Privacy Notice
This notice describes the account, session and order-ticket data used by the current storefront. The site does not collect card or wallet secrets and does not load advertising trackers.
1. Data stored in your browser
The cart is stored in your browser using local storage under the key prshop-cart. It contains product identifiers and quantities, not payment details or Discord credentials. It stays on the device until you remove the cart or clear site storage.
2. Customer accounts and sessions
Registration stores the supplied name, normalized email address, a salted password hash, account timestamps and server-side session records. The password itself is not stored. A secure HTTP-only cookie identifies the active session. Session records include an opaque session identifier, a shortened device/browser description and activity and expiry timestamps. Customers can review and revoke sessions, change their password, sign out all sessions, or delete their account and associated tickets from the account panel. Failed login attempts are temporarily recorded in pseudonymised form to limit abuse. Successful, failed and blocked administrator logins and administrative security events are recorded in a restricted audit log. The audit log stores a keyed hash of the network address rather than the address itself.
3. Technical request data
When the site is accessed, the hosting and network providers may process an IP address, request time, requested path, user agent and security-related request information to deliver the site, maintain availability and prevent abuse. Where EU data-protection law applies, this processing is generally based on operating a secure service and legitimate interests, subject to the operator's final legal assessment.
Application errors are written to restricted Vercel runtime logs. If transactional email is configured, a limited alert containing the route, error type, time and hosting request identifier is sent to the administrator notification address. The same limited event is also sent to the operator's alert recipient if the optional error-alert webhook is configured. Customer passwords, session tokens and payment details are not included in these alerts.
4. Live-stock requests
The browser requests the same-origin PRshop product endpoint. The public response contains product, price and stock information and does not require a customer identifier. The server contacts the allowlisted inventory source; it does not send the customer's cart to that source.
5. Order tickets and support
Order tickets store the account owner, selected products, quantities, calculated totals, payment preference, status history, timestamps, customer/admin messages and delivery notes. Tickets are visible to the account owner and authenticated administrators. Following a Discord support link also causes Discord to process data under its own terms.
6. Transactional email
If transactional email is enabled, the account email address and short-lived, single-use verification or password-reset tokens are processed to send verification, security and order-status messages. Email delivery remains disabled until a verified sending provider and sender address are configured. The provider must be added to this notice when activated.
7. Cookies and analytics
The supplied storefront does not set analytics or advertising cookies and does not load third-party analytics scripts. If analytics, embedded media, advertising or additional cookies are added later, this notice and any required consent controls must be updated before deployment.
8. Storage, retention and recipients
Account, session and ticket records are stored in Neon PostgreSQL; the application is hosted by Vercel. Browser-cart retention is controlled by the customer. Possible recipients are Neon, Vercel, network providers, Discord when its support link is used, and a payment provider selected during a confirmed order, and the operator's alert recipient if error alerts are enabled. Exact operational log, audit-log and backup retention periods still require operator confirmation.
9. Your rights
Depending on applicable law, customers may have rights to information, access, correction, deletion, restriction, objection, portability and complaint to a data-protection authority. A request can be made through an official support ticket. Identity may need to be verified before account-related information is disclosed.
Retention periods require confirmation
Julius Weber is identified as the responsible operator in the legal notice. Actual log-retention and audit-log and backup periods still require confirmation before commercial launch.