Legal
Privacy Policy
What we do with personal information, why, who else sees it, how long we keep it, and what you can ask us to do about it.
Last updated
Who we are, and what this policy covers
Jeweliful is a wholesale jewelry platform operated by B.F Entreprises, whose registered office is at [REGISTERED ADDRESS]. In this policy, “Jeweliful”, “we”, “us” and “our” mean that company.
This policy covers the jeweliful.com website, the Jeweliful merchant dashboard, and the Jeweliful app you install on your store. It explains what personal information we handle, why, who we give it to, how long we keep it, and what you can ask us to do about it.
What the service does, so that the rest of this policy has something concrete to attach to: you choose pieces from our catalog, set your own retail prices, and publish them to the store you already sell from. When one of your customers buys one, the order comes to us, we make the piece, we put your branding on the packaging, and we ship it to your customer. We then write the tracking number back to your store. That round trip is the only reason we ever see anyone’s address.
It does not cover the websites of other companies we link to, or your own store. When one of your customers buys from you, your privacy notice applies to that sale, not ours.
The two different roles we play
Data protection law separates the party who decides what happens to personal information from the party who only follows instructions. We are each of those, for different information, at the same time.
For information about you and your business, we are the controller. We decided to collect it, we decided what it is for, and we answer for it. Sections 3 and 5 to 17 of this policy are about that information.
For information about the people who buy from you, you are the controller and we are your processor (in California, your service provider). We receive that information because you sent us an order to fulfil, and we use it only to fulfil it. Section 4 says what that means in practice.
The distinction is not decoration. It decides who a buyer asks when they want their data, who has to answer them, and what we are allowed to do without being told. If we ever started using buyers’ data for a purpose of our own, we would become a controller of it and this policy would have to change. We have designed the service so that does not happen, and section 4 states it as a commitment.
What we collect about you, and why
Almost all of it comes from you, when you open an account, set up your brand, place an order or write to us. A small amount is generated automatically as you use the service, and some comes from the store platform you connect (for example, the shop domain and the store name).
| Information | Why we have it | Lawful basis |
|---|---|---|
| Your name, email address, sign-in credentials and security settings, including whether you use a second factor | To create your account, to sign you in, and to keep the account out of anyone else's hands | Performance of our contract with you, and our legitimate interest in keeping accounts secure |
| Your company name, contact name, phone number, business address, country and tax registration number | To run your wholesale account, invoice you correctly, and apply the right tax treatment | Performance of our contract with you, and compliance with our legal obligations |
| Your card's brand, last four digits and expiry date, and the reference our payment provider gives us for it | To charge you for the orders you place, and to show you which card is on file. The card number itself is held by Stripe and never reaches us | Performance of our contract with you |
| Your brand material: logo, brand name, the pieces you curate and the prices you set | To make the packaging and the pieces you ordered, and to run your storefront listings | Performance of our contract with you |
| Your orders, invoices, payments, credits and account history | To operate the account, and to keep the business records we are required to keep | Performance of our contract with you, and compliance with our legal obligations |
| Support conversations, the messages you send us and the tickets they belong to | To answer you, and to keep a record of what was asked and agreed | Performance of our contract with you |
| Technical records: request logs with the request's own identifier, the IP address a request arrives from, sign-in and security events | To keep the service running, diagnose failures, and detect abuse | Our legitimate interest in the security and reliability of the service |
| Your language preference and interface settings | To show you the site in the language you chose, and to remember where you were | Performance of our contract with you |
We send account and service email: order and payment notices, statements, security messages, and answers to your support requests. We do not send marketing email, and we do not pass your details to anyone who would.
Where we rely on legitimate interests, we have weighed our interest against your rights, and we have written down which interest applies against each purpose in the table above. You can object to any of it: see section 10.
Your customers' information
When a sale reaches us from your store, or when you place an order by hand, we receive what a parcel needs. We are your processor for all of it, and the Data Processing Terms are the contract that governs it.
What we receive
| What | Why we need it |
|---|---|
| Recipient name | Printed on the shipping label and on the card in the box, so the parcel reaches the right person. |
| Shipping address | Where the parcel is delivered. Passed to our shipping provider to buy the label. |
| Recipient phone number, where the order carries one | Carriers require a contact number for many destinations, for customs and delivery coordination. It goes on the label and nowhere else. |
| Gift message and personalization text | The words engraved on the piece or printed on the card. Free text written by the buyer, so it may contain anything they chose to type. |
| Order and line-item references | The merchant's order number and the items on it, so production, shipment and tracking can be matched back to the sale. |
What we do not receive
- Buyer email addresses. We do not request or store them, and buyer notification stays with the merchant's own store.
- Payment details of any kind. The merchant's checkout takes the buyer's money; we never see a card, and no payment instrument reaches us.
- Browsing, advertising or profiling data about buyers. We run no tracking on any buyer-facing surface.
An order that contains none of our pieces is discarded before it is stored, so the buyer’s address on it never enters our database at all.
