Legal
Privacy Policy
Last updated: July 27, 2026
This Privacy Policy explains what information Framed Honors (a brand of Timshel Inc.) collects, where we got it, how we use it, who we share it with, and the choices you have. It covers framedhonors.com (the “Site”) and our made-to-order keepsakes of press coverage.
If we mailed you, we knew about you before you ever heard of us, because a publication wrote about you, and we read it. Everything on the page we prepared for you came from that published coverage. You never gave us anything, you owe us nothing, and one email stops all of it.
1. Where we got your information
This is the part most privacy policies skip, so we will start here.
We read publicly available press coverage – articles published by newspapers, magazines, trade publications, broadcasters, and news websites – and we note who was featured in it. From that coverage we record the featured person's name, their business or organization if the article names one, the publication, the headline, the date the coverage ran, a link to the article, and the general subject area it falls under. We pair that with a mailing address so we can send an invitation.
We store this in our own records before you visit us, so that when you scan the code on our mailing, the page that loads already shows your feature. That is the whole trick: there is no magic, we just did the reading in advance.
We did not buy this from you, and you did not sign up for it. If you would rather we did not hold it, say so and we will delete it. See Section 8.
2. What we collect
- Published coverage and the people in it. As described in Section 1 – name, business, publication, headline, article date, article link, subject area, and a mailing address.
- What you give us. Your email address when you ask us to hold a piece or send you a preview; your name, shipping address, and the options you configured when you order; and whatever you write to us in an email or a form.
- How you used the Site. Pages viewed, clicks, which options you selected, whether you reached checkout, the approximate location implied by your IP address, your device and browser, and the page that referred you. We keep our own server-side record of key actions as well as using an analytics provider. See Section 4.
- Identifiers we create. A random first-party visitor id stored in your browser (in local storage and in a cookie named
pg_vid), the personal link code from your mailing, and the campaign andutm_tags that tell us which mailing or link brought you here. We keep both your first-touch and most recent set of those tags in your browser. - Payment information. Handled by Stripe. We receive the fact of a payment, the amount, the last part of the card for reference, and your shipping address – never the full card number, and never your CVC.
We do not knowingly collect Social Security numbers, precise geolocation, health information, government identifiers, or account credentials.
3. How we use it
- To prepare the personalized page for your feature, show you a preview, and produce and ship your keepsake.
- To invite you, once, to have a keepsake made of coverage you were featured in, and to stop, permanently, if you tell us to.
- To email you about a piece you asked us to hold, a preview you requested, an order you placed, or a question you sent us.
- To understand whether our mailings and pages work – how many people scanned, arrived, configured a piece, and ordered.
- To keep the Site working and secure, including rate-limiting abuse and diagnosing errors.
- To meet our legal, tax, and accounting obligations and to resolve disputes.
We do not use your information to build profiles for advertisers, and we do not run behavioral advertising.
4. Cookies, analytics, and session recording
Cookies and local storage. We use a small number of first-party items: the visitor id described above, attribution tags from your link, and whatever Stripe needs to run checkout securely. You can clear or block these in your browser; blocking them may break checkout.
Analytics. We use PostHog (hosted in the United States) to understand how the Site is used. It automatically records page views and clicks, and we send it specific events – arriving from a mailing, configuring a piece, adding to a cart, reaching checkout. Analytics only run when we have configured them; when they are not configured, nothing is collected at all.
Session recording. PostHog can record a replay of a browsing session – the screens you saw and where you clicked – which we review to find the places the Site confuses people. Replay runs across the Site, including personalized pages. In session replays, anything you type is always masked before it leaves your browser, anything we mark sensitive is masked the same way, and the web addresses captured inside a replay are stripped of query strings. Checkout's payment fields are handled by Stripe inside its own frame and are never part of a recording.
Do Not Track and Global Privacy Control. If your browser sends a Do Not Track header or a Global Privacy Control signal, we do not collect analytics from you at all. We opt you out at the moment the page loads, before anything is sent.
Our own server-side record. Independently of PostHog, our own servers log key events – an arrival from a mailing, an item added, a checkout attempt, an email submitted – with the link code, campaign, your browser's user-agent string, and the referring page. This is how we count accurately when an ad blocker stops the analytics script. It is stored in our own database and shared with no one. We also keep what you type into the forms on this Site, including text you do not send, so we can prepare your piece and improve the Site.
