Skip to main content
SKIP TO CONTENT KREMAGE

Star Thing LLC · Kremage · Legal

Published policies for KREMAGE. These are the terms and commitments that govern your use of this store. Short where it can be, specific where it must be.

Privacy policy

PRIVACY POLICY
Operator: Star Thing LLC · Store: Kremage (kremage.com) · Mobile app: Kremage for iOS
Effective Date: July 9, 2026 (supersedes the version dated July 4, 2026) · Last Updated: July 9, 2026

Statement Descriptor: Charges appear as "KREMAGE" (or a variant containing "KREMAGE") on your statement.

Quick Summary

Who we are: Star Thing LLC, the legal entity that owns and operates Kremage. We operate the kremage.com website and the Kremage iOS app. We ship within the United States and to select countries outside the US, set per brand and shown at checkout.

What we collect (on the website): Name, email, address, payment info (processed by Shopify/Stripe — we never store full card numbers), order history, device info, browsing data, how you found us (including whether an AI assistant referred you), the pre-purchase policy acknowledgments you give at checkout, and materials you choose to submit with a return or claim. The iOS app collects none of this — see Section 5A.

Our iOS app: The Kremage app is a catalog browser that hands checkout off to Shopify's secure web checkout. On the App Store it is listed as collecting no data — it runs no analytics, advertising, or tracking SDKs, does not track you across apps or websites, and stores your bag, recently-viewed items, and cached catalog/images only on your device. See Section 5A.

What runs on the site: Shopify analytics, Klaviyo (email marketing), payment processor tracking, hCaptcha (bot protection), and content delivery networks (Google Fonts, Cloudflare, Shopify CDN) that receive your IP address to serve files. Pinterest and TikTok pixel code exists in the theme but is currently dormant.

What we don't do: We do not sell your personal data. We do not use Google Analytics 4, Meta Pixel, session replay tools, or advertising fingerprinting. We do not display third-party ads. We do not train AI models on your data.

Who we share with: Service providers needed to operate the business (Shopify, Klaviyo, payment processors, shipping carriers, our bot-protection and CDN providers) and the Partner Brand fulfilling your order (name and shipping address only).

Visitors outside the US: We ship internationally where the fulfilling brand supports it, so if you are in a covered jurisdiction its privacy law may apply — and we honor GDPR, UK GDPR, PIPEDA, and Australian Privacy Principles rights for all customers regardless. See Section 10.

Your rights: Access, correct, delete, or port your data at any time. Email afterglow@kremage.com or call (917) 920-5868.

1. Who We Are

This Privacy Policy describes how Star Thing LLC ("we," "us," or "our") collects, uses, shares, and protects your personal information when you visit or make a purchase from kremage.com (the "Site") or use the Kremage application for iOS (the "App"; together with the Site, the "Services"). Star Thing LLC is the Data Controller for your personal information. We are incorporated in the United States and ship within the US and to select countries outside it (availability is set per brand and shown at checkout).

Compliance: This policy is designed to comply with applicable privacy laws in the jurisdictions where our customers and visitors reside, including:

US state laws: California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the Florida Digital Bill of Rights (FDBR), the Delaware Personal Data Privacy Act (DPDPA), Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, and Iowa ICDPA.
European Union: General Data Protection Regulation (GDPR, Regulation 2016/679). United Kingdom: UK GDPR and the Data Protection Act 2018. Canada: PIPEDA. Australia: Privacy Act 1988 and the Australian Privacy Principles. Because we ship to customers outside the United States, the privacy law of a covered jurisdiction may apply to our processing of your personal data where you reside there; regardless of strict applicability, we honor the core rights described in this policy for all customers and visitors.
Where laws of your jurisdiction grant you greater rights than described in this policy, those greater rights apply.

2. Information We Collect

We limit data collection to what is necessary to operate our business and fulfill your orders. This section describes information collected through the Site. The Kremage iOS app collects no personal information itself; how the App handles data on your device is described separately in Section 5A.