If you are the person who bought the jewelry
You may have arrived here from a parcel or a packing slip. The brand you bought from is the one that decides what happens to your information, and it is the one to ask. We only made and posted the item on its instructions. Its privacy notice covers your purchase, and its contact details are the ones to use for a question about your data, a correction, or a deletion. If you write to us instead, we will pass your message to the brand rather than answer it ourselves, because we hold nothing about you that did not come from them.
Who we share information with
We give personal information to the companies below, and to nobody else except as described at the end of this section. Each of them works on our instructions, under a contract, and for the single purpose named.
| Provider | What it does for us | What it receives |
|---|---|---|
| ShipStation Auctane LLC d/b/a ShipStation (United States) | Shipping labels and carrier hand-off | The ship-to block of each order we fulfil (recipient name, postal address and, where the order carries one, phone), together with the production detail the parcel needs: the engraving or personalization text and any note attached to the order. |
| Supabase Supabase Pte. Ltd (Singapore) | Managed Postgres database | The application database, in which order records and their ship-to details are stored, encrypted at rest. |
| Vercel Vercel Inc. (Delaware, United States) | Application hosting and file storage | The running application and its request logs (from which personal data is stripped before writing), plus product and brand imagery. Order data passes through in transit. |
| Stripe Stripe, LLC (United States) or Stripe Payments Europe, Limited (Ireland), per account location | Merchant billing and card payments | Merchant billing details and card credentials. Stripe acts on our instructions for taking payment, and also as a controller in its own right for fraud prevention and payment-network compliance, under its own privacy policy. No end-customer data is sent to Stripe. |
| Clerk Clerk, Inc. (United States) | Merchant sign-in and account security | Merchant account credentials, sessions and second factors. No end-customer data is sent to Clerk. |
| Resend Resend | Account and statement email | The address we send an account email to, and the contents of that email. No end-customer data is sent to Resend. |
One of them is not only our service provider. Stripe also decides some things for itself, for fraud prevention and for the rules the card networks impose on it, and for that part of the processing it is a controller in its own right under its own privacy policy at stripe.com/privacy. We name it here rather than let it sit inside a row, because a second decision-maker in the chain is exactly the kind of thing a reader is entitled to be told about plainly.
We also disclose personal information:
- to our professional advisers (accountants, auditors, lawyers and insurers) where they need it to advise us, and under a duty of confidence;
- where the law requires it, or where we must establish, exercise or defend a legal claim, in which case we disclose only what is needed and tell you unless we are forbidden to;
- to a buyer of the business, or of the part of it that runs this service, if it is ever sold, in which case the information continues to be used for the purposes described here.
Where information is stored, and transfers abroad
We operate from Israel. The application and the database run on providers in the United States and, for the database, in the region we have configured with a provider incorporated in Singapore. Finished orders are produced and posted in the United States. The table in section 5 names each provider and the country it contracts from.
Depending on where you are, that may be a transfer of personal information out of the United Kingdom or the European Economic Area. Where it is, we rely on a mechanism the relevant law recognises. For transfers to Israel that is an adequacy decision, which is in force today. For a destination not covered by one, it is the European Commission’s standard contractual clauses, together with the United Kingdom international data transfer addendum where UK law applies, and with the adaptations the Swiss authority requires where Swiss law applies.
We do not print a list of adequate countries here, because the list changes and a stale list is worse than none. You can ask us for a copy of the safeguards that apply to a particular transfer, using the contact details in section 17.
How long we keep information
We do not keep personal information for longer than the purpose it was collected for needs. In practice that means:
| Information | How long |
|---|---|
| Your account and company profile | For as long as your account is open, and afterwards for as long as we need it to close the relationship out. |
| Orders, invoices, payments and tax records | For the period the tax and accounting law that applies to us requires us to keep business records. This is the one category we cannot shorten on request, and we will tell you when that is why we are keeping something. |
| Support conversations | While your account is open, and for as long afterwards as any question arising from them could still be raised. |
| Technical and security logs | For the short operational period our hosting provider retains them. Personal information is stripped from log lines before they are written. |
| Your customers' order information | For as long as fulfilling and supporting that order requires, and then no longer, except for orders already produced and shipped, which are kept as transaction records. The Data Processing Terms set this out in full. |
Some of this runs on a schedule: aged records that no longer serve a purpose are deleted automatically, and that schedule is suspended in full while any security incident or legal hold is open, so that evidence cannot be swept away while it is needed.
How we protect information
We keep technical and organisational measures appropriate to the risk. These are the current ones:
- Encryption in transit. Every connection to the service, and every connection from it to a provider, runs over TLS.
- Encryption at rest. The database and the file storage encrypt their contents with AES-256.
- A second layer over the keys to a merchant's store. The access tokens that let us read a connected store are encrypted field by field with a rotating key, on top of the storage encryption.
- Personal data is stripped from logs before they are written, and error reporting is configured to send none.
