Privacy Policy
1. Overview & Data Controller
444 Design Corp (founder Luc Nijman) is the data controller for this website. This policy explains how personal data is processed in connection with the Frames shop and the certificate of authenticity (CA) system.
Contact for all privacy matters: use the contact form.
Last updated: 1 August 2026.
2. Data Collected
Orders. When an order is placed on the Frames page, the payment processor Stripe collects name, email address and delivery address to process the payment and arrange delivery. Order details — artwork, size (A4/A2), edition (framed or unframed), quantity and total — together with the delivery address and email, are received and used solely for shipment and order confirmation. Card details are processed entirely by Stripe and never reach 444 Design Corp.
Verification. When a certificate is verified on the Prove Authenticity page, the email address, order number and artwork number are transmitted once, over HTTPS. Only a one-way SHA-256 hash of the email is stored. Neither the plaintext email nor the codes are logged or retained by the verification endpoint.
Browser. Your cart is stored in your own browser's session storage and clears when the tab is closed. Cloudflare processes technical request data (such as IP address and user agent) to deliver pages and protect against abuse.
3. How Data Is Used
- Fulfil orders — production, framing, delivery arrangement and invoicing.
- Send order confirmations and the order number.
- Operate the authenticity database and the verification service.
- Security, fraud prevention and legal compliance.
Personal data is not used for advertising, profiling or analytics, and is never sold or rented to anyone.
4. Legal Basis
Performance of a contract — processing orders and delivering products.
Legitimate interest — the authenticity database and verification service exist to prove provenance and ownership; this outweighs any privacy impact because the email is stored only as a one-way hash.
Legal obligation — retaining order records for tax and accounting purposes.
5. Processors & Transfers
- Stripe — payment processing. Their privacy policy applies to payment data: stripe.com/privacy.
- Resend — delivery of transactional emails (order confirmation, artist notification).
- Cloudflare — hosting, the D1 authenticity database and image storage (R2).
Some of these processors are based in the United States. Transfers are protected by standard contractual clauses and, where applicable, EU adequacy decisions. Where you purchase as a consumer, your data is never shared for marketing purposes.
6. Storage & Security
The buyer's email is hashed with SHA-256 before storage and the plaintext is never persisted in the authenticity database. Inputs to the verification endpoint are never stored or logged. Data in transit is encrypted with TLS, the database is protected by Cloudflare access controls, and secrets are kept as encrypted environment variables. Because only a hash is stored, it is not possible to recover or "read" an email from the database — which is also why proof is never re-sent by email.
7. Retention
Authenticity records (email hash, order number and artwork number) are kept indefinitely — permanent proof of ownership is the purpose of the system. Order and accounting records are kept for the duration required by applicable tax and accounting law.
8. Your Rights
You may request access, rectification, erasure, restriction, portability of, or objection to the processing of your personal data at any time via the contact form.
Please note: erasing an authenticity record permanently removes proof of ownership. You will be informed of this consequence before deletion, and records required by law are retained. You also have the right to lodge a complaint with your national data protection authority (in France, the CNIL).
9. Cookies & Local Storage
This site uses no cookies, no analytics and no third-party trackers. The Frames page stores your cart in your browser's local storage only; you can clear it at any time through your browser settings.
10. Children
This site is not directed to minors. Personal data from children under 16 years of age is not knowingly collected.
11. Policy Changes
This policy may be updated when the site's features change. Material changes are announced on this page. Continued use of the site after a change constitutes acceptance of the updated policy.