/ Privacy Policy & Trust
Privacy Policy — how we protect your brand, your data and your payments.
This page is maintained by Rockstars Digitals to answer common security and privacy questions about our checkout, brand portal and campaign delivery. It describes the controls currently in place — it is not an independent certification or audit report.
Last updated: 20 June 2026
01 · Accounts & Authentication
Each order gets a private, unguessable URL we e-mail to the customer. No password, no login needed; the link is the credential. We do not store or transmit passwords.
Sessions are bound to your browser via the auth provider's secure cookie / token storage. Signing out clears the session and revokes the local token.
We will never ask for your password or any one-time code by email, chat or phone. Any such request claiming to come from us should be treated as fraudulent and reported.
02 · Google Sign-In & Google User Data
When you choose "Continue with Google" we request only the basic, non-sensitive OAuth scopes: openid, your email address (.../auth/userinfo.email) and your basic profile (.../auth/userinfo.profile, which returns your name and profile picture URL).
We do not request and do not access any Google restricted or sensitive scopes. Specifically we never read or write Gmail, Google Drive, Google Calendar, Google Contacts, Google Photos or any other Google user data.
The email, name and profile picture URL returned by Google are used solely to create and identify your Rockstars Digitals account, to display your name in the brand portal, and to send transactional emails related to your orders. This data is never sold, never shared with third parties for their own purposes, and never used to train any AI model.
You can disconnect Google access at any time from your Google Account at myaccount.google.com/permissions, and you can request deletion of your Rockstars Digitals account and associated profile data through the contact form (subject to the tax-record retention described below).
03 · Admin & Role Separation
Administrative actions (managing campaigns, brand records and orders) are gated by a separate role table on the backend. Roles are checked server-side on every privileged operation; a signed-in customer cannot self-promote to admin from the browser.
Sensitive internal fields on our model catalogue (internal notes, sales counts, revenue, exclusivity windows, record authorship) are excluded from public and customer reads at the database layer and are only reachable through role-checked admin functions.
04 · Payments
Card and bank payments are processed by Mollie Payments B.V., a licensed European payment institution. You enter card details directly on Mollie's checkout — full card numbers, CVCs and bank credentials never reach our servers or our database.
Payment amounts are resolved on our server from the authoritative product record at the moment of checkout. Prices cannot be changed from the browser; client-supplied amounts are ignored.
Payment status is verified by re-fetching the order from Mollie's API on every webhook event, before any order is marked paid or fulfilled.
05 · Data We Collect
We collect only what we need to deliver your campaign and operate the site:
- Account identity: email address and (for Google sign-in) the basic profile fields Google returns.
- Order & billing details: name, billing address, phone, the order line items, and the Mollie payment reference. We do not store card numbers.
- Brief & brand inputs: the references, mood, garments and notes you upload through the brand portal or the brief form.
- Operational logs: timestamps, request IDs and error traces needed to keep the service running. These are kept on the backend and not shared.
We do not sell personal data, and we do not run third-party advertising trackers or behavioural ad networks on this site.
06 · How Your Brand Inputs Are Used
Materials you upload (references, garments, copy) are used only to produce the deliverables you ordered. We do not use your uploads to train, fine-tune or feed any generative AI model.
Generated deliverables may be shown in our public showroom, lookbook and social channels as portfolio work, as described in our Terms & Conditions. If you need a confidentiality arrangement, request it in writing before checkout.
07 · Subprocessors & Hosting
We rely on a small set of established providers to run the service:
- Managed Postgres (EU region) — database, authentication and file storage.
- Mollie Payments B.V. — payment processing.
- Cloudflare — edge hosting and DDoS protection for the website and API endpoints.
- Google — optional sign-in identity provider.
Each provider is contractually bound by its own data-processing terms. Data may be processed in the EU and in other regions where these providers operate.
08 · Encryption
Traffic between your browser and our site is served over HTTPS (TLS). Connections to our database and to payment, auth and storage providers use TLS in transit.
Data at rest in our managed database and file storage is encrypted by the underlying provider. We do not claim end-to-end encryption — operational access by our backend code is required to deliver the service.
09 · Cookies & Analytics
We use the minimum cookies required to keep you signed in and to complete checkout. We do not run third-party advertising cookies on this site.
Lightweight, privacy-respecting usage analytics may be enabled to understand which pages and campaigns get traffic. Where used, IPs are not retained in a way that identifies individual visitors.
10 · Retention & Deletion
Order, invoice and tax records are retained for the periods required by Estonian and EU tax law (currently 7 years).
Brand portal uploads and brief contents are retained for the lifetime of your relationship with us so that we can re-export or revisit a campaign on request. You may ask us to delete brand inputs that are no longer needed at any time.
On a verified request from an account owner we will close the account and delete the associated profile and brief data, subject to the tax-record obligation above.
11 · Your Privacy Rights
If you are in the EU/EEA, the UK or another region with comparable privacy law, you may request access to, correction of, or deletion of your personal data, and you may object to specific processing.
Send privacy requests through the contact form. We respond within 30 days. We may need to verify your identity by reference to the email on the account before acting on a request.
12 · Incident Response
If we become aware of a security incident that affects your account or personal data, we will notify affected users by email without undue delay and post a status update on this page, in line with our obligations under EU GDPR.
Suspected incidents can be reported to us at any time through the contact form. We treat well-described, good-faith vulnerability reports as cooperation, not as an attack.
13 · Scope & Shared Responsibility
Rockstars Digitals is responsible for the controls on this site, the brand portal and the backend that supports them. Mollie, our managed Postgres host, Cloudflare and Google are responsible for the security and certifications of their own platforms.
You are responsible for keeping your sign-in email account secure, only sharing portal access with people you trust, and ensuring that the materials you upload are owned by or licensed to you.
Nothing on this page constitutes a certification, audit opinion or legal guarantee. If you require contractual security commitments (DPA, NDA, specific compliance attestations), contact us before purchase.
Reporting & Contact
Report a suspected security issue, abuse, or a privacy concern by writing to us through the contact form. Include enough detail to reproduce the issue. We acknowledge reports within a few business days.
Rockstars Digitals (trade name of Cryptofamily Nederland OÜ) · Lõõtsa tn 5, 11415 Tallinn, Estonia (EU) · Registration No. 17156167
