In short: we collect what we need to fulfill your order, keep your account secure, and personalize your experience. We never sell your data. You can request a copy or deletion any time by emailing .
1. Who we are
Rubysta Jewelry ("we", "us") operates this website and the services offered through it. Our atelier and registered office address is on file with our contact page.
2. Data we collect
- Account & order data — name, email, phone, shipping/billing address, ring size, order history, and any preferences you save (wishlist, recently viewed).
- Payment data — handled by our payment processors (Stripe, PayPal). We never see or store your full card number.
- Communications — emails, WhatsApp messages, contact-form submissions, product enquiries.
- Usage data — IP address, browser type, pages viewed, referrer, device information. Collected via cookies and analytics tools.
3. How we use your data
- To process your orders, ship, and provide post-sale care (sizing, repair, lifetime cleaning).
- To send transactional emails (order confirmations, shipping updates) — these are not optional while an order is active.
- To send marketing emails — only with your consent, unsubscribe in one click anytime.
- To improve the site (anonymized analytics, A/B tests, abandoned-cart recovery).
- To prevent fraud and meet legal/tax obligations.
4. Legal basis (GDPR / equivalents)
We rely on (a) contract — to fulfill orders you've placed; (b) legitimate interests — to keep the site secure and improve it; (c) consent — for marketing emails and non-essential cookies; (d) legal obligation — for tax, accounting and compliance records.
5. Who we share data with
We share only what's required, with vendors that meet our security standards: payment processors, shipping carriers, fraud-detection providers, email service, analytics platforms. A current sub-processor list is available on request.
6. How long we keep it
Order and accounting records: 7 years (legal requirement). Marketing data: until you unsubscribe + 30 days. Analytics data: anonymized after 26 months. Wishlist and recently-viewed: stored on your device or against your account until you remove it.
7. Your rights
- Access — request a copy of the data we hold about you.
- Correction — fix anything inaccurate.
- Deletion — ask us to forget you (subject to legal-retention rules).
- Portability — receive your data in a machine-readable format.
- Object / restrict — opt out of marketing or limit our processing.
Email to exercise any of these — we respond within 30 days.
8. Security
All site traffic is encrypted (HTTPS/TLS). Payment data is tokenized by our processors. We follow the principle of least privilege internally and run periodic security reviews.
9. Cookies
See our Cookie Policy for details on what we set and why, plus how to change your preferences.
10. Changes to this policy
We'll update the "Last updated" date at the top whenever the policy changes. Material changes are also emailed to active customers.
11. Contact us
Questions? Email or use the contact form.