Your Cart is Waiting
Discover a fragrance designed to make home feel unforgettable, or take the scent quiz for a personalized match.
Drawer menu
Your Cart is Waiting
Discover a fragrance designed to make home feel unforgettable, or take the scent quiz for a personalized match.
Phoenix Crafted
Your signup has been accepted.
Effective date: September 5, 2026
This Privacy Policy explains how Phoenix Crafted ("Phoenix," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information in connection with the commercial Phoenix Operations Hub product and its related websites, applications, integrations, support, billing, and customer-facing services. This Policy applies specifically to Phoenix Operations Hub. It does not govern the separate Phoenix Crafted retail and home-fragrance storefront unless a Hub-related flow expressly adopts this Policy.
Phoenix Operations Hub is primarily a business service. Depending on the context, Phoenix may process information for its own business purposes and may process other information on behalf of a customer organization. When Phoenix processes personal information on behalf of a customer, the customer's instructions, applicable agreement, and any applicable Data Processing Agreement may govern that processing.
Depending on the features a customer uses, we may collect or process account and identity data; business profile and organization data; subscription and billing metadata; customer business and operational data; information received from or sent to customer-authorized integrations; support and communications data; usage, device, security, audit, and diagnostic data; AI inputs and outputs when a customer chooses to use an AI-enabled feature; and cookie or public-site analytics data where enabled.
Customer business and operational data can include inventory, materials, products, orders, customer records, financial records, production information, costs, reports, documents, files, workflows, and other information entered into, imported into, or generated through the Hub. Full payment credentials may be handled by payment providers rather than stored directly by Phoenix.
We use information as reasonably necessary to operate, provide, maintain, secure, support, troubleshoot, personalize, and improve Phoenix Operations Hub and its integrations. Uses may include account administration, authentication, subscription and billing management, fraud and abuse prevention, security monitoring, diagnostics, analytics, feature delivery, customer support, service communications, legal and compliance obligations, enforcing agreements, data export, recovery, and service reliability.
We may use properly aggregated or de-identified information for analytics, reliability, security, product planning, and service improvement when it cannot reasonably identify a customer or expose confidential customer business information.
Phoenix Operations Hub connects to Google services only after an authorized user or administrator grants access through Google's authorization process. Depending on the capabilities a customer chooses to connect, supported Google services may include Google Workspace and other Google services such as Gmail, Calendar, Drive, Contacts, Docs, Sheets, Slides, Tasks, Chat, Forms, Classroom, Keep, Groups, Workspace administration and reporting services, and supported Google Cloud services.
We request Google permissions based on the functionality a customer selects and use Google user data only to provide, secure, support, and troubleshoot the Hub features the customer has authorized. The categories of Google data accessed depend on the permissions granted and may include service content, files, messages, events, contacts, metadata, settings, directory or administrative information, and other data required by the selected capability.
Google OAuth access and refresh tokens are treated as credentials, handled server-side, and used only to maintain authorized connections. Customers can disconnect a Google integration through available Hub controls and may also revoke access through their Google Account or administrator controls. Disconnecting or revoking access stops future access through the revoked authorization, although information previously imported or stored may remain subject to the retention, deletion, backup, security, and legal requirements described in this Policy.
We do not sell Google user data. We do not use Google user data for behavioral advertising. We do not use Google user data to train generalized or general-purpose AI or machine-learning models. We share Google user data only as reasonably necessary with service providers acting on our behalf to operate, secure, or support the authorized functionality; with customer-authorized services; or when disclosure is required by law or valid legal process. Human access to Google user data is limited to circumstances reasonably necessary for security, support, troubleshooting, legal compliance, or other uses the customer has authorized.
Phoenix Operations Hub's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including applicable Limited Use requirements.
When a customer organization uses the Hub to process information relating to its own customers, employees, suppliers, or other individuals, that customer is generally responsible for determining the lawful basis, notices, permissions, and instructions applicable to that information. Phoenix may act as a processor, service provider, or similar vendor with respect to customer-controlled personal information. Phoenix may separately process account, billing, security, support, legal, fraud-prevention, and service-administration information for its own legitimate business purposes and legal obligations.
When a customer chooses to use an AI-enabled feature, Phoenix may process prompts, files, context, and generated outputs as reasonably necessary to provide that requested functionality, operate and secure the service, and troubleshoot issues. Phoenix will not use identifiable confidential customer business data to train generalized AI models unless that use is separately disclosed and affirmative agreement is obtained where required. The stricter rule for Google user data stated above applies to Google user data.
