Privacy Policy
Last updated: June 2025
1. Who We Are
Plaque Direct operates the website www.plaque-direct.com and provides custom metal plaque manufacturing and worldwide shipping services. Our studio is based in Jerusalem, Israel.
For privacy matters, contact us at info@plaque-direct.com.
2. What Data We Collect
We collect only the data necessary to process and deliver your order:
- Contact details — name, email address, phone number
- Shipping address — full postal address for delivery
- Order details — plaque specifications, custom text, uploaded artwork
- Payment information — processed securely by Stripe; we never store card numbers
- Usage data — pages visited, time on site, browser type (collected anonymously via Google Analytics)
3. How We Use Your Data
- To produce and ship your custom plaque order
- To send you a design proof and communicate about your order status
- To process payment and issue refunds if applicable
- To respond to enquiries submitted via the contact form
- To analyse website traffic and improve our service (anonymised analytics only)
We do not use your data for automated decision-making or profiling.
4. Legal Basis for Processing (GDPR)
For customers in the European Economic Area and United Kingdom, our legal basis for processing your data is:
- Contract performance — to fulfil your order
- Legitimate interests — fraud prevention, improving our service
- Consent — for marketing communications (only if you opt in)
5. Third Parties We Share Data With
- Stripe — payment processing. Stripe Privacy Policy
- DHL / shipping carriers — your name and delivery address for shipment
- Cloudflare — hosting and CDN infrastructure
- Google Analytics — anonymised usage statistics
- Microsoft Clarity — anonymised session recordings for UX improvement
We do not sell your personal data to any third party.
6. Data Retention
We retain order records (including name, address, and order details) for 7 years to comply with Israeli tax and consumer protection law. Email correspondence is retained for 3 years. You may request deletion of data not required by law at any time.
7. Your Rights
Under GDPR and applicable privacy laws, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of data we are not legally required to retain
- Data portability — receive your data in a machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, email us at info@plaque-direct.com. We will respond within 30 days.
8. Cookies
We use the following cookies:
- Essential cookies — required for the website and checkout to function
- Analytics cookies — Google Analytics (anonymised IP) and Microsoft Clarity to understand how visitors use the site
You can control cookies through your browser settings. Disabling analytics cookies does not affect your ability to place an order.
9. Security
All data is transmitted over HTTPS. Payment data is processed directly by Stripe and never passes through our servers. We use Cloudflare's infrastructure for DDoS protection and encryption at rest.
10. Changes to This Policy
We may update this policy from time to time. The current version will always be available at www.plaque-direct.com/privacy-policy. Significant changes will be communicated by email to customers with active orders.
11. Contact & Complaints
For any privacy-related questions, contact us at info@plaque-direct.com.
If you are in the EU/EEA and believe we have mishandled your data, you have the right to lodge a complaint with your local data protection authority.