Mesh & Moss / Legal
Privacy policy
This policy explains how we handle personal data when you browse the shop, buy an asset, or access your library.
1. Who is responsible
Trivomesh Limited, whose UK incorporation is pending, is the intended operator and data controller for Mesh & Moss after incorporation. This draft describes the intended shop's handling of personal data under applicable UK data protection law and, where applicable, the EU GDPR. It covers the website, checkout, customer library, and related communications.
Controller details pending confirmation: registered office address, company registration number, support/privacy email, and any required EU representative. These contact details must be completed before this policy is used for live sales.
2. Data we collect
- Purchase information: your email address, billing information requested at checkout, country, cart contents, purchased assets, prices, tax amounts, order references, and payment status.
- Account and access information: your customer identifier, email verification records, sign-in and session records, password hash if you choose password access, and library and download access records.
- Transaction evidence: the license and terms associated with an order, immediate-delivery consent, timestamps, and location evidence used to determine VAT, such as declared billing country, IP-derived country, and payment-country information where available.
- Technical information: IP address, browser and device information, request times, security events, and error information generated when our systems receive your requests.
- Communications: information you send when asking for help, together with transactional email delivery information.
We receive data from you, from your interaction with the shop, and from payment and delivery providers involved in your order. Payment credentials are handled by the payment provider; our shop does not ask you to send card details by email or store full card numbers or card security codes.
3. Why we use it
- To perform our contract with you: manage your cart, process orders, deliver files and confirmations, provide account and library access, and respond to purchase-related support requests.
- To meet legal obligations: keep accounting and tax records, determine applicable VAT, handle statutory remedies, and respond to legally binding requests.
- For legitimate interests: protect the shop and our customers against fraud and misuse, diagnose failures, maintain reliable service, and establish or defend legal claims. We must balance these interests against your rights and expectations.
- With consent, where required: any optional marketing or non-essential tracking introduced in the future would require its own information and, where applicable, a separate choice. Buying an asset is not consent to receive marketing.
Without the information needed to process payment, meet tax requirements, or verify access, we may be unable to complete a purchase or provide your library. Setting a password is optional; email sign-in remains available.
4. Cookies and external fonts
The current storefront uses cookies for cart continuity, sign-in, checkout security, and access to a recent order. It does not include advertising pixels or optional analytics integrations.
- Cart cookie: remembers your cart for up to 30 days.
- Security cookie: helps protect form and checkout requests against forgery; expires after up to 24 hours and may be renewed.
- Recent-order cookie: allows access to the recent checkout confirmation for up to 24 hours.
- Session cookies: keep you authenticated while your session is valid. Signing out ends the associated authenticated access.
You can remove or block cookies in your browser. Doing so may prevent checkout, sign-in, or library access from working correctly. Cookie expiry is separate from how long we retain an order or other server records.
This site currently loads fonts from Google Fonts. Your browser sends Google your IP address and request information, including browser headers and potentially the referring site, when retrieving those fonts. This is an external request even though the storefront has no analytics pixels. See Google's font privacy information. The legal basis and transfer arrangements for this integration remain part of the pre-launch privacy review.
5. Who receives data
Access is limited to people and service providers who need the information for their role. Recipients may include hosting and storage providers, network and security providers, transactional email providers, payment providers, professional advisers, and authorities where disclosure is legally required. We do not sell personal data.
Payment providers may act as independent controllers for payment processing, fraud prevention, and their own legal duties. Their notices apply to those activities. Our processors must handle data under our instructions and appropriate contractual protections.
Some providers may process data outside the UK or the European Economic Area. Where this constitutes a restricted transfer, an applicable adequacy decision or other lawful safeguard is required. Depending on the transfer, this may include EU standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, and additional measures where necessary. You may request information about the applicable safeguards and a copy of them. The final provider list, processing locations, and transfer mechanisms must be confirmed before launch.
6. How long data is kept
We retain data according to its purpose and applicable legal requirements. Order, license, and library records are needed to administer your purchase and continued access. Accounting and tax records are kept for the relevant statutory period; where EU VAT One Stop Shop rules apply, the associated records must generally be retained for ten years from the end of the transaction year.
Security and support records are kept for the time needed to investigate issues, resolve requests, and handle any resulting legal claims. Data subject to a specific dispute or legal retention requirement may need to be kept longer, with access limited to that purpose. Backup copies follow the applicable backup rotation schedule.
The final operational retention periods for support records, security logs, download history, and backups are pending confirmation. This draft does not promise an unimplemented automatic deletion schedule. Deleting an account does not necessarily erase records we are legally required to keep.
7. Your rights and choices
Subject to the conditions in data protection law, you can request access to your personal data, correction of inaccurate data, erasure, restriction of processing, and a portable copy of data you provided. You may object to processing based on legitimate interests. If we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.
Send requests to our privacy contact. We may need proportionate evidence to verify your identity before disclosing or changing account information. We normally respond within one month; if a lawful extension is necessary, we will explain why within that first month.
You can complain to the UK Information Commissioner's Office or, where EU data protection law applies, your local EU supervisory authority. You do not have to contact us before doing so.
8. Automated checks and security
Our systems check payment status, access permissions, and consistency of checkout location information. A failed check may prevent payment or delay download access. If you believe a check is wrong, contact support to request a human review. Payment providers may perform their own checks under their own privacy notices.
We use access controls, protected sign-in and download links, and other technical and organisational measures appropriate to the data. No system can promise absolute security. Please keep access links private and tell us if you suspect unauthorised use of your account.
9. Changes to this policy
We may update this notice when the shop, its providers, or legal requirements change. The date above identifies the latest revision. We will provide additional notice of material changes where required and obtain fresh consent if a new use of data requires it.