never touch or store raw credit card or bank account details. Marketplace card payments, Seller payout details, and paid-feature subscriptions are handled by Stripe.

Disclaimer: While we strive to use commercially acceptable means to protect your Personal Data, essentially no method of transmission over the Internet is 100% secure.


We use cookies and similar browser storage. Exact provider cookie names can change, but the main categories currently include:

Cookie or storagePurposeTypical durationCategory
better-auth.session_token or secure equivalentAuthenticationSession or account-session durationEssential
artos_cart_session_idGuest cart and checkout30 daysEssential
theme, theme-resolvedAppearance preference and stable page rendering1 yearFunctional
delivery-country, delivery-country-dismissedDelivery-country preference and dismissed region notice1 yearFunctional
site-announcement-dismissedDismissed announcement1 yearFunctional
ph_* and related PostHog browser storageProduct analytics and optional session analyticsProvider-configured; commonly 1 yearAnalytics (choice-dependent)
artos_attribution and artos_visitor_id storageReferral, Ambassador, Parish Partner, and Share & Save creditAttribution window or until clearedMarketing (choice-dependent)
Google tag cookies and artos-google-ad-click-ids dataAnalytics, ad attribution, and consented purchase measurementProvider-configured; click IDs 90 daysAnalytics/Marketing (opt-in)

We may also use local or session storage to remember preferences, prevent duplicate event reporting, hold a guest cancellation token, and keep temporary checkout or attribution state. Essential and functional storage supports the Service; analytics and marketing storage follows your consent choice, regional requirements, and GPC signal. You can clear browser storage through your browser, but doing so may sign you out, empty a guest cart, remove referral credit, or reset preferences.


Analytics and Performance Services

When analytics or marketing choices permit the relevant processing, we use the following services:

  • PostHog: Product analytics to understand user journeys and feature usage. We limit direct identifiers and treat analytics identifiers as pseudonymous rather than anonymous.
  • Sentry: Essential error tracking and crash reporting with default personal-data collection limited; performance tracing and session replay may be enabled with your analytics consent.
  • Axiom: Performance monitoring (Core Web Vitals) and structured application logging.
  • Google tag and advertising measurement: Consent-mode signaling, analytics, ad-click attribution, and purchase measurement. Analytics and advertising storage are denied by default and enabled only when the matching choice permits it.

Referral and Attribution Tracking

When marketing cookies are permitted, we may store first-party attribution identifiers to credit:

  • Parish Partner referrals
  • Ambassador referrals
  • Share & Save referrals

In regions where prior consent is required, we do not persist these identifiers until you allow marketing cookies. If you decline or leave before opting in, referral credit for that visit may be lost.


8. Your Rights & Choices

Depending on your location, you may have rights regarding your data:

  • Access & Update: You can access and update many records directly in your account or Dashboard, including your profile, address book, recurring subscriptions, shop settings, public program profile, collections, inventory locations, media, and Shop Sync destination settings. A privacy export includes eligible account- and Seller-owned data but excludes security secrets, privileged internal material, and another person's personal data.
  • Opt-Out and Cancellation: You can manage email notification preferences in your Account Settings and unsubscribe from Artos or Seller marketing emails using the unsubscribe link in those emails. A signed-in user can cancel a pending shop launch notification from the shop page. A guest can cancel from the same browser while its removal token remains available, which may be for up to one year. Cancelling a launch alert does not change a separate Artos marketing preference. If you no longer have access to that browser or token, contact privacy@artosmarket.com to request removal. You generally cannot opt out of critical transactional emails (e.g., "Order Confirmation").
  • Deletion: You may request that we delete your personal data, subject to our legal obligations to retain marketplace records needed for transactions, fraud review, disputes, and financial compliance.

U.S. State Privacy Rights

Where an applicable U.S. state privacy law applies to Artos and your request, you may also have the right to confirm whether we process your personal data, access it, correct inaccuracies, obtain a portable copy, delete eligible data, and opt out of targeted advertising, sale, or certain significant automated profiling. We do not sell personal data for money. You may submit a request or appeal a decision on a prior request by emailing privacy@artosmarket.com with "Privacy Request" or "Privacy Appeal" in the subject line. We will authenticate and respond to the request or appeal within the period required by applicable law. We will not discriminate against you for exercising a privacy right.

Global Privacy Control (GPC)

We respect the Global Privacy Control (GPC) signal, a browser setting that indicates your preference to opt out of the sale or sharing of your personal information.

How it works:

  • When you enable GPC in your browser, we automatically detect this signal
  • Analytics tracking (PostHog) is immediately disabled
  • Marketing cookies and attribution identifiers are immediately disabled
  • Your GPC preference is logged for compliance purposes
  • No further action is required from you

To use GPC, enable a browser or browser extension that sends the Sec-GPC: 1 signal. Ordinary "Do Not Track" or cross-site-tracking settings do not necessarily send GPC, so consult your browser or extension documentation.

You may also use our public Privacy Choices page or, when signed in, manage preferences through Cookie Settings.

Note: Simple Analytics, used on our marketing site, does not use cookies or track visitors across sites. It is privacy-friendly by design and requires no opt-out.


9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Your California Rights

  1. Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell/share about you.

  2. Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions (e.g., financial transaction records we are legally required to retain).