2.1 Information you provide directly:

Identity: Name, email address, phone number.
Shipping & billing: Shipping address, billing address.
Payment: Payment details are processed securely by Shopify Payments and Stripe. We never see, store, or have access to your full card number, CVV, or bank account details.
Order history: Products purchased, order dates, amounts, transaction IDs, and your return history — including whether your one-time free return label has been used and the outcome of return inspections.
Communications: Emails, messages, or other correspondence you send us.
Return and claim verification: Photos or videos you submit in connection with a return, damage, defect, or missing-item claim. If you report a package stolen after confirmed delivery and choose to submit a police report or carrier claim number in support of a goodwill review, we collect that document or number solely to evaluate and document the claim. Redact any information a police report contains beyond your name, the incident, and the report number — we do not need it and ask that you not send it.
Purchase acknowledgments: When you buy a final-sale or custom-order item, the checkbox acknowledgment you give before purchase is recorded with a timestamp and attached to your order.
Account info: If you create an account, your login credentials (password is hashed and not readable by us).
2.2 Information collected automatically:

Device data: IP address, browser type and version, operating system, time zone, device model.
Browsing activity: Pages visited, time spent on pages, referring URL (how you found us), click patterns.
Referral source, including AI assistants: If you arrive at the Site from an AI assistant or AI search surface (for example via a referral link or campaign parameters in the URL), we detect and record that referral source and attach it to your cart and order as an order attribute. This tells us which channels bring customers; it does not identify you to the AI platform and does not send any of your data to the AI platform.
Pre-checkout disclosure and acknowledgment record: When you shop, a timestamped record that our Terms, Return, and Shipping policies were displayed to you before checkout — and, where applicable, that you affirmatively acknowledged final-sale or custom-order terms — is attached to your cart and order. We use this for dispute resolution and fraud defense.
Cookies, client-side storage, and tracking technologies: We use cookies, session storage, local storage, and IndexedDB in your browser. Client-side storage (local storage and IndexedDB) is used for preferences and performance caching on your own device and is not a tracking mechanism. See Section 5 for the complete disclosure. Automatic collection in this Section 2.2 describes the website; the App does not perform this collection (see Section 5A).
2.3 Information we do NOT collect:

We do not collect biometric data, neural data, or geolocation data beyond IP-based approximation. We do not use facial recognition or any form of automated profiling to make decisions about you. We do not knowingly collect sensitive personal information as defined by the CCPA/CPRA or special categories of personal data under GDPR Article 9 (Social Security numbers, government IDs, racial/ethnic origin, religious beliefs, political opinions, trade union membership, sexual orientation, health data, etc.). A police report you voluntarily submit under Section 2.1 is used solely for the claim it supports and is never used for any other purpose.

3. How We Use Your Information

We use your personal information to operate Kremage and serve you. Legal bases under GDPR/UK GDPR are noted in brackets where applicable.

Order fulfillment [contract performance — GDPR Art. 6(1)(b)]: Processing payments, shipping products, sending order confirmations and tracking information.
Account and authentication [contract performance]: If you create an account, we store your login credentials, order history, saved addresses, and wishlist to give you a faster experience on return visits.
Customer support [contract performance]: Responding to your inquiries, processing returns and claims, and resolving disputes.
Marketing communications [consent — GDPR Art. 6(1)(a)]: If you opt in to our email list, we send newsletters, product announcements, and curated content. You can unsubscribe at any time via the link in any marketing email or by emailing afterglow@kremage.com. We do not send marketing texts unless you separately opt in to SMS.
Site analytics and product improvement [legitimate interest — GDPR Art. 6(1)(f)]: We track aggregate usage of the site (pages viewed, products viewed, cart actions, search queries) and referral channels (including AI-assistant referrals) to understand what's working. This is done through Shopify's built-in analytics and through Klaviyo, which receives behavioral data tied to subscribed customers. See Section 5.
Fraud prevention, security, and return-program integrity [legitimate interest, legal obligation]: Detecting unauthorized transactions, verifying identities, distinguishing humans from bots (through our captcha provider), monitoring for malicious activity, maintaining order-level records (pre-checkout disclosure and acknowledgment records) used in payment-dispute resolution, and monitoring return activity for the abuse patterns described in Section 10 of our Return & Refund Policy (such as serial returns or repeated damage claims). We use automated systems solely for fraud prevention and security; these systems do not make decisions about pricing, product availability, or access to services, and any decision to limit an account for return abuse is made by a human.
Legal compliance [legal obligation — GDPR Art. 6(1)(c)]: Maintaining records required by tax, accounting, and consumer protection laws; responding to lawful subpoenas, court orders, and regulatory requests.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

