Privacy Policy
Written to describe what actually happens on this site, not to cover every possible hypothetical. If anything here isn't clear, ask us and we'll explain.
Last updated August 1, 2026
Who we are
AERA FIT WEAR operates https://aerafitwear.com. For questions about your data, write to support@aerafitwear.com. A real person reads this inbox.
What we collect
When you browse
A cart identifier is stored in a cookie so your bag survives a page reload. It is httpOnly, meaning no page script can read it, and it contains random text rather than any information about you. We also log page visits and campaign parameters (like utm_source) to know which ads work. Details are in the cookies section below.
When you place an order
Name, email, shipping and billing address, phone number if you provide it, and the order contents. We keep only the last four digits and the card brand, to link a payment to an order. The full number, expiration date, and security code are typed directly into fields hosted by Stripe and never reach our servers.
When you join our email list
Your email and where you signed up. Nothing else, and never as a requirement to buy.
Security and fraud signals
At checkout, we log the IP address, a device fingerprint hash, and signals like how many attempts came from the same address. This exists to prevent card testing and orders with stolen cards. It is a legitimate interest in fraud prevention, and these logs are kept separate from your order history.
Why we collect it
| Purpose | Data used | Basis |
|---|---|---|
| Deliver your order | Name, address, email, order items | Contract performance |
| Process payment | Card data (via Stripe), billing address | Contract performance |
| Prevent fraud | IP, device signals, order patterns | Legitimate interest |
| Marketing email | Email address | Your consent |
| Measure ads | Page visits, hashed email, event data | Your consent |
Who processes your data
We use a small number of vendors, each with a specific role. We do not sell personal data to anyone, and we never have.
- Stripe: payment processing and card data storage. Certified as a PCI Service Provider Level 1.
- Resend: sending order confirmations, shipping notices, and, if you opted in, marketing email.
- Meta Platforms: Ad measurement. In the purchase events we send, your email goes through SHA-256 hashing before leaving our server, so Meta receives an irreversible fingerprint instead of your address.
- Our hosting provider: has server infrastructure in the United States. Order data is encrypted at rest.
Cookies and tracking
We use three types, and no more than necessary.
- Essential. We use the cart cookie and a session cookie for the admin area. The site does not work without them.
- Attribution. When you arrive via an ad, campaign parameters stay in your browser's session storage and are attached to the order if you buy. This is cleared when you close the tab.
- Advertising. The Meta Pixel logs page visits and purchases so we know which ads drive sales.
We respect the Global Privacy Control signal and browser Do Not Track headers for advertising cookies. If your browser sends either, ad events are not fired.
How long we keep it
| Data | Retention period |
|---|---|
| Order records | Seven years (tax and accounting requirement) |
| Abandoned carts | Thirty days, then deleted |
| Email list | Until you unsubscribe |
| Fraud and security logs | Twelve months |
Your rights
Wherever you live in the United States, you can ask us for any of these things at no cost:
- Tell you what personal data we have about you
- Send you a copy of it
- Correct anything that is wrong
- Delete the data, except records the law requires us to keep for tax reasons
- Stop using your data for ad measurement
- Unsubscribe from marketing whenever you want
Send the request to: support@aerafitwear.com We respond within thirty days and will not treat you differently for asking. If you are in California, this includes your rights under the CCPA and CPRA, and you can designate an authorized agent to make the request on your behalf.
Children
This store is not directed at children under thirteen, and we do not knowingly collect their data. If you believe a child has given us information, write to us and we will remove it.
Security
The site runs entirely on HTTPS, with HSTS enabled. Admin passwords are hashed with scrypt and never stored in readable format. Access to order data is restricted to accounts that need it, and every admin action is logged. No system is perfect; if we ever suffer a breach affecting your data, we will notify you directly instead of hiding a notice on this page.
Changes
When this policy changes, we update the date at the top. If the change materially affects how we use your data, we email everyone on our list, rather than expecting you to come check.
See also our: terms of service and shipping and returns policy.