PRIVACY POLICY
Effective date: 9/4/2025
CONTROLLER
MPCUSA legal entity: Mana Vibe Tech KFT, Hungary.
Registered address: 1136 Budapest 13. ker., Hegedűs Gyula utca 29. A. ép. Ü-1. ajtó
Operations location: California, United States
Contact for privacy requests use our contact form
SCOPE
This policy covers mpcusa.com and related services. It applies to website visits, accounts, orders, design uploads, customer support, and payments processed by our providers.
DATA WE COLLECT
• Account and identity data: name, email, password, phone, billing and shipping details
• Order data: items, quantities, prices, tax, discounts, order notes, status, returns
• Payment data: processed by Stripe and paypal. We do not see or store full card number or CVC. We receive limited payment metadata such as last four digits, brand, expiry, payment method ID, and status
• Uploaded content: images, artwork, design files, and related metadata you submit
• Support data: messages, emails, tickets, attachments, preferences
• Device and usage data: IP address, browser and device, pages viewed, time on page, clicks, diagnostics
• Cookies and similar technologies: used for core functions, security, preferences, and analytics
WHY WE USE DATA AND LEGAL BASES
• Run the site and tools: legitimate interests. Consent for non essential cookies where required
• Take and fulfill orders: contract necessity
• Process payments via Stripe and prevent fraud: contract necessity and legitimate interests
• Ship products and provide support: contract necessity or legitimate interests
• Improve services and communicate service updates: legitimate interests
• Marketing communications: consent where required with opt out at any time
• Comply with law and tax: legal obligation
SHARING
We share data with service providers that follow our instructions and protect your data:
• Payments: Stripe (payment processing and webhooks)
• Hosting and cloud and CDN
• Shipping and logistics partners
• Customer support and email providers
• Analytics and performance tools (consent based in the EEA and UK)
We may disclose data if required by law or to protect our rights. In a merger or asset transfer, data may be transferred to the new owner under this policy.
INTERNATIONAL TRANSFERS
We operate in the EU and the United States. When data is transferred outside your region we use lawful safeguards. For EEA and UK transfers we rely on Standard Contractual Clauses or other valid mechanisms.
RETENTION
• Orders and invoices: 7 years for tax and accounting
• Support records: 24 months after ticket closure unless needed for disputes
• Payment confirmation data and fraud logs: up to 18 months after the chargeback window ends
• Uploaded design files: kept through production and for 60 days for reprint purposes. You can request deletion
• Analytics data: 12 to 26 months depending on tool settings
SECURITY
We use TLS in transit, access controls, least privilege, network monitoring, and periodic reviews of processors. No method is perfectly secure. We continually improve safeguards.
YOUR RIGHTS
• EEA and UK: access, rectification, erasure, restriction, portability, and objection. You can withdraw consent
• Other regions: rights available under local law
To exercise rights, contact us. We will verify and respond within required timelines. Authorized agents may submit requests subject to verification.
COOKIES
We use the following categories:
• Strictly necessary: login, cart, checkout, security
• Performance and analytics: site usage and diagnostics. Consent where required
• Functional: preferences such as language and region
• Advertising: used only if enabled. Disabled by default in the EEA and UK unless you opt in
Manage cookies in your browser or in Cookies Settings. Blocking cookies may affect features.
USER CONTENT AND IP
You may only upload content you own or are authorized to use. We do not print infringing, counterfeit, or unauthorized designs. Orders that violate this rule will be cancelled. See our DMCA page for notice instructions and our repeat infringer policy.
PAYMENTS AND STRIPE
Payments are processed by Stripe. Card details are entered through Stripe secure fields. We never see or store full card numbers or CVC. Stripe sends us payment confirmations and limited metadata. We receive events from Stripe via webhooks to fulfill orders, prevent fraud, and manage refunds.
CHANGES
We will update this policy when needed. The updated version will show a new effective date. We will notify you of material changes by site notice or email.
CONTACT
Contact form