ACM Android App Privacy Policy
How Arctic Crystal Memories handles personal data in the ACM Android app and the acm.is service it displays.
One service across Android and the web
The ACM Android app securely displays www.acm.is. The same account, shopping, crystal-design, privacy and consent controls apply whether you use the app or an ordinary web browser.
Effective: 22 August 2026
1. Controller and scope
Kristaltærar Minningar ehf. (Arctic Crystal Memories), Icelandic ID 620626-3250, Faxafen 10, 2nd floor, 108 Reykjavík, Iceland, is responsible for personal data processed through the ACM Android app and acm.is. Questions and privacy requests may be sent to [email protected] or +354 761 7603.
2. Data you provide
We process only the information needed for the features you choose.
- Account and identity details, such as name, email address, Google sign-in identifier and verification status.
- Contact, billing, shipping and optional company information.
- Photos, engraving text, placement choices, special instructions and saved crystal designs.
- Orders, support conversations, returns, consent records and communication preferences.
- Teya payment status and limited reconciliation details, such as payment reference, method, brand and masked digits. ACM does not receive or store a full card number or security code.
3. Data collected through use
The service may process IP address, browser/WebView and device information, security logs, page and feature interactions, cookie choices and diagnostic information. Optional analytics or advertising measurements run only after the corresponding consent choice. ACM does not sell personal data.
4. How data is used
We use data to authenticate accounts; save and produce customer designs; operate carts, checkout, payments, delivery and support; prevent fraud and misuse; meet accounting and consumer-law duties; remember privacy choices; improve reliability; and, only with the required consent, measure analytics or advertising performance.
5. Service providers and sharing
Data is disclosed only as needed to operate the requested service or meet legal duties. Providers may include Teya for hosted card payment, Cloudflare for delivery and private file storage, Google for optional sign-in and consented measurement, Meta for consented marketing measurement, Resend for email delivery, Pósturinn for shipping, and professional accounting, infrastructure or legal providers. Each provider processes only the information needed for its role and may apply its own privacy notice on its separate service.
6. Android access and permissions
The Android package requests internet access only. It does not request Android location, contacts, microphone, SMS, call-log or broad camera permission. When you choose a photo, Android's system picker or the website's file chooser gives the service access only to the file you select.
7. Cookies, analytics and advertising
Necessary storage supports authentication, security, carts, design recovery and consent. Preferences, analytics and marketing are separate optional categories. You can reject them or change them at any time through Cookie settings. Refusing optional categories does not prevent ordinary shopping or account use.
8. Retention
Guest design drafts are eligible for deletion after 7 days of inactivity, signed-in design drafts after 30 days, and paid-order photo files after three months, subject to an active complaint, chargeback, fraud investigation or legal hold. Account data is deleted or anonymised after a verified deletion request, while limited order, invoice, payment, consent, fraud-prevention and support records may be retained for accounting, security or legal obligations.
9. Security and international processing
Connections use HTTPS and customer files use private storage with access controls and time-limited links. We use reasonable technical and organisational safeguards, but no online service can guarantee absolute security. Some providers may process data outside Iceland or the EEA using an adequacy decision or other lawful transfer safeguards where required.
10. Your rights and account deletion
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent at any time. You can initiate permanent account deletion from Account Settings in the app or through the public deletion page below. We verify ownership, remove associated data that is not lawfully retained, and explain any retained record categories. You may also complain to Persónuvernd, the Icelandic Data Protection Authority.