Trust Center
Trust & Security at Krax Style
This page is maintained by Krax Ventures LLC to answer common security and privacy questions about Krax Style (www.kraxstyle.com). It describes practices and platform controls currently in place — it is editable content, not an independent certification or audit.
Shared responsibility
Krax Style runs on managed cloud infrastructure. The underlying hosting platform provides physical security, network protection, and patched runtimes. Krax Ventures LLC is responsible for application logic, access control, and the data we collect from customers. You are responsible for safeguarding your account credentials.
Authentication & account access
Customer accounts use email and password authentication with sessions managed by our authentication provider. Passwords are never stored in plaintext — they are hashed and salted by the auth provider. Administrative areas of the site are protected by server-side role checks; client-side flags are never trusted for authorization.
Guest checkout is supported. Guest order confirmation pages require a one-time access token delivered in the order link and are not browsable without it.
Data protection
Customer data is stored in a managed PostgreSQL database with row-level security policies that restrict each user to their own orders, addresses, and profile. Sensitive write operations run through authenticated server functions rather than direct client-to-database calls.
Data is transmitted over HTTPS/TLS. We collect the minimum information needed to fulfill orders: name, shipping address, email, phone, and order contents.
Payments
Payments are processed by Stripe. Card numbers, CVCs, and full payment instruments are entered directly into Stripe-hosted fields and never touch Krax Style servers. We retain only Stripe identifiers and non-sensitive metadata (amount, currency, status) needed to manage your order and issue refunds.
Subprocessors
We rely on the following categories of subprocessors to operate the store: a managed database and auth provider, Stripe for payments, an email delivery provider for transactional emails, and a cloud hosting provider for the web application. Each is used only for the purpose described.
Cookies & analytics
We use strictly necessary cookies for cart state and authenticated sessions. Any analytics or marketing cookies, if added, are described in our Cookie Policy.
Retention & deletion
Order records are retained as long as required to support returns, refunds, accounting, and applicable tax obligations. You can request deletion of your account and associated personal data by contacting us; we will retain only what is legally required.
Privacy requests
To request access to, correction of, or deletion of your personal data, contact us via the contact page. See our Privacy Policy for full details.
Reporting a security issue
If you believe you have found a security vulnerability affecting Krax Style, please report it responsibly through our contact page with the subject line "Security". Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.
Compliance
Krax Style does not currently hold independent security certifications (such as SOC 2 or ISO 27001). Where regulated payment data is involved, processing is delegated to Stripe, which maintains its own PCI DSS compliance. This page will be updated as our program evolves.
Last reviewed 7/27/2026.
