🇪🇺We've temporarily suspended shipping to EU countries due to new EU packaging regulations.Learn more
🇺🇸Good news! We've re-instated shipping to the USA on a trial basis.Learn more
Last updated: 19 July 2026
This Privacy Policy explains how Ómra Creative (“we”, “us”, “our”) collects, uses, shares and protects your personal information. It applies to our website omracreative.ie and to our Ómra Creative mobile apps for iOS and Android (together, the “Services”).
We are the data controller for the personal information described here.
If you have any question about this policy or your data, email us at the address above.
We are an Irish small business selling stickers, prints and related personalised products. This policy covers everything you do with us – browsing and buying on our website, using our mobile apps, contacting our support team, and receiving communications from us. Where a section applies only to the apps or only to the website, we say so.
When you create an account or place an order: your name, email address, password (stored only in encrypted/”hashed” form – we never see it), and phone number. If you choose “Email me a sign-in link” instead of a password, we email a one-time link to your address; the link is stored only in a protected, hashed form, works once and expires after 15 minutes.
Your billing and delivery address, the items you order, your order and returns history, and any personalisation you enter (for example a name or text for an engraved or custom product). This information is needed to process and deliver your order.
Card payments (including Apple Pay and Google Pay) are processed securely by WooPayments, which is powered by Stripe. Your full card number is entered on Stripe’s secure payment page and is handled by Stripe – we do not receive or store your full card details. We receive confirmation of payment and limited details such as the card type and last four digits. If you use gift credit / store credit, your balance, top-ups, gifts and redemption history are held within our own store systems. When you send gift credit to someone, we collect the recipient name and email address you provide so we can deliver and protect the gift (it can only be claimed with that email address); if someone sends you credit, we receive your name and email from them for the same reason.
When you message our support team (in the app or on the site), we collect the content of your messages and any photos you choose to attach from your device’s photo library (for example a picture of a product or a design reference). We store these so we can answer your query and keep a record of the conversation. If you create a custom sticker or personalised product, we store the image you upload and the design you compose so we can print your order, show the design on your order page, and handle any reprint or support query. The apps only access photos you specifically select – we do not access your wider photo library, and the apps do not use your camera.
Like most online services, we automatically receive some technical information: your IP address, device type, operating system, app version, and general (city/country-level) location inferred from your IP. At checkout we use Cloudflare Turnstile to tell humans from bots, which processes limited device and interaction signals to protect against fraud and abuse. When you’re signed in we also keep simple activity signals – when your account was last active and what’s in your shopping cart – so we can help with checkout problems and, occasionally, remind you about items left in your cart.
We also keep a record of what people search for in the shop: the words typed into the search box, on the website and in both apps. We use this to understand what customers are looking for and to decide what to stock or make next. For each search we record the words, the date and time, whether it came from the website or an app, and how many products it matched. If you are signed in, the search is recorded against your account. If you are not signed in, it is recorded with no identifier at all. We never store your IP address alongside a search, and we do not use searches to build a profile of you or to advertise to you.
Some information is kept only on your own device and is not sent to us: your recent searches list (the shortcuts the app offers you under the search box), cached images and content (for faster loading), your wishlist cache, and your login tokens (stored in the secure iOS Keychain / Android Keystore). You can clear recent searches at any time in the app’s Settings, and clearing them or uninstalling the app removes this local data. The search words themselves are recorded separately on our own systems, as described in section 3(e), and clearing your local list does not remove that record.
If you choose to subscribe to our newsletter, we store your email address (and your name, if you give one), together with the date and IP address of your sign-up as a record of your consent. Subscription is double opt-in: nothing is sent until you click the confirmation link we email you, and unconfirmed sign-ups are deleted automatically after 30 days. Every newsletter includes a one-click unsubscribe link, and unsubscribing removes you from the list immediately. We count how often the links in a newsletter are clicked, but only in aggregate – the counts are anonymous and we do not track which individual subscribers opened or clicked anything. Your notification and marketing preferences are also stored so we only contact you the way you’ve asked.