What we do not do: We do not sell your personal information to data brokers or advertisers. We do not share your data for cross-context behavioral advertising. We do not buy customer lists to email you unsolicited. We do not train AI models on your data. We honor Global Privacy Control (GPC) signals as opt-out requests.

4. Sharing & Disclosure

We do not sell your personal information. We do not share your data for cross-context behavioral advertising. We do not allow third parties to use your data for their own marketing purposes.

We share data only with the following categories of service providers, solely to operate our business:

E-commerce platform: Shopify (hosting, checkout, order management, built-in analytics). Tracking and data processing occur through Shopify and its service-provider ecosystem as part of operating the store, even where Kremage itself runs no separate tracker.
Email service provider: Klaviyo (transactional and marketing email, behavioral analytics tied to subscribed customers).
Payment processors: Stripe, Shopify Payments, PayPal, Apple Pay, Google Pay, Shop Pay, Amazon Pay.
Bot protection: hCaptcha (Intuition Machines, Inc.) processes your IP address, device and browser characteristics, and interaction signals solely to distinguish humans from automated traffic on protected forms.
Content delivery networks: Google Fonts (fonts.googleapis.com / fonts.gstatic.com), Cloudflare (cdnjs.cloudflare.com), and Shopify's CDN receive your IP address and user-agent to serve fonts, scripts, and images. These requests are technical file delivery; we do not send them your identity, and they do not build behavioral profiles for us.
Shipping carriers: USPS, UPS, FedEx, and other carriers receive your name, address, and package details to deliver your order. International shipments additionally involve the destination country's customs and postal authorities, which receive the information required to clear and deliver the package. If you direct your order to a freight-forwarding service, anything that company does with your information after US delivery is governed by its privacy policy, not ours.
Partner Brands (fulfillment): Your name and shipping address are shared with the Partner Brand fulfilling your order.
App distribution (Apple): When you download or use the Kremage iOS app, Apple processes your download and any App Store activity under Apple's own privacy policy. The App sends Apple no personal information; Apple may share with us only aggregate, non-identifying App Analytics and sales reports (see Section 5A). We share no customer data with Apple.
Google services (limited): Google Merchant Center receives our product catalog feed (no personal information) so products appear in Google Shopping. Google Customer Reviews may send an optional post-purchase survey to your order email if you opt in at checkout.
AI commerce platforms (conditional): If we enable purchases through AI shopping channels (such as ChatGPT Instant Checkout or Google's AI shopping surfaces), and you choose to buy through one, that platform and its payment partner collect and process your order and payment information under their own privacy policies, and share with us what is needed to fulfill your order. Shopping inside an AI assistant is governed by that assistant's privacy policy; this policy governs what we receive. We will keep this policy updated as channels launch.
Sub-processors: Where our service providers process personal data on our behalf, they act as data processors bound by contractual obligations consistent with applicable privacy law, including GDPR Article 28 requirements and the EU-US Data Privacy Framework where applicable. A complete list of our sub-processors is available on request via afterglow@kremage.com.
We may also disclose data if required by law, subpoena, court order, or government request, or to protect the rights, property, or safety of Star Thing LLC, our customers, or the public.

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity with equivalent privacy protections. You will be notified before any such transfer that materially changes how your data is processed.

