Effective date: 9 August 2026 | Last updated: 9 August 2026
Mypixia, LLC ("Mypixia", "we", "us", "our") operates the marketplace at https://mypixia.com (the "Site") and the merchant back-office at merchant.mypixia.com. For the personal information described in this policy, Mypixia, LLC is the controller.
Products sold on the Site are made by independent sellers. For the order information a seller needs in order to produce and ship your item, that seller is an independent controller of the data they receive. This policy covers what Mypixia does; a seller's own use of your data is governed by their privacy notice.
Mypixia, LLC
5960 Fairview Road, Suite 300
Charlotte, NC 28210, United States
Privacy contact: [email protected]
Some sellers operate a Mypixia self-service kiosk in their physical shop. If you use one, we process the design you create, any photograph you send to the kiosk from your phone, and the order details needed to print your collection ticket. Kiosk upload sessions and their images are automatically deleted after a short period. Payment is taken by the shop at their own till, not on the kiosk.
We do not collect identity documents, passports, driving licences, selfies, biometric data, government identification numbers, or precise geolocation from customers. Sellers who take payouts are verified by Stripe directly β those documents go to Stripe and never to Mypixia.
If you are in the EEA, the UK or Switzerland, the "legal basis" column is the ground we rely on under Article 6 of the GDPR.
| What we do | Data used | Legal basis |
|---|---|---|
| Create and run your account; sign you in | Account details, technical data | Performance of a contract |
| Let you create, save and re-use designs | Designs, uploads, account details | Performance of a contract |
| Take payment and prevent payment fraud | Payment token, order records, technical data | Performance of a contract; legitimate interests (fraud prevention) |
| Send your order to the seller and get it made and shipped | Order records, delivery details, designs | Performance of a contract |
| Handle returns, refunds and disputes | Order records, messages | Performance of a contract; legal obligation |
| Service messages (order confirmations, dispatch, password resets) | Account and order details | Performance of a contract |
| Generate images with AI when you ask for it | Your prompt, the design or photo you supply | Performance of a contract |
| Marketing emails and newsletters | Email address, purchase history | Consent (withdraw any time) |
| Analytics and measuring how the Site is used | Cookie and usage data | Consent (withdraw any time) |
| Keep the Site secure, debug faults, prevent abuse | Technical data, logs | Legitimate interests (security and reliability) |
| Moderate designs and reviews against our content rules | Designs, review text, account details | Legitimate interests (lawful, safe marketplace) |
| Keep tax, accounting and consumer-law records | Order and payment records | Legal obligation |
Automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means alone. Design and review moderation may be assisted by automated screening, but a person decides any rejection and you can contest it using the contact details in section 14.
Do you have to give us this? The account, delivery and payment information marked as required is needed to form and perform our contract with you β without it we cannot take your order. Everything else is optional.
The design editor includes optional AI features that generate or modify images. When you use them, the prompt you type and the image you supply are sent to our AI processing provider, which acts as our processor, to produce the result. We use these inputs to fulfil your request and to investigate misuse; we do not use your designs to train our own models, and our agreement with that provider does not permit them to train their models on it.
Images produced by these features are generated by artificial intelligence. Where the law requires it, AI-generated output is labelled as such.
We do not sell your personal information for money. We disclose it to the following categories of recipient:
The categories of provider we use are set out at mypixia.com/subprocessors. The detailed list β each named provider, its role, its location and the transfer safeguard relied on β is available on request from [email protected] or via our privacy request form.
Mypixia is based in the United States and our infrastructure and service providers are largely located there. If you are in the EEA, the UK or Switzerland, your personal information will be transferred outside your country.
Where we make such a transfer we rely on one of the following safeguards: the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum for UK transfers; an adequacy decision where one applies to the recipient; or, for certified recipients, the EUβUS Data Privacy Framework and its UK Extension and SwissβUS equivalent. You can request a copy of the relevant safeguard using the contact details in section 14.
| Data | Retention |
|---|---|
| Account record | While your account is open, then deleted within 30 days of closure (except where a longer period below applies) |
| Order, payment and refund records | 7 years from the transaction, to meet tax, accounting and consumer-law obligations |
| Designs and uploads | While your account is open; deleted on account closure, except designs attached to an order, which follow the order record |
| Messages and collaboration threads | 3 years from the last message, or the life of any related dispute |
| Reviews | Retained while the product is listed; disassociated from your account on closure |
| Kiosk upload sessions and images | Automatically deleted 7 days after the session |
| Marketing consent and unsubscribe records | Kept for as long as needed to prove consent and to honour your opt-out |
| Security and access logs | 12 months |
| Analytics data | 14 months |
We use strictly necessary cookies to sign you in, keep your cart and protect the Site. These do not require your consent because the Site cannot work without them.
