Privacy Policy

How Folded Petal collects, uses, and protects your personal information.
30 avr. 2026

Last updated: 30 April 2026.

1. Who we are

This website www.foldedpetal.com and the Folded Petal mail subscription service are operated by Joydeer Limited, a private company limited by shares incorporated in Hong Kong (Company No. 78997328), with registered office at Room D07, 8/F, Kai Tak Factory Building, No. 99 King Fuk Street, San Po Kong, Hong Kong ("we", "us", "our").

For any privacy-related question, write to us at hello@foldedpetal.com.

2. What we collect

We collect only what we need to ship you a postcard and run a small studio.

CategoryExamplesPurpose
Identity & contactName, email, postal addressAccount, shipping the envelope, sending tracking and receipts
PaymentLast four digits of card, billing country, Stripe customer IDProcessing your subscription. Full card numbers are never stored on our servers — they are handled by Stripe
CommunicationEmails you send us, support replies, commission briefsAnswering you and improving our product
TechnicalIP address, browser type, locale, pages viewedSite security, debugging, basic analytics (aggregated)
CookiesSession cookie, Stripe checkout cookieKeeping you signed in and processing checkout

We do not collect: precise location, biometric data, government IDs, or any special-category personal data. We do not buy or sell personal data.

Is providing this data optional? Providing the identity, contact, and payment data above is a contractual requirement — we need it to fulfil your order. If you choose not to provide it, we cannot ship your envelope or process your subscription, and the contract cannot be performed. There is no statutory obligation to give us this data.

Automated decision-making. We do not make any decisions about you using purely automated processing or profiling that produces legal or similarly significant effects.

3. Lawful bases (GDPR / UK GDPR)

If you are in the UK or EEA, we process your data under one or more of these bases:

  • Contract — to fulfil your subscription (shipping, billing, support).
  • Legitimate interest — preventing fraud, securing the site, replying to inquiries.
  • Consent — non-essential cookies and marketing emails (you can withdraw at any time).
  • Legal obligation — tax records, accounting, fraud reporting.

4. Who we share it with

We use a small number of trusted processors. Each one is contractually required to protect your data and use it only for our service:

ServicePurposeRegion
Stripe Payments Europe Ltd / Stripe Inc.Card processing & subscription billingIreland / United States
Vercel Inc.Website hostingUnited States (Washington D.C.)
Neon Inc.Database (encrypted at rest)United States (AWS US East)
Resend Inc.Transactional emails (receipts, tracking, dispatch)United States
China Post / commercial mail carriersPhysical mail deliveryHong Kong / mainland China handover, then your country's postal service

We never share your information for advertising, profiling, or third-party marketing. Under the California Consumer Privacy Act (CCPA/CPRA), we do not "sell" or "share" your personal information as those terms are defined in §1798.140 — see Section 8 below.

5. International transfers

Because our infrastructure is hosted in the United States and our mail leaves from Hong Kong, your data crosses borders. Where required (notably for UK and EU residents), we rely on:

  • Standard Contractual Clauses with Stripe, Vercel, Neon and Resend; or
  • Adequacy decisions issued by the relevant authority; or
  • Your explicit consent at sign-up.

You may request a copy of the transfer safeguards by writing to us.

6. How long we keep it

DataRetention
Subscription recordsDuration of your subscription + 7 years (Hong Kong tax / accounting)
Postal addresses (active)Until you cancel and request deletion
Postal addresses (cancelled)Deleted within 90 days of cancellation, unless you ask sooner
Email correspondence24 months from last reply, then deleted
Server logs30 days

How we destroy data. When personal data reaches the end of its retention period or is the subject of a verified deletion request:

  • Production database (Neon): deleted by SQL DELETE and cascade, irrecoverable from the live database within minutes.
  • Routine backups: Neon retains point-in-time recovery for up to 30 days. Personal data may persist in encrypted backups during this window. We do not restore old backups for any purpose other than disaster recovery, and we re-apply deletion automatically after restoration.
  • Application logs and email systems (Resend): rotated out within 30 days for logs and per the Resend retention schedule for emails.
  • Backups older than 35 days: cycled out and the storage segments overwritten by the cloud provider — equivalent to cryptographic erasure because the database is encrypted at rest with keys we control.

This means a deletion request is fully effective in the live system immediately and across all backup storage within 35 days at the latest.

7. Your rights

Wherever you live, you may write to hello@foldedpetal.com to:

  • Access the personal data we hold about you;
  • Correct anything inaccurate;
  • Delete your data (right to be forgotten);
  • Export your data in a portable format;
  • Object to or restrict processing;
  • Withdraw consent for non-essential cookies or marketing.

We respond within 30 days. To protect your account we may verify your identity by asking you to confirm details we already hold (e.g. order number plus the email on file).

If you wish to lodge a complaint with a regulator, you may contact the supervisory authority in your country. Examples:

For other jurisdictions, please contact your national data protection authority.

8. Notice for California residents

This section provides the disclosures required by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA/CPRA").

