Privacy Policy
Last Updated: March 1, 2026
This Privacy Policy describes how ("we", "us", or "our") collects, uses, and discloses your personal information when you visit or make a purchase from our website.
Introduction
At DIY Gifts, we respect your privacy and are committed to protecting your personal data. This privacy policy will inform you about how we look after your personal data when you visit our website (regardless of where you visit it from) and tell you about your privacy rights and how the law protects you.
This website is not intended for children and we do not knowingly collect data relating to children. It is important that you read this privacy policy together with any other privacy policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data.
Information We Collect
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Personal Data You Provide to Us
- Identity Data: first name, last name, username or similar identifier, title, date of birth, and gender.
- Contact Data: billing address, delivery address, email address, and telephone numbers.
- Financial Data: payment card details (processed securely by our payment providers - we do not store full card numbers).
- Transaction Data: details about payments to and from you and other details of products you have purchased from us.
- Technical Data: internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
- Profile Data: your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
- Usage Data: information about how you use our website, products and services.
- Marketing and Communications Data: your preferences in receiving marketing from us and our third parties and your communication preferences.
Customization Information
When you create custom products, we collect information about your design choices, including:
- Selected materials, colors, and finishes
- Engraving text and font preferences
- Dimensions and size specifications
- Reference images or sketches you upload
- Design notes and special instructions
This information is necessary to fulfill your custom order and is stored as part of your order history.
How We Use Your Information
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
To Provide Our Services
- To process and deliver your orders, including managing payments and shipping
- To manage your account and provide customer support
- To communicate with you about your orders, customizations, and inquiries
- To facilitate the customization process and share design proofs
To Improve Our Website
- To administer and protect our business and website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
- To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you
- To use data analytics to improve our website, products/services, marketing, customer relationships and experiences
Marketing Communications
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. You will receive marketing communications from us if you have:
- Requested information from us or purchased goods from us and you have not opted out of receiving that marketing
- Provided us with your details and ticked the box at the point of entry of your details for us to send you marketing communications
- You can opt out of marketing at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at hello@customcraft.com
Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
Security Measures
- Encryption: All data transmitted between your browser and our servers is encrypted using SSL/TLS technology.
- PCI Compliance: Our payment processing is fully PCI-DSS compliant. We do not store full credit card numbers on our servers.
- Access Controls: Strict access controls and authentication measures protect your data from unauthorized access.
- Regular Audits: We regularly review our information collection, storage, and processing practices to prevent unauthorized access.
We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
For All Users
- Access: You can request access to your personal data and ask for a copy of the information we hold about you.
- Correction: You can request that we correct any incomplete or inaccurate data we hold about you.
- Deletion: You can request that we delete your personal data where there is no good reason for us continuing to process it.
- Objection: You can object to our processing of your personal data where we are relying on a legitimate interest.
- Restriction: You can request that we suspend the processing of your personal data in certain scenarios.
- Data Portability: You can request the transfer of your personal data to you or a third party in a structured, commonly used, machine-readable format.
For EU Residents (GDPR)
If you are located in the European Union, you have additional rights under the General Data Protection Regulation (GDPR). We are the data controller responsible for your personal data. Our legal basis for collecting and using your personal data depends on the specific context:
- We need to perform a contract with you (e.g., to process your order)
- It is necessary for our legitimate interests (e.g., to improve our services)
- You have given us consent (e.g., to receive marketing communications)
- We need to comply with a legal obligation
For California Residents (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You can request that we disclose the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You can request that we delete personal information we have collected from you.
- Right to Opt-Out: You can opt-out of the sale of your personal information (we do not sell your personal information).
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise any of these rights, please contact us at hello@customcraft.com. We will respond to all legitimate requests within one month.
Children's Privacy
Our website is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from a child without verification of parental consent, we take steps to remove that information from our servers.
International Data Transfers
We are based in the United States and may transfer your personal data to countries outside your country of residence, including the United States. These countries may have data protection laws different from those of your country.
When we transfer personal data from the European Union to the United States, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission. We also comply with the EU-U.S. Privacy Shield Framework (where applicable).
By submitting your personal data, you agree to this transfer, storage, and processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.
Changes to This Privacy Policy
We may update our privacy policy from time to time. We will notify you of any changes by posting the new privacy policy on this page and updating the "Last Updated" date at the top of this policy.
You are advised to review this privacy policy periodically for any changes. Changes to this privacy policy are effective when they are posted on this page.
Contact Us
If you have any questions about this privacy policy or our data practices, please contact us at:
Address:
Email: hello@customcraft.com
Phone: +1 (800) 456-7890
Data Protection Officer: privacy@luxecustom.com
For privacy-related requests, please include "Privacy Request" in the subject line of your email to help us process your request quickly.