Privacy Policy
WHO HANDLES YOUR DATA — the controller is DC ESCRYPT SL, NIF/VAT B55413975, Calle Torre Bermeja 2, Urb. Marbella Views, Villa 8, 29679 Benahavis (Malaga), Spain, entered in the Registro Mercantil de Malaga and published in the BORME on 19 June 2024. We trade as KRAHS and we run krahs.app. We are established in Spain, so Spanish and EU data protection law applies. Write to support@krahs.app, or use our support page. The same details appear on every proforma we issue.
WE HAVE NO DATA PROTECTION OFFICER, AND THIS IS WHY — Art. 37 GDPR requires one from public authorities, from organisations whose core activity is regular and systematic monitoring of people on a large scale, and from those whose core activity is large-scale processing of special-category or criminal-offence data. We are none of the three: we sell phones and printed clothing to individual customers, and the measurement we do runs only on consent. We are not in any of the further cases listed in Art. 34 LOPDGDD either. So there is no DPO to write to, and no queue behind one: anything about your data goes to support@krahs.app and is answered by us.
WHAT WE COLLECT — only what an order needs. Name, email, delivery address and phone: you type them at checkout; the carrier cannot deliver without a name and a reachable contact. Telegram handle and order notes: optional, only if you fill them in. Order contents, amount and payment method. IP address and browser user-agent: recorded with the order and in server logs, to answer chargebacks and to limit abuse. We do not buy data sets and we do not profile you with data from third parties.
CARD DETAILS NEVER REACH US, AND NEITHER DO YOUR KEYS — card payments go straight to Stripe, on Stripe’s own page; we receive the confirmation and the amount, never the card number. Crypto payments go through the BTCPay server we host ourselves, so using it hands your payment to nobody else — but it does mean we see the address, the amount and the confirmation. Your wallet’s keys stay with you and are never sent anywhere, and the transaction itself sits on a public blockchain, as every blockchain transaction does.
WHY, AND ON WHAT LEGAL BASIS — to produce and ship your order, and to answer you about it: performance of the contract, Art. 6(1)(b) GDPR. To issue the proforma and keep accounting records: legal obligation, Art. 6(1)(c). To prevent fraud and abuse: legitimate interest, Art. 6(1)(f).
WHAT YOU ADD YOURSELF, AND WHEN YOU WRITE TO US — the Telegram field at checkout is optional and we do not need it; you give it so we can reach you faster than email about your order, and that is your consent, Art. 6(1)(a). Ask us and we delete the handle; the order is not affected. The notes box is yours to fill or leave empty, and what you write there we use to make and ship what you asked for: performance of the contract, Art. 6(1)(b) — please keep health details and other sensitive information out of it, we have no use for them. A support ticket or an email to us: if it concerns an order, performance of the contract, Art. 6(1)(b); if it is a general question with no order behind it, our legitimate interest in answering people who write to us, Art. 6(1)(f). We keep the thread so whoever picks it up next has the history.
AUDIENCE MEASUREMENT AND ADVERTISING — your consent, Art. 6(1)(a), asked separately for each of the two and never assumed. Nothing for a purpose loads until you switch that purpose on, and Cookie settings at the foot of every page takes it back. What each tool is and what it sets is in our cookie policy.
CRASH REPORTS — when the site breaks on your screen, the browser can send us a report about the failure through Sentry: the page address, the error and your browser version. We switch off the option that would attach personal data to it. The reporter is armed per build with a key our deploy supplies; without that key it stays dormant and nothing leaves your browser. Legal basis: our legitimate interest in a shop that works, Art. 6(1)(f).
CONTENT GUARD — product photography and text on this site are watermarked, and copying a long passage or pressing a screenshot key shows you a notice and tells our operator that it happened. That alert carries the event and the page address only: no IP address, no device string, nothing that identifies you. Legal basis: our legitimate interest in protecting our own imagery, Art. 6(1)(f) GDPR. Your ordinary visit is still recorded in the server access log described above.
