Privacy Policy
Last updated: August 2026
Stephan's Tyre Mart PVT Ltd ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you visit our website at stephanstyremart.com.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Name - Your display name
- Email address - Used for authentication and communication
- Profile image - Optional avatar you upload
1.2 Authentication Data
We use magic link (passwordless) authentication and optionally GitHub OAuth. When you sign in via GitHub, we receive your GitHub account identifier. We do not store passwords for magic link accounts. For GitHub users, encrypted access tokens are stored to maintain your session.
1.3 Session Data
When you are logged in, we store session records including:
- IP address
- Browser and device user agent
- Session creation and expiry times
1.4 Wishlist and Cart Data
If you are logged in, your wishlist and cart items are stored on our servers linked to your account. If you are not logged in, this data is stored only on your device in your browser's local storage and is not transmitted to us. When you sign in, any local cart or wishlist data is transferred to your account.
1.5 Discount Usage
When you apply a discount code, we record the discount used, the date, and link it to your account for audit purposes.
2. How We Use Your Information
We use the information we collect to:
- Provide and maintain our services
- Authenticate your identity and manage your account
- Process your wishlist and cart
- Send authentication emails (magic links) via Resend
- Prevent fraud and abuse
- Comply with legal obligations
3. Email Communications
We use Resend to deliver authentication emails (magic sign-in links) from the address noreply@stephanstyremart.com. We do not send marketing emails, newsletters, or promotional communications. Your email address is shared with Resend solely for the purpose of delivering these authentication emails.
4. Cookies and Local Storage
We use the following cookies and local storage:
- Session cookies - Essential cookies for authentication. These are httpOnly, secure, and use same-site=None. They are required for the website to function.
- Sidebar preference cookie - Stores your sidebar open/closed preference for the admin dashboard.
- Guest cart localStorage - Stores your shopping cart locally when not signed in (key: "guest-cart"). Cleared on login.
- Guest wishlist localStorage - Stores your wishlist locally when not signed in (key: "guest-wishlist"). Cleared on login.
We do not use analytics cookies, advertising cookies, or any third-party tracking cookies.
5. Third-Party Services
We use the following third-party services that may process your data:
- Cloudflare - Website hosting, CDN, database (D1), file storage (R2), and security (DDoS protection, Turnstile CAPTCHA). Cloudflare may collect standard web server logs (IP addresses, user agents) as part of their infrastructure service.
- Resend - Email delivery for authentication magic links. Your email address is processed by Resend to deliver these emails.
- GitHub - If you choose to link your GitHub account for sign-in, GitHub provides your account identifier to us.
We do not sell, trade, or share your personal information with any other third parties.
6. Data Storage and Security
Your data is stored in Cloudflare D1 (a SQLite-based database) and Cloudflare R2 (for uploaded images). All data is transmitted over encrypted HTTPS connections. We implement the following security measures:
- HTTPS enforced on all pages and API endpoints
- httpOnly, secure session cookies
- CAPTCHA protection on sign-in (Cloudflare Turnstile)
- Input validation on all data using Zod schemas
- Role-based access control for admin functions
- File upload validation (type and size restrictions)
7. Data Retention
- Account data - Retained until you request deletion or we terminate your account.
- Session data - Automatically expires. You can also manually revoke sessions from your account settings.
- Guest localStorage - Cleared from your device when you sign in (after syncing to your account).
- Product images - Retained in cloud storage even after being removed from the product catalogue (soft deletion).
- Authentication tokens - Expire automatically and are cleaned up periodically.
8. Your Rights
You have the right to:
- Access - Request a copy of the personal data we hold about you
- Rectification - Update or correct your account information (name, email, profile image) through your account settings
- Deletion - Request deletion of your account and associated data by contacting us
- Session management - View and revoke active sessions from your account settings
- Linked accounts - Link or unlink GitHub and other social providers from your account settings
9. Children's Privacy
Our website is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child, we will take steps to delete that information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
11. Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Stephan's Tyre Mart PVT Ltd
438/A/13 CITY TERRECE, VIHARA MW, WALIVITA KADUWELA, Sri Lanka
Email: stephanstyremart@outlook.com
Phone: +94 77 141 3777