
Privacy & Data Handling Policy
1. What this covers
COACO Design is our internal system for custom-printed orders (tissue paper, food paper, napkins, stickers and packing tape). It is used only by COACO staff. This policy explains how we collect, process, store, use, share and dispose of the data we receive to fulfil orders from Amazon, Etsy, Faire (wholesale orders from retail shops) and customers who order from us directly.
2. What we collect
- Order details: order number, products, sizes, quantities and the options the buyer chose.
- Buyer name and shipping address, to print and ship the order.
- Customization data: the logo files and text the buyer provides for the design.
- An email address only when a direct (non-Amazon) customer gives it to us to receive their design. We never ask Amazon buyers for an email address.
- Quote requests and questions sent from our business site's forms: name, organization, work email, phone, ship-to city, state and ZIP, the products asked about and any artwork files.
3. How we use it
Only to design, print and ship the specific order, and to communicate with the buyer about that order. We do not use it for marketing, we do not sell it, and we do not make automated decisions about people with it.
4. Amazon information
- We receive Amazon data only through the Amazon Selling Partner API, for orders we fulfil ourselves.
- We contact Amazon buyers only through Amazon Buyer-Seller Messaging, never outside Amazon.
- Amazon information is not shared with third parties and is not delegated to any other application.
- Amazon buyer personal information is deleted within 30 days after the order ships.
5. How we store and protect it
- Data is stored in our application hosted in the United States (Railway). All connections use HTTPS/TLS.
- Personal information (names, addresses, customization files) is encrypted at rest with AES-256-GCM. Encryption keys are kept only in our hosting provider's secret store, never in code, and are rotated every year or immediately if exposure is suspected.
- Every staff member has an individual account with a password of at least 12 characters including a special character, multi-factor authentication, and a password change every 365 days. Accounts lock after 5 failed sign-ins.
- Access follows need-to-know: only staff who design, print or ship orders can see buyer personal information. Accounts are reviewed every quarter and disabled the day someone leaves.
- Sign-ins, account changes, views of personal information and file downloads are logged per user, kept for 12 months and reviewed every two weeks.
- Daily backups are encrypted on our server (AES-256) before they leave it and are kept for 30 days at a separate backup provider (Backblaze, Canada), then deleted. The backup copy can only be added to by our server, not read or deleted by it.
- Company computers use disk encryption, anti-malware and a policy that blocks USB storage. Production personal information is never copied to test systems or personal devices.
6. Who we share it with
We do not sell or rent personal information. We use a small number of service providers only to run the system: our hosting provider (Railway); Google Workspace, to email designs to direct customers who asked for them and to answer requests from our business site; Canva, which receives design images only, without buyer personal information; and, only when our staff ask for it on an Etsy or direct order, our AI agent and the AI image service it uses, which receive the buyer's logo image alone to redraw it as a printable logo. Amazon orders are never sent to an AI service. Amazon information is not shared with anyone except as needed to host our own system.
7. How long we keep it and how we dispose of it
- Amazon buyer personal information: deleted within 30 days after shipment.
- Other customers' personal information: deleted within 30 days after the order is delivered, unless the law requires us to keep it longer.
- Requests from our business site's forms: artwork files are deleted after 12 months unless the request became an order; the request itself is deleted 3 years after it last changed.
- Order records without personal information may be kept for accounting.
- Backups age out within 30 days, so deleted data does not remain in backups longer than that.
8. Security incidents
If we detect unauthorized access, a data leak or any other security incident, we contain it (disable accounts, rotate keys and credentials), investigate with our logs, notify Amazon at security@amazon.com within 24 hours when Amazon information is involved, and notify affected people as the law requires. Our incident response plan is reviewed every 6 months.
9. Contact
Questions about your data or this policy: info@coacousa.com
Security and incident contact: Andrea Kim, andreakim@bngknit.com
We review this policy every 6 months and update the date above when it changes.