WHO WE SHARE IT WITH — Printful, our production and fulfilment partner, receives your name, address, phone and what you ordered, because they print and ship it. The carrier that brings the parcel receives what a delivery needs: typically DHL, DPD or a national postal service in the EU, and Royal Mail or Evri in the UK, chosen at dispatch by destination — our shipping page explains how. Stripe receives payment data for card orders. Resend delivers our email to you. Sentry receives the crash reports described above. Google, Meta and Pinterest receive measurement data, and only for a purpose you switched on. We do not sell your data to anyone.
THE TELEGRAM NOTIFICATION, IN FULL — a new order is announced to our operator by a Telegram bot, and that message is not a bare ping: it carries the order number, what was ordered, the total, your email, your Telegram handle if you gave one, where it ships to and your notes. Those details therefore pass through Telegram’s servers, which are not ours. Telegram states that data for accounts registered in the EEA or the UK is held in data centres in the Netherlands and that it has a representative in the EU under Art. 27 GDPR.
YOUR RIGHT TO OBJECT — this stands on its own, because the law requires it to be put to you clearly and separately, and not buried in a list. You can object at any time, on grounds relating to your particular situation, to anything we do on the basis of legitimate interest: fraud and abuse prevention, the content guard, crash reports, and answering an enquiry that is not about an order. Write to support@krahs.app and say what you object to. We then stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless we need the data to establish, exercise or defend a legal claim — and if we do not stop, we tell you why. Should we ever process your data for direct marketing, you can object to that too and we must stop at once, with nothing to weigh up. Art. 21 GDPR.
WHERE IT GOES — our servers are in the EU. Several of the companies above are American and data reaches the United States. Stripe, Google, Meta, Pinterest, Resend (Plus Five Five, Inc.) and Sentry (Functional Software, Inc.) each state that they are certified under the EU-U.S. Data Privacy Framework, the European Commission’s adequacy decision of 10 July 2023 under Art. 45 GDPR; Stripe, Google, Pinterest, Resend and Sentry additionally name the Commission’s standard contractual clauses, Art. 46 GDPR, for transfers that framework does not cover. Printful relies on those same standard contractual clauses; five apparel items are printed and shipped from the United States, so for those your delivery details go there as well, and our shipping page marks them one by one. Carriers see only what a parcel needs, in the country it travels to.
ONE-TIME NOTES AND FILES — KrahsNote and the one-time file service are built so that we cannot read what you send. A note or a file is encrypted in your browser before it leaves; the key travels only in the part of the link after “#”, which browsers never send to any server. Our servers hold ciphertext and a few housekeeping fields — size, expiry time, and, if you set one, a hash of the password — nothing else: no IP address, no browser string, no file name. Notes live on our EU server and are destroyed on first reading or on expiry. Files live on a server we rent in Canada (Montréal), outside the EEA, for at most 24 hours or until the first complete download, whichever comes first, and are then deleted. Because what reaches that server is unreadable ciphertext with no key and no identifying data, no personal data of yours is transferred there in a form anyone could use; we still name it here so you can decide for yourself. Legal basis for running the service: performance of the contract with the person using it, Art. 6(1)(b) GDPR.
HOW LONG WE KEEP IT — order records and invoices for the period Spanish commercial and tax law requires (currently six years). Support correspondence for two years. Server logs for 90 days. Analytics data for the retention window set in the provider, at most 14 months. Crash reports for as long as our plan with Sentry retains them; we keep no copy. Your cookie answer never reaches us at all — it stays in your browser and is treated as expired after 24 months.
YOUR RIGHTS — access, rectification, erasure, restriction and portability, plus the right to object set out above. Withdrawing a consent is deliberately as easy as giving it: Cookie settings at the foot of every page for analytics and advertising, a line to support@krahs.app for the Telegram handle. A withdrawal works from the moment you make it and does not make what came before it unlawful. Write to support@krahs.app; we answer within one month, and tell you if a complex request needs the two further months Art. 12(3) GDPR allows. You can also complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es). Erasure has one limit: an invoice we are legally required to keep cannot be deleted before its retention period ends.
SECURITY — the site is served over HTTPS only, the admin area requires a password and a one-time code, and payment pages belong to the payment providers, not to us.
CHANGES — the date below is when this text last changed. A material change is announced on this page before it takes effect, and a change to what we measure or who measures it also resets the cookie banner, so you are asked again rather than carried over.