Privacy policy

Last updated: October 1, 2026

Love Scholar LLC operates this store under the CruxChristi brand (also displayed as Crux Christi). This policy explains how we handle information when you browse, order, create an account, contact us, or subscribe to email. For privacy requests, contact alex@cruxchristi.com. Our business contact address is 300 Angelita Drive, La Feria, TX 78559, United States. Our contact page provides our contact details.

Information we collect and why

  • Shopping and orders: your email, name, delivery and billing addresses, phone number where supplied, basket contents, order history, promotions, payment status, and delivery details. We use these to process payments, fulfil orders, answer questions, handle returns, prevent fraud, and maintain required business records.
  • Payments: Stripe collects payment details through its payment interface. Our store receives payment identifiers, status and limited payment-method information; we do not store your full card number or security code in our store database.
  • Accounts: account contact details, saved addresses and authentication records. Authentication credentials are handled by our account system; we do not share passwords with marketing or fulfilment partners.
  • Messages, requests and reviews: information you submit in contact forms, sourcing requests, return requests, and reviews. A published review may show the display name and review text you provide. Avoid including private contact details in a review.
  • Personalised products: requested printing, names, numbers, patches and previews. This information can be copied into basket and order lines and shared with the supplier making your order. Supply information you are entitled to use.
  • Technical information: IP address, browser and device details, page requests and security logs to operate and protect the service. Approximate country or region may be supplied by our hosting infrastructure to explain local rights; it does not establish your residence or the applicability of a law.
  • Optional measurement and marketing: when enabled and you permit the relevant category, browsing events and identifiers used for measurement or advertising. Email subscription and unsubscribe records are handled separately from browser cookie choices.

We use information to provide the service you request, comply with applicable duties, protect legitimate operational interests, and carry out optional activities with consent where required. Buying a product is not consent to optional advertising or to selling your personal information.

Where information is stored and who receives it

The storefront runs on Vercel. Our Medusa commerce services run on Railway, with the main commerce database in Supabase PostgreSQL in the US West region. Redis supports caching, events, workflow coordination and background work. Basket and account identifiers also reside in your browser. These systems may hold additional service logs and backups under their own configured retention and recovery arrangements.

  • Stripe: payment processing, fraud prevention, refunds and tax calculation/reporting. See Stripe's privacy notice.
  • Vercel, Railway and Supabase: hosting, database storage, delivery and security of the store.
  • Google email services: transactional messages and staff correspondence through the configured Gmail/SMTP service. Messages may contain order or support details needed to handle them.
  • Telegram: configured staff alerts contain order/payment identifiers, totals and status, with a link to the authenticated admin. Customer contact details and printing instructions belong in the admin rather than these chat alerts.
  • Suppliers, shipping services and carriers: information needed to make and deliver your order, including relevant contact, address and product-personalisation details.
  • Optional services: PostHog for product measurement, Meta for advertising measurement, and Klaviyo for browser marketing and subscribed-customer email marketing, if enabled. Browser integrations require the appropriate optional permission; identified server marketing events require current email-marketing permission and must respect suppression. These integrations were not configured in the September 30 audit. Enabling a service requires its own configuration and accurate notices; this paragraph does not activate it.
  • Other recipients: professional advisers, authorities when lawfully required, or parties to a business transaction subject to applicable safeguards.

We share service information for the purposes above. A recipient's location and applicable transfer safeguards depend on the services and markets involved. Contact us for information about a particular recipient or international transfer. We do not claim that every provider stores all information in one country.

Cookies and other browser storage

Essential storage supports baskets, accounts, country selection, promotions and your privacy choices. Optional analytics and marketing start only after an affirmative choice. Rejecting optional storage does not prevent shopping. Manage separate categories or reject all optional tracking at Your Privacy Choices. We honour Global Privacy Control as a refusal of optional tracking, including a request-header signal or browser signal, even if an older choice permitted it.

