Privacy Policy
Last updated: July 2026
This page explains how Casopra collects, uses, shares, and protects customer information when visitors browse the store or place an order.
1. Introduction and Scope
Casopra operates this store, website and related information, content, features, tools, products and services (collectively, the “Services”) in order to provide customers and visitors with a curated shopping, editorial and visual-culture experience. The Services are powered in part by Shopify.
This Privacy Policy explains how Casopra collects, uses, discloses, stores, retains and protects personal information when you visit or use the Services, make or attempt to make a purchase, communicate with Casopra, subscribe to communications, interact with Casopra content, or otherwise engage with Casopra.
This Privacy Policy also describes Casopra’s use of official third-party platform integrations and Casopra Automator, an internal first-party publishing tool used only with accounts, pages, sites, blogs, profiles, boards, galleries, collections, channels or organizations owned or controlled by Casopra.
If there is a conflict between Casopra’s Terms of Service and this Privacy Policy with respect to the collection, use or disclosure of personal information, this Privacy Policy will control.
2. Personal Information We Collect or Process
“Personal information” means information that identifies an individual or can reasonably be linked to an individual, whether alone or in combination with other information. Personal information does not include information that has been lawfully anonymized or de-identified so that it cannot reasonably identify an individual.
Depending on how you interact with the Services, Casopra may collect or process the following categories of personal information:
- Contact and identity information, such as your name, email address, telephone number, billing address, shipping address and other contact details you provide.
- Account information, such as login-related account details, saved preferences, wishlist activity and information associated with an account you create through the Services.
- Order and transaction information, such as products viewed or purchased, order history, cart activity, returns, exchanges, refunds, fulfillment information and transaction-related records.
- Payment-related information. Payments are generally processed by Shopify and payment service providers. Casopra may receive transaction status, billing information and limited payment-related details, but does not ordinarily receive complete payment-card numbers.
- Communications, such as messages, customer-service inquiries, reviews, feedback, survey responses and other information you provide when communicating with Casopra.
- Device, browser and usage information, such as IP address, browser type, device type, operating system, language, time zone, referring pages, pages viewed, links selected, session information, approximate location derived from an IP address, and information about how you use the Services.
- Marketing and preference information, such as communication preferences, email subscription status, interests inferred from interactions with the Services and responses to marketing communications.
- Fraud-prevention, security and technical information, such as authentication events, risk indicators, diagnostic records, system logs and information used to protect the Services, users and transactions.
- Platform-integration information associated with accounts owned or controlled by Casopra. Depending on the platform and the permissions granted, this may include platform account, profile, page, blog, site, channel, board, gallery, collection or organization identifiers; display names and handles; granted permissions and authorization scopes; OAuth access tokens and refresh tokens where issued; service or instance URLs; post, Pin, article, video, media, record, deviation, status or upload identifiers; publishing status; timestamps; destination URLs; tags and categories; limited content-performance information; and technical or error information required to operate and troubleshoot the integration.
Platform-integration information generally relates to Casopra’s own authorized publishing or business accounts rather than customer social-media accounts.
3. Sources of Personal Information
Casopra may collect personal information:
- directly from you when you place an order, create an account, complete a form, subscribe, contact Casopra, submit content or otherwise provide information;
- automatically from your device or browser through the Services, cookies and similar technologies;
- from Shopify and related commerce, payment, fraud-prevention, fulfillment, shipping and customer-support providers;
- from analytics, advertising, marketing, email, hosting, security and technology providers;
- from publicly available sources where permitted by law; and
- directly from a third-party platform when Casopra authorizes an official API, OAuth or comparable integration. The information received depends on the platform, the permissions granted and the functions enabled.
