Last updated: 2026-05-21
When you place an order, we receive your name, email, shipping address, and a PayPal payment confirmation (we never see your card number or PayPal password — those stay with PayPal). When you create an account, we store your username, email, and a bcrypt-hashed password. When you sign up for a restock alert or newsletter, we keep your email. When you submit a review, contact form, or wiki article, we keep what you typed plus a timestamp.
Our server records standard web access logs (IP, timestamp, page URL, user agent) for security and debugging. These are auto-rotated after a few weeks.
We share the minimum needed with the services that make the site work:
We do not sell your data, run third-party ad trackers, or share your email with marketers.
We set one session cookie to keep you logged in (browser-only, no third parties). It is HttpOnly, marked Secure, and SameSite=Lax. We use localStorage on your browser to remember recently-viewed products — this never leaves your machine.
Email us (see contact) to:
Passwords are bcrypt-hashed, never stored as plain text. Our server uses HTTPS with TLS 1.2/1.3, security headers (CSP, HSTS, X-Frame-Options), and CSRF protection on every form. Backups are encrypted at rest. We log security events and review them regularly.
If we materially change this policy, we'll bump the "Last updated" date and email account holders.
Questions about this policy? Get in touch.
Collectors, tinkerers, and computing history preservers. Share projects and get first access to new boards.
New boards, builds, and events delivered to your inbox. No spam, ever.