Free shipping over $120 · 30-day returns
Printed to order in the US and the EU

Privacy Policy

We collect what an order needs and nothing beyond it. This page says exactly what that is, who else touches it, and how to have it removed.

Effective 2026-09-08 · Last updated 2026-09-08


1. Who is responsible

The data controller is Yair Sivan, trading as MERIDIAN, sole proprietor (osek patur) registered in Israel, at 15 Har Meron Street, Beit Shemesh 9958923, Israel. Questions, requests and complaints: privacy@meridianplate.com.

Israel holds a European Commission adequacy decision for personal data transfers, so data reaching us from the EU stays within a jurisdiction the EU recognises as offering equivalent protection.

2. What we collect

Only what an order needs to exist and arrive:

  • To fulfilName, delivery address, country, postal code, telephone (carriers ask for it)
  • To confirmEmail address — receipt, dispatch note, tracking
  • The orderItems, sizes, colours, prices, shipping cost, order reference, status
  • PaymentA processor transaction reference and the last four digits and brand of the card. Nothing more
  • If you subscribeYour email address, and only that
  • TechnicalServer logs: IP address, timestamp, page requested, user agent

We never receive your card number. The card fields on our checkout are iframes served by our payment processor, on their own domain. The number, expiry and security code go from your browser to them and never pass through, or rest on, meridianplate.com. We could not disclose a card number if we were asked to — we do not have one.

We do not run advertising trackers, analytics pixels, session recording, or profiling. There is no third-party marketing script on this site.

3. Why, and on what legal basis

  • ContractTaking payment, printing, shipping, handling returns — Art. 6(1)(b) GDPR
  • Legal dutyTax and accounting records — Art. 6(1)(c)
  • Legitimate interestKeeping the site up, preventing fraud and card testing — Art. 6(1)(f)
  • ConsentThe mailing list, and nothing else. Withdraw it at any time — Art. 6(1)(a)

4. Who else sees it

Four parties, each for one job, none of them permitted to use your data for their own purposes:

  • BlueSnap Inc.Payment processing. Receives the amount, the order reference and your billing details. PCI DSS Level 1
  • PrintifyProduction and dispatch. Receives your name, delivery address and the items — passed on to the printing partner and carrier that serve your region
  • CarriersWhoever carries the parcel, as selected for your address, receives the delivery details
  • CloudflareDNS, and the email routing that carries messages sent to our addresses

Web fonts are loaded from Google Fonts, which means Google's servers see your IP address when a page loads. That is the only third-party request a page makes.

We do not sell personal data, and we do not share it for cross-context behavioural advertising — under any definition, including the CCPA's.

5. Where it goes

Orders are stored on our server in Israel. Production data reaches printers in the United States or the European Union, chosen by proximity to your address. Where personal data moves from the EEA or the UK to a country without an adequacy decision, it moves under the European Commission's Standard Contractual Clauses.

6. How long we keep it

  • Order recordsSeven years — the retention Israeli tax law requires
  • Server logsThirty days
  • Mailing listUntil you unsubscribe
  • Abandoned basketsNever reach us — a basket lives in your own browser until you order

7. Your rights

Wherever you live, you may ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, or ask for it in a portable file. Under the GDPR you may also object to processing based on legitimate interest, and lodge a complaint with your national supervisory authority. Under the CCPA you may ask what we collected and have it deleted, and we will not treat you differently for asking.

Write to privacy@meridianplate.com. We answer within thirty days, usually within one business day. There is no charge and no form to fill in.

One limit worth stating plainly: we cannot delete an order record before its seven-year tax retention has run. We can delete everything else, and we will.

8. Cookies and local storage

This site sets no tracking cookies. There is no consent banner because there is nothing to consent to.

What we do use is your browser's own local storage, which never leaves your device and is never sent to us: your basket, your recently viewed items, and your saved sizes. Clearing your browser data clears them. Our payment processor sets cookies of its own inside its card iframes, for fraud prevention — those are strictly necessary to take a payment, and are governed by its own privacy notice.

9. Security

The site is served only over HTTPS, with HSTS. Card data is isolated in the processor's hosted fields, which is what keeps our own scope narrow. Order pages are reachable only with a per-order token, so an order number guessed or overheard is not enough to read an address. Access to the order database is limited to the operator named in section 1.

If we ever suffer a breach affecting your data, we will tell you and the relevant authority without undue delay.

10. Children

This shop is not intended for children under sixteen and we do not knowingly collect their data. If a child's data has reached us, write and it will be deleted.

11. Changes

If this policy changes materially we will update the date at the top of the page, and email anyone on the list where the change affects them.

12. Contact

privacy@meridianplate.com for anything on this page. hello@meridianplate.com for everything else. Postal address and telephone are in the Terms of Sale.