Free standard shipping on U.S. orders over $95.00 USD · 30-day returns · Shipped from Asheville, NC

Privacy Policy

What we collect when you shop with Maison Aurevia LLC, what our payment processors Stripe and Square receive, how long we keep it and the rights you have over it.

Last updated: 24 September 2026 Applies to: Maison Aurevia LLC Questions: Maisonaureviallc@outlook.com

Who we are

This Privacy Policy explains what personal data Maison Aurevia LLC collects when you use maisonaurevia.com, why we collect it, who we share it with and what you can make us do about it.

Data controllerMaison Aurevia LLC, a Wyoming limited liability company (filing ID 2026-002088090)
Postal addressMaison Aurevia LLC, 72 N Market St, Apt 34, Asheville, NC 28801, United States
Privacy contactMaisonaureviallc@outlook.com · (828) 998-4813
Effective24 September 2026

We are a small company. There is no data team here — the email above reaches a person who can actually action your request.

What we collect, and when

We collect only what an order needs. We do not buy data about you from anyone else and we do not build advertising profiles.

When you browseStrictly necessary cookies and local storage that keep your cart and remember your cookie choice. Standard web-server logs (IP address, browser type, pages requested, timestamps) kept for security and fraud prevention.
When you check outYour name, email address, telephone number, delivery address, any delivery note you write, the items and quantities ordered, and the amount charged.
Your card detailsEntered directly into a form served by Stripe or Square. Maison Aurevia LLC never receives, processes or stores your full card number, expiry date or security code. We are shown only the card brand, the last four digits and whether the payment succeeded.
When you contact usWhatever you put in the contact form or your email or phone call, so we can answer you.

Data collected even if you do not complete a purchase

Please be aware of this, because it is not obvious. Our payment processors may collect information from the checkout page before and even if you never finish the order — for example, partial form entries, the device and browser you are using, your IP address, and details of any attempted or failed card authorisation. They do this to detect fraud and card testing. This data goes to Stripe or Square under their own privacy policies. Separately, if you type your email into our checkout and leave, that email may be held in our order records as an incomplete order for up to 90 days so we can help if you contact us about it. We do not send marketing to an abandoned checkout.

Why we use it

  • To take and fulfil your order — performance of our contract with you.
  • To take payment and prevent fraud — our legitimate interest and our card-network obligations, carried out through Stripe and Square.
  • To answer your questions and handle returns, refunds and cancellations.
  • To meet legal duties — tax, accounting and consumer-protection record keeping.
  • To keep the site working and secure — server logs, rate limiting, abuse prevention.

We do not use your data for profiling that produces legal effects, automated decisions about you, or targeted advertising.

Payment processing, Stripe and Square

We use Stripe and Square for payment processing. When you pay, the personal data needed to complete that payment — your name, email address, billing and delivery address, card details, and details of the order — is shared with the processor you chose. They act as independent data controllers for the payment itself.

Stripe

Payments made through the Stripe option are processed by Stripe, Inc. Stripe collects your name, email address, address, card details and order information at checkout. Stripe also uses transaction data, including failed and declined transactions, for fraud detection and prevention, and may collect data from the checkout form even where a purchase is not completed. Stripe's privacy policy is available at stripe.com/privacy.

We do not use Stripe Identity, so no selfie, photo ID or biometric data is collected by or for us. If that ever changes we will update this policy and ask for your explicit consent first.

Square

Payments made through the Square option are processed by Block, Inc. (Square). Square receives the same categories of payment data and likewise uses it to authorise the payment and to detect and prevent fraud. Square's privacy notice is available at squareup.com/us/en/legal/general/privacy.

Security standards

Payments are processed by Stripe and Square, both certified PCI-DSS Level 1 service providers — the highest level of certification available in the payments industry. We do not store card details. The whole of this website is served over TLS (HTTPS) encryption. See our Payment Security Statement for the detail.

Who else we share data with

Stripe, Inc.Card payment processing and fraud prevention
Block, Inc. (Square)Card payment processing and fraud prevention
Shipping carriersUSPS, UPS and FedEx receive the name, delivery address and telephone number needed to deliver your parcel
Our web hostStores the site and its order records on secured servers
Our accountant and tax authoritiesTransaction totals, as required by law
Law enforcementOnly where we are legally compelled, or to protect our rights, safety or property

We do not sell, rent, trade or otherwise disclose your personal data to third parties for their own marketing purposes. If Maison Aurevia LLC is ever sold or merged, customer data may transfer to the buyer; we would tell you before that happened and you could ask for erasure first.

