Overview
Grad School Alternative LLC, a California limited liability company based in Orange, California (“we,” “us,” “our”), operates the Apollo Lamps storefront at apollolamps.com. This Privacy Policy explains what personal information we collect when you visit the site, place an order, or choose to receive Apollo Lamps product news; how we use it; who we share it with; and the choices you have. We do not sell or share your personal information for cross-context behavioural advertising, and we do not use third-party analytics or tracking pixels.
Information we collect
Information you provide
When you place an order, you give us:
- Your email address
- Your full name and shipping address
- Payment details — handled entirely by our payment processors (Stripe or PayPal); we never see or store your full card number, expiry, or CVC
- The lamp design you created in the designer, or the exact Evolution specimen you captured (shape, time, and color). This describes a product, not you, and is not personal information.
If you contact us through the order-status page or by email, we keep your messages so we can respond and follow up.
After a purchase is confirmed, you may choose to join the Apollo Lamps mailing list by selecting the opt-in button on the thank-you page. If you do, we use the email address from that order and record when and through which order you opted in. Purchasing a lamp by itself does not add you to the mailing list.
In the categories defined by the California Consumer Privacy Act, what we collect falls into: identifiers (name, postal address, email address, IP address, order ID); commercial information (records of products purchased and amounts paid); and internet or electronic network activity (browser user-agent, timestamps of requests to our site). We do not collect personal information in any of the other CCPA categories.
Information collected automatically
- Your IP address and the country it resolves to (provided by our hosting provider, Cloudflare)
- Your browser’s user-agent string
- Timestamps of requests to the site
This information is used to keep an audit log of order events and to protect the site against abuse. It is not used to profile you or to track you across other websites.
The Evolution page also sends first-party aggregate event counts, such as page load, successful rendering, adding a captured lamp to the cart, reservation expiry, checkout start, and purchase. These records contain the event name and, where operationally useful, a coarse product or compatibility category. They do not contain a cookie identifier, account, retained IP address, session replay, or advertising identifier and are not used to change the evolving lamp.
Information stored in your browser
The store works without an account, so a few items are kept in your browser to make it function:
- Cart —
al_cart_v1keeps the designs, colors, quantities, and preview images in your cart. It remains in local storage until checkout clears the cart, you clear it, or you clear browser data. - Saved design —
lamp.designer.v1keeps the lamp you’re shaping so a reload or dropped connection does not lose your work. It remains in local storage until you replace it or clear browser data. - Checkout hand-off —
lamp.buyDesign.v1temporarily passes a design, color, and quantity from the designer to checkout. It is session storage and is removed after a completed purchase; the browser also normally removes it when the tab session ends. - Promotion code —
lamp.promoCode.v1keeps a code during the current tab session so it can be applied at checkout. It is removed after purchase or when the site determines that the code is no longer usable. - Venue attribution —
lamp.venueTag.v1keeps the participating venue associated with a venue link or code. It is session storage and is discarded when the configured attribution period expires or the tab session ends. - Load a cart design —
lamp.cartLoad.v1temporarily carries one cart design back into the designer for editing. The designer removes it as soon as it reads it. - Gift claim —
lamp.giftClaim.v1temporarily keeps a gift-claim code and limited gift context during the claim flow. It is removed after a successful claim, when you return to an ordinary purchase flow, or when the tab session ends. - Checkout fields —
lamp.checkout.v1keeps contact and shipping details, quantity, and color in local storage so an unfinished checkout can be restored. It does not contain full card details. It remains until you overwrite it or clear browser data. - Display units —
lamp.units.v1remembers whether the designer shows inches or millimetres. It remains until you change it or clear browser data. - Pending Evolution capture —
apollo.evolution.pending.v1temporarily keeps the signed time and segment for a lamp you caught while your connection was unavailable. It is removed after the capture is redeemed or when you clear browser data.
Browser storage is first-party storage on your device. Values needed to price, process, attribute, or fulfil an order are sent to us when you use the relevant feature or submit checkout; payment-card details are not stored in these keys.