5. Cookies, Tracking Technologies, and Service Providers

Kremage uses cookies and tracking technologies on the Site. The following is a complete and honest disclosure of what runs on the website (kremage.com). The Kremage iOS app does not use cookies or web tracking technologies; the App's on-device storage is described in Section 5A.

Essential cookies and client-side storage. Required for the cart, checkout, login state, currency selection, and country preference to function. We also use local storage and IndexedDB in your browser for preferences and performance caching (for example, caching catalog data on your device so pages load faster). Client-side storage stays on your device and is not used to track you across sites. Essential cookies cannot be disabled without breaking the Site.
Shopify analytics. Shopify collects standard analytics on every transaction (pages viewed, products viewed, conversion data, device type, referrer). This is built into the platform and cannot be disabled without leaving Shopify. Shopify is a PCI-DSS Level 1 service provider and acts as a data processor under GDPR.
Klaviyo (email service provider). When you subscribe, place an order, or create an account, your email and certain behavioral data (pages viewed, products viewed, cart events, purchase history) are sent to Klaviyo for our email flows (welcome series, post-purchase, abandoned cart recovery, product recommendations). Klaviyo is our data processor under GDPR. You can request deletion of your Klaviyo profile by emailing afterglow@kremage.com.
Payment processor tracking. Shopify Payments, Apple Pay, Google Pay, Shop Pay, PayPal, and Amazon Pay collect transaction data necessary to process payments and detect fraud, each under its own privacy policy.
hCaptcha (bot protection). Protected forms use hCaptcha, which analyzes your IP address, browser and device characteristics, and interaction patterns solely to distinguish humans from bots. Its privacy policy governs its processing.
Content delivery networks. The Site loads files from Google Fonts, Cloudflare's cdnjs, and Shopify's CDN. When your browser requests these files, the CDN receives your IP address and user-agent as part of the request. This is standard technical delivery, not behavioral tracking.
Embedded video (when present). Some pages may embed video using YouTube's privacy-enhanced mode (youtube-nocookie.com), which does not set advertising cookies unless you play the video. If you play an embedded video, Google/YouTube receives your IP address and playback data under its own privacy policy.
Order attribution and evidence attributes. Your order may carry first-party attributes we set: (a) a referral-source attribute recording the channel that brought you (including AI-assistant referrals detected from the referring URL or campaign parameters); (b) a timestamped record that our Terms, Return, and Shipping policies were displayed before checkout; and (c) where applicable, a timestamped record of your final-sale or custom-order acknowledgment checkbox. These live with your order data in Shopify, are used for channel analytics and payment-dispute defense, contain no information beyond what is described, and are never shared with advertising platforms.
Pinterest Tag (conditional). Code for a Pinterest conversion tag exists in our theme but is not currently active. If we activate it, this policy will be updated and the tag will collect page views, product views, and purchase events for advertising measurement under Pinterest's privacy policy.
TikTok Pixel (conditional). Code for a TikTok conversion pixel exists in our theme but is not currently active. If we activate it, this policy will be updated and the pixel will collect page views, product views, and purchase events for advertising measurement under TikTok's privacy policy.
Google Merchant Center. Our product catalog is submitted to Google Merchant Center to appear in Google Shopping. This is a one-way feed of product data and does not transmit your personal information.
Google Customer Reviews. After a purchase, you may receive an optional survey from Google Customer Reviews. Participation is voluntary and governed by Google's privacy policy.
What we do not run. We do not use Google Analytics 4. We do not run Meta Pixel. We do not use programmatic advertising trackers, third-party data brokers, or session replay tools (such as Hotjar, FullStory, or Mouseflow). We do not fingerprint visitors for advertising or cross-site tracking; our captcha provider analyzes device signals solely for bot detection. We do not sell tracking data to anyone.
Your choices. Most browsers let you block cookies, but blocking essential cookies will break the cart and checkout. You can opt out of Klaviyo marketing emails by unsubscribing. You can request deletion of your behavioral profile by emailing afterglow@kremage.com. We honor Global Privacy Control (GPC) signals as an opt-out of any tracking that requires opt-out under applicable law. For EU and UK visitors: strictly necessary cookies require no consent under the ePrivacy Directive; for non-essential analytics, use your browser settings or contact us to opt out.

