Privacy policy

Privacy Policy

Last Updated: June 27, 2026

This policy describes what personal information The Bespoke Bibliophile collects, how it is used, with whom it is shared, how long it is kept, and what rights you hold over it. It is written to satisfy applicable US state privacy laws and to address the particular data flows of this shop — print-on-demand journals, dropshipped curiosity items, and email correspondence. Read it once; keep it.


1. Who We Are

The Bespoke Bibliophile operates at thebespokebibliophile.com as a US sole proprietorship. For privacy matters, contact: curator@thebespokebibliophile.com.

This shop ships within the United States only. Orders cannot be completed from all US states; checkout enforces any applicable geographic restriction at the point of purchase.


2. Information We Collect

Information You Provide

  • Order and account data: Name, billing address, shipping address, email address, and phone number (if provided).
  • Payment data: Payment card details. These are processed exclusively by PCI DSS-compliant processors (Shopify Payments and/or Stripe). We do not receive, store, or have access to full card numbers.
  • Correspondence: The content of any email you send to curator@thebespokebibliophile.com.

Information Collected Automatically

  • Device and browsing data: IP address, browser type, referring pages, pages visited, time on site. Collected via Shopify's platform and, if active, analytics tools.
  • Cookies and tracking identifiers: Session cookies required for checkout; analytics and advertising cookies only with your consent. See our Cookie Policy for the complete cookie inventory.
  • Order history: Products purchased, order dates, and shipping details retained in our Shopify account.

Information We Do Not Collect

We do not knowingly collect biometric identifiers, precise geolocation, government identification numbers, or any personal information from children under 13. We do not target our marketing to anyone under 18.


3. How We Use Personal Information

Purpose Legal Basis (where applicable)
Fulfilling and shipping orders; coordinating with Lulu Direct and dropship vendors Contract performance
Processing payments and issuing refunds Contract performance
Customer service correspondence Contract performance / legitimate interest
Fraud detection and prevention Legitimate interest / legal obligation
Compliance with tax and accounting obligations Legal obligation (minimum 7 years)
Email marketing (if you have subscribed) Consent (opt-out available at any time)
Site analytics — understanding traffic and improving the site Consent (via cookie banner)
Advertising attribution (Meta Pixel, if active) Consent (via cookie banner)

We do not sell personal information for monetary consideration. We do not use personal information to build consumer profiles for third-party advertising outside of the consent-based cookie uses described above.


4. Third Parties Who Receive Your Personal Information

We share personal information only as necessary to operate this shop. The categories of recipients and their roles are as follows:

  • Shopify Inc. — Our e-commerce platform processes order, payment, and browsing data as a service provider under contract. Shopify's Data Processing Addendum governs that processing. Shopify DPA.
  • Payment processors (Shopify Payments / Stripe) — Receive card data for payment authorization only. PCI DSS-compliant. Neither we nor Shopify store full card numbers.
  • Lulu Direct (Lulu.com) — Receives your name and shipping address solely for the purpose of printing and shipping Bindery journals. Lulu is contractually restricted from using this information for any independent purpose. Lulu's Privacy Policy.
  • Faire Wholesale / CJ Dropshipping — For orders containing curiosity items fulfilled by dropship vendors, your name, shipping address, and item details are shared with the relevant vendor. CJ Dropshipping may have operations and fulfillment centers outside the United States; international data transfers may occur. We require vendors to use order data only for fulfillment. These vendors may be classified as third parties rather than service providers under California law; see Section 6 (Your Rights) for opt-out rights.
  • Email marketing platform — If you have subscribed to correspondence from us, your email address and (if applicable) order history are shared with our email platform for the purpose of sending that correspondence. You may unsubscribe at any time via the link in any marketing email or by writing to curator@thebespokebibliophile.com.
  • Analytics provider (Google Analytics 4, if active) — Receives anonymized behavioral data (pages visited, session duration, general location) when you consent via the cookie banner. You may opt out at any time by updating your cookie preferences or using the Google Analytics opt-out browser add-on.
  • Meta Platforms, Inc. (Meta Pixel, if active) — Receives page-visit and conversion data for advertising attribution when you consent via the cookie banner. Under California law, this may constitute "sharing" of personal information for cross-context behavioral advertising. You may opt out via the cookie banner, by enabling the Global Privacy Control signal in your browser, or via Meta's ad preferences.
  • Carriers (USPS, UPS, FedEx, and others) — Receive your name and shipping address to deliver your order.
  • Legal and regulatory authorities — We disclose personal information to courts or regulators when required by law or to protect our legal rights.

We do not sell personal information to data brokers or marketing aggregators.


5. Data Retention

Category Retention Period Reason
Order records (name, address, order contents) 7 years from order date Tax and accounting legal obligations
Payment processor records Per processor's policy (typically 7 years) Financial and fraud compliance
Email correspondence 3 years from last contact Customer service and legal claims
Marketing email list Until unsubscribe or deletion request Consent-based; no retention beyond withdrawal
Analytics data 26 months (GA4 default); session cookies expire at session end Site improvement; consent-based
Cookie consent records 12 months from consent date Compliance audit trail
Privacy request records 24 months from request date CCPA/CPRA recordkeeping requirement

Personal information that is no longer necessary for any of the above purposes is deleted or anonymized. We do not retain children's data beyond the immediate transaction that required it, and we do not retain data from visitors under 13 who have not provided verifiable parental consent.


