Grey Studio collects identity, account, session, order, contract, payment, delivery, support, staff, audit, fraud, appeal, and security information needed to operate its services.
Where a customer chooses to save a card, Grey Studio retains an encrypted payment token issued by the payment provider, the last four digits of the card, the expiry date, the issuing bank, and the payment status.
Grey Studio does not receive or store a full card number, security code, or PIN. Card details are entered only on the payment provider's own hosted page.
A card entered by a third party paying on a customer's behalf is never saved to that customer's account and may be used only for the single payment request it was entered for.
Payment tokens are encrypted at rest using authenticated encryption with a key held outside the database, are never sent to a browser, and are never written to logs or audit records.
Data is retained only for documented operational, legal, security, contract, payment, accounting, support, and dispute purposes, then deleted, restricted, or anonymized where practical.
Depending on applicable law, people may request access, correction, deletion, restriction, objection, or export, subject to identity verification and lawful retention needs.