Skip to content

Privacy Policy

How Mutual Act LLC handles the personal data you share with us — what we collect, why, who else sees it (including our fulfilment partner in Georgia), and the rights you have under GDPR, UK GDPR and CCPA.

Effective date: 18 September 2026.

This policy explains what personal data Mutual Act collects when you visit our site or place an order, how we use it, who we share it with, and the rights you have. We aim for plain language — if anything is unclear, please write to hello@mutual-act.com.

1. Who we are

Mutual Act is an independent jewelry brand. The data controller is Mutual Act LLC, a limited liability company organized under the laws of the State of Wyoming, United States, 30 N Gould St #50733, Sheridan, WY 82801, United States. For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR and the California Consumer Privacy Act (CCPA/CPRA), we are the controller of the personal data described below. Contact: hello@mutual-act.com.

2. What data we collect

Depending on how you use the site, we may process:

  • Contact details you give us: name, email, phone number.
  • Delivery address: country, city, region, postal code, street.
  • Order details: items purchased, size, quantity, price, currency, any discount code used.
  • Account credentials: your email and a hashed password (only if you create an account).
  • Marketing preference: whether you subscribed to release announcements.
  • Back-in-stock requests: your email and the piece (and size) you asked to be notified about.
  • Payment metadata: the transaction reference returned by our payment provider. We do NOT receive or store your card number, CVV or expiry — the card page is hosted by the payment provider.
  • Communications: emails you send us and our replies.
  • Visit statistics (first-party, pseudonymous): the path you visit, the referring site, an approximate country derived from your IP address using a locally installed GeoLite2 database (the IP itself is not stored and is not sent to any third party) and, as a correction for VPN use, your browser's time-zone name (e.g. “Europe/Berlin”), which is used only to estimate the country and is not stored, device type (mobile / desktop / tablet), browser family and a random visitor identifier stored in a cookie. Full IP addresses and full user-agent strings are not stored. You can switch statistics off for your browser at any time — see section 5.
  • Cookies and browser storage — see section 5.

3. Why we use it, and our legal bases

Under GDPR Article 6 we rely on the following legal bases for each purpose:

  • Fulfilling your order — contract (Art. 6(1)(b)). This covers payment, packaging, shipping, invoicing, customs paperwork and after-sales support.
  • Running your account, if you create one — contract (Art. 6(1)(b)).
  • Sending transactional emails (order confirmation, shipping, cancellation, password reset) — contract (Art. 6(1)(b)).
  • Release announcements (the “Stay tuned” form) — consent (Art. 6(1)(a)). You opt in by submitting the form and can withdraw at any time by emailing us.
  • Back-in-stock notifications (the “Notify me” form on a sold-out piece) — consent (Art. 6(1)(a)). We email you once when the piece is available again; you can withdraw by emailing us.
  • Fraud prevention, security and rate-limiting on sensitive endpoints — legitimate interests (Art. 6(1)(f)) in protecting our shop and customers.
  • Visit statistics — legitimate interests (Art. 6(1)(f)) in understanding which pages are useful and improving the Site. They are used solely for that purpose, are not shared with anyone else, and are switched off if your browser sends Do Not Track (DNT) or Global Privacy Control (GPC) or if you use the “Don't count my visits” switch in section 5.
  • Accounting, tax and customs compliance — legal obligation (Art. 6(1)(c)).

4. Who we share data with

Processors acting on our instructions

These companies process personal data only on our documented instructions, under a data-processing agreement:

  • Hetzner Online GmbH (Gunzenhausen, Germany, EU) — hosting of the site, database and object storage of your order data, account data and uploaded media, in its Falkenstein (Germany) data centre.
  • Plus Five Five, Inc., trading as Resend (San Francisco, USA) — transactional email delivery (order confirmations, shipping notices, account emails). Resend stores email metadata and logs in the United States; transfers are covered by its Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK Addendum, and by its certification under the EU–US Data Privacy Framework.
  • Backblaze, Inc. (San Francisco, USA) — off-site storage of encrypted database backups in its EU (Amsterdam) region; transfers are covered by its Data Processing Agreement incorporating the EU Standard Contractual Clauses and its UK addendum.
  • Cloudflare, Inc. (San Francisco, USA) — DNS resolution for our domain (no page content passes through Cloudflare); transfers under the EU Standard Contractual Clauses.
  • Mapbox, Inc. (San Francisco, USA) — address autocomplete on the checkout page. Only what you type into the address field is sent to Mapbox, and only while you are actively typing; transfers under the EU Standard Contractual Clauses.
  • Our fulfilment partner, Individual Entrepreneur Nikita Diachenko (Tbilisi, Georgia, ID 304821664) — makes, packs, exports and dispatches your order and handles returns on our behalf, as our processor under a written agreement. We share your name, delivery address, phone number, email address, order number, the Products ordered, sizes, quantities, order value and selected delivery service, and the information required for customs declarations; this data is transferred to Georgia for that purpose (see section 6).

