Loading...
Katura 1999 ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or make a purchase.
Katura 1999 ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or make a purchase.
This Privacy Policy ("Policy") applies to all personal data collected by October Skies Benediction LLC, doing business as Katura 1999 ("Katura," "we," "us," or "our"), a South Carolina limited liability company, through:
By using our Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use our Services. This Policy is incorporated into and subject to our Terms of Service.
We may collect personal information that you voluntarily provide to us when you:
When you visit our website, we may automatically collect certain information, including:
Sensitive Data: We do not intentionally collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, genetic data, biometric data, or health information. If you voluntarily provide such information (e.g., in a custom design request), we will treat it with heightened protection.
We use the information we collect to:
Order Fulfillment
Process purchases, send confirmations, arrange shipping, handle returns and exchanges
Account Management
Create and maintain your account, authenticate logins, manage your preferences
Customer Service
Respond to inquiries, process repair requests, provide consultations, resolve disputes
Fraud Prevention
Detect and prevent fraudulent transactions, chargebacks, and unauthorized account access
Marketing (with consent)
Send promotional emails, personalized offers, and new collection announcements β you can opt out anytime
Product Improvement
Analyze usage patterns to improve our website, mobile app, and product offerings
Legal Compliance
Meet tax reporting obligations, respond to lawful requests from authorities, enforce our Terms of Service
Security
Monitor for threats, maintain system integrity, and protect against cyberattacks
For individuals in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data under the following lawful bases as defined by the GDPR:
Contract Performance (Art. 6(1)(b))
Order processing, account creation, shipping, returns, repair services
Legitimate Interests (Art. 6(1)(f))
Fraud prevention, analytics, security monitoring, product improvement. We balance our interests against your rights and freedoms.
Consent (Art. 6(1)(a))
Marketing emails, optional cookies, newsletter subscriptions. You may withdraw consent at any time without affecting the lawfulness of prior processing.
Legal Obligation (Art. 6(1)(c))
Tax reporting, anti-money laundering compliance, law enforcement requests, consumer protection obligations
Katura 1999 is based in Atlanta, Georgia, United States. Your data may be transferred to, stored, and processed in the United States and other countries where our service providers operate.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on the following legal mechanisms:
Our primary infrastructure providers (Vercel, Supabase, Stripe) maintain robust compliance programs and process data in accordance with applicable data protection regulations.
Brazil (LGPD): If you are located in Brazil, we comply with the Lei Geral de ProteΓ§Γ£o de Dados (LGPD). International transfers are conducted under appropriate safeguards, including standard contractual clauses and adequacy assessments as required by Brazil's National Data Protection Authority (ANPD).
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, or as required by law. Below are our specific retention periods:
Account Data
Account functionality, then grace period for accidental deletion recovery
Order & Transaction Records
Tax reporting, audit requirements, warranty claims (IRS requires 7-year retention)
Payment Card Data
PCI DSS compliance; Stripe retains data per their privacy policy
Customer Support Logs
Quality assurance, dispute resolution, legal claims
Marketing Preferences
Honoring opt-out requests
Analytics Data
Google Analytics default; IP addresses anonymized after 30 days
Server Logs
Security monitoring, debugging, performance analysis
Repair Service Records
Warranty tracking, quality assurance, repeat service reference
Wholesale / B2B Records
Tax, compliance, ongoing trade account management
After the applicable retention period, data is securely deleted or anonymized so that it can no longer be associated with you. Anonymized data may be retained indefinitely for statistical purposes.
We implement appropriate technical and organizational measures to protect your personal information. However, no method of transmission over the Internet is 100% secure.
