Privacy policy.
Last updated: March 31, 2026
We collect what we need to ship instruments, answer questions, and process refunds — nothing more. We do not sell your data, do not share it with advertising networks, and do not maintain marketing profiles on individuals.
01 — Summary
If you only read one section, read this one:
- What: Name, email, shipping address, order history, and basic site analytics.
- Why: To ship your order, answer your questions, and improve the site.
- Who: Our payment processor (Stripe), our fulfilment partner (Austin, TX), and our email tool (Postmark). No one else.
- Rights: You can ask us to show, correct, or delete your data at any time.
02 — What we collect
You give us:
- Name, email address, shipping & billing address, phone number (optional).
- Order details and any messages you send us.
- Newsletter subscription, if you opt in.
We collect automatically:
- IP address and approximate location (country / city level).
- Browser type, device type, and pages visited.
- A first-party analytics cookie, refreshed every 30 days.
03 — Why we collect it
We process your data on the following lawful bases:
- Contract: to fulfil orders and provide warranty service.
- Legitimate interests: to detect fraud, improve the site, and respond to your questions.
- Consent: to send our newsletter (you may unsubscribe at any time).
- Legal obligation: to keep tax and accounting records as required by US law.
04 — How we store it
Customer data is stored in encrypted databases hosted by AWS in the US East (Virginia) region. Access is restricted to studio staff on a need-to-know basis. We retain order records for seven years to comply with tax law; all other personal data is deleted within 24 months of your last interaction with us.
05 — Who we share with
We share data only with the following processors, and only the minimum required for them to perform their function:
- Stripe — payment processing.
- ShipBob — domestic fulfilment from Austin, TX.
- Postmark — transactional email (order confirmations, shipping updates).
- Plausible Analytics — privacy-friendly site analytics, no personal data shared.
We do not share data with advertising platforms, data brokers, or social-media tracking pixels.
06 — Cookies
We set a small number of first-party cookies, all of which are strictly necessary:
- nbw_session — keeps your bag and login session active.
- nbw_pref — stores currency and locale preferences.
- plausible_id — first-party analytics, expires every 30 days, no cross-site tracking.
07 — Your rights
Regardless of where you live, we will honour the following requests by email to privacy@nicebodywork.studio:
- Show me everything you have on me.
- Correct an error in my data.
- Delete my data and account.
- Stop sending me marketing.
- Send my data to another provider in a portable format.
We respond within 30 days. We never charge for these requests.
08 — International transfers
We are based in the United States and store all customer data within US jurisdictions. If you are located outside the US, your data may be transferred to the United States when you place an order. We take reasonable steps to ensure your data is handled securely.
09 — Children
The site is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe we have, please write to us and we will delete it promptly.
10 — Contact & complaints
For privacy questions, write to privacy@nicebodywork.studio. If you are dissatisfied with our response, you have the right to complain to your local data protection authority.