5A. Our Mobile App (iOS Application)

The Kremage iOS app (the "App") is a native catalog-browsing companion to kremage.com. Its data practices differ from the website's, and this section governs them. In plain terms: the App collects no personal information, contains no analytics, advertising, or tracking SDKs, and does not track you across apps or websites.

What the App does. The App displays our product catalog, which it fetches read-only over an encrypted HTTPS connection from kremage.com. You do not need an account, a login, or any personal information to browse. Because the App fetches the catalog from kremage.com over HTTPS, our servers and content delivery network receive your device's IP address to route each response, exactly as any website does. We use it only to deliver the catalog and images, do not link it to your identity, and do not use it for tracking or advertising — which is why the App still qualifies as "Data Not Collected" under Apple's criteria.
Apple "Data Not Collected." On the App Store, Kremage is listed as collecting no data. Our bundled Apple Privacy Manifest declares no tracking (NSPrivacyTracking = false), no tracking domains, and no collected data types. The App requests no access to your location, camera, microphone, contacts, photos, or health data, uses no advertising identifier (IDFA), and shows no App Tracking Transparency prompt because it performs no tracking.
On-device storage only. The App stores your shopping bag and your recently-viewed items on your device (using Apple's UserDefaults) and caches catalog data and product images on your device so browsing is fast and works with a poor connection. This information stays on your device, is never transmitted to us or to any third party, and is removed when you delete the App. Two Apple "required-reason" APIs are declared for these on-device purposes only: on-device preference storage, and reading system uptime solely to time an in-app animation. Neither is used for tracking or fingerprinting.
Checkout happens on Shopify. The App has no in-app payment and never sees your card details. When you choose to buy, the App opens Shopify's secure, PCI-DSS-compliant hosted checkout in an in-app Safari view (SFSafariViewController) on kremage.com. Everything you enter there — contact, shipping, and payment information — is collected and processed exactly as described in Sections 4 and 5 of this policy (Shopify, Stripe/Shopify Payments, and the wallet you choose). The App only ever opens https pages on our own domain.
No third-party SDKs. The App bundles no third-party analytics, advertising, attribution, crash-reporting, or social SDKs. Its only network connection is to kremage.com (and the Shopify-hosted checkout that domain routes to).
Apple's role. The App is distributed through Apple's App Store. Your download and any App Store activity are governed by Apple's privacy policy, not ours. Apple may provide us with aggregate, non-identifying App Analytics and sales reports through App Store Connect; you can turn off sharing this diagnostic and usage data in iOS Settings › Privacy & Security › Analytics & Improvements. We receive no individual identity from Apple.
Your rights in the App. Because the App keeps data only on your device and collects nothing on our servers, you can exercise the strongest form of deletion at any time by deleting the App, which removes all of its on-device data. All rights in Section 7 still apply to any order you place through the App, because that order is processed by Shopify exactly like a website order.

6. Do Not Sell / Do Not Share / Global Privacy Control

Under the CCPA/CPRA and other US state privacy laws, you have the right to opt out of the sale or sharing of your personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, so there is no sale or share to opt out of.

Global Privacy Control. We recognize and honor GPC signals as a valid opt-out preference signal in compliance with CCPA regulations (11 CCR § 7025). When we detect a GPC signal, we treat it as an opt-out request for any non-essential tracking that requires opt-out under applicable law, including ceasing transmission of behavioral data to Klaviyo for non-subscribed visitors and disabling any conditional tracking pixels that have been activated.

For GDPR / UK GDPR visitors: You have the right to object to processing based on legitimate interests (Article 21 GDPR) by contacting afterglow@kremage.com. We will cease the relevant processing unless we have compelling legitimate grounds that override your interests, or processing is necessary for legal claims.

