Effective date: August 21, 2026
Chriuus Designs operates this licensed seller directory and seller dashboard. This notice explains what information we process, why we need it, what may become public, and the service providers that help operate the site. We minimize collection and do not sell or rent personal information.
Plain-language summary
- Anyone may browse the public seller directory without creating an account.
- Seller and administrator accounts use emailed codes. We do not create or store passwords.
- Patreon login happens on Patreon. We never receive or store your Patreon password or payment details.
- We do not retain a seller-specific Patreon access token or refresh token after the connection check.
- We do not process purchases, orders, card details, or customer messages between visitors and sellers.
- We do not use advertising trackers or sell personal information.
Information we process
Public visitors
Our hosting and security provider receives ordinary request information such as IP address, browser details, requested page, and timestamps. We use this only to deliver, secure, and troubleshoot the site. Directory searches may be included in the requested URL, but we do not build advertising profiles from searches.
If you choose Find Near Me, your browser obtains your precise coordinates and performs the distance calculation in that browser tab. Chriuus Designs does not receive or permanently store those precise visitor coordinates.
Account and sign-in information
If you complete sign-in, or if an administrator prepares an invited seller profile, we store the private login email, account role and status, and login timestamps. During code delivery and abuse prevention, we store keyed hashes of the email, login code, and requesting IP address rather than those values in the code record. Resend necessarily processes the delivery email address and message to send the code or invitation.
A strictly necessary, secure, HTTP-only session cookie keeps you signed in. The server stores only keyed hashes of the session and request-protection secrets, plus creation, activity, expiration, and revocation timestamps.
Patreon license verification
Connecting Patreon redirects you to Patreon, where you sign in and approve access. This site requests the minimum identity and membership scopes needed to verify the Chriuus Designs Commercial License. We do not request Patreon email, shipping address, or payment information.
We temporarily use the OAuth result to ask Patreon who connected and whether that account has the applicable campaign membership and entitled tier. We then retain the Patreon user and member identifiers, relevant campaign and tier identifiers, current entitlement state, verification health, check timestamps, limited error codes, and membership-check history. This lets us prevent duplicate account linking and recheck eligibility. Seller-specific Patreon OAuth access and refresh tokens are deliberately not retained.
A temporary Patreon outage does not immediately deactivate a last-confirmed active license. The application may apply a verification grace period of up to 72 hours while retrying. A membership Patreon confirms as inactive is not treated as active during that grace period.
Seller profiles and locations
Seller account data may include profile text, business name, logo, fulfillment options, categories, storefront and social links, model showcase text and images, a private account email, an optional public contact email, and profile and showcase revision history. Administrators may also retain private review notes and security or accountability audit records.
We do not ask for a street address, legal name, or phone number. A seller may optionally submit a postal code to help choose a general locality. The postal code is sent to Geoapify for that search and, if retained, is encrypted and kept private. Public pages use only a seller-approved general locality and an intentionally approximate map marker. They never publish a submitted postal code or residence coordinate.
Design Board
Eligible sellers may submit idea text, up to three reference images, and votes. Images are decoded, resized, converted to WebP, and stripped of original metadata before storage. The sanitized text and image content is sent to OpenAI's moderation endpoint for an automated safety check. We retain the moderation result, model, timestamps, limited category names, and provider error code when applicable, but not raw moderation scores. Design Board content is available only to eligible sellers and administrators unless an item remains private for review.
What becomes public
A seller profile becomes public only after the seller claims it, verifies an active Commercial License, verifies the general location, submits the profile, and receives administrator approval. Public data may include the business name, descriptions, sanitized logo and showcase images, general locality, approximate marker, fulfillment options, categories, approved model showcases, seller-selected links, and an email only when the seller chooses to publish it.
Private login emails, private postal codes, Patreon identifiers, session records, login records, administrator notes, and audit internals are not included in public seller responses.
Service providers
We disclose limited information to providers only as needed to operate these features:
- Cloudflare hosts the Worker, database, media storage, image processing, network security, and necessary Turnstile challenge.
- Resend delivers login codes and seller invitations.
- Patreon handles its own login and provides membership verification data after authorization.
- Geoapify processes submitted locality search terms and an optional postal code for geocoding.
- OpenFreeMap supplies public map tiles and may receive normal tile-request metadata from the browser.
- OpenAI processes Design Board text and sanitized reference images for safety moderation.
- Ko-fi handles optional donations after a visitor chooses the external support link. Chriuus Designs does not receive card details through this site.
Public seller links lead to independent third-party sites. Their privacy practices apply after you follow those links.
Cookies and tracking choices
The site uses a necessary session cookie only after login. Cloudflare Turnstile may process device and request signals to prevent automated abuse. We do not currently use advertising cookies or cross-site behavioral advertising. Because we do not perform that kind of tracking, a browser's Do Not Track setting does not change the site's behavior.
Retention
- Login codes expire after 10 minutes and are cleaned after a short security window.
- Rate-limit hashes are normally removed after about two days of inactivity.
- Sessions expire after 14 days of inactivity and no later than 30 days after creation; expired or revoked server records are later cleaned.
- Patreon OAuth state is short-lived, and detailed membership-check history is normally kept for 180 days.
- Unattached staged images are normally removed after 24 hours, with orphaned database records cleaned later.
- An account that signs in but never becomes or participates as a seller is automatically cleaned after its login activity and associated security records age out. This process begins only after at least 30 days and may take longer.
- Seller profiles and revisions, Design Board submissions and votes, moderation results, administrator notes, and audit records may be retained as product, licensing, security, or accountability history.
We may keep information longer when reasonably necessary to comply with law, resolve a dispute, protect the service, or enforce the Terms.
Your choices and requests
Sellers can edit their working profile and model showcase drafts, archive showcases, and choose whether to participate in the public directory. To request a copy, correction, disconnection, or deletion of account information, email chriuus@chriuusdesigns.com. We may need to verify the requesting email before acting. Some audit or legal records may be retained when deletion is not appropriate or legally required.
Security and international processing
We use access controls, encrypted connections, hashed authentication secrets, encrypted sensitive stored values, private media storage, metadata-stripping image processing, and server-side authorization. No Internet service can guarantee absolute security. Providers may process information in countries other than your own, subject to their terms and privacy safeguards.
Children
Seller accounts and the Design Board are not directed to children under 13, and we do not knowingly collect account information from them. Contact us if you believe a child has provided account information.
Changes and contact
We may update this notice as the service changes. The effective date above will be updated, and material changes will be communicated when appropriate. Questions or privacy requests may be sent to chriuus@chriuusdesigns.com.