Analytics, preference and marketing cookies are only set after you agree. When you first visit we show a banner where you can accept all, reject all in one click, or choose individual categories. Rejecting is as easy as accepting, and nothing non-essential loads until you choose. You can change or withdraw your choice at any time on the Cookie Policy page, which also sets out each group of cookies we use, who sets them, what they do and how long they last, and how to ask us for the cookie-by-cookie detail.
We honour the Global Privacy Control (GPC) browser signal. If your browser sends it, we treat it as an opt-out of analytics and marketing cookies and, for US state-law purposes, as a valid request to opt out of "sale" and "sharing".
We use technical and organisational measures appropriate to the risk, including encryption in transit, hashed passwords, access controls, optional multi-factor authentication on accounts, and separation of payment data into Stripe's environment. No system is perfectly secure, so we cannot guarantee absolute security.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will notify you without undue delay where the breach is likely to result in a high risk to you.
You have the right to:
To exercise any of these, email [email protected] or use our privacy request form. We may ask for information to verify your identity. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. Exercising your rights is free unless a request is manifestly unfounded or excessive.
This section, together with section 2, is our notice at collection for the purposes of the California Consumer Privacy Act as amended by the CPRA. The categories below use the statutory California categories.
| Category of personal information | Examples we collect | Source | Purpose | Disclosed to | Retention |
|---|---|---|---|---|---|
| Identifiers | Name, email, postal address, phone, IP address, account ID | You; your device | Accounts, orders, delivery, support, security | Sellers, payment, shipping, hosting, email providers | See section 7 |
| Customer records (Cal. Civ. Code Β§1798.80) | Name, address, payment token, card brand and last four digits | You; Stripe | Payment, refunds, fraud prevention | Payment processor, hosting provider | 7 years |
| Commercial information | Orders, returns, products viewed, reviews | You; your use of the Site | Fulfilment, support, service improvement | Sellers, hosting, analytics (with consent) | 7 years for orders |
| Internet or network activity | Pages viewed, session data, referring URL, diagnostics | Your device | Security, debugging, analytics (with consent) | Hosting, analytics (with consent) | 12 months (logs); 14 months (analytics) |
| Visual information / user content | Designs, uploaded photographs and artwork | You | Producing your order; storing your designs | Sellers, hosting, AI processor | See section 7 |
| Audio, electronic or similar information | Messages, chat and collaboration content, support emails | You | Support, order collaboration, dispute resolution | Sellers (collaboration only), hosting, email providers | 3 years |
| Inferences | Product recommendations from your purchase history | Derived by us | Personalising suggestions and, with consent, marketing | Hosting, email provider | While your account is open |
Sensitive personal information. We do not collect sensitive personal information from customers, and we do not use or disclose any for purposes that would require us to offer a "Limit the Use of My Sensitive Personal Information" choice.
We do not and will not sell personal information for money, and we have not done so in the preceding 12 months. We also do not knowingly sell or share the personal information of consumers under 16.
Analytics and advertising cookies may constitute "sharing" for cross-context behavioural advertising, or a "sale" or "targeted advertising" under some state laws. We therefore only run them where you have opted in, and you can opt out at any time via Do Not Sell or Share My Personal Information or by sending a Global Privacy Control signal, which we honour automatically.
Depending on where you live, you may have the right to know or access, delete, correct, obtain a portable copy, opt out of sale/sharing/targeted advertising and profiling, limit the use of sensitive information, and not be discriminated against for exercising any of them. We will never deny you goods or services, charge you a different price or give you a lower quality of service because you exercised a privacy right.
California residents may request information about disclosures of personal information to third parties for their own direct marketing purposes under Cal. Civ. Code Β§1798.83. We do not make such disclosures.
There is no common industry standard for Do Not Track. We do not respond to DNT signals, but we do honour the Global Privacy Control signal as described in section 8.
The Site is not directed at children and we do not knowingly collect their personal information.
If you believe a child has given us personal information, contact [email protected] and we will delete it.
We may update this policy to reflect changes in our service, technology or the law. We will update the "last updated" date above, and where the change is material we will notify you by email or by a prominent notice on the Site before it takes effect. Previous versions are available on request.
Privacy questions and data rights requests:
[email protected]
General support:
[email protected]
Legal: [email protected]
Mypixia, LLC
5960 Fairview Road, Suite 300
Charlotte, NC 28210, United States
(800) 884-3514
See also our Terms and Conditions, Cookie Policy, Sub-processors and Returns & FAQs.