Privacy Policy
We keep this simple: we only ask for what we need to reply to you, send the dispatch if you want it, and get your decants to your door.
Last updated: 4 August 2026
Who we are
Robot Fragrances (“we”, “us”) is an independent perfume decanting business — a sole proprietorship trading under that assumed name from New York City, New York, United States. We decide what this site collects and why, so we’re the ones responsible for it. Any question about this policy: hello@robotfragrances.com.
The short version
We collect the least we can get away with. There are no analytics on this site, no advertising pixels, and no tracking cookies — we genuinely don’t know who you are until you write to us or buy something. We have never sold personal data and won’t.
What we collect
- Newsletter sign-up: your email address, and nothing else, when you choose to subscribe.
- Contact form: your name, email address, the topic you pick, and the message you write.
- Orders: your name, shipping address, email address, and what you ordered. Payment is taken on Stripe’s own page — your card number never touches our site or our servers, and all we ever see back is the last four digits, the card brand, and whether it worked.
- On your device: your cart is kept in your browser’s
localStorageand also written into the page address, so it survives a refresh and a cart can be bookmarked or sent to someone. Your Scent Finder answers work the same way. None of it reaches us unless you check out, and we set no cookies of our own.
Worth knowing: because the cart travels in the address, any link you copy from a page while your cart is filled will show its contents to whoever you send it to — that’s what makes a cart shareable, but it cuts both ways. Empty the cart first if you’re sending someone a link and would rather they didn’t see it. (The Scent Finder’s own “copy link” button is an exception: it shares your answers only, never your cart.) - Automatically, in server logs: like every website, the services that serve these pages record technical request data including your IP address, browser type, and the page requested. We use it only to keep the site up and to spot abuse. We don’t build profiles from it and we don’t combine it with anything above.
How we use it
- To reply to your message, or help you put a discovery set together.
- To take, pack and ship your order, and to contact you about that order.
- To send the newsletter, only if you asked for it — see below.
- To keep the tax and accounting records a business is required to keep.
That is the whole list. We don’t use your details for advertising, we don’t enrich them from other sources, and we make no automated decisions about you.
Who else touches it
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. It reaches these companies only because they run part of the shop:
- Formspree — delivers both the contact form and the newsletter sign-up to our inbox. It receives whatever you type into those forms. Privacy policy.
- Stripe — takes the payment and collects your shipping and billing address on its own secure page. Privacy policy.
- Cloudflare — runs the small service that prices your basket and creates the Stripe session. Privacy policy.
- GitHub (GitHub Pages) — hosts and serves these pages. Privacy statement.
- Shipping carriers — get your name and address so a parcel can reach you.
We may also disclose information if the law requires it, or to protect our rights or someone’s safety. All of these companies process data in the United States.
That is the whole list. Notably absent: fonts. The two typefaces here are served from our own site rather than from Google, so loading a page doesn’t announce your IP address to a third party you never chose to visit.
The newsletter, honestly
Right now the sign-up form simply emails your address to us; there is no mailing platform behind it yet, so there is no automatic unsubscribe link to click. Instead the opt-out sits next to every sign-up box on the site, and here: unsubscribe by email. Reply to any message we send and that works too. No reason needed, we’ll confirm, and we’ll do it within a few days rather than the ten the law allows.
We are moving to a dedicated email platform. When we do, we’ll name it here, every marketing email will carry a one-click unsubscribe link and our postal address, and we’ll update the date at the top of this page. We won’t add you to any list you didn’t ask to join, and we don’t email customers marketing they didn’t opt into.
How long we keep it
- Orders, receipts and shipping records — 7 years. Long enough to cover tax and accounting requirements and any dispute about an old order.
- Contact form messages — 24 months from your last message to us, then deleted.
- Newsletter address — until you unsubscribe, then removed within 30 days. We keep a minimal suppression record so we don’t accidentally re-add you.
- Server logs — whatever our hosting and payment providers keep under their own policies, linked above. We don’t hold copies.
Your choices
Write to hello@robotfragrances.com and you can ask us to:
- tell you what personal information we hold about you and give you a copy;
- correct anything that’s wrong;
- delete it, unless we’re legally required to keep it (an order record inside its 7 years, typically);
- stop emailing you.
We’ll answer within 30 days. We won’t charge you, and we won’t treat you any differently for asking.
Some US states — California, Colorado, Connecticut, Virginia and others — give residents these rights by statute, but only against businesses above a certain size, and we are well below those thresholds. Rather than make you work out whether a law covers you, we offer the rights above to everyone who asks, wherever you live.
We sell and ship within the United States only and don’t offer goods or services to people in the EU or UK, so we don’t operate under the GDPR. If you’re browsing from outside the US and want us to delete something, ask anyway and we will.
How we look after it
New York’s SHIELD Act requires businesses holding New York residents’ private information to keep reasonable safeguards around it. In practice, for a shop this size: the whole site is served over HTTPS; card numbers never reach us, because Stripe collects them; our payment credentials live in an encrypted secret store, never in the website’s code; access is limited to the people running the shop; and we collect as little as the job allows, which is the safeguard that never fails. No system is perfect — if a breach ever affected your information, we’d tell you and the relevant New York authorities as the law requires.
Children
This is a shop for adults and isn’t directed at children. Please don’t use it or send us your details if you’re under 18. We don’t knowingly collect personal information from anyone under 13; if you believe a child has given us theirs, email us and we’ll delete it.
Changes
We’ll update this policy as the shop grows — a mailing platform, an inventory system, anything that changes who touches your data. The “last updated” date at the top changes when we do, and material changes will be flagged on the site.
Questions? Get in touch — a real person on the bench will reply.