Current policy · Pre-launch store
Privacy notice
Last updated: August 15, 2026
Information we process
When you contact us, submit a wholesale enquiry, or subscribe to the newsletter, we process the details you choose to provide. The server also processes limited technical request logs needed for security, troubleshooting, and operating the site.
Purpose and retention
We use form data to answer your enquiry and maintain necessary business records. Newsletter addresses become active only after email confirmation. We keep personal data only as long as needed for its purpose, legal obligations, or handling claims.
Private buyer conversations
You can start a private conversation without creating a customer account. We store the name you provide, your messages, and any relevant product or order context so the Larimar Miner owner can answer your enquiry and maintain necessary customer correspondence. An email address is optional for ordinary conversations and required for a trade enquiry. It is stored with the conversation; private return links and reply alerts are sent only if you explicitly request them.
For a trade enquiry, we also store the business or trading name, operating country, business presence details, sales or working channels, product interests, and sourcing stage you provide. Authorized owner administrators see these details as buyer-provided context to assess and answer the trade enquiry; they are not treated as independently verified identity information and are not used to create a marketing subscription.
Access in your browser is protected by a private, secure access token. If you provide an email address and request reply notifications, we send a time-limited, one-use access link and notices that a reply is waiting. Message content is not included in those emails. These notices are only for the conversation and do not subscribe you to marketing.
You can attach up to five photographs to a message. Before private storage, each is re-encoded to remove embedded metadata such as EXIF and GPS location data. Photographs are accessible only inside the protected conversation to you and authorized owner administrators, and are not included in notification emails.
Conversations are accessible only to you through your private access credentials and to authorized owner administrators in Larimar Studio. We retain them only as long as needed to handle the enquiry, maintain necessary business records, protect the service, meet legal obligations, or handle claims.
AI-assisted translation and reply drafts
When an authorized owner administrator chooses to use the language assistant in Larimar Studio, we send only the content needed for that task to OpenAI’s API: depending on the task, this may include the selected buyer message, the administrator’s English guidance, and a limited excerpt of buyer-visible conversation and product context. We do not add separate participant-name or email-address fields, owner-only notes, trade-profile details, photographs, private access tokens, or network and security records to the assistant context. Larimar sends each request with store=false, so OpenAI does not retain a reusable Responses object. Under OpenAI’s default API data controls, prompt-caching application state may be retained for up to 24 hours and abuse-monitoring logs may retain submitted content and output for up to 30 days. Any stricter project-specific retention control must be verified before this feature is enabled.
Assistant output is a private preview for the administrator. It cannot send a message, make a decision, or commit Larimar Miner to an offer or course of action. The administrator must review it, choose whether to place it in the ordinary reply box, and then explicitly send the reply through the normal conversation workflow.
Successful translations of incoming messages are encrypted and retained with the conversation under the same retention rules. Unsent reply drafts and reply translations, their encrypted working inputs, and failed assistant requests expire automatically no later than 24 hours after creation.
Network and security observations
When you send a message, we record its originating IP address in a restricted security record. We may use a local geolocation database to derive an approximate country, region or city, and network or ASN information. When an external abuse check is configured, we may submit the IP address to a selected security provider and record advisory reported-abuse signals. This is used only to protect against spam, fraud, and abuse—not for marketing.
IP geolocation is approximate, and shared networks or VPNs can produce misleading results. Authorized owner administrators review these signals. They do not make an automated decision: a message is never automatically rejected or hidden because of them. The exact IP address and these security observations are never shown on buyer-facing or public pages.
Identifiable network-security observations are assigned an expiry of no more than 90 days. An automated process redacts expired values, including the exact IP address, a pseudonymous correlation code derived from it, all derived location data including country, network and ASN identity, and security-provider details. An audit marker recording that and when a security observation was made and redacted may remain linked to the conversation.
Sharing and your choices
Data may be shared with selected hosting, email, or other service providers where needed to provide the relevant service. We do not sell mailing lists. You can unsubscribe through every newsletter email and can request access, correction, or deletion where applicable.
Contact
For privacy requests, contact sales@larimarminer.com. The data controller and seller of record is Mercury Project s.r.o., Radlická 112/22, 150 00 Praha 5, Czech Republic, company registration number 25087410, VAT identification number CZ25087410.