How we use it
- To make and ship your order — printing your lamp, milling and assembling it, printing labels, and sending you tracking updates
- To verify that your shipping address is deliverable
- To process payment and prevent fraud
- To respond to your support questions and order requests
- When you opt in, to send occasional first-party Apollo Lamps product news and related offers
- To meet our legal, tax, and accounting obligations
- To keep an audit trail of orders and admin actions for security and dispute resolution
Marketing email is opt-in and concerns Apollo Lamps; we do not use the mailing list for third-party marketing, cross-site profiling, or behavioural advertising. Every marketing email includes an unsubscribe link and, where supported by your mail provider, a native one-click unsubscribe control. You may also reply to a marketing email or email support@apollolamps.com to ask us to remove you. We process opt-outs as promptly as reasonably practicable.
Unsubscribing from marketing does not stop transactional messages needed for an order or a request you make, such as confirmations, shipping notices, support replies, or material notices concerning a past order.
Service providers we share data with
We rely on a small number of vendors to run the shop. By category, these are: payment processors, shipping providers, email-delivery providers, and hosting / content-delivery providers. Each receives only the information they need to perform their service, and each is contractually bound to handle it in line with their published data-handling commitments:
- Stripe — card and wallet (Apple Pay / Google Pay) payment processing. Receives your billing details, email, and shipping address. See stripe.com/privacy.
- PayPal — payment processing when you choose PayPal at checkout. Receives the order amount and the details PayPal needs to process the payment. See paypal.com/legalhub/privacy.
- Shippo — address verification, shipping labels, and tracking notifications. Receives your name, shipping address, and email. See goshippo.com/privacy.
- Resend — delivery of transactional messages (such as order confirmations and shipping notifications) and opt-in marketing messages. Receives the recipient email address, message content, and delivery metadata needed to send and manage those messages. See resend.com/legal/privacy-policy.
- Cloudflare — website hosting, content delivery, and security. Sees your IP address and request metadata at the network edge. See cloudflare.com/privacypolicy.
We may also disclose information if required by law (e.g. a valid subpoena, court order, or other legal process), or to protect the rights, safety, or property of Grad School Alternative LLC, our customers, or the public.
We do not sell or share your information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). We have not done so in the prior 12 months and have no plans to do so.
Sensitive personal information. We do not collect “sensitive personal information” as defined by the CPRA. The payment details you enter at checkout are handled directly by Stripe or PayPal under PCI-DSS and never reach our systems.
Shine the Light Act. California Civil Code §1798.83 gives California residents the right to ask whether we have disclosed their personal information to third parties for those third parties' direct-marketing purposes. We have not, and we have no plans to do so.
Service providers. We use the vendors listed above to perform services on our behalf and provide them information for those purposes. Their applicable terms, privacy commitments, and data-processing terms govern their handling of that information. We do not provide customer information to them so that they can market their own products to you.
How long we keep it
- Order records (email, shipping address, design, amounts, payment reference): kept for as long as required by tax and accounting law, typically up to 7 years.
- Audit log entries (IP address, user-agent, timestamps tied to order events): up to 12 months after the related order is delivered or cancelled.
- Support messages: up to 2 years after the conversation closes.
- Mailing-list records (email address, consent source and time, and unsubscribe or delivery-suppression status): while you are subscribed and afterward as reasonably needed to honour opt-outs, document consent, handle complaints, and protect email deliverability. We do not use a retained suppression record to send marketing.
- Browser storage on your device: until you clear it or your browser does, or until the shorter workflow-specific period described above.
- Evolution aggregate counters: retained as daily totals for product reliability and funnel measurement; they are not linked to a person or browser identifier.
Security
All traffic between you and the site is encrypted in transit using HTTPS. Payment details are handled by Stripe and PayPal under PCI-DSS, never stored on our systems. Access to order records is restricted to authorised operators using bearer-token authentication. No system can be guaranteed perfectly secure; we work to keep ours reasonable for the data it holds.
