Privacy Policy

Privacy notice — effective 13 September 2026. This notice covers Own Object accounts, private references, customisation requests, related payment records, public-page visitor statistics and optional advertising measurement. PayPal processes approved quote payments. Google sign-in is not connected.

1. Who is responsible

Own Object is operated by 北杭科技有限公司. Business contact location: Nanning, Guangxi, China (广西南宁). Website: ownobject.com. Contact the studio about privacy or your information at hello@ownobject.com.

2. Information you choose to provide

Accounts: email address, display name, password authentication records, verification and privacy acknowledgement records, and account recovery information. Email is necessary for account setup and recovery. Please use an address you control.

Customisation: saved style, size, quantity, important features, story, intended date, contact details and destination country or postcode. A saved person or pet profile can contain a name or nickname, characteristics and authorised reference photographs. Share only information relevant to your request. Do not upload identity documents, card details or unrelated sensitive information.

Project records: the exact brief and selected references you submit, studio conversations, quotations, design versions, acknowledgements and staff actions. Saving a draft and submitting it are separate actions. Submission requests human review; it does not confirm a paid order or start production.

Technical information: login and session information, security and rate-limit identifiers, and server logs used to operate and protect the site. Some application identifiers are hashed. Server logs may still contain an IP address, requested page, time and browser information.

3. Purposes and your choices

We use information to provide the account and customisation service you request, authenticate and recover access, assess a submitted brief, communicate with you and keep a record of what was agreed. We use security and audit information to protect accounts, investigate misuse or errors and handle disputes. These activities support the requested service and the legitimate need to keep it secure. Where applicable law requires consent for a particular use, we obtain that consent separately; permission to save a reference is not permission for unrelated uses. Optional detail can be left out, although we may need clarification before assessing your request.

Upload only images you are entitled to provide. Obtain permission from other people shown, including appropriate parent or guardian authority for a child. Do not provide photographs or sensitive details where you lack that authority. We may ask you to clarify authorisation or remove a reference before proceeding.

Saving or submitting material does not permit its publication in a gallery, advertising or AI training. The current workflow does not automatically send customer photographs to an external AI service. Any proposed use of an external AI provider requires a separate explanation of the provider, data sent and handling terms before use.

4. Private reference handling

Uploads first enter a temporary server processing area. A successful upload is scanned, decoded and re-encoded to remove embedded metadata; the temporary input is deleted and the processed image is stored outside the public media library. Customer ownership and authorised staff access are checked. These measures reduce risk, but do not guarantee that every file is harmless or that a failure can never leave a temporary copy.

Private references are not public portfolio images. Editing a reusable profile does not rewrite the fixed brief already submitted for another project. Anonymous planner choices remain in the open page unless you choose an account continuation link. That choice can temporarily retain only direction, style, size, quantity and base in the same browser tab for up to two hours; photographs and personal notes are not included. Continuing does not automatically submit a request. This short-lived planner handoff is separate from optional advertising measurement.

5. Staff, hosting and email

Authorised studio and administrative staff can access information needed to handle your request and operate the service. The website uses an EU-region Contabo VPS. The business operates from Nanning, China, so staff access may involve processing in China. EU hosting does not mean that all access remains in the EU. This notice does not assert an EU-only processing arrangement or a particular international-transfer certification.

Service email uses the GoDaddy-provided mailbox hello@ownobject.com. Account messages contain a setup or recovery link. Project notification emails, when sent, contain a reference and sign-in link rather than private photographs or conversation text. Project updates are available in your account; do not rely on an automatic email after every action. Direct emails and their contents are handled through the email service. Please do not send private photos or identity documents by ordinary email. Account email is not a marketing subscription.

6. Reuse and retention

New reference images, reusable profiles and saved unsubmitted drafts have a 180-day reuse period from their first save. Editing does not restart that period. Expired material cannot be reused in a new submission; expired reference images are no longer available for online preview. Existing expiry dates are not silently changed when a setting changes.

Expiry stops reuse; it is not automatic physical erasure. Cleanup is a separate staff action. The studio’s handling target is to review and clear expired, unreferenced material within 30 days after expiry. There is no automatic cleanup job guaranteeing that deadline. If material remains linked to a submitted project, staff must review the specific dependency and any necessary retention before erasure.

Other categories do not share a single 180-day deletion deadline. Account information is needed while the account is maintained and for handling closure or recovery. Submitted briefs, conversations, quotations and design versions are retained while the request or agreed service is being handled, and only as needed afterwards to resolve an identified dispute or meet an applicable obligation. Privacy and deletion audit records document the handling of the request and any necessary exception. Contact the studio to request review or deletion of these categories; an exception needs a specific reason, restricted access and a review date, not indefinite retention merely because a technical dependency exists.

Server logs have separate operational rotation settings. At publication, web logs are configured for daily rotation with 14 rotated files, and PHP service logs for weekly rotation with 12 rotated files. Rotation depends on the job running and is not a guarantee of an exact deletion time or a single retention rule for every security, system or provider record.

7. Deletion handling and current backup limitation

You can request deletion of references, profiles and unsubmitted drafts in your private space. A request stops further reuse but does not immediately erase the stored file. Studio staff check links to other items and fixed submitted projects before a specific primary-storage deletion. Account closure, submitted projects and any necessary exception are reviewed separately through hello@ownobject.com. A request marked resolved is not proof that all copies were erased.

Routine backups and a verified disaster-recovery process are not currently enabled. A server failure or data loss may therefore be unrecoverable. Keep your original photographs and important information on your own device. Existing deployment recovery copies are not a tested rolling backup service, and may require separate review when handling deletion. We do not promise automatic removal of all copies or a successful restoration. Backup configuration and any future retention or restoration procedure will be reviewed separately before being represented as operational.

