Who is responsible
Memory Figure is the working brand name. The legal business entity and mailing address are not configured yet. Privacy requests should go to support@memoryfigure.com.
Information we collect
We may collect contact, order, delivery, customization, uploaded photo, support, device, and fraud-prevention information needed to provide the requested product. Shopify and its payment providers handle payment details; this site should not store complete card numbers.
How information is used
To create and deliver the requested item, generate and review previews, communicate about the order, provide support, prevent abuse and fraud, maintain security, and meet tax, accounting, and legal obligations.
Service providers and transfers
Shopify provides commerce and checkout. Vercel provides website hosting and private encrypted photo storage in a United States region. When AI preview generation is enabled, OpenAI processes the photos and customization instructions needed to create the requested preview. Provider terms, retention controls, and international data-transfer requirements still require legal review before paid traffic begins.
Retention
Order and accounting records may be retained as required by law. Customer source photos are scheduled for deletion 30 days after upload unless a support, fraud, dispute, or legal hold requires a separately documented retention decision.
Analytics and advertising
Google Analytics, Meta Pixel, and TikTok Pixel are not currently loaded. They must not be enabled until tracking disclosures, consent behavior, and duplicate-event testing are approved.
Your choices
Depending on location, customers may request access, correction, deletion, or information about disclosure of eligible personal information. Identity may need to be verified before fulfilling a request.
Children and sensitive content
The store is not directed to children. Customers should not upload photographs they lack permission to use, or sensitive documents and payment information.
Security
We use server-only credentials, encrypted HTTPS connections, private object storage, short-lived upload permissions, file-signature verification, session-bound deletion, and expiring viewing links. No system is completely secure, and incident-response contacts must be established before launch.