StoragePurposeUsual lifetime
aj_cartEssential basket identifier; the basket contents are on the commerce server30 days
aj_regionEssential shopping region selection365 days
aj_sessionEssential account session7 days, or until sign-out
aj_pending_codesEssential saved promotion codes30 days
aj_consentPrivacy categories, consent version and choice time180 days; invalid or expired choices require a new choice
__kla_offEssential Klaviyo refusal preference, when that service is configured180 days; removed when you permit that browser marketing again
crux:presence session storageOptional first-party live-viewer measurement using a random identifier for this tab, after analytics permissionTab session; removed on withdrawal where accessible
Optional vendor cookies/local storagePermitted measurement or marketing when that vendor is enabledDepends on the enabled service and its configuration; known browser identifiers are cleared on withdrawal where our code can access them
crux_meta_* local storagePrevent repeating permitted advertising eventsLimited by expiry and removed when marketing permission is withdrawn; no marker is written for a blocked event

On HTTPS, our own cookies use Secure and SameSite=Lax. Basket, region, promotion and account cookies are HttpOnly; the consent cookie is readable by our consent controls. Necessary payment technologies can be supplied by Stripe. See Stripe's cookie policy for its payment-related storage. Local withdrawal stops future optional browser tracking and clears accessible identifiers; it does not by itself erase information already held by a remote provider. Contact us for an access or deletion request concerning that information.

Our first-party live-viewer measurement sends a random tab identifier and page path only after analytics permission. The feature reduces sensitive page paths and does not store account details or IP addresses in its viewer records. Those records are held in Redis, with an in-process fallback, and are pruned when measurement or admin reads run against a one-minute active window. Redis keys expire after ten minutes without activity. Hosting/security logs have separate retention.

Sale, sharing and future data monetisation

We do not currently operate a programme selling customer information to data buyers. Advertising-related disclosures may be treated as a sale, sharing, or targeted advertising under some state laws even without a cash payment. Any configured advertising use must follow the choices above and applicable law. Installing a pixel does not pay the store for customer data.

We may consider a future paid data programme. Before starting one, we must identify the recipients, information, purposes and applicable restrictions, provide the required notice, obtain any required separate consent, and implement refusal and deletion controls. A change to these Terms or this policy cannot retroactively authorise a materially different use of information already collected. We do not create religious-belief profiles for resale, and no future programme is authorised by this notice to sell children's or sensitive information.

How long we keep information

We retain information for the purpose for which it was collected and for applicable accounting, tax, fraud, dispute and fulfilment requirements. We consider the type of information, open orders or disputes, applicable record-keeping duties and your requests. We do not describe seven years as a universal legal requirement.

Our internal review schedule includes up to two years for ordinary messages, sourcing requests and printing values, and 180 days for abandoned baskets. Automated retention starts in review mode and is enabled only for reviewed categories. Open transactions and documented holds can delay erasure. Accounting and return records need a market-specific decision. These are review schedules, not a promise that every copy disappears automatically on that date. Staff process verified requests and report what was removed, retained or remains to be addressed.

A minimal marketing-refusal record is retained so that deletion or a later import does not subscribe you again. We separately manage provider copies, emails, shared media, logs and backup expiry. Backups are not instantly rewritten by a deletion request; if restored, outstanding deletion and suppression requests must be reapplied before ordinary use. Browser consent withdrawal does not cancel an order or remove a required transaction record.

Your choices and rights

Use Your Privacy Choices for this browser. Use the unsubscribe link in a marketing email to stop email marketing, or email us. For account-wide choices, access, correction, portability, deletion, objection, restrictions or an appeal, contact alex@cruxchristi.com. Rights, exceptions and deadlines depend on your residence and whether a particular law applies to us. We may request proportionate verification or an authorised agent's authority; creating an account is not required to request help.

Where applicable, US state laws provide rights concerning sale, sharing and targeted advertising. California and several other states require recognised opt-out signals. Some states impose additional sensitive-data and children's-data restrictions, and Maryland restricts sensitive-data sales. Our browser controls accept refusal and Global Privacy Control for every visitor, regardless of whether a statutory threshold is met. We do not penalise you for exercising applicable rights.

Where the EU or UK GDPR applies, we respond without undue delay and ordinarily within one calendar month, with an extension only as permitted and notified. Other laws set different periods. We explain a refusal and any applicable appeal route. You can complain to the relevant privacy authority or state Attorney General under the rules that apply to your request.

Children, security and updates

The store is intended for adults purchasing products. We do not knowingly run paid data sales or targeted-advertising profiles involving children. Contact us if you believe a child has submitted information. We use access controls, authenticated staff tools, HTTPS and data minimisation; no service can guarantee absolute security.

We update this policy when our practices change and give additional notice or request a new choice when required. The date above identifies this version. Contact us for questions about this policy or an outstanding privacy request.