8. Privacy requests

Contact hello@ownobject.com to request access, correction, deletion, a restriction or withdrawal of permission. Depending on applicable law, you may also have rights to object, receive portable information or complain to a relevant data-protection authority. Withdrawing permission does not itself invalidate prior lawful use, but we will review future use and any information that must be retained for a specific reason.

The studio’s manual handling target is an initial reply within 7 days and completion, or an explanation of any necessary remaining retention, within 30 days. Applicable legal deadlines still apply. These are handling targets, not an automated response or erasure guarantee. We may request proportionate information to verify that a request concerns your data. Do not send identity documents unless a specific secure method has been agreed.

The private-space JSON download provides a customer-visible summary, not all photographs or every internal record. Ask the studio if you need a fuller access response or help with a request that cannot be completed through the account tools.

9. Cookies and changes

WordPress uses necessary login and session cookies. Blocking them may prevent account access. Server logs and security records are separate from browser cookies. Google sign-in and an advertising subscription are not connected. For an accepted studio quote, PayPal receives the amount, currency and the customer and delivery information needed to process payment. Own Object retains the related order, transaction references and payment status. Enter payment credentials only in the PayPal payment interface, not in your project brief or uploads. PayPal handles information under its privacy statement. Additional analytics or external AI features require review and updated information before collecting customer data.

We will update this notice when the service or its handling changes. Its effective date appears above. You can ask the studio about the current handling of your information at any time.

10. Public-page visitor statistics

We use WP Statistics to understand visits to our public website, including visit times, public page paths, referring sites, approximate countries and browser/device categories. Analytics are stored in our own WordPress database; we do not send these visitor statistics to Google or the plugin provider. The analytics configuration does not use tracking cookies. IP addresses are reduced and hashed before storage rather than stored as original IP addresses. Operational server logs are separate, as described above.

We exclude logged-in users, account and login pages, private requests and uploads, and checkout/payment pages from these statistics. URL query parameters are not retained in the analytics page URLs. We do not collect form contents, private photographs, account identities or session recordings through this tool. Browser Do Not Track requests are respected. Analytics reports are restricted to website administrators.

Detailed analytics are scheduled for automatic aggregation and cleanup after 90 days; aggregate visitor and page-view totals may be retained longer. Cleanup depends on the WordPress scheduled task running and is not a guarantee of deletion at an exact time. This retention setting does not change the separate rules for customer references, projects, payments or server logs. Contact hello@ownobject.com with questions about this processing.

11. Optional advertising measurement

Your choice comes first. Advertising measurement is off until you choose Accept optional in Cookie preferences. Decline optional has equal prominence. Refusing does not prevent browsing, registration, private uploads, requests or payment. You can reopen Cookie preferences on a public page at any time and turn optional measurement off. Closing the panel is not acceptance. Necessary account, checkout and preference-security cookies are separate.

After acceptance, our own server can record a random browser identifier, consent time, approved public page paths, event times, the four campaign labels utm_source, utm_medium, utm_campaign and utm_content, and an advertising click identifier (fbclid or twclid) when one is present. We keep a first source and a most recent non-direct source; a direct return does not replace the latter. We do not collect search terms, arbitrary query parameters, full referring URLs or form contents through this measurement.

With that permission, a source may be linked internally to your customer account and fixed to a submitted project so that a later return, request or payment can be measured. Registration and saved drafts are not counted as submitted requests. A WhatsApp link click is only a click, not proof of a conversation. A purchase requires the existing payment system to verify an actual Live payment; arriving back at the website is not sufficient.

Sharing with advertising platforms: where a connection is enabled and a usable, consented click identifier is available, the server may send Meta or X that platform’s click identifier, an event name and time, a deduplication identifier and a public website address. A verified purchase may also include the actual amount and currency. After explicit acceptance of the updated notice, eligible Meta events also include the actual event browser information (User-Agent), which describes the browser and operating system. This information is captured from the browser request for the relevant action; we do not substitute a server browser or backfill historical events. Earlier acceptance does not authorise this additional field: you must choose Accept optional again. We do not send customer names, email addresses, phone numbers, IP addresses, photographs, private notes, project contents, private account URLs or password links through advertising measurement. It does not load Meta or X advertising scripts into private pages or use customer-list uploads or automatic advanced matching. These advertising identifiers are pseudonymous, not a promise of complete anonymity.

Duration: optional browser/source identifiers, event browser information (User-Agent) and account/project attribution links expire no later than 30 days after the initial grant; ordinary visits do not extend that period. The preference cookie also lasts up to 30 days, and a separate security cookie for saving your choice lasts up to one hour. When the source expires, further linked sending stops. Scheduled cleanup removes the source, browser information and account/project links and reduces reporting to campaign labels, event counts and amounts/currencies, without customer or project identifiers or User-Agent. Those reduced reporting records are retained for up to 180 days. Withdrawing optional measurement also clears the retained browser information associated with the withdrawn source. Cleanup depends on the plugin and scheduled task running; expiry is not a guarantee of physical deletion at the exact second. These rules do not change necessary project, payment or operational-log retention described elsewhere in this notice.

Turning optional measurement off stops future eligible collection and queued sharing and clears the current browser’s linked source. If you are signed in as a customer, withdrawal also stops the retained sources linked to that account. Logging out clears this browser’s optional attribution association. Withdrawal cannot recall information already received by an advertising platform; contact us or the relevant platform about that information. Meta and X apply their own processing and retention rules, which are not limited by our 30-day source lifetime, and processing may take place outside your country. See Meta’s privacy policy and X’s privacy policy.

Source reports are available only to authorised website administrators. A recorded source or a platform receipt is not proof that an advertisement caused a sale. Connections that are not enabled do not receive events. To ask about your choices or linked information, contact hello@ownobject.com.