4. How We Use Personal Information
Casopra may use personal information to:
- provide, operate, maintain, tailor and improve the Services;
- process payments, complete transactions, fulfill orders, arrange shipping, facilitate returns and exchanges and provide order-related communications;
- create and manage customer accounts, remember preferences and provide requested features;
- communicate with you, respond to inquiries, provide customer support and send administrative, transactional or legal notices;
- personalize content, product recommendations and the shopping experience;
- conduct analytics, measure performance, understand usage and improve products, content, technology and operations;
- send marketing communications and measure marketing or advertising performance, subject to applicable law and available choices;
- detect, investigate and prevent fraud, misuse, security incidents and other harmful or unlawful activity;
- protect the rights, property, safety and security of Casopra, users, service providers and others;
- comply with legal, tax, accounting, regulatory and contractual obligations, respond to lawful requests and enforce Casopra’s terms and policies;
- support operational, administrative, audit, recordkeeping, insurance, dispute-resolution and business-continuity purposes; and
- operate authorized platform integrations, including authenticating and maintaining a connection; identifying the relevant Casopra account, page, site, blog, board, channel, profile, gallery or organization; preparing, reviewing, uploading, publishing, scheduling, updating, verifying or deleting Casopra content where enabled; retrieving publication status or limited performance information; maintaining audit and operational records; troubleshooting technical errors; rotating or revoking credentials; and complying with platform rules and legal obligations.
5. Legal Bases for Processing, Where Applicable
Where a law requires Casopra to identify a legal basis for processing personal information, Casopra may rely on one or more of the following, as appropriate:
- performance of a contract or steps taken at your request before entering into a contract, including processing and fulfilling an order;
- consent, including consent to receive certain marketing communications or to enable optional technologies where required;
- compliance with legal obligations;
- Casopra’s legitimate interests or the legitimate interests of another party, such as operating and improving the Services, protecting security, preventing fraud, communicating with customers, maintaining records and conducting appropriate marketing, provided those interests are not overridden by applicable privacy rights; and
- other grounds permitted by applicable law.
Where processing is based on consent, you may withdraw consent subject to applicable legal and contractual restrictions. Withdrawal does not affect processing that occurred lawfully before withdrawal.
6. Marketing and Advertising
Casopra may use personal information for marketing and promotional purposes, including sending emails, presenting or measuring online advertising and communicating about products, services, content or events that may be relevant to you.
You may unsubscribe from promotional emails by using the unsubscribe link in the message or by contacting Casopra. Even if you opt out of promotional communications, Casopra may continue to send non-promotional messages relating to orders, accounts, customer service, security or legal matters.
Casopra’s editorial, cultural, educational and visual content may naturally refer or link to Casopra products, collections or resources. Such content may support brand awareness and organic discovery even where it does not contain a direct purchase request.
7. How We Disclose Personal Information
Casopra may disclose personal information to:
- Shopify and related commerce infrastructure providers;
- payment processors, fraud-prevention providers, fulfillment partners, printers, manufacturers, shipping carriers and return-management providers;
- hosting, cloud-storage, database, security, communications, email, analytics, advertising, marketing, customer-support and other technology providers;
- professional advisors, including legal, accounting, audit, insurance and financial advisors;
- government authorities, regulators, courts, law-enforcement agencies or other parties where disclosure is required or permitted by law;
- a buyer, investor, lender, successor or other relevant party in connection with an actual or proposed merger, acquisition, financing, reorganization, insolvency, bankruptcy, sale of assets or similar business transaction;
- other members of Casopra’s corporate group, if any; and
- other parties when you direct Casopra to disclose information or provide consent.
When Casopra activates a platform integration, limited information and content may be transmitted to the relevant platform to perform the authorized action, such as authenticating an account, uploading media, creating or updating a publication, retrieving an identifier, or verifying publication status. Service providers supporting Casopra Automator receive only the information reasonably necessary to provide their services.
Casopra does not sell platform API data.
8. Relationship with Shopify
The Services are hosted in part by Shopify. Shopify collects and processes personal information about access to and use of the Services in order to provide, protect and improve its services and Casopra’s store. Information submitted through the Services may be transmitted to Shopify and to providers that may operate outside your province, territory or country.
Shopify may process certain personal information as a service provider to Casopra and may process other information for its own purposes as described in Shopify’s privacy notices. Your use of Shopify-powered features may also be subject to Shopify’s applicable terms and policies.
