Privacy Policy
This policy explains how the Yana’s Flowers website handles information when you browse, create an account, save products or addresses, place an order, make a payment, or contact us.
Effective and last updated:
- Address
- 560 W Harvard St, Glendale, CA 91204
- Phone
- +1 (818) 770-2509
- Hours
- Monday–Sunday, 9:00 AM–1:00 AM
Scope and contact
Yana’s Flowers operates this storefront. This policy applies to this website and the account, checkout, and support services available through it. A third-party site or payment provider applies its own privacy notice when you use that service.
Questions or privacy requests may be sent to yanasflowersla@gmail.com or made by calling +1 (818) 770-2509. Our mailing address is 560 W Harvard St, Glendale, CA 91204.
Information we handle
The website handles the following categories of information:
- Account and contact information. Your name, email address, password or third-party sign-in credential, optional phone number, verification status, and account preferences.
- Recipient and delivery information. Recipient names and phone numbers, delivery or pickup choice, address, requested date and window, delivery instructions, and gate or access codes.
- Shopping and order information. Bag contents, saved products, product options, quantities, prices, gift or card messages, order status, and communications about an order.
- Payment and transaction information. The selected payment method, totals, payment status, provider references, and refund or chargeback information. Stripe and PayPal supply their own payment interfaces. When QuickBooks Payments is offered, your browser sends the card fields directly to Intuit for tokenization; the Yana’s Flowers order service receives a payment token and provider references rather than the full card number or security code. Intuit describes the browser-created token as one-time and valid for 15 minutes. If a QuickBooks charge has an uncertain result, the opaque token is stored in encrypted payment metadata while reconciliation retries. It is removed when a provider charge is attached or the attempt definitively fails. If provider or transport ambiguity continues, the retries and encrypted, expired token currently have no configured deadline, so the token may remain in retained financial records. The token is not a card number or security code.
- Technical and security information. Internet requests ordinarily include an IP address, browser and device information, timestamps, requested pages, and similar diagnostics. We also handle session, authentication, fraud-prevention, and error information needed to operate and protect the service. Refresh session records can include the IP address and a limited user-agent string.
- Communications. Information you include when you email, call, or otherwise ask us for support.
We receive information from you, from your browser or device, and from services you choose to use, such as Google Sign-In and the payment provider selected at checkout.
How we use information
- Create, authenticate, secure, and administer accounts.
- Quote, prepare, fulfill, deliver, support, and document orders.
- Process and reconcile payments, refunds, disputes, and chargebacks.
- Provide saved-product, address-book, and shopping-bag features.
- Send transactional messages, including verification, password reset, receipt, and order-status communications.
- Detect misuse, troubleshoot problems, protect customers and the service, comply with law, and enforce our terms.
The current website does not include an advertising pixel, behavioral advertising system, or general-purpose audience analytics service. We do not use information collected through this website for cross-context behavioral advertising.
The current Yana’s Intelligence experience does not send a customer prompt, image, or other personal information to an external AI provider. This policy must be updated before a future AI feature does so.
Cookies and browser storage
The site uses necessary, HttpOnly cookies for signed-in sessions and security. They are configured without a fixed browser expiration, so the browser ordinarily treats them as session cookies. Payment and identity providers may use their own cookies or similar technology when their interfaces load or you choose to use them.
The site also uses browser storage for specific features:
- Shopping-bag and saved-product state may remain in local storage until you remove it, clear site data, or the application clears it. A card or gift message saved with a bag may contain text you enter.
- A checkout draft may contain customer, recipient, delivery, address, and instruction fields. The application treats that draft as expired after 24 hours.
- Password-reset email state expires after 10 minutes. Checkout references, return routes, and similar short-lived workflow state are kept in session storage and generally end with the browser-tab session or when the workflow clears them.
- An authentication-activity timestamp and role are kept locally to support automatic sign-out after inactivity. Authentication tokens are not placed in local storage by this application.
Because this site does not currently conduct cross-site behavioral tracking or sell or share website information for behavioral advertising, browser “Do Not Track” and Global Privacy Control signals do not change the site’s current behavior. If those practices change, we will update this policy and provide any controls required by law. You can also clear cookies and site storage through your browser.
Service providers and other disclosures
Information is disclosed only as reasonably needed to:
- Use Stripe, PayPal, or Intuit QuickBooks Payments to authorize, capture, refund, and reconcile payments.
- Use Google when you choose Google Sign-In.
- Operate hosting, databases, media storage, and security, and use Resend to deliver transactional account and order emails. The email provider receives the destination and email content needed for delivery.
- Fulfill an order or another request you make, investigate misuse, respond to lawful process, or protect rights and safety.
Links to services such as Instagram, Apple Maps, or Google Maps take you to a third-party site, where that service’s terms and privacy practices apply. The current website is not designed to sell personal information or share it for cross-context behavioral advertising.
Retention and account deletion
We use the following criteria rather than one period for every type of information:
- Account information is kept while the account is active and until it is deleted, except for information that must remain in separate transaction, security, or legal records.
- Order snapshots, recipient and delivery details, payment records, support records, and related communications are kept as reasonably needed to fulfill and support the order; process refunds, chargebacks, and disputes; prevent fraud; keep tax and accounting records; and meet other legal obligations.
- Security and diagnostic information is kept according to the need to investigate incidents, prevent misuse, maintain the service, and establish or defend legal claims.
- Browser-held information follows the expiration and clearing rules described in the section above.
Deleting your account removes the user record and associated saved addresses, authentication sessions and codes, and saved arrangements. It unlinks the account from its orders, but it does not delete every order or financial record: order snapshots and transaction records, including customer, recipient, fulfillment, line-item, and card-message details, may remain separately for the purposes above even when they are no longer linked to an active account.
Your choices and security
- Review or update profile and address-book information from your account.
- Remove saved products and shopping-bag items.
- Delete an address individually or use Privacy & Security in your account to request account deletion.
- Contact us to request access, correction, or deletion when the self-service controls do not cover your request.
We use administrative and technical safeguards intended to protect information, but no internet transmission or storage system can be guaranteed completely secure. Do not send a password, full payment card number, or card security code by email.
California privacy rights
Depending on which California privacy laws apply to a request, California residents may have rights to know or access personal information, correct it, delete it, receive information about disclosures, opt out of a sale or sharing, limit certain uses of sensitive personal information, and receive equal service when using a privacy right. Some information and requests are subject to legal exceptions.
Submit a request by emailing yanasflowersla@gmail.com with “Privacy Request” in the subject or by calling +1 (818) 770-2509. Describe the right you want to exercise and the account or order at issue. We may ask for enough information to reasonably verify your identity and authority. An authorized agent may submit a request, but we may request signed permission and direct identity verification as allowed by law.
The site does not currently provide a “Do Not Sell or Share” link because it is not designed to sell personal information or share it for cross-context behavioral advertising. Contact us if you believe the site has handled a signal or request incorrectly.
Children’s privacy
This storefront is intended for a general audience and is not directed to children under 13. If you believe a child under 13 has provided personal information through the site, contact us so we can review and address it.
Changes to this policy
We may update this policy when the website, providers, or legal requirements change. We will post the revised policy here, update the date above, and provide additional notice when required. Please review this page periodically.