6. Your Privacy Rights

Depending on your state of residence, you may hold some or all of the following rights. We honor all requests regardless of whether your state's law technically applies to our shop, because we believe these rights are reasonable and because the Texas Data Privacy and Security Act applies to us without a size or revenue threshold.

Rights Available Under US State Laws

  • Right to Know / Access: Request a copy of the personal information we hold about you, including its source, the purposes for which it is used, and the categories of third parties with whom it has been shared. (Available under: California CCPA/CPRA, Virginia VCDPA, Colorado ColoPA, Connecticut CTDPA, Texas TDPSA, Oregon OCDPA, Montana MCDPA, Iowa CDPA, Indiana ICDPA, and others.)
  • Right to Delete: Request deletion of your personal information, subject to legal retention obligations described in Section 5. (Available under: California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana.)
  • Right to Correct: Request correction of inaccurate personal information. (Available under: California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Tennessee, Indiana. Note: Iowa does not currently provide a right to correct.)
  • Right to Data Portability: Request a copy of your personal information in a portable format. (Available under: California, Virginia, Colorado, Connecticut, Texas, Oregon, Indiana.)
  • Right to Opt Out of Sale or Sharing: You may opt out of the sale of your personal information or the sharing of your personal information for cross-context behavioral advertising (including via Meta Pixel). To exercise this right, email curator@thebespokebibliophile.com with the subject line "Do Not Sell or Share My Personal Information," or enable the Global Privacy Control (GPC) signal in your browser — we will treat it as a valid opt-out request and confirm processing within 15 business days.
  • Right to Opt Out of Targeted Advertising: You may opt out of the use of your personal information for targeted advertising. Use the same mechanism as the opt-out of sale/sharing above, or update your cookie preferences via the banner on the site.
  • Right to Limit Use of Sensitive Personal Information: We do not process sensitive personal information (as defined by California CPRA) for purposes beyond what is necessary for fulfillment and legal compliance. No further limitation mechanism is required at this time.
  • Right of Non-Discrimination: Exercising any of these rights will not affect your ability to place orders or receive service from us.

Children's Privacy (COPPA)

This shop is not directed to children under 13. No one under 13 may submit personal information without verifiable parental consent. If you are a parent or guardian and believe your child has provided personal information to us, write to curator@thebespokebibliophile.com and we will delete it promptly. In the event we have actual knowledge that a visitor under 13 has submitted personal information, we will not share that information with any third party except as strictly necessary to complete a transaction (e.g., a shipping address to a carrier), and we will seek verifiable parental consent before any such disclosure. Information collected from users under 13 is retained only for the duration of the immediate transaction unless parental consent for longer retention is provided. Data collected from users under 16 constitutes sensitive personal information under California CPRA and is handled accordingly.

Global Privacy Control

We honor the Global Privacy Control (GPC) signal. If your browser transmits a GPC signal, we will treat it as a valid opt-out request under California CCPA/CPRA (effective January 1, 2026), Colorado ColoPA, Connecticut CTDPA, Texas TDPSA, and Oregon OCDPA. We will confirm that your opt-out has been processed.

How to Submit a Privacy Request

Write to curator@thebespokebibliophile.com with the subject line identifying your request type (e.g., "Access Request," "Deletion Request," "Do Not Sell or Share"). Include your name and the email address associated with your account or order. We will acknowledge your request within 10 business days and fulfill it within 30 days. If additional time is required (up to 45 additional days under most state laws), we will notify you promptly. We may ask you to verify your identity before processing access or deletion requests.

Note on telephone requests: We provide customer service exclusively by email. We do not offer a telephone number. Customers who meet CCPA thresholds and require an alternative access channel may submit requests in writing to the email address above; we will make reasonable accommodations.


7. Security

This site is served over TLS/SSL encryption. Shopify is PCI DSS Level 1 certified. We limit access to order data to the minimum necessary for order fulfillment and customer service. No security measure is absolute; in the event of a data breach involving your personal information, we will notify you as required by applicable law.


8. A Note on EU Visitors

This shop ships to US addresses only and does not actively market to residents of the European Union or European Economic Area. If you are visiting from the EU or EEA, please be aware that any behavioral tracking technology active on this site (analytics, advertising pixels) may process your data in a way that engages the GDPR's extraterritorial provisions. Our cookie banner provides consent controls for EU visitors. You have the right under GDPR to access, correct, erase, restrict processing of, and port your data, and to lodge a complaint with your local supervisory authority.


9. Changes to This Policy

When material changes are made to this policy, the "Last Updated" date at the top will be revised. Continued use of this site after a policy update does not constitute consent to the revised terms. Where required by law, we will provide notice of material changes before they take effect.