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
TLS 1.3 Encryption
All data in transit encrypted with the latest TLS standard
AES-256 Encryption at Rest
Database and backups encrypted with AES-256
PCI DSS Level 1 (via Stripe)
We never store, process, or transmit cardholder data
Row-Level Security (RLS)
Database-level access controls on every table
SOC 2 Type II Infrastructure
Vercel and Supabase maintain SOC 2 Type II compliance
Bcrypt Password Hashing
Passwords are salted and hashed β never stored in plaintext
CSRF & XSS Protection
Cross-site request forgery tokens and content security policies
Rate Limiting
Brute-force protection on authentication and API endpoints
Breach Notification: In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals within 72 hours of becoming aware of the breach (as required by GDPR Article 33), and promptly notify relevant supervisory authorities. We will also comply with all applicable U.S. state breach notification laws.
Depending on your location, you have specific rights regarding your personal data. We honor these rights regardless of where you live, to the extent commercially practicable:
Right of Access
Request a copy of the personal data we hold about you
Right to Rectification
Request correction of inaccurate or incomplete personal data
Right to Erasure
Request deletion of your personal data ("right to be forgotten")
Right to Restrict Processing
Request that we limit how we use your data while a dispute is resolved
Right to Data Portability
Receive your data in a structured, machine-readable format (JSON or CSV)
Right to Object
Object to processing based on legitimate interests, including profiling
Right to Withdraw Consent
Withdraw consent for marketing or optional data processing at any time
Right to Opt Out of Sale
We do not sell personal data, but you may still submit a formal opt-out request
Right to Non-Discrimination
Exercise your privacy rights without receiving different pricing or service quality
To exercise any of these rights, email legal@katura1999.com with the subject line "Privacy Rights Request." We will verify your identity and respond within 30 days (extendable by 60 days for complex requests, with notice).
California Residents (CCPA/CPRA): You have the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share personal information as defined by the CCPA. You may designate an authorized agent to make requests on your behalf. We will not discriminate against you for exercising your CCPA rights.
EU / EEA / UK Residents (GDPR / UK GDPR): You have the right to lodge a complaint with your local supervisory authority if you believe we have violated data protection law. For EU residents, you may contact the data protection authority in your country of residence. For UK residents, contact the Information Commissioner's Office (ICO) at ico.org.uk.
Brazil Residents (LGPD): You have the right to confirmation of processing, access, correction, anonymization, portability, deletion of data processed with consent, information about shared data, and the right to revoke consent. Complaints may be filed with Brazil's National Data Protection Authority (ANPD).
Some browsers transmit a "Do Not Track" (DNT) signal. There is currently no uniform standard for interpreting DNT signals. However, when we detect a DNT signal, we:
We also support the Global Privacy Control (GPC) signal. When we detect a GPC signal, we treat it as a valid opt-out of the sale or sharing of personal information under CCPA/CPRA.
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at legal@katura1999.com.
If we discover that we have collected personal data from a child under 16 without verified parental consent, we will delete that data within 48 hours and notify the parent or guardian.
We do not use automated decision-making (including profiling) that produces legal effects or similarly significantly affects you. Specifically:
If we introduce automated decision-making in the future, we will update this Policy, provide meaningful information about the logic involved, and offer the right to contest decisions and obtain human review.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
We encourage you to periodically review this Policy. The full revision history is available upon request by emailing legal@katura1999.com.
If you have a concern about our privacy practices that we cannot resolve directly, you may pursue the following options:
Class Action Waiver: To the fullest extent permitted by law, any disputes arising under this Policy shall be resolved on an individual basis. You agree to waive the right to participate in a class action, class-wide arbitration, or representative proceeding.
For any privacy-related questions, data subject requests, or to exercise your rights under CCPA, GDPR, LGPD, or any other applicable privacy law:
Privacy & Legal
legal@katura1999.comData Protection Officer
dpo@katura1999.comGeneral Support
clientcare@katura1999.comResponse Time
30 days (GDPR/CCPA), 15 days (LGPD)
Mailing Address
October Skies Benediction LLC β Attn: Data Protection Officer
d/b/a Katura 1999
South Carolina, United States