Breach notification. If we ever become aware of a personal-data breach that creates a meaningful risk to your rights or freedoms, we will notify the relevant supervisory authority within 72 hours where required by law (GDPR Article 33), and we will notify you directly without undue delay if the breach is likely to result in a high risk to you (GDPR Article 34). For breaches affecting California residents, we follow the notification timing required by California Civil Code §1798.82.
Cookies and similar storage
We do not use analytics cookies, advertising cookies, or any tracking pixels. The storage relevant to ordinary storefront use is:
- The cart, design, checkout, promotion, venue, gift, and preference items in your browser’s local and session storage described above. They support features you request and are not used to track you across websites.
- On the checkout page only, Stripe and PayPal set first-party cookies used for payment fraud prevention. These are strictly necessary for the payment services to work; without them, they cannot reliably secure your transaction.
Do Not Track signals
Some browsers offer a “Do Not Track” (DNT) signal that asks websites not to track the user across sites. We do not track users across third-party sites, run third-party analytics, or participate in cross-context behavioural advertising, so a DNT signal does not change our behaviour — there is nothing for it to switch off. We treat all visitors the same regardless of whether a DNT signal is sent.
Your rights
California residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and retain about you
- Request a copy of the personal information we hold
- Request deletion of your personal information, subject to legal retention requirements
- Request correction of inaccurate personal information
- Not receive discriminatory treatment for exercising any of these rights
As stated above, we do not sell or share personal information, so there is no need to opt out of those activities. To exercise any other right, email support@apollolamps.com. We will verify your request by confirming you control the email address tied to your order. We will acknowledge receipt within 10 business days and respond substantively within 45 calendar days; if your request is unusually complex, we may extend that by up to another 45 days and will tell you in writing why.
EU, UK, and EEA residents (GDPR / UK GDPR)
If you are in the EU, UK, or EEA, you have the right to access, rectify, erase, restrict the processing of, port, and object to the processing of your personal information. Our legal bases for processing are:
- Contract performance — for processing necessary to make and ship the order you placed (your name, address, email, payment details)
- Legitimate interests — for fraud prevention, site security, and the audit log of order events
- Legal obligation — for tax and accounting records
- Consent — for optional Apollo Lamps marketing email. You may withdraw that consent at any time using the unsubscribe methods described above, without affecting processing that occurred before withdrawal.
To exercise any right, email support@apollolamps.com. You also have the right to lodge a complaint with your local data protection supervisory authority.
International data transfers
Grad School Alternative LLC is based in Orange, California, United States. We host the site on Cloudflare’s global network, and our service providers operate primarily from the United States. If you visit the site from outside the United States, your information will be transferred to and processed in the United States and other countries where these vendors operate. (We currently ship to U.S. addresses only.)
Where personal information leaves the EU, EEA, or UK in the course of these service providers performing their work, those providers rely on transfer mechanisms recognised by EU and UK law — primarily the European Commission’s Standard Contractual Clauses (June 2021 version), supplemented by the UK International Data Transfer Addendum where UK personal data is involved. Each provider’s privacy and DPA pages, linked above, describe their current safeguards in more detail.
Children
The site is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe we have collected information about a child under 13, contact us and we’ll delete it. You must be at least 18 years old to place an order.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page. Continued use of the site after a change takes effect means you accept the revised policy.
Accessibility
We aim to make this site usable by everyone, including people using assistive technologies, and we target Web Content Accessibility Guidelines (WCAG) 2.1 Level AA conformance as a baseline. If you encounter a barrier on the site — a screen-reader issue, a low-contrast control, a focus trap, anything — email support@apollolamps.com and tell us what happened. We will work to fix it, and to give you another way to do what you were trying to do in the meantime.
Contact
Questions, requests, or complaints about this Privacy Policy:
Grad School Alternative LLC (Apollo Lamps)
445 N Pine St, Orange, CA 92866
Email: support@apollolamps.com