9. Cookies and Similar Technologies
Casopra and its providers may use cookies, pixels, web beacons, tags, local storage and similar technologies to operate the Services, maintain security, remember preferences, enable cart and account functions, analyze performance, measure marketing, personalize experiences, prevent fraud and provide advertising.
Where required, Casopra will request consent before enabling optional cookies or similar technologies. Available cookie choices may depend on your location, browser, device and the tools implemented on the Services.
You may be able to block, restrict or delete cookies through browser or device settings. Certain features may not function correctly if required cookies are disabled.
10. Third-Party Websites, Platforms and Links
The Services and Casopra content may contain links to websites, applications or online platforms operated by third parties. Information you provide directly to a third party is governed by that party’s privacy and security practices. Casopra is not responsible for the privacy, security, accuracy, availability or practices of third-party sites or services.
11. Platform Integrations and Casopra Automator
This section explains how Casopra Automator connects to authorized third-party platforms, the limited information used to operate those connections, and the safeguards and choices that apply to platform-related information.
11.1 General Operation and Scope
Casopra may use internal tools and official third-party platform integrations to support Casopra’s own visual, editorial, educational, cultural, analytics and publishing workflows.
Casopra Automator is an internal first-party publishing tool used by Casopra to review, prepare, upload, publish, schedule, update, verify and track Casopra’s own original content through accounts, pages, sites, blogs, profiles, boards, galleries, collections, channels or organizations owned or controlled by Casopra.
Casopra Automator is not offered as a public software-as-a-service product to third-party customers and is not intended to manage unrelated third-party accounts. Where authorization is required, the relevant account is connected through the platform’s official OAuth, application-password or comparable authorization process.
Casopra requests only the permissions reasonably necessary for the enabled workflow. Permissions may vary by platform and may be reduced, expanded or revoked as the workflow changes.
11.2 Authentication, Authorization and Credentials
Sign-in and authorization are handled by the relevant platform. Casopra Automator does not request or collect the ordinary password used to sign in to a connected third-party platform and does not intentionally collect or store third-party session cookies.
Where a platform issues a client secret, application password, access token, refresh token or comparable credential, Casopra may retain the credential for as long as reasonably necessary to operate the authorized integration. Credentials are treated as confidential operational information, are not intentionally disclosed publicly and are restricted to systems and persons reasonably necessary to operate or maintain the integration.
Casopra may store token-expiration information, granted scopes and other authorization metadata to determine when credentials must be refreshed, verify that requested permissions were granted, prevent failed publication attempts and maintain an audit trail.
11.3 Content and Operational Metadata
Depending on the platform, Casopra Automator may transmit Casopra-created text, images, videos, titles, descriptions, tags, categories, alt text, links and publication settings to the platform.
Casopra may store limited operational metadata returned by the platform, including account or site identifiers, content identifiers, upload identifiers, record URIs, content hashes or CIDs, publication URLs, status, visibility, processing state, timestamps, error messages and limited performance information.
This information is used only to operate, secure, audit, verify and troubleshoot Casopra’s own publishing workflows, avoid accidental duplicate publication, associate a local content record with the corresponding platform publication and perform authorized updates or deletion where enabled.
11.4 Pinterest
When Casopra Automator connects to Pinterest, it uses Pinterest OAuth and the official Pinterest API. Casopra does not collect Pinterest passwords, session cookies or ordinary Pinterest login credentials.
Casopra Automator may access limited information about the authorized Casopra Pinterest business account and its boards and may create, review, publish, update or verify Casopra’s own original Pins where permitted.
Casopra may store limited operational metadata such as the authorized Pinterest account identifier, board IDs, Pin IDs, destination URLs, title and description fields, publication status, timestamps, returned scopes and technical error information. This information is used for publishing workflow management, audit, duplicate prevention and troubleshooting.
Casopra does not sell Pinterest API data, scrape Pinterest, manipulate engagement or use Casopra Automator to manage unrelated third-party Pinterest accounts.
11.5 Tumblr
When Casopra Automator connects to Tumblr, it uses Tumblr OAuth and the official Tumblr API. Casopra does not collect Tumblr passwords, session cookies or ordinary Tumblr login credentials.
