The short version: we collect what we need to print and ship your order and nothing else. We do not sell your personal information. Payment card details never reach our servers — Stripe handles them directly.
Who we are
shirts.com ("we", "us") sells custom-printed apparel, bulk apparel orders, creator storefronts and secondhand apparel. For privacy questions, or to exercise any right described below, email Contact us.
What we collect
| Category | Examples | Why |
|---|---|---|
| Order information | Name, email, shipping address, items ordered | To print, ship and support your order |
| Account information | Email, hashed password, order history | To let you sign in and see past orders |
| Payment information | Handled by Stripe; we store only the last four digits and a payment reference | To take payment and process refunds |
| Artwork you supply | Uploaded or AI-generated designs | To print your shirt and to reprint it if something goes wrong |
| Technical data | IP address, browser type, pages requested | Security, fraud prevention and rate limiting |
| Marketing | Email address, if you subscribe | To send drops and price breaks — only if you opt in |
What we do not collect
We do not collect your full payment card number, we do not buy personal data from third parties, and we do not run cross-site advertising trackers on this site.
How we use it
- To fulfil your order. Your name, address and artwork go to the print provider that makes your shirt.
- To communicate. Order confirmations, shipping notifications, cancellation and refund notices. These are transactional and are sent regardless of marketing preferences.
- To prevent fraud. Unusually large or high-risk orders are screened, and some are held for manual review before printing.
- To improve the site. Aggregate patterns only — which shirts sell, where orders fail.
- To meet legal obligations. Tax and accounting records.
Who we share it with
We share only what each party needs to do its job:
- Print and fulfilment providers — your shipping address, the items, and the artwork to be printed.
- Stripe — payment processing. Stripe is the controller of your card data; see their privacy policy.
- Cloudflare — hosting, storage and content delivery for this site.
- Resend — sending transactional email.
- Carriers — your address, to deliver the parcel.
- Marketplace counterparties — if you buy or sell in the Archive, the other party receives the shipping details needed to complete the sale. Sellers never see your email address or payment details.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Cookies
We use a small number of cookies, all functional:
- Session cookie — keeps you signed in. Expires after 30 days.
- Cart cookie — remembers your basket between visits.
Both are set with HttpOnly, Secure and SameSite=Lax.
We do not use advertising or analytics cookies, so there is no consent banner to dismiss.
How long we keep it
- Order records: seven years, for tax and accounting.
- Artwork: as long as your account is open, so we can reprint your order.
- Account data: until you ask us to delete it.
- Marketing list: until you unsubscribe.
Your rights
Wherever you live, you can ask us to:
- Access the personal information we hold about you.
- Correct anything inaccurate.
- Delete your account and personal data, subject to records we must keep by law.
- Export your data in a portable format.
- Opt out of marketing email, at any time, from any marketing message.
Email Contact us and we will respond within 30 days. If you are in the EEA or UK, our legal basis is contract performance for order data, legitimate interests for fraud prevention, and consent for marketing. If you are in California, the rights above satisfy the CCPA/CPRA, and we do not sell or share personal information as those terms are defined.
Security
Passwords are hashed with PBKDF2-SHA256 and never stored in plain text. Session tokens are stored only as hashes, so a copy of our database cannot be replayed as live sessions. Traffic is encrypted with TLS. No system is perfectly secure, but we do not keep the data that would be most damaging to lose — card numbers never touch our servers.
Children
This site is not directed at children under 13 and we do not knowingly collect their personal information. If you believe a child has given us data, contact us and we will delete it.
International transfers
We operate on globally distributed infrastructure, so your data may be processed outside your country. Where required, transfers rely on Standard Contractual Clauses or equivalent safeguards.
Changes
If we make a material change we will update the date at the top of this page and, where the change affects how we use data you have already given us, email you about it.
Note: this policy describes our actual practices, but it is not legal advice and has not been reviewed by a lawyer for your jurisdiction. If you operate in a regulated market, have counsel review it before relying on it.