Store and local data
Cart and wishlist data are stored locally in your browser. A sell-your-shirt text draft may also remain on that device for up to 24 hours; photo files are not included in the local draft.
Legal draft
Draft for professional review. This page is not legal advice and is not ready for production use.
Cart and wishlist data are stored locally in your browser. A sell-your-shirt text draft may also remain on that device for up to 24 hours; photo files are not included in the local draft.
On the production site, Google Analytics 4 may process pseudonymous usage data to help us understand visits and improve the archive. Google may set analytics cookies according to your browser and consent settings.
When you submit a shirt we process your name, contact details, country, shirt information, photos, confirmations, private review status and correspondence reference to assess a possible private purchase. Submitting is not a public listing, an offer or a transfer of ownership. Authorised administrators can access the record; photos are stored privately. Production deployment must identify the controller, lawful basis, hosting processors, exact retention period and monitored privacy contact.
SUBMISSION_RETENTION_DAYS defines the intended operational retention period. Until an automated deletion schedule is configured, the owner must review expired records and anonymise or delete them from the protected admin area. Records linked to an agreed purchase may need a different legal retention period.
If you explicitly join the mailing list, we store your email address, consent record and subscription status. A confirmation email verifies the request before marketing begins. Resend processes delivery, unsubscribe, bounce and complaint events on our behalf. Every marketing email includes an unsubscribe link.
A one-way hash derived from the network address may be kept briefly to rate-limit automated submissions and newsletter sign-ups. Cloudflare Turnstile is used in configured production environments and may process technical anti-abuse data under its own privacy terms.
Before launch, provide a monitored privacy address and a verified process for access, correction, deletion, restriction, portability and objection requests.