Casopra Automator may access limited information about Casopra’s authorized Tumblr blog and may prepare, review, create, update, publish, reblog where expressly authorized, or track Casopra’s own original visual and editorial posts.
Casopra may store limited operational metadata such as the authorized blog identifier, post IDs, tags, timestamps, publication URLs, publishing status and technical error information. This information is used for publishing workflow management, audit, duplicate prevention and troubleshooting.
Casopra does not sell Tumblr API data, scrape Tumblr, manipulate engagement or use Casopra Automator to manage unrelated third-party Tumblr blogs.
11.6 Meta Platforms: Instagram, Facebook and Threads
Casopra Automator may connect to Casopra-owned Instagram accounts, Facebook Pages and Threads profiles through Meta’s official authorization systems and APIs.
Depending on the enabled integration and permissions, Casopra may process limited information such as account, profile or Page identifiers; display names; granted permissions; media-container or upload identifiers; post, thread or media IDs; publication status; timestamps; destination URLs; and limited content-performance information.
This information is used to prepare, publish, verify, manage and evaluate Casopra’s own content. Casopra does not collect Meta account passwords or session cookies and does not use these integrations to manage unrelated third-party accounts.
11.7 YouTube and Google
Casopra Automator may use YouTube API Services and Google authorization systems to manage Casopra’s own YouTube channels and content.
When Casopra authorizes the YouTube integration, Casopra Automator may access limited information such as the authorized channel identifier and channel information, granted permissions, video IDs, titles and descriptions, upload and processing status, privacy settings, playlist identifiers, timestamps, destination URLs and technical error information necessary to upload, manage or verify Casopra’s videos.
Casopra does not request or store the ordinary password for a Google or YouTube account. Casopra uses authorized YouTube API data only to operate Casopra’s own publishing workflow and does not sell or use that data for unrelated profiling.
Use of YouTube-related functionality is also subject to the YouTube Terms of Service and Google’s Privacy Policy. Access granted to Casopra Automator may be revoked through the connected-app or security settings of the relevant Google Account. A request to delete authorized YouTube-related information held by Casopra may also be submitted using the contact information in this Privacy Policy.
11.8 LinkedIn
If and when enabled, Casopra Automator may connect to LinkedIn through LinkedIn’s official authorization systems and approved APIs.
Depending on the approved permissions, Casopra may process limited information relating to the authorized Casopra organization, Page or administrator, such as organization or Page identifiers, authorized account identifiers, granted permissions, post and media IDs, publication status, timestamps, destination URLs, limited engagement information and technical error records.
Casopra uses this information only to manage Casopra’s own LinkedIn presence and approved publishing workflows. Casopra does not collect LinkedIn passwords or session cookies and does not use the integration to manage unrelated third-party organizations or accounts.
11.9 DeviantArt
When Casopra Automator connects to DeviantArt, it uses DeviantArt’s official OAuth authorization process and API. Casopra does not collect DeviantArt passwords or session cookies.
Casopra Automator may process limited information associated with Casopra’s authorized DeviantArt account, including the username or account identifier, granted scopes, access and refresh tokens, token-expiration information, Sta.sh submission identifiers, deviation identifiers, gallery or folder identifiers, titles, descriptions, tags, publication status, publication URLs, timestamps and technical error information.
This information is used to upload, prepare, publish, verify, update or track Casopra’s own original artwork and editorial content, refresh authorized access and troubleshoot the integration. Casopra does not scrape DeviantArt, automate engagement manipulation, repost unauthorized third-party artwork or manage unrelated third-party DeviantArt accounts.
11.10 Bluesky
When Casopra Automator connects to Bluesky, it may use an app password and Bluesky’s official AT Protocol services to create an authenticated session for Casopra’s account. Casopra does not store the ordinary Bluesky account password.
Casopra Automator may process limited information such as Casopra’s handle, decentralized identifier (DID), personal data server or service URL, app password, session tokens, post record URIs, content identifiers or CIDs, media-blob references, publication URLs, timestamps and technical error information.