Other recipients

These recipients determine their own purposes and means for the data they receive, and their own privacy notices apply to them:

  • Our payment provider — payment processing. Your card details are entered on the provider's own secure page and never reach us; we receive only the transaction reference and outcome. The provider processes payment data under its own terms and applicable payment-scheme and anti-fraud rules.
  • Shipping carriers (the international courier or postal operator shown for your delivery option at checkout) — the name, delivery address, phone number and email address needed to deliver your order and to complete customs formalities. Carriers act as independent controllers of shipment data under their own privacy notices.
  • Customs and tax authorities of the country of dispatch and of destination — the data required on the commercial invoice and export/import declarations, as required by law.
  • Google LLC / YouTube — only if you press play on a YouTube Shorts video embedded on a product page. We embed in “no-cookie” mode, so no YouTube cookies are set until you interact.

We do not sell your personal data and we do not share it with advertising networks.

5. Cookies and browser storage

We use only first-party cookies and browser storage. Nothing here is used for advertising or cross-site tracking, and no third-party analytics service receives your data. The current inventory:

Strictly necessary (needed for the service you request)

  • payload-token (cookie, session, up to 2 hours) — keeps you signed in to your account.
  • ma-cart (browser localStorage, until you clear it) — the contents of your bag, so it survives a page reload.
  • ma-currency (cookie, 1 year) — the currency you selected in the header.
  • ma-reward (cookie) — remembers that you unlocked the sudoku discount, so it survives a refresh.
  • ma-gate (cookie) — used only while a private preview of the site is enabled; remembers that you have entered the team password.
  • ma-analytics (cookie, 1 year) — set only if you switch visit statistics off (below); records your objection.

Visit statistics

  • ma-vid (cookie, 1 year) — a random identifier used solely to count how many different browsers visit which pages, so that we can improve the Site. It is set by our own server, is not linked to your name or account unless you are signed in, is never shared with anyone else, and the visit records it relates to are deleted after 90 days.

Visit statistics are not required for the Site to work. If you prefer not to be counted, use the “Don't count my visits” switch below this policy: it sets the ma-analytics cookie and we stop recording your page views in this browser immediately. We also honour the Do Not Track and Global Privacy Control signals sent by your browser. We do not display a cookie banner because we set no advertising or third-party cookies; if the law of your country requires prior consent for visit statistics, you may object at any time using the switch and we will respect that choice.

Attribution: country detection uses GeoLite2 data created by MaxMind, available from https://www.maxmind.com, installed on our own server.

6. International transfers

Our servers and database are located in Germany (EU), and database backups are stored in Germany and in the Netherlands (EU). The controller, Mutual Act LLC, is established in the United States and accesses your data from there. Transactional email is delivered by a US-based processor. Where personal data is transferred from the EU or UK to a processor in the United States (Resend, Backblaze, Cloudflare, Mapbox), the transfer relies on the European Commission's Standard Contractual Clauses incorporated in that processor's data-processing agreement, the UK International Data Transfer Addendum where applicable, and, for processors certified under it, the EU–US Data Privacy Framework and its UK Extension.

Order and delivery data is transferred to Georgia to our fulfilment partner so that your order can be made, exported and shipped. Georgia is not covered by an EU or UK adequacy decision. This transfer is necessary for the performance of your contract with us (GDPR Art. 49(1)(b)); in addition, we are putting in place the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum with our fulfilment partner, and will update this policy when they are executed. Carriers and customs authorities in the country of destination receive the data required to deliver and clear your parcel.

7. How long we keep data

  • Order records, commercial invoices, customs documents and payment references: 7 years from the end of the year of the order, to meet accounting, tax and customs record-keeping obligations. This period does not apply to other data.
  • Account data: until you ask us to delete it, or 3 years after your last order — whichever is later.
  • Marketing list: until you unsubscribe.
  • Back-in-stock requests: 12 months from the request, or until you ask us to delete it.
  • Analytics records: automatically deleted after 90 days.
  • Support emails: up to 3 years after the conversation ends.

8. Your rights

Under the GDPR and UK GDPR you have the right to:

  • access the personal data we hold about you;
  • correct it if it is inaccurate;
  • delete it (right to be forgotten), unless we are required by law to keep it — e.g. accounting records for the statutory retention period;
  • restrict or object to certain processing;
  • receive your data in a portable, machine-readable format;
  • withdraw consent to marketing communications at any time.

Under the California CCPA/CPRA, if you are a California resident, you have the right to know what personal data we collect, to request that we delete it, to correct it, to opt out of “sale” or “sharing” (we do neither), to limit the use of any sensitive personal information (we do not process any), and not to be discriminated against for exercising these rights.

To exercise any of these rights, email hello@mutual-act.com. We respond without undue delay and normally within one month, subject to any extension or different period permitted by applicable law; we will tell you if we need longer.

If you believe we have mishandled your data you also have the right to complain to your local supervisory authority — for the EU, the list of national authorities is at edpb.europa.eu; in the UK, it is the ICO (ico.org.uk).

9. Children

Mutual Act is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us with data, please contact us and we will delete it.

10. Security

We host on hardened EU infrastructure with automatic HTTPS, hashed passwords, rate limiting on sensitive endpoints, encrypted database backups with an immutable off-site copy, and access limited to the founder and the developer of this site. No online system is perfect, but we treat your data the way we would want ours treated.

11. Changes to this policy

If we make material changes, we will update the effective date at the top of this page and, where required, notify you by email or by a notice on the site.

12. Contact

Questions, requests, or complaints: hello@mutual-act.com. We answer every message we receive.

Visit statistics: on. Page views are counted anonymously (no IP address, no cross-site tracking).