Legal
Privacy Policy
Your privacy matters to us. This policy explains how we collect, use, and protect your information.
Last updated: April 2026
1. Information We Collect
When you use VellaFlora, we collect information you provide directly, including your name, email address, phone number, delivery address, and any messages you send through our contact forms. When you create an account, we store your profile information to enable order history, gallery participation, and saved preferences. When you browse our website, we automatically collect certain technical data such as your IP address, browser type, device information, and pages visited. If you use our AI-powered bouquet builder, we store your design configurations and generated preview images.
2. How We Use Your Information
We use your information to process and fulfill your flower orders, provide customer support, send order confirmations and delivery updates, and improve our services. Your email may be used for transactional communications related to your orders, account activity, and password resets. If you subscribe to our newsletter, we will send periodic marketing emails — you can unsubscribe at any time. We use your design data to power the community gallery and enable remix features. We do not sell your personal information to third parties.
3. Payment Processing
All payments are processed securely through Stripe, a PCI-compliant payment processor. When you make a purchase, your payment card information is transmitted directly to Stripe and is never stored on our servers. We retain only a reference to your Stripe payment session and payment intent for order tracking and refund purposes. Stripe may collect additional information as described in their privacy policy at stripe.com/privacy. Gift card transactions are also processed through Stripe, with card codes and balances stored securely in our database.
4. Cookies & Tracking
VellaFlora uses cookies and similar technologies to maintain your session, remember your cart contents, and provide a personalized experience. Essential cookies are required for the website to function properly, including authentication cookies for buyer, vendor, and admin sessions. We use localStorage to persist your shopping cart between visits. We do not use third-party advertising cookies. You can control cookie settings through your browser, but disabling essential cookies may affect website functionality.
5. Data Sharing & Third-Party Services
We share your information only with trusted third-party services necessary to operate VellaFlora. Supabase provides our database hosting and stores your account information, order details, and gallery designs. Stripe processes all payment transactions. Resend handles transactional email delivery, including order confirmations and password reset emails. Replicate powers our AI bouquet preview generation using the FLUX model. Each of these providers has their own privacy policies governing how they handle data. We do not sell, rent, or trade your personal information to any third party for marketing purposes.
6. Data Retention
We retain your account information for as long as your account is active. Order records are retained for tax and legal compliance purposes. Gallery designs and associated images are retained as long as they remain published. If you request account deletion, we will remove your personal information within 30 days, except for data we are legally required to retain. Anonymized or aggregated data that cannot identify you may be retained indefinitely for analytics and service improvement. Newsletter subscriptions are maintained until you unsubscribe.
7. Your Rights
You have the right to access, correct, or delete your personal information. You can update your profile information directly through your account settings page. To request a copy of your data or to request deletion, please contact us at hello@vellaflora.com. You have the right to opt out of marketing communications at any time using the unsubscribe link in our emails. If you are a resident of California, you may have additional rights under the CCPA, including the right to know what personal information we collect and the right to request deletion. If you are located in the European Economic Area, you may have rights under GDPR including data portability and the right to lodge a complaint with a supervisory authority.
8. Children's Privacy
VellaFlora is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@vellaflora.com and we will promptly delete such information from our records.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal information. Authentication sessions use HMAC-SHA256 signed cookies. Passwords are hashed using bcrypt with a work factor of 12. All data is transmitted over HTTPS. Payment processing is handled by PCI-compliant Stripe infrastructure. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Your continued use of VellaFlora after any changes constitutes acceptance of the revised policy. For material changes, we may notify registered users via email.
11. Contact
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
Email: hello@vellaflora.com
Phone: (612) 555-0199
Location: Minneapolis, MN
Privacy Questions?
If you have any questions about how we handle your data, please reach out.
Contact Us