Privacy Policy
Last updated: April 16, 2026
Apollo Replica ("we", "us", or "our"), operating at apolloreplica.com, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website and purchase our handcrafted Apollo DSKY replicas.
1. Data We Collect
We collect the following categories of personal data:
- Account information: name, email address, and authentication identifiers when you create an account via Google or Discord OAuth.
- Order information: shipping address, billing address, phone number, and order history.
- Payment information: payment details are processed securely by Stripe. We do not store your full credit card number on our servers.
- Technical data: IP address, browser type, device information, and browsing patterns collected through cookies and similar technologies.
- Communications: any messages or inquiries you send to us via email or our contact channels.
2. How We Use Your Data
We use your personal data for the following purposes:
- To process and fulfill your orders for DSKY replicas and related products.
- To create and manage your user account.
- To communicate with you about your orders, including shipping updates and delivery confirmations.
- To comply with legal obligations, including EU consumer protection and tax requirements.
- To improve our website, products, and customer experience.
- To prevent fraud and ensure the security of our platform.
3. Cookies
We use cookies and similar tracking technologies to maintain your session, remember your preferences, and analyze website traffic. Essential cookies are required for the website to function properly (e.g., shopping cart, authentication). Analytics cookies help us understand how visitors interact with our site. You can manage your cookie preferences through your browser settings. Note that disabling essential cookies may affect website functionality.
4. Third-Party Services
We share your data with the following third-party service providers, each acting as a data processor on our behalf:
- Stripe: processes payments securely. Stripe's privacy policy governs their handling of your payment data.
- Google OAuth: provides authentication services. Subject to Google's privacy policy.
- Discord OAuth: provides authentication services. Subject to Discord's privacy policy.
- MongoDB Atlas: hosts our database infrastructure where your account and order data is stored, with data encrypted at rest and in transit.
- Vercel: hosts our website and processes requests.
We do not sell your personal data to any third party. Data is only shared as necessary to provide our services.
5. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR) and applicable EU/EEA data protection laws, you have the following rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data, subject to legal retention obligations.
- Right to restriction: request restriction of processing of your personal data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to the processing of your personal data for certain purposes.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at the address below. We will respond to your request within 30 days.
6. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes described in this policy, comply with legal obligations (including tax and accounting requirements), resolve disputes, and enforce our agreements. Order records are retained for a minimum of 7 years in accordance with EU tax regulations. You may request deletion of your account data at any time, subject to these retention requirements.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS/SSL), encrypted database storage, and access controls. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
8. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:
privacy@apolloreplica.com
You also have the right to lodge a complaint with your local data protection supervisory authority.