// LEGAL

Privacy Policy

We keep this short and plain. Here is exactly what data we collect, why, and how we handle it.

Last updated: March 2026

01

Who We Are

Nekurai is a Texas-based S Corp operating at nekurai.com. We run a resale shop and provide custom software development services. We are the sole data controller for information collected through this website. Contact us at contact@nekurai.com.

02

What We Collect

Shop customers — when you make a purchase:

  • Name, email address, shipping address
  • Order details (items, amounts, dates)
  • Payment confirmation data from Stripe (we never see or store full card numbers)
  • IP address and browser type (collected automatically by our hosting platform)

Contact form submissions — when you reach out:

  • Name, email address, and the message you send
  • We do not require a phone number, though you may provide one

Software development clients — when you engage us for a project:

  • Name, company, email, phone number (for project communication)
  • Project details and any content you provide for the site (copy, images, credentials)
  • Payment records (invoices, amounts paid — not card data)

What we do NOT collect:

  • Tracking cookies or advertising pixels — none
  • Social media data — no OAuth logins, no tracking across platforms
  • Biometrics, location data beyond shipping address, or sensitive personal information
03

How We Use It

  • To fulfill orders: Process payments, pack and ship items, handle returns.
  • To communicate: Respond to inquiries, send order confirmations and tracking updates, coordinate project work.
  • To deliver projects: Use client-supplied content to build and deploy their site.
  • To protect our business: Document transactions to dispute fraudulent chargebacks or misrepresentation claims.
  • We do not sell, rent, trade, or share your data with third parties for marketing purposes. Ever.
04

Third-Party Services

We use a small number of third-party services that may process your data:

Stripe

Payment processing

Handles all card data. We receive only a payment confirmation and last-4 digits. Stripe is PCI-DSS compliant.

eBay

Secondary marketplace

Listings cross-posted to eBay are subject to eBay's privacy policy. We comply with eBay's Marketplace Account Deletion requirements.

Vercel

Website hosting

This site is hosted on Vercel, which may collect access logs (IP, browser, request timestamps). See Vercel's privacy policy.

Neon / Vercel Postgres

Database

Order and site data is stored in a managed Postgres database. Data is encrypted at rest and in transit.

05

Demo Sites

Demo sites (at /tempsites/[slug]) are password-protected previews built for specific clients. They use a session cookie to remember that you have authenticated during your browser session. This cookie contains no personal information — only a session identifier. No analytics, tracking, or third-party scripts are loaded on demo sites.

Demo sites expire and are not intended for public access. If you accessed a demo site that was not intended for you, please contact us.

06

Data Retention

  • Order records: Retained for 7 years to comply with standard business and tax record-keeping requirements.
  • Contact form submissions: Retained for up to 2 years for reference, then deleted.
  • Software development project files: Retained for 1 year post-delivery, then securely deleted unless ongoing work continues.
  • Inactive accounts / demo sites: Demo site records are archived when expired and permanently deleted upon admin request.
07

Security

All data transmission to and from nekurai.com is encrypted via HTTPS/TLS. Database access is restricted and authenticated. Admin areas require secure login credentials. Passwords are hashed using bcrypt and are never stored in plain text.

No system is perfectly secure. In the event of a data breach that affects your personal information, we will notify affected parties promptly and take immediate steps to contain and address the incident.

08

Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate information
  • Request deletion of your data (subject to legal retention requirements)
  • Opt out of any future marketing communications (we send very few)
  • Request a copy of your data in a portable format

To exercise any of these rights, email us at contact@nekurai.com with your request. We will respond within 10 business days.

eBay-specific data deletion requests are handled in accordance with eBay's Marketplace Account Deletion/Closure notification requirements via our webhook endpoint.

09

Contact

Questions, concerns, or requests related to this policy should be directed to:

Nekurai

contact@nekurai.com

Texas, United States