Privacy Policy
Last updated: September 4, 2026.
This policy explains the information ManCaves.Store handles when you browse, create an optional account, pay through Stripe, request support, or receive an order.
Information we handle
- Checkout and contact data: name, email, phone number, billing and shipping address, and messages you send.
- Order data: items, variants, quantity, price, Stripe order references, fulfillment status, tracking, and return/refund status and reason.
- After-sales evidence: photos, video, and written descriptions you send about damage, defects, incorrect items, or non-delivery, which we may share with the fulfillment partner (including CJdropshipping) and the carrier to open a required dispute.
- Account data: verified email, a one-way password verifier (not the password itself), session and security state, and an optional saved address note.
- Payment data: Stripe processes the payment credentials. ManCaves.Store does not receive or store the full card number or card security code.
- Device and operations data: IP address and request, browser, error, security, and server-log information generated when the site or API is used.
- On-device data: cart contents, recently viewed products, room interests, and short-lived checkout or diagnostic state stored in local or session storage.
How we use information
- Provide checkout, verify accounts, display the correct customer’s orders, and prevent unauthorized access.
- Review payment and fraud signals and hold flagged orders before fulfillment.
- Validate supplier product, variant, stock, freight, and margin before purchasing fulfillment.
- Send the order to a supplier and carrier, provide tracking, answer support, and administer cancellations, returns, refunds, disputes, and chargebacks.
- Diagnose errors, secure the service, keep audit records, comply with law, and enforce our terms.
Service providers and disclosures
We disclose only the information reasonably needed for the service:
- Stripe: checkout, payment, fraud screening, receipts, refunds, customer and order references, and account-support metadata.
- Fulfillment partners, including CJdropshipping: purchased items and the recipient name, address, phone, and other delivery details needed to buy and ship the order.
- Carriers and logistics providers: delivery and tracking information.
- Email provider: recipient, subject, and message content for account verification, password reset, order operations, and support notifications.
- Hosting and security providers: site content, request data, logs, and abuse-prevention information.
- Authorities or advisers: when reasonably necessary to comply with law, protect rights and safety, investigate fraud, or handle a legal claim.
Some suppliers or service providers may process information outside your state or country, including where an overseas warehouse fulfills the order. We do not sell personal information for money.
Cookies and browser storage
A signed, HttpOnly account session cookie keeps a verified user signed in. A preference cookie and browser storage can remember interests, cart contents, and recently viewed products. Essential account and cart functions may not work if these are blocked or cleared. See the Cookies Policy for the current list; we will update that notice before adding nonessential analytics or advertising technologies.
Retention
We keep records for as long as reasonably needed for the purposes above, including fulfillment, accounting, tax, fraud, warranty, dispute, and legal requirements. Account challenge codes expire quickly; sessions expire or are invalidated after security changes. Stripe, suppliers, carriers, and email providers keep their own records under their policies. We delete or de-identify data when it is no longer needed, unless retention is required or appropriate for a legal claim.
Your choices and requests
Depending on applicable law, you may ask to access, correct, delete, or receive a copy of personal information, or object to certain uses. We may need to verify the request and may retain transaction records required for tax, fraud, dispute, or other legal purposes. You can clear on-device storage in your browser and unsubscribe from any marketing email using its instructions.
Security
We use transport encryption, HttpOnly signed cookies, email verification, one-way password hashing, request-origin checks, rate and lockout controls, least-necessary API access, and manual controls around fulfillment and refunds. No system can promise absolute security. Do not send passwords, verification codes, full card numbers, or card security codes through support or return forms.
Children
The store is not directed to children under 13, and we do not knowingly collect their personal information. Contact us if you believe a child provided information so we can investigate and respond.
Updates and contact
We will post material policy changes here with a new update date.