  3. Right to Opt-Out of Sale/Sharing: You have the right to opt out of the "sale" or "sharing" of your personal information. While we do not sell personal information for monetary consideration, we recognize that our use of analytics and marketing cookies may constitute "sharing" under California law.

  4. Right to Correct: You have the right to request correction of inaccurate personal information.

  5. Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of sensitive personal information (such as religious affiliation data for sellers) to only what is necessary to provide our services.

  6. Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.

How to Exercise Your Rights

To submit a request, contact us:

Email: privacy@artosmarket.com

Please include "California Privacy Rights Request" in the subject line. We will verify your identity before processing your request and respond within the timeframe required by law (typically 45 days, with a possible 45-day extension).

Authorized Agents

You may designate an authorized agent to make requests on your behalf. The agent must provide proof of authorization and we may require you to verify your identity directly with us.

California Disclosures

Personal Information Collected and Disclosed for Business Purposes (Last 12 Months):

CategoryExamplesCategories of recipients
IdentifiersName, email, username, account, order, subscription, referral, program, and invitation identifiers; shop launch notification and consent recordsInfrastructure and email providers; Sellers fulfilling an order or subscription; program administrators; the relevant Seller receiving a masked launch-interest signal; enabled fulfillment recipients
Commercial informationPurchases, subscriptions, payments, refunds, shipping, Shop Sync import/export history, order contents, fulfillment, tracking, commissions, payouts, referral rewards, and charitable-impact allocationsStripe; infrastructure providers; the relevant Seller; shipping/tracking providers; Seller-chosen fulfillment recipients when enabled
Professional and operational informationSeller/shop, Ambassador, Parish Partner, and collection-manager details; warehouse or inventory-location names and addresses; catalog links, destination settings, media metadataInfrastructure providers; authorized Artos staff; relevant program or collection administrators; Seller-chosen fulfillment recipients where needed
Internet or electronic activityIP address, browser/device data, app activity, referral and ad-click identifiers, consent signals, analytics, purchase-measurement, and error eventsHosting, security, analytics, advertising-measurement, performance and error-monitoring providers, subject to the choices described above
CommunicationsMarketplace messages, reviews, support requests, invitations, public content, transactional email metadata, and one-time shop launch notification and delivery recordsThe intended user, Seller, or invited manager; public visitors for content published publicly; Resend; infrastructure providers; authorized Artos support staff
Sensitive personal informationReligious affiliation used for Guild membership verification; account credentials stored as protected hashes; limited order fields where applicable law classifies them as sensitiveRestricted Artos verification staff; infrastructure providers as necessary to operate the Service; Seller-chosen fulfillment recipients only when needed and enabled

We have not sold personal information for monetary consideration in the preceding 12 months. Optional analytics or marketing technologies may constitute “sharing” under California law; the opt-out methods above apply to that activity. Operational disclosure to a Seller or Seller-chosen fulfillment provider is used to provide the requested transaction or service, not cross-context behavioral advertising.

Browser Signals: We honor Global Privacy Control (GPC) signals as described above. An ordinary "Do Not Track" signal is not necessarily a GPC signal and may not receive the same response.


10. International Transfers

Artos is based in New Hampshire, USA and uses service providers that process personal data in the United States and other countries. Those providers include categories such as hosting and application infrastructure, database and backend services, file storage, transactional email, internal operational communications, analytics and error-monitoring tools, advertising measurement, shipping, print production and tracking services, fulfillment tools selected by Sellers, and payment or billing providers. In our current stack, this includes providers such as Vercel, Convex, Cloudflare R2, Resend, Slack, PostHog, Sentry, Axiom, Google, Stripe, Shippo, and Prodigi. ShipStation or another webhook recipient receives data only when enabled by a Seller.

When personal data protected by EEA, Swiss, or UK data-protection laws is transferred outside the relevant jurisdiction, we rely on lawful transfer mechanisms that may include an adequacy decision where available, the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum or UK International Data Transfer Agreement, together with supplementary safeguards where appropriate. The exact transfer tool depends on the provider and the service being used.

For Prodigi's processing of print-fulfillment customer data, its incorporated Data Processing Addendum uses the European Commission's Standard Contractual Clauses, including controller-to-processor and relevant subprocessor modules, and the UK International Data Transfer Addendum or International Data Transfer Agreement where required. Its global fulfillment notice identifies recipient categories and typical regions rather than publicly naming each production partner.

You may request more information about the safeguards relevant to a specific provider by contacting us at privacy@artosmarket.com. If you have a privacy complaint or want to exercise a privacy right, contact us at that address and we will review the request under the laws that apply to your location. If you are in the EEA or the UK, you may also have the right to complain to your local supervisory authority or the UK Information Commissioner's Office, as applicable.


11. Changes to This Policy

We may update this Privacy Policy from time to time. For every update, we will post the revised Privacy Policy on this page, update the "Last Updated" date, and send an email notice to each registered User at the email address associated with their account. We will also email other affected individuals when we have a valid email address for them. The notice will summarize the change and identify its effective date. These legal notices are service communications, not marketing messages.

For a material change, we will send the email notice before the change takes effect when reasonably practicable and may also provide a prominent notice through the Service. If we do not have a valid email address for an affected individual, we may provide notice through the Service or another method permitted by law. Continued use of the Service after the effective date constitutes acknowledgment of the revised policy to the extent permitted by law.


12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Lampstand Digital LLC
66 Evans Street
Gorham, NH 03581
New Hampshire, USA