- An access log over end-customer data. Every read or export by our staff, and every send to our shipping provider, is recorded with who, what, why and when.
- Least privilege. Every route in the application is permission-guarded by construction, staff accounts exist only by invitation, and the ability to move money is narrower than the ability to fulfil an order.
- Separation of test and production. Development and preview environments run on their own databases and never receive production data.
- Retention limits that run on a schedule, with a hold switch that suspends every one of them while an incident is open.
- A written security incident response policy with severity levels, containment runbooks and notification duties.
No system is perfect, and we would rather say what we do than promise what nobody can. If something goes wrong, we have a written incident response policy with severity levels, containment steps and notification duties, and we follow it.
Your rights over your information
Where the United Kingdom or European Union data protection law applies, you have the following rights over the information we hold about you as controller. Most of them are not absolute, and we will tell you plainly if an exception applies rather than simply declining.
- Access. Ask us for a copy of the personal information we hold about you, and for an explanation of what we do with it.
- Rectification. Have information that is wrong corrected, and information that is incomplete completed.
- Erasure. Ask us to delete information, where we no longer need it for the purpose we collected it for.
- Restriction. Ask us to stop using information while a dispute about its accuracy or our use of it is resolved.
- Portability. Receive the information you gave us in a structured, commonly used, machine-readable form, or have us send it to someone else where that is technically possible.
- Objection. Object to processing we do on the basis of legitimate interests. Section 10 sets this out on its own.
- Withdrawal of consent. Where we rely on your consent for something, withdraw it at any time. Withdrawing it does not undo what was done while it was in force.
- Automated decisions. Not be subject to a decision based solely on automated processing that produces legal effects for you or similarly significantly affects you. Section 13 explains why this does not arise here.
To use any of them, write to privacy@jeweliful.com. We answer within one month, and we will tell you within that month if a request is complex enough to need longer. We may need to check who you are before we act, and we will ask for no more than we need in order to do that. There is no charge, unless a request is manifestly unfounded or excessive, in which case we will explain why before doing anything.
If your request is about information one of your customers gave you, send it to us as the merchant on that account, and see section 4.
Your right to object
Complaining to a regulator
If you think we have handled your personal information badly, please tell us first at privacy@jeweliful.com, so that we get the chance to put it right.
You also have the right to complain to a data protection supervisory authority, and doing so does not depend on asking us first. In the United Kingdom that is the Information Commissioner’s Office (ico.org.uk). In the European Economic Area it is the authority for the country you live in, work in, or where you think the problem happened; the European Data Protection Board publishes the list of them.
Cookies and analytics
We use no advertising cookies, no advertising pixels and no cross-site trackers. The cookies we set are the ones the service needs in order to work:
| Cookie | What it is for |
|---|---|
| NEXT_LOCALE | Remembers the language you chose. |
| Clerk session cookies | Keep you signed in and protect the sign-in flow. Set by Clerk, our sign-in provider. |
| beleco_store | Remembers which of your connected stores you are looking at. |
| beleco_setup | Remembers whether you have dismissed the setup panel on your dashboard. |
| beleco_channel_oauth, beleco_pending_shop | Hold the state of a store connection while you are being sent to the store platform and back. They are short-lived and are cleared when the connection finishes. |
| beleco_agent_ref | Records that you arrived through a Jeweliful sales agent's link, so that the agent is credited. Set only if you follow such a link. |
We also use Vercel Web Analytics to count page views and see which pages of our own site are used. It is operated by Vercel on our behalf and reports traffic in aggregate. It has no interface that would let us look up what a named person did, and we do not try to build one.
Automated decision-making
We make no decision about you, and none about your customers, that is based solely on automated processing and that produces a legal effect or similarly significantly affects anyone.
The service does raise an automatic flag when a merchant account’s payment standing needs attention. That flag suspends nothing by itself. Any decision to restrict an account is taken by a person, who looks at the account first, and you can ask us to explain and to reconsider.
Children
This is a service for businesses. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to privacy@jeweliful.com and we will delete it.
If you are in California
For the personal information of your customers that reaches us through an order, we act as your service provider under the California Consumer Privacy Act. We do not sell or share that information, we use it only for the business purposes set out in the Data Processing Terms, we do not use or disclose it outside our business relationship with you, and we do not combine it with personal information from any other source. Those undertakings are written out in full in section 14 of the Data Processing Terms.
For your own account information, we do not sell or share it either. The categories we collect and the purposes we collect them for are in section 3, who receives them is in section 5, and how long we keep them is in section 7. To make a request about it, write to privacy@jeweliful.com. We will not treat you differently for exercising a privacy right.
Changes to this policy
When this policy changes, we change the date printed at the top of it. If a change matters to you, for example a new purpose or a new recipient, we will tell account holders before it takes effect rather than leave it to be discovered.
How to reach us
For anything in this policy, including a request about your own information, write to privacy@jeweliful.com, or to B.F Entreprises at [REGISTERED ADDRESS].