Privacy
The short version: we collect what we need to send you shoes and answer your emails. We do not sell it, we do not run ad trackers, and you can have it deleted by asking.
Last updated 24 August 2026
What we collect
If you join the launch list
Your email address, and the date you joined. That is the whole record.
If you create an account
Your email address, a name if you give us one, and your password — stored only as a bcrypt hash, so we cannot read it and neither can anyone who steals the database.
If you order
Your email, shipping address, the sizes you bought, the amount, and a Stripe reference. We never receive your card number. It goes from your browser to Stripe directly; we get back the last four digits, the card brand, and whether it worked.
Automatically
Our host keeps standard server logs — IP address, timestamp, which page, which browser. They are kept for security and debugging. We do not run Google Analytics, advertising pixels, or any cross-site tracker, and this site sets no marketing cookies. The only cookie we set is the one that keeps you signed in.
Why we hold it
- To fulfil your order. We cannot post shoes to an address we do not have.
- To answer you. Support replies need the order they refer to.
- To email you when the shoe ships, but only if you asked for that.
- To meet tax and accounting law, which requires us to keep sale records.
Who else sees it
Four companies, each doing one job:
- Stripe. Payments. They receive your card and billing details directly.
- Vercel. Hosting. They serve the site and keep the request logs.
- Neon. The database holding accounts and orders.
- Resend. Sends the order confirmation and the launch email.
Plus the courier that carries the parcel, who needs your address to deliver it. Nobody else. We do not sell, rent, or trade your details, and there is no scenario in which we would.
How long we keep it
- Launch list. Until you unsubscribe, then deleted.
- Account. Until you ask us to close it.
- Orders. Seven years, because tax law says so. After that, deleted.
- Server logs. About 30 days.
Your rights
Wherever you live, we will do all of these — GDPR and UK GDPR make them a legal right, and we see no reason to treat anyone else worse.
- Get a copy of everything we hold on you.
- Have anything wrong about it corrected.
- Have it deleted, except order records we are legally required to keep.
- Unsubscribe from any email, from a link in every email we send.
- Object to how we are using it.
Email cs@aeroshoes.store and we will action it within 30 days, usually much sooner. We will not ask you why.
Security
The whole site runs over HTTPS. Passwords are bcrypt-hashed. Session cookies are HTTP-only and same-site, so a script on another page cannot read them. Card data never reaches our infrastructure at all.
We are a small operation and we are not going to claim we are unhackable. If something happens that affects you, we will tell you what happened and what to do about it, quickly and in plain words.
Children
AERO is not intended for under-16s and we do not knowingly collect their data. If you believe a child has given us information, email us and we will remove it.
Changes
If this policy changes in a way that affects you, we will email anyone on the list rather than quietly editing the page and updating the date.
Questions about any of this go to cs@aeroshoes.store.