This information is used to publish, verify, update or delete Casopra’s own posts where enabled, prevent accidental duplicates and troubleshoot the integration. Casopra Automator is not configured to access Bluesky direct messages unless Casopra separately enables and authorizes that function and updates this Privacy Policy where required.
11.11 Mastodon and Federated Social Services
When Casopra Automator connects to Mastodon, it uses the official OAuth and API functions provided by the selected Mastodon instance.
Casopra Automator may process limited information such as the instance URL, account identifier, handle, client ID, client secret, access token, granted scopes, media IDs, status IDs, visibility or language settings, publication URLs, timestamps and technical error information.
This information is used to upload media and publish, verify, update or delete Casopra’s own statuses where enabled. Casopra Automator is not configured to read private messages, conversations, follower lists or unrelated account data unless Casopra separately enables and authorizes such functions and updates this Privacy Policy where required.
Because Mastodon is federated, a public post may be copied, cached, displayed or retained by other servers participating in the network. Removal from Casopra’s home instance may not immediately remove every federated copy, cache or quotation controlled by another server.
If Casopra later connects to another compatible federated service, such as Pixelfed, Misskey or Lemmy, Casopra will apply the same principles of account ownership, limited permissions, credential protection and operational-data minimization and will update this Privacy Policy if the integration materially changes Casopra’s processing practices.
11.12 WordPress.com
When Casopra Automator connects to WordPress.com, it uses WordPress.com OAuth2 and the official WordPress.com REST API.
Casopra Automator may process limited information associated with the authorized Casopra Journal site, including the WordPress.com client credentials, access token, authorized site or blog ID, site URL, granted scopes, post and page IDs, media IDs, tags, categories, publication status, scheduling information, timestamps, publication URLs and technical error information.
This information is used to create, upload, schedule, publish, update, verify or delete Casopra’s own original editorial and visual content on a Casopra-owned WordPress.com site, manage associated media and taxonomy, prevent accidental duplicates and troubleshoot the integration.
Casopra does not collect the ordinary WordPress.com password through Casopra Automator, does not scrape WordPress.com, does not manage unrelated third-party WordPress.com sites and does not access Reader subscriptions, private messages or unrelated account data unless Casopra separately enables and authorizes those functions and updates this Privacy Policy where required.
11.13 Conditional or Future Platform Integrations
Casopra may evaluate or later enable additional official integrations, including TikTok, Snapchat, Dailymotion, Vimeo, Flickr, Are.na, Reddit, Imgur, X or other publishing and social platforms.
An integration listed in this subsection is not necessarily active. If an integration is enabled, Casopra will use an account owned or controlled by Casopra, request only permissions reasonably necessary for the approved workflow, protect platform credentials, avoid collecting ordinary platform passwords or session cookies, and use limited platform information only to operate, secure, verify and troubleshoot Casopra’s own publishing workflow.
Casopra will update this Privacy Policy before or when a new integration materially changes the categories of personal information processed, the purposes of processing, the parties receiving information or the rights and choices available to individuals.
11.14 Revocation, Disconnection and Deletion of Platform Data
Authorization for a connected platform may generally be revoked through the connected-app, security, developer or permissions settings provided by that platform. Casopra may also revoke or rotate credentials from within the relevant platform or Casopra Automator.
Revocation stops future access through the revoked credential but may not automatically delete operational records already held by Casopra. A person authorized to act for the connected account may request deletion of platform-related information held by Casopra by contacting contact@casopra.com and identifying the relevant platform and account.
Casopra may take reasonable steps to verify the requester’s identity and authority. Subject to legal, fraud-prevention, security, audit, backup and dispute-resolution requirements, Casopra will delete, deactivate or de-identify relevant authorization credentials and platform-related operational records within a reasonable period after verifying a valid request.
Content already published to a third-party platform may remain subject to that platform’s own retention, backup, caching, federation, republication and deletion practices. Requests concerning information held directly by a third-party platform should be directed to that platform.