5. Your personal link, and being recognized
The mailing we send carries a code unique to you. When you open that link, three things happen: the page loads your feature; we record that the invitation reached someone; and, in our analytics, your session is associated with that link code together with the campaign it came from.
That means the activity on your visit is not anonymous to us. It is connected to the person we prepared the page for. We do this so we can follow up properly and get your piece right. That includes session replays of your visit, handled under the rules in Section 4. Anything you type is always masked in session replays.
Personalized pages are excluded from search engines, and a link code that isn't ours returns a “not found” page rather than a generic personalized one. You can ignore the link entirely; you can also ask us to take your page down.
6. Who we share it with
We do not sell your personal information, and we do not share it for anyone else's advertising. We share it only with the companies that help us run the business, each under a contract limiting what they may do with it:
- Neon – our database, where records described above are stored.
- Vercel – hosting for the Site.
- Cloudflare – our domain, network protection, and routing of email sent to us.
- PostHog – product analytics (United States).
- Resend – sending our email to you.
- Stripe – payments, checkout, and sales-tax calculation.
- Sentry – error monitoring, so we can find and fix faults.
- Our print-and-ship partner – which receives what it needs to make and deliver your piece: the artwork, your name, and your shipping address.
- Our direct-mail provider – which receives the name, address, and personalized artwork needed to print and post your invitation.
We may also disclose information when the law requires it, to enforce our Terms, to protect someone's rights or safety, or to a buyer or successor if the business is sold, in which case this Policy continues to apply until we tell you otherwise.
7. Payments
When live checkout is running, payment is handled by Stripe on its own systems. We pass Stripe the items you chose, the amount, and your email; Stripe collects your card details and shipping address directly and calculates any sales tax. We receive back the result, your shipping address, and a reference – never your full card number. Stripe handles that data under its own privacy policy.
At times we run a reservation flow instead: you give us an email and the configuration you want, and no payment details are collected at all.
8. Your choices
- Stop hearing from us. Email hello@framedhonors.com and we will add you to our do-not-contact list and stop mailing you.
- Take my page down. Ask, and we will remove the personalized page prepared for you.
- See, correct, or delete what we hold. Ask us for a copy of the information we hold about you, or to correct or delete it. We will comply subject to records we must keep for tax, accounting, or legal reasons.
- Turn off analytics. Enable Global Privacy Control or Do Not Track in your browser and we will not collect analytics from you.
We will not treat you differently, or charge you more, for exercising any of these.
9. California privacy rights
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the right to:
- Know what personal information we have collected about you, where we got it, why we collected it, and who we disclosed it to.
- Access a copy of that information.
- Correct information that is inaccurate.
- Delete the information we hold about you, subject to the exceptions the law allows.
- Opt out of the sale or sharing of your personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we honor Global Privacy Control signals in any case.
- Not be discriminated against for exercising any of these rights.
The categories we collect are described in Section 2, our sources in Section 1, our purposes in Section 3, and the parties we disclose to in Section 6. We do not knowingly collect “sensitive personal information” as the CCPA defines it. To make a request, email hello@framedhonors.com; we may need to verify your identity, and you may use an authorized agent.
10. Other state privacy laws
Several other states – including Delaware, Virginia, Colorado, Connecticut, Texas, Oregon, and Utah – give residents similar rights to access, correct, delete, and opt out. Wherever you live, email hello@framedhonors.com and we will honor the rights that apply to you under your state's law.
Our Site is intended for people in the United States, and we ship only within the United States.
11. How long we keep it
We keep order records for as long as we need them for tax, accounting, and warranty purposes. We keep the coverage records and analytics we use to run campaigns for as long as the campaign and its follow-up are active. When we no longer need something, we delete it or strip it of anything identifying. If you ask us to delete your information, we do so except where we must keep a record by law.
12. Security, children, and changes
We protect information with encryption in transit, access controls on our database, masking of form inputs in any analytics we collect, and rate limits on the forms that write to our records. No method is perfectly secure, and we cannot promise absolute security.
The Site is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has given us information, email us and we will delete it.
We may update this Policy. The “last updated” date at the top reflects the current version; if we make a material change we will say so on this page. Questions or requests? Email hello@framedhonors.com.