10. Contact

All privacy inquiries: curator@thebespokebibliophile.com
For accessibility inquiries, see our Accessibility Statement.
For cookie preferences, see our Cookie Policy.

The Bespoke Bibliophile | thebespokebibliophile.com


Cookie Policy

Cookie Policy

Last Updated: June 27, 2026

Cookies are small text files placed on your device when you visit a website. This policy identifies the cookies set on thebespokebibliophile.com, explains why each is used, and tells you how to manage your preferences.


1. Cookie Categories and Inventory

Category 1: Essential Cookies (No Consent Required)

These cookies are necessary for the site to function. They enable your shopping cart, secure checkout, and session authentication. They cannot be disabled without breaking the site. They do not track you across other websites.

Cookie Name Provider Purpose Duration
_session_id Shopify Maintains your shopping session Session
cart Shopify Stores cart contents 2 weeks
secure_customer_sig Shopify Authenticates logged-in customers 20 years (presence only; invalidated on logout)
storefront_digest Shopify Password-protected storefront access Session
_ab Shopify A/B testing — no personal data collected Session
_orig_referrer Shopify Tracks referral source for internal analytics 2 weeks
_landing_page Shopify Records entry page for internal session analytics 2 weeks

Category 2: Analytics Cookies (Consent Required)

If you consent via the banner below, analytics cookies collect anonymized data about how visitors use this site — pages visited, time on site, general traffic sources. This information is used to improve the site and is not used to build advertising profiles.

Cookie Name Provider Purpose Duration
_ga Google Analytics 4 Distinguishes unique visitors (anonymized) 2 years
_ga_[ID] Google Analytics 4 Session state for GA4 measurement 2 years

If Google Analytics is not installed, these cookies are not set and this row can be removed. See Owner Action Items.

To opt out of Google Analytics independently of this site's banner, use the Google Analytics opt-out browser add-on.

Category 3: Advertising and Tracking Cookies (Consent Required)

If you consent via the banner, advertising cookies allow attribution of website activity to advertising campaigns. The Meta Pixel is the specific tool in this category.

Cookie Name Provider Purpose Duration
_fbp Meta Platforms, Inc. Identifies browsers for advertising attribution; may share data with Meta for ad optimization 3 months
_fbc Meta Platforms, Inc. Stores click identifier from Meta ads 3 months

If Meta Pixel is not installed, these cookies are not set and this row can be removed. See Owner Action Items.

Use of the Meta Pixel may constitute "sharing" of personal information for cross-context behavioral advertising under California law (CCPA/CPRA), even without a monetary transaction. This triggers "Do Not Sell or Share" rights for California residents. To exercise that right: use the consent banner's "Reject" option, enable the Global Privacy Control (GPC) signal in your browser, or write to curator@thebespokebibliophile.com with the subject line "Do Not Sell or Share My Personal Information."

To manage Meta's use of your data independently of this site, visit Meta Ad Preferences.


2. Your Consent Choices

When you first visit this site, a consent banner presents two equally prominent options: Accept (all cookie categories) and Reject (essential cookies only). Closing or navigating away from the banner without making a selection does not constitute consent. Non-essential cookies are not set before you make a choice.

To change your preferences at any time, click [Cookie Preferences] in the site footer. Your previous preferences will be shown and you may update them. Consent records expire after 12 months, at which point you will be asked again.

These choices comply with California CPRA regulations effective January 1, 2026 (symmetrical accept/reject requirement), Connecticut CTDPA, and the GDPR consent requirements described in Section 4.


3. Global Privacy Control

If your browser transmits a Global Privacy Control (GPC) signal, we treat it as a valid opt-out request for the sale and sharing of your personal information, consistent with obligations under California CCPA/CPRA (effective January 1, 2026), Colorado ColoPA, Connecticut CTDPA, Texas TDPSA, and Oregon OCDPA. We will confirm that your opt-out has been recorded. The GPC signal will also suppress the Meta Pixel and any analytics sharing where technically feasible.


4. EU and EEA Visitors

This shop ships to US addresses only and does not actively target EU or EEA consumers. However, if you are visiting from the EU or EEA, any behavioral tracking technology active on this site — including Google Analytics and Meta Pixel — may process your data in a way that engages GDPR obligations. We present a GDPR-compliant consent banner to EU visitors that blocks all non-essential cookies prior to your explicit consent. You may withdraw consent at any time via [Cookie Preferences] in the footer.


5. Cookie Banner Accessibility

The consent banner meets WCAG 2.1 AA requirements: it is keyboard navigable, screen-reader accessible, maintains sufficient color contrast, and manages focus appropriately. If you encounter an accessibility issue with the banner itself, write to curator@thebespokebibliophile.com.


6. More Information

For full details on how personal information is collected, used, retained, and shared — and for instructions on exercising your privacy rights — see our Privacy Policy.

For cookie-related questions: curator@thebespokebibliophile.com

The Bespoke Bibliophile | thebespokebibliophile.com