Privacy

Privacy policy

Effective September 10, 2026

Quote requests

When you request a quote, we collect the contact, project, shipping, referral, and artwork information you provide so we can respond, prepare your quote, and fulfill your request.

Authorized staff sign-in with Google

Our private management portal allows approved staff to sign in with Google. We receive the staff member’s verified email address and may receive their name and profile image. We use this information only to confirm that the person is authorized, establish a short-lived signed-in session, display their account identity, and protect the management portal.

Signing in with Google does not give the management portal access to the person’s Gmail messages, Google Drive files, contacts, or calendar.

Google Workspace email

We use Google OAuth to authorize a designated Artistic Custom Badges and Coins business mailbox. Our email automation uses that authorization to send approved customer-service, quote, proof, and order-related messages and to monitor messages received in that business mailbox so replies can be linked to customer conversations and shown to authorized staff.

For incoming messages, the workflow processes the sender and recipient addresses, sender name, subject, message text, received time, Google message and thread identifiers, and attached files. Supported attachments may be stored in access-controlled private storage and linked to the related customer conversation or order record. Unsupported or oversized attachments are not retained in the customer-management system. The workflow is limited to the designated business mailbox and does not access unrelated personal Google accounts.

OAuth credentials are kept in access-controlled credential storage and are available only to the systems and authorized administrators responsible for operating the email workflow. We do not use Google account information or email content for advertising, and we do not sell it.

Google API Limited Use

Artistic Custom Badges and Coins’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Website analytics

We use privacy-conscious Red Eye Metrics to understand site traffic, navigation, campaign attribution, and whether visitors use contact or quote features. A small sample of sessions may be recorded with strict masking; quote forms are blocked from recording. We do not intentionally record form contents, proof-review pages, or customer proof tokens.

Cloudflare Turnstile

Our quote form uses Cloudflare Turnstile to distinguish people from automated abuse. Turnstile may process security signals such as your IP address, TLS fingerprint, browser user-agent, site key, and the site origin. Cloudflare states that these signals are used to detect and block bots and to improve Turnstile’s bot-detection capabilities, rather than to identify, profile, or target individuals.

Turnstile’s security signals and any associated cookies are treated as strictly necessary to protect the form and website. Cloudflare processes relevant signals on our behalf when providing the service and separately acts as a controller when improving its bot-detection system. For details, including information for EU and UK residents and privacy-contact information, read Cloudflare’s Turnstile Privacy Addendum.

Service providers and sharing

We use information to operate the website and management portal, respond to inquiries, prepare and fulfill orders, send approved business communications, improve our services, maintain records, and protect against abuse. We may provide information to hosting, security, analytics, communications, workflow, and production service providers only as reasonably necessary for them to perform services for us. We may also disclose information when required by law or to protect legal rights and safety.

We do not sell personal information or Google user data, and we do not share it with advertisers or data brokers.

Retention, deletion, and authorization choices

We retain information only for as long as reasonably needed to provide services, administer authorized access, maintain customer and order records, meet legal obligations, resolve disputes, and protect our systems. Customer-service email content and supported attachments linked to a customer conversation may be retained with the related customer or order record. Short-lived staff sign-in sessions expire automatically. Some security, audit, customer-service, and transaction records may be retained when reasonably necessary for those purposes.

A Google account holder can review or revoke an application’s Google authorization through their Google Account permissions. Revoking access may prevent the related sign-in or email function from operating. You may also contact us to ask about accessing, correcting, or deleting information, subject to applicable legal and recordkeeping requirements.

Questions

Contact us through the phone numbers or email addresses listed on our contact page if you have a privacy question or request.