International transfers

Maison Aurevia LLC operates from the United States and our servers are located in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, using this site means your data is transferred to the United States.

Our payment processors operate globally. Stripe may transfer personal data to the United States and to India, among other countries, for processing and support. Stripe and Square maintain compliance frameworks for such transfers — including Standard Contractual Clauses and, where applicable, certification under the EU–U.S. Data Privacy Framework and its UK Extension. Details are in each processor's own privacy policy, linked above.

Cookies and tracking

We use a deliberately small number of cookies and similar technologies:

  • Strictly necessary — keeping your cart, remembering your cookie choice, and protecting the checkout against abuse. These cannot be switched off without breaking the site.
  • Payment processor cookies — Stripe and Square set cookies on the checkout page for fraud detection, device fingerprinting and autofill features such as Stripe Link. These load only when you reach checkout.
  • Optional analytics — off by default. Nothing analytical loads until you turn it on in the cookie banner, and you can change your mind at any time.

The full list, with retention periods, is in our Cookie Policy.

How long we keep it

Completed orders7 years, because U.S. tax and accounting rules require it
Transaction and payment recordsRetained for regulatory, accounting, chargeback and fraud-prevention purposes, including after you stop using the site
Incomplete checkouts90 days, then deleted
Contact-form messages24 months from your last message
Server security logs90 days
Marketing consent recordsUntil you withdraw consent, plus 24 months to prove when consent was given and withdrawn

To be explicit: transaction data may be retained even after you stop using our site, for regulatory and fraud-prevention purposes. A request to erase your data cannot override that legal obligation, but everything not covered by it will be deleted.

Your rights over your data

Whatever jurisdiction you are in, we will honour the following. You have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Correct — have inaccurate data fixed.
  • Delete — have your data erased, except records we must keep by law.
  • Port — receive your data in a portable, machine-readable format.
  • Object and restrict — object to processing based on legitimate interests, or ask us to limit what we do with your data while a dispute is resolved.
  • Opt out — of marketing at any time, and of any sharing of your data with third parties for advertising purposes. We do not share data for advertising, so there is nothing to opt out of, but the right stands.
  • Withdraw consent — where we relied on consent, withdrawing it is as easy as giving it.
  • Non-discrimination — we will never give you a worse price or service for exercising any of these rights.

How to exercise them: email Maisonaureviallc@outlook.com with the subject line "Data request", or write to Maison Aurevia LLC, 72 N Market St, Apt 34, Asheville, NC 28801, United States. Tell us which right you are exercising. We will verify your identity (usually by asking you to reply from the email address on your order) and respond within 30 days. It is free. If we need longer for a complex request we will tell you why within those 30 days.

You may also authorise an agent to make a request on your behalf, and you may complain to your state attorney general or, in the EEA/UK, your supervisory authority.

Marketing and consent

We will not add you to a marketing list without your consent — not when you buy, and not when you start a checkout and leave. Buying from us does not sign you up for anything.

If you do opt in, every message includes a one-click unsubscribe link and we act on it promptly — in practice within 24 hours and always within 10 business days. You can also just email Maisonaureviallc@outlook.com and ask to be removed. We use customer email addresses only for the purpose you gave them for.

Children

Our services are not directed to individuals under the age of 13, and we do not knowingly collect personal data from anyone under 13. Our payment processors likewise cannot be used by children under 13. If you believe a child has given us personal data, email Maisonaureviallc@outlook.com and we will delete it promptly. Customers must be at least 18, or the age of majority where they live, to place an order.

How we protect your data

  • The entire site is served over HTTPS with TLS encryption — there is no unencrypted version.
  • Card data is tokenised by Stripe or Square in your browser. It does not pass through our servers.
  • Order records are stored outside the public web root and are not reachable from a browser.
  • Payment endpoints are rate limited and monitored to block card-testing attacks.
  • Access to order data is limited to the people who need it to fulfil and support your order.

No system is perfect. If a breach ever affected your personal data we would notify you and the relevant authorities as required by law, without undue delay.

Changes to this policy

If we change this policy we update the date at the top of the page. Material changes — anything that changes what we collect, why, or who we share it with — will be announced with a notice on the site for at least 30 days. Continuing to use the site after a change means you accept the updated policy.

Questions about any of this: Maisonaureviallc@outlook.com or (828) 998-4813, Monday to Friday, 9:00am – 5:00pm Eastern.

Need a human? Email Maisonaureviallc@outlook.com or call (828) 998-4813, Monday to Friday, 9:00am – 5:00pm Eastern.