A "Do Not Sell or Share My Personal Information" link is available in the Site footer to satisfy the CCPA disclosure requirement, even though we do not engage in sale or sharing as defined by CCPA.

7. Your Privacy Rights

Regardless of where you live, we extend the following rights to all customers and visitors: Right to Know / Access · Right to Correction · Right to Deletion (subject to legal retention requirements such as tax records and active dispute evidence) · Right to Data Portability · Right to Restrict Processing · Right to Object (including to direct marketing and legitimate-interests processing) · Right to Limit Sensitive Information (we do not collect sensitive personal information, but we recognize the right) · Right to Opt Out of Marketing (CAN-SPAM opt-outs processed within 10 business days) · Right to Non-Discrimination (exercising your rights never affects your service, pricing, or quality) · Right to Withdraw Consent · Right to Lodge a Complaint with your supervisory authority (your state attorney general or the California Privacy Protection Agency; the ICO for the UK; your national DPA in the EU; the OPC in Canada; the OAIC in Australia) — with or without contacting us first, though we appreciate the chance to resolve issues directly.

How to exercise your rights: Email afterglow@kremage.com (subject: "Privacy Request") or call (917) 920-5868. We verify identity before processing (typically via email confirmation to your order email). Response times: US — within 45 calendar days (extendable by 45 with notice); GDPR/UK GDPR — within one month (extendable by two for complex requests, with notice); PIPEDA and Australia — within 30 days. You may designate an authorized agent with written proof of authorization.

8. Data Retention

We retain personal data only as long as necessary for the purpose it was collected (GDPR Article 5(1)(e) and equivalents):

Order and transaction records (including the referral, disclosure, and acknowledgment attributes in Section 5, and your free-return-label usage flag): 7 years (US tax, accounting, and chargeback-defense requirements).
Customer account data: Until you request deletion or close your account.
Marketing email addresses: Until you unsubscribe.
Klaviyo behavioral profiles: Until you request deletion or unsubscribe.
Return and claim verification media (photos, videos, police report or carrier claim documentation): Until the later of 90 days after the case closes or the expiration of applicable payment-dispute and legal claim windows for that order — no longer than 2 years — then deleted. We retain claim evidence through the dispute window because deleting it earlier would leave both you and us unable to substantiate the claim.
Customer support correspondence: 3 years from last contact.
Browsing/device data: 12 months from collection, then automatically deleted.
App on-device data (bag, recently-viewed, cached catalog and images): stored only on your device and controlled entirely by you — it persists until you delete the App (offloading the App keeps this data; deleting it removes it). We hold no copy and set no retention period because it never reaches us.
When data is no longer needed for any purpose above, it is securely deleted or anonymized.

9. Data Security

All data transmitted to and from kremage.com is encrypted via TLS/SSL. The Kremage iOS app connects only over encrypted HTTPS (Apple App Transport Security enforced), holds no payment data, and hands checkout to Shopify's hosted checkout in an in-app Safari view (SFSafariViewController). Payment processing is handled by PCI-DSS Level 1 compliant processors (Shopify Payments, Stripe); we do not store payment card data on our servers or in the App. Access to customer data is restricted to authorized personnel. We use Content Security Policy (CSP) headers, Subresource Integrity (SRI), and other browser-level security controls.

Breach notification: In the event of a personal data breach, we will notify affected individuals and relevant supervisory authorities as required by applicable law, including notifying the relevant supervisory authority within 72 hours of becoming aware for GDPR-covered processing (Article 33), notifying affected individuals without undue delay where required (Article 34), and meeting the timeframes of applicable US state breach-notification laws.

While no method of transmission over the internet is 100% secure, we take commercially reasonable steps to protect your personal information.

10. International Visitors & Data Transfers

We ship within the US and to select countries outside it, the Site is reachable worldwide, and the App is available on the App Store. The Site is operated from the United States, and your personal information will be transferred to, stored, and processed in the United States, where data protection laws may differ from your country's.

