logo

Legal

Privacy
Policy

We believe in being straightforward about data. Here is exactly what we collect, why we collect it, and who we share it with.

Effective date: April 30, 2025

01

Information We Collect

Account Information

When you create an account, we collect your full name, email address, and password (stored as a secure hash — we never store your password in plain text). You may also add a phone number to your profile at any time.

Order & Shipping Information

When you place an order, we collect your name, email address, phone number, and full shipping and billing address (street, city, province, and postal code). This information is required to fulfil and deliver your order.

Payment Information

We do not store your credit or debit card details. All payment information is handled directly and securely by Stripe, our payment processor. We only retain a reference ID provided by Stripe to associate a payment with your order.

Contact Messages

If you contact us through our contact form, we collect your name, email address, and the content of your message. This information is used solely to respond to your inquiry and is not stored in our database.

Sign In With Google

If you choose to sign in with Google, we receive your name, email address, and profile picture from Google. We use this to create and manage your account. We do not receive or store your Google password.

Cart Data

Your shopping cart is stored locally in your browser (localStorage). It contains only product details — no personal information. This data stays on your device and is cleared when you clear your browser data.

02

How We Use Your Information

  • Process and fulfil your orders, including coordinating shipping with our carrier.
  • Send order confirmation, shipping updates, and delivery notifications to your email.
  • Manage your account and allow you to view your order history.
  • Respond to messages sent through our contact form.
  • Send a password reset email when you request one.
  • Prevent fraud, abuse, and unauthorized access to your account.
  • Comply with applicable legal obligations.

03

Sharing Your Information

We do not sell, rent, or trade your personal information. We share your data only with the third-party services listed below, and only to the extent necessary to operate the store.

Stripe Payment Processing

Handles credit/debit card payments and Klarna buy-now-pay-later. Stripe receives your payment details, email, and billing address. Stripe is PCI-DSS compliant.

Klarna Buy Now, Pay Later

If you select Klarna at checkout, your email, shipping address, phone number, and order total are shared with Klarna to process your instalment plan.

UniUni Shipping & Delivery

Your name, phone number, email address, and shipping address are shared with UniUni to create and track your shipment.

Resend Transactional Email

Your email address and relevant order details are sent through Resend to deliver order confirmations, shipping updates, and password reset emails.

Google Authentication (Optional)

If you use "Sign in with Google", Google handles authentication and shares your basic profile with us. This is only used if you choose this sign-in option.

04

Data Retention

Account data

Retained while your account is active. Deleted upon request.

Order records

Retained indefinitely for accounting and order history purposes.

Login sessions

Expire automatically after 30 days.

Password reset tokens

Expire 1 hour after being issued and are deleted once used.

Contact messages

Not stored in our database. Delivered to our inbox and handled like regular email.

Cart data

Stored only in your browser. We have no access to it.

05

Security

We take reasonable steps to protect your personal information from unauthorized access, disclosure, or misuse. Measures we have in place include:

  • Passwords are hashed using bcrypt — we cannot see your password.
  • Sessions are managed using secure, httpOnly JWT cookies.
  • All webhook communications (Stripe and UniUni) are verified with HMAC-SHA256 signatures.
  • Payment card data is never transmitted to or stored on our servers — Stripe handles it entirely.
  • All data is transmitted over HTTPS.

No method of transmission over the internet is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

06

Your Rights

You have the following rights regarding your personal information:

  • Access — You can view your profile and order history at any time from your account page.
  • Correction — You can update your name and phone number directly in your account settings.
  • Password change — You can change your password at any time from your account page.
  • Deletion — You can request that we delete your account and personal data by contacting us. Note that order records may be retained for legal and accounting purposes.
  • Data portability — You may request a copy of the personal data we hold about you.

To exercise any of the above rights, please contact us at hello@versetwofit.com. We will respond within a reasonable timeframe.

07

Cookies

We use a small number of cookies that are necessary for the site to function:

next-auth.session-token

Keeps you logged in for up to 30 days. HttpOnly — not accessible by scripts.

next-auth.csrf-token

Protects against cross-site request forgery attacks.

next-auth.callback-url

Remembers where to redirect you after logging in.

We do not use advertising cookies, analytics cookies, or any third-party tracking cookies. No Google Analytics, Meta Pixel, or session recording tools are present on this site.

08

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. We encourage you to review this page periodically. Continued use of the site after changes have been posted constitutes your acceptance of the updated policy.

Questions?

We're happy
to explain more.