8.1 Categories of personal information collected (last 12 months)

Category (CCPA)Collected?SourcesDisclosed to
Identifiers (name, email, postal address, IP)YesDirectly from youService providers in §4
Customer records (billing, order history)YesDirectly from you, StripeStripe, our database
Commercial information (purchases)YesStripe, our databaseService providers in §4
Internet/network activity (page views, session data)YesDirectly from your deviceVercel (hosting logs only)
Geolocation (general, derived from IP)Yes (general only)Directly from your deviceVercel
InferencesNo
Sensitive personal informationNo
Biometric, health, precise geolocationNo

8.2 Purposes

We collect the categories above to (i) fulfil orders, (ii) prevent fraud, (iii) provide customer support, (iv) comply with tax and legal obligations, and (v) improve our service. Each purpose is described against the relevant data category in Section 2.

8.3 Your California rights

  • Right to know what personal information we have collected about you and how we use it.
  • Right to delete personal information we hold about you, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of "sale" or "sharing" of your personal information. We do not sell or share personal information as those terms are defined under CCPA/CPRA, including for cross-context behavioural advertising. Therefore there is nothing to opt out of, but you have a continuing right to confirm this with us.
  • Right to limit use of sensitive personal information. We do not collect sensitive personal information.
  • Right to non-discrimination. We will not deny service, charge a different price, or provide a different quality of service because you exercised any of these rights.

8.4 How to exercise your rights

Email hello@foldedpetal.com with the subject line "California Privacy Request". To verify your identity we will ask for two pieces of information already on file (such as the email associated with your account plus your most recent order number). We respond within 45 days, extendable by another 45 days where reasonably necessary.

8.5 Authorized agents

You may use an authorized agent to make a request. We require: (a) written permission signed by you authorizing the agent, and (b) verification of your own identity directly with us. Powers of attorney are accepted in lieu of (a).

8.6 Contact for California-specific inquiries

Use the email above and mention "California". We do not maintain a toll-free number — small studio, online only.

9. Notice for Hong Kong residents (PDPO)

This section is the Personal Information Collection Statement required by Data Protection Principle 1 of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO").

9.1 Purposes of collection (DPP1)

We collect personal data for the following purposes only:

  • to administer your account and process your subscription, originals or commission orders;
  • to ship physical mail and provide tracking and customer support;
  • to comply with Hong Kong tax, accounting and anti-fraud obligations;
  • to communicate with you about the service when necessary.

We will not use your personal data for direct marketing without your separate consent (PDPO Part 6A).

9.2 Classes of transferees (DPP3)

Your personal data may be transferred only to the service providers listed in Section 4 (Stripe, Vercel, Neon, Resend) and to postal carriers for the purpose of delivering your envelope.

9.3 Data Access Request (DAR) and Data Correction Request (DCR)

You have the right under sections 18 and 22 PDPO to:

  • request a copy of any personal data we hold about you (DAR);
  • request correction of any inaccurate personal data (DCR).

To make a request, write to hello@foldedpetal.com with the subject line "PDPO Request" stating your full name, email used to register, and the data you wish to access or correct. We will:

  • acknowledge your request within 7 days;
  • respond substantively within 40 days as required by PDPO s.19(1);
  • charge no fee for routine DARs (we reserve the right to charge a reasonable fee, capped per PCPD guidance, for unusually voluminous or repetitive requests).

If you are dissatisfied with our response you may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.

10. Children

Folded Petal is not directed at children under 13 (or the higher minimum age set by your local data protection law, e.g. 16 in some EU member states). We do not knowingly collect personal data from children. If you believe a child has subscribed, write to us and we will delete the account immediately.

11. Cookies

We currently use only strictly necessary cookies as defined under the UK PECR / EU ePrivacy Directive — that is, cookies without which the site or your transaction cannot function. We do not use third-party advertising cookies, behavioural tracking pixels, or analytics cookies as of the date of this policy.

Cookie familySet byPurposeTypeDuration
better-auth.* (session token)foldedpetal.com (first-party)Keeping you signed in to your accountStrictly necessaryUp to 30 days, refreshed on activity
__stripe_* / m / cidstripe.com (third-party, set on checkout pages only)Fraud prevention and processing your card payment securelyStrictly necessaryUp to 1 year (Stripe-controlled)
NEXT_LOCALEfoldedpetal.com (first-party)Remembering your language preferenceStrictly necessary1 year
__cf_bm / cf_clearance (only when Cloudflare is in front of a sub-resource)cloudflare.comBot protection and DDoS mitigationStrictly necessary30 minutes – 1 year

You can clear or block these cookies in your browser at any time, but doing so may break sign-in, checkout, and your language preference. Because they are strictly necessary, no consent is required under PECR / ePrivacy.

If we ever add non-essential cookies (analytics, advertising, social-media pixels, etc.), we will deploy a cookie-consent banner allowing you to accept or reject each non-essential category before any such cookie is set, and we will update this section to list every new cookie by name, purpose, and duration.

12. Security

Your data is protected with industry-standard measures: TLS 1.2+ in transit, AES-256 encryption at rest at the database layer (Neon), restricted role-based internal access, and Stripe's PCI-DSS Level 1 environment for all card data. No system is perfectly secure; if a breach affects you, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.

13. Changes to this policy

We may update this policy from time to time. The "Created" date below reflects the latest revision. Material changes will be notified by email to active subscribers at least 14 days before they take effect.

14. Contact

Joydeer Limited Room D07, 8/F, Kai Tak Factory Building No. 99 King Fuk Street, San Po Kong Hong Kong SAR

Email: hello@foldedpetal.com