For visitors in the EEA, UK, and Switzerland: Where we transfer personal data to the United States, we rely on transfer mechanisms recognized under GDPR Chapter V and equivalent UK provisions: our key service providers (including Shopify and Stripe) are certified under the EU-US Data Privacy Framework, its UK Extension, and the Swiss-US DPF; where a provider is not certified, we rely on Standard Contractual Clauses approved by the European Commission (and UK equivalents). By using the Site, you acknowledge that your data will be processed in the United States under these safeguards.

For visitors in Canada, Australia, and elsewhere: Your data is processed in the United States subject to this policy and contractual safeguards with our service providers.

11. Children's Privacy

The Services are not intended for anyone under 18, and per our Terms of Service you must be 18 or older to place an order. The Kremage app is age-rated for adults on the App Store; because the App itself collects nothing and requires no account, the 18-or-older purchase requirement is enforced at Shopify checkout rather than inside the App. We do not knowingly collect personal information from minors, and we do not knowingly collect personal information from children under 16 for GDPR-covered processing (Article 8 GDPR). If we learn we have collected data from a minor, we will delete it immediately. If you believe a minor has provided us with personal information, contact afterglow@kremage.com.

12. Third-Party Links

The Site may link to third-party websites and social platforms (brand partner sites, Instagram, TikTok, Pinterest, X, Facebook, YouTube). Following such an outbound link on the Site takes you off our Services; we are not responsible for those websites' privacy practices. The App itself contains no third-party outbound links: its in-app Safari view (SFSafariViewController) is limited to kremage.com checkout and catalog pages. Read a third party's policy before providing it personal information.

13. Dispute Resolution

Disputes regarding your data or privacy are resolved under Section 15 of our Terms of Service (informal resolution first, then binding individual arbitration under AAA Consumer Arbitration Rules, with a class-action waiver, small-claims exception, and 30-day arbitration opt-out). Star Thing LLC pays all arbitration fees and costs beyond the initial consumer filing fee, as required by AAA Consumer Arbitration Rules. Rather than restating those terms here, we incorporate them by reference so the two documents can never conflict.

Two things always remain true regardless of that section: (1) nothing limits your right to file a complaint with any data protection authority or regulator with jurisdiction over your personal data (including the California Privacy Protection Agency, your state attorney general, the ICO, an EU DPA, the OPC, or the OAIC); and (2) for visitors in the EU, UK, Switzerland, and other jurisdictions where binding pre-dispute arbitration of consumer claims is not permitted, the arbitration and class-waiver provisions do not apply to the extent they conflict with mandatory consumer protection law, and you retain the right to bring claims before the competent courts of your country of residence.

Governing law: This policy is governed by the laws of the State of Florida, United States, without regard to conflict-of-law principles, except where mandatory consumer protection law in your country of residence requires otherwise.

14. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes we will: update the "Last Updated" date above; post the revised policy on kremage.com; for significant changes, email customers with active accounts; and for EU/UK visitors, provide advance notice where changes materially affect processing. Continued use of the Services after changes are posted constitutes acceptance.

15. Contact

Data Controller: Star Thing LLC · afterglow@kremage.com (Subject: "Privacy Request") · (917) 920-5868
Response time: per Section 7. Mailing address: 7901 4th St N, #30711, St. Petersburg, FL 33702

EU/UK Representative: Because we now ship to select destinations outside the United States, GDPR or UK GDPR may apply where we offer goods to and ship to data subjects in the EU or UK, and an Article 27 representative may be required in that case. Star Thing LLC is assessing this obligation as it expands international shipping and will appoint a designated representative and update this policy if and when the threshold is met. In the meantime, EU and UK visitors can reach us directly at afterglow@kremage.com for any privacy matter, and we will respond directly.

By using kremage.com or the Kremage app, you acknowledge that you have read and understood this Privacy Policy.

© 2026 Star Thing LLC — Kremage™ — All rights reserved.