12. Children’s Data
The Services are not directed to children under the age of majority applicable in their jurisdiction. Casopra does not knowingly collect personal information from children in circumstances where parental or guardian consent is legally required. If you believe a child has provided personal information to Casopra contrary to applicable law, contact Casopra so that appropriate action may be taken.
13. Security, Confidentiality Incidents and Retention
No security measure is perfect or impenetrable. Casopra uses reasonable administrative, organizational, physical and technical safeguards designed to protect personal information under Casopra’s control against loss, theft and unauthorized access, use, disclosure, alteration or destruction.
Safeguards may include access controls, credential separation, restricted permissions, secure connections, logging, backups, software updates, token rotation and other measures appropriate to the sensitivity and context of the information.
Access tokens, refresh tokens, client secrets, app passwords and other platform authorization credentials are treated as confidential operational information. Access is restricted to systems and persons reasonably necessary to operate or maintain the relevant integration.
Casopra retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, completing transactions, maintaining business and tax records, preventing fraud, protecting security, resolving disputes, enforcing agreements and complying with legal obligations.
Casopra retains platform credentials and publishing metadata only for as long as reasonably necessary to maintain the integration, document publishing activity, prevent duplicate publication, troubleshoot errors, protect security, comply with platform requirements and satisfy legitimate legal, audit or operational obligations. When an integration is permanently disconnected, Casopra may delete or deactivate associated credentials and delete or de-identify related operational records, subject to applicable retention requirements and secure backup cycles.
If Casopra becomes aware of a confidentiality or security incident involving personal information, Casopra will assess the incident and provide notices or take other steps where required by applicable law.
14. Your Rights and Choices
Depending on where you live, you may have rights to:
- request access to personal information held about you;
- request correction of inaccurate or incomplete personal information;
- request deletion or de-indexing in circumstances provided by law;
- obtain information about the categories of personal information collected, the purposes of processing, the categories of persons with access and applicable retention periods;
- withdraw consent, subject to legal or contractual restrictions;
- object to or restrict certain processing;
- receive a copy of certain information in a structured or portable format where required;
- opt out of certain marketing communications or forms of targeted advertising; and
- make a complaint to Casopra or an applicable privacy regulator.
To exercise an available right, contact Casopra using the information in Section 17. Casopra may request information reasonably necessary to verify your identity, authority and the scope of your request. Casopra will not discriminate against you for exercising a privacy right.
If you are authorized to act for a platform account connected to Casopra Automator, you may request information about platform-related data held by Casopra or request its correction or deletion. You may also revoke future platform access using the connected-app, security or permissions settings provided by the relevant platform. Revocation does not necessarily delete records already retained by Casopra, so a separate deletion request may be required.
15. International and Interprovincial Transfers
Casopra, Shopify and Casopra’s service providers may transfer, store or process personal information outside your province, territory or country, including in Canada, the United States and other jurisdictions where service providers or platform operators maintain systems or personnel.
Privacy and data-protection laws in those jurisdictions may differ from the laws where you live. Personal information may be accessible to courts, law-enforcement agencies or other authorities in those jurisdictions in accordance with applicable law. Casopra takes reasonable steps appropriate to the circumstances before using service providers or transferring personal information.
16. Changes to This Privacy Policy
Casopra may update this Privacy Policy from time to time to reflect changes to practices, technology, platform integrations, legal requirements or business operations.
Casopra will post the revised Privacy Policy on the Services, update the “Last updated” date and provide additional notice where required by applicable law. Material changes to platform integrations will be reflected when they materially change the categories of information processed, the purposes of processing, disclosures or available rights and choices.
17. Privacy Officer and Contact
Casopra has designated a person responsible for the protection of personal information.
Title: Privacy Officer, Casopra
Email: contact@casopra.com
Questions, requests, complaints or comments concerning this Privacy Policy, Casopra’s privacy practices or Casopra Automator may be sent to contact@casopra.com.
When contacting Casopra about a privacy request, please provide enough information to identify the relevant interaction, order, account or platform integration without sending passwords, complete payment-card information, access tokens, refresh tokens, client secrets or other confidential credentials.