Our website uses a small number of essential cookies needed to run the shop – for example to remember your shopping cart and session (WooCommerce), to process payments (Stripe), and for security and performance (Cloudflare). We do not currently run third-party advertising or analytics trackers such as Google Analytics, Meta/Facebook Pixel or similar. Because we list our products on Google so they appear in Google Search and Shopping, some Google services and tags may be present on the website and may set cookies; these are governed by Google’s own privacy policy. See section 14 for more on cookies and how to control them.
The apps do not use tracking cookies and do not include any third-party analytics or advertising software. We do not track you across other companies’ apps or websites.
If you take part in our free Ómra Rewards programme, we keep your points balance, level, achievements and the activity that earned them (for example orders and profile actions). You can optionally add your date of birth to receive a birthday reward – we use it only for that purpose, and to keep the reward fair it can be changed once a year (contact support if it ever needs correcting). Removing your date of birth from your profile deletes it.
A small number of products carry a content warning. If you turn on Show sensitive content, either in the app’s Settings or in your account details, we store that choice against your account, so the shop behaves the same way on every device you sign in on. If you leave the warning on and tap to reveal an individual product, we store that product against your account too, so you’re not asked about it again.
We use these only to show you the shop the way you’ve asked for it. They are not used for marketing, advertising or recommendations, they are never shared, and they are deleted when you delete your account.
The app lets you optionally lock your account behind Face ID or Touch ID. This uses Apple’s (or your Android device’s) built-in biometric system. Your biometric data never leaves your device and is never seen, collected or stored by us – the device simply tells the app “unlock” or “don’t”. You can turn this off in the app’s Settings.
If you allow notifications, we send updates about your orders and support messages using Apple Push Notification service (APNs) on iOS and Google Firebase Cloud Messaging (FCM) on Android. This involves a device notification token. Notifications about new products and special offers are sent only if you opt in to the “New products & special offers” preference in the app – it’s off by default. You can turn any category, or all notifications, off at any time in your device settings or in the app.
Under the GDPR we must have a lawful basis for using your information. We rely on:
We do not sell your personal information. We share it only with trusted providers who help us run the Services, and only as needed:
Each provider is only permitted to use your information to provide their service to us, under appropriate data-protection terms.
Our website and app backend are hosted in Ireland/the EU. Some of our providers (for example Stripe, Cloudflare, Apple and Google) are based in, or process data in, the United States. Where personal information is transferred outside the European Economic Area, it is protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
Under the GDPR you have the right to:
To exercise any of these, email [email protected]. We will respond within one month, and there is no charge for making a request (unless it is manifestly unfounded, excessive or repetitive, as allowed by law).
You can delete your account and associated personal data at any time:
When you delete your account we remove your personal information from our active systems, except for the limited order and transaction records we are legally required to retain for tax purposes (see section 9).
Please note that deleting your account cancels any remaining gift credit or store credit, which cannot be restored afterwards. Our account deletion page sets out the full detail of what is erased and what is kept.
Our Services are intended for general audiences and are not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will delete it.
We use appropriate technical and organisational measures to protect your information, including HTTPS/TLS encryption in transit, hashed (irreversible) password storage, secure storage of login tokens in the iOS Keychain / Android Keystore, Cloudflare security and bot protection, and access controls that limit who can see your data. No method of transmission over the internet is 100% secure, but we work to protect your information and continually review our safeguards.
Cookies are small files stored by your browser. Our website uses:
We do not currently use advertising or analytics cookies. You can control or block cookies through your browser settings; blocking strictly necessary cookies may stop parts of the shop from working. Our mobile apps do not use advertising or tracking cookies.
We may update this policy from time to time. When we do, we’ll change the “Last updated” date at the top, and for significant changes we’ll take reasonable steps to let you know.
If you have a concern about how we handle your personal information, please contact us first at [email protected] so we can help. You also have the right to lodge a complaint with the Irish supervisory authority:
Data Protection Commission (Ireland)
21 Fitzwilliam Square South, Dublin 2, D02 RD28
www.dataprotection.ie
Chat is for Ómra Creative account holders, so we can tie your questions to your orders. Sign in and we'll be right with you.
Sign in