Privacy

Privacy & data retention.

This notice explains what the PW Customs order workspace stores, who can see it, why it is used, and what happens when an account or store is deleted.

Effective August 17, 2026 · Deletion policy version PW_CUSTOMS_ACCOUNT_DELETION_V2 · Policy digest ecc09241ab9f5f910fa26346d350da35f5a0350798827277d3abf92e919ebdf8

Who this notice covers

Virani investments LLC operates the PW Customs private workspace used by customer stores, PW Customs staff, and assigned factory teams to coordinate custom orders. This notice covers information handled through the website, mobile application, and supporting account, messaging, file, production, and shipping services.

Business location: 6E-333B, 75 John Portman Blvd NW, Atlanta, GA 30303, United States.

What the service stores

  • Account and security data: name, email address, phone number when supplied, password hash, roles, store or factory membership, verification status, sign-in and activity times, failed-sign-in and lockout information, MFA configuration, sessions, approved-device records, and device installation identifiers.
  • Business profiles: customer-store and factory records, including contact person, phone number, and postal address when provided.
  • Orders and fulfilment: order identifiers and names, jewellery specifications, sizes, materials, stones, requested dates, status and approval history, notes, cancellation and clarification records, production assignments, shipping address, carrier, tracking details, and delivery timestamps.
  • Messages and collaboration: message text, replies and quoted-message snapshots, reactions, moderation and release records, read and participation state, attachments, captions, voice-note duration, and the time and account associated with an action.
  • Files and voluntary chat content: reference images, videos, audio, documents, CAD and production files, original filename, file type and size, uploader, order, and private storage key. A user can also choose to share precise location coordinates, a written address, or contact-card name, phone, and email in a chat.
  • Operations and security: audit events, actor and entity identifiers, before-and-after values where recorded, IP address, browser or device user agent, notification and email-delivery state, token hashes, rate-limit and idempotency records, and provider-delivery errors.
  • Optional communications: if transactional SMS consent is offered and chosen, the phone number, opt-in or opt-out state, time, source, disclosure version, and a hashed destination fingerprint used as consent evidence. Push-token records are created only when push delivery is enabled and registered on a device.

Why the information is used

The service uses this information to create and secure accounts; enforce role, store, factory, and approved-device access; receive order briefs; coordinate CAD review, approvals, production, quality checks, and shipping; deliver files and messages; send requested account and order notices; provide support; investigate misuse; maintain auditability; and operate deletion and retention controls.

Who can see or receive the information

  • Your customer store: active members of the same store can access that store’s shared orders, threads, files, and business history. Store-private notes are visible only to members of that store.
  • PW Customs staff: authorized administrators and operations staff can access account, order, message, file, production, and shipping information needed to run the workflow and support the service.
  • Assigned factories: an assigned production team can access the order specifications, files, CAD, production conversation, and workflow information needed for its work. A factory account receives the real customer name, phone number, or delivery address only when its role has the shipping-read permission; otherwise the customer or store identity is masked from that view.
  • Infrastructure: Amazon Web Services hosts the service’s core network and computing infrastructure. Customer files are kept in private object storage and delivered through authenticated or expiring access rather than a public bucket.
  • Required disclosures: information may be preserved or disclosed where Virani investments LLC is legally required to do so or where needed to investigate abuse and protect the service, its users, or others.

When transactional account email is enabled, Amazon Simple Email Service receives the destination address, message content, and delivery outcome needed to send a requested verification, reset, deletion message, or an eligible customer order milestone. Messages a person chooses to send to the public support, privacy, or security address are processed by the operator’s domain-mailbox provider. An SMS or push provider receives the minimum delivery data for that channel only when the channel is enabled and the user is eligible.

What deletion actually does

Deletion permanently disables the account’s sign-in and removes its profile and contact details, credentials, sessions, device tokens, and account-specific settings. Shared business records are handled differently according to account role and whether another member still operates the store or factory.

Customer in an active store

The deleted account’s uploaded attachments are removed. Shared message text, order records, shipping addresses and tracking details can remain available to the active store and authorized workflow participants. The account profile is removed and retained sender attribution is shown as “Deleted user.” These shared active-store records receive no new deletion deadline solely because one member leaves.

Last customer in a store

The store closes. Its customer chat, order messages, uploaded order media, CAD and file records, shipping addresses, shipment-routing details, and store-private notes are removed. A reduced commercial order record can retain order identifiers, product specifications, commercial amounts, workflow and delivery timestamps, and PW Customs or factory operational notes. Those orders receive a retention deadline 2,555 days after store closure.

Factory team member

The person’s account, personal contact data, sessions, device tokens, role and permission settings are removed. The factory’s orders, files, CAD, production media, and messages are unaffected because they are shared factory and customer work records. Retained personal account attribution is replaced with “Deleted user.”

Factory owner

The owner must first remove remaining team members and clear in-flight orders. The factory contact name, phone number, and address are erased. Finished-order CAD, production media, messages, and the factory trading name can remain with the customer and PW Customs record and receive no new deadline solely because the factory account is deleted.

Other schedules

Security audit logs are scheduled for cleanup after 365 days and identifying fields are scrubbed when an account is deleted. Required SMS-consent evidence is scheduled for cleanup after 1,461 days. A deletion-status record is available for up to 30 days; an encrypted completion-email destination is kept for no more than 7 days while provider-file cleanup finishes. Physical file deletion is retried until the storage provider confirms completion.

A pseudonymous database row can remain while a retained shared record still requires it; that row uses “Deleted user,” a randomized invalid email address, and no active credentials or roles. This policy does not promise a maximum deletion deadline for backup copies.

Team administrators and account choices

A customer-store administrator can permanently erase another member of that same store. The member’s account-specific data is erased through the same deletion engine, while shared store records remain as described above. A factory owner can remove a member from the factory; removal closes access but is separate from that person’s self-service account deletion.

Eligible customer and factory users can delete their own account in the application. The external deletion page can send a confirmation link when production account-email delivery is operating. If that path is unavailable, the page says so without claiming a message was sent. You can also email support@pw-customs.com to request access, correction, or a copy of account information. Virani investments LLC may need to verify the requester and may retain shared or legally required records as explained in this notice.

How information is protected

Controls include role- and tenant-scoped access, password hashing, session and token revocation, MFA and approved-device controls for protected administration, private file access, request limits, audit logging, and encryption or hashing for selected secrets and delivery fields. No security control eliminates all risk; report a suspected account or data issue through the contact address below.

Questions about this notice

Material changes will be published on this page with a new effective date and, when deletion consequences change, a new deletion-policy version. For privacy, account, or security questions, contact support@pw-customs.com. Virani investments LLC operates the PW Customs service.

Live deletion schedule

Loading the current policy…