Third-party AI providers may process customer inputs and outputs only as reasonably necessary to provide an applicable AI feature and subject to applicable vendor, privacy, data-processing, security, and legal requirements.
We may share information as reasonably necessary with service providers and subprocessors that help operate the Hub, such as hosting and database providers, payment processors, communications providers, analytics and security services, AI providers where required for a customer-selected feature, support infrastructure, and customer-authorized integrations. Providers should receive only information reasonably necessary for their role and are subject to applicable contractual, security, privacy, and legal obligations.
We may also disclose information when reasonably necessary to comply with law or valid legal process, meet regulatory obligations, enforce agreements, investigate fraud or abuse, protect the security or integrity of the service, or protect Phoenix, customers, users, or others from material harm. Information may be transferred in connection with a legitimate merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, subject to applicable law and appropriate safeguards.
Phoenix does not sell identifiable customer business data to data brokers or disclose identifiable confidential customer business data for unrelated third-party purposes inconsistent with this Policy, customer instructions, or law.
Customers may choose to connect third-party services. By enabling an integration, the customer authorizes Phoenix to exchange data reasonably necessary to provide the requested integration functionality. Third-party services operate independently and remain subject to their own terms and privacy practices. Customers are responsible for maintaining valid third-party accounts, permissions, licenses, and lawful authority for the data they connect.
Phoenix Operations Hub may use essential cookies, local storage, session technologies, and similar mechanisms reasonably necessary for authentication, security, preferences, billing flows, integrations, and core functionality. We may use analytics, reliability, diagnostic, and security tools to understand service performance, feature usage, reliability, product quality, and customer experience.
Advertising, retargeting, or marketing cookies on public sites, if used, are subject to applicable notice and consent or opt-out requirements. We do not use identifiable confidential customer business information for unrelated behavioral advertising.
We generally retain account, organization, and customer business data while the applicable account or subscription is active, subject to operational, security, contractual, and legal requirements. After account closure or subscription termination, information may be retained for a limited period for export, recovery, backup rotation, billing, accounting, tax, fraud prevention, security, audit, dispute resolution, legal obligations, agreement enforcement, or other legitimate purposes before deletion or de-identification under applicable retention practices.
Backup copies may persist for a limited period after deletion from active systems and may be removed through normal backup rotation rather than immediate record-by-record deletion. Properly aggregated or de-identified information may be retained for legitimate analytics, reliability, security, and product-improvement purposes.
Where technically practical and appropriate to a feature, Phoenix provides or may provide reasonable means for customers to export their own business data in commonly usable formats. Export scope, format, timing, and availability may be subject to technical limits, data volume, feature capabilities, retention rules, legal restrictions, third-party system limitations, and security requirements. We may verify identity, authority, and organization permissions before releasing sensitive exports.
Eligible individuals may request access to, correction of, deletion of, or other action regarding personal information to the extent those rights apply under applicable law. We may take reasonable steps to verify a requester's identity and authority and may request information reasonably necessary to prevent unauthorized disclosure, deletion, or account takeover.
When Phoenix processes personal information on behalf of a customer organization, a request concerning information controlled by that organization may need to be directed to that organization, with Phoenix providing assistance as required by law and contract.
Phoenix uses reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information, service, and risks involved. Measures may include access controls, authentication, encryption where appropriate, logging and monitoring, backups, vulnerability management, least-privilege practices, and restricted staff or contractor access. No internet-connected service, transmission method, software system, or storage system can be guaranteed completely secure.
Customers are responsible for protecting their credentials, devices, authorized users, roles, permissions, connected accounts, and integration credentials and should promptly notify Phoenix of suspected unauthorized access or compromised credentials.
Phoenix investigates suspected security incidents and takes reasonable containment, remediation, recovery, and evidence-preservation steps appropriate to the circumstances. Phoenix will notify affected customers of a confirmed security incident when notification is required by applicable law, an applicable Data Processing Agreement, or another binding agreement.
Phoenix Operations Hub is a general-purpose business service and is not represented as specifically designed or certified for every category of specially regulated or highly sensitive information. Customers must not place unsupported specially regulated or highly sensitive data in the Hub unless the applicable feature expressly supports that use and Phoenix has agreed to the required safeguards, terms, and operational controls.
Customer and user information may be processed, transferred, or stored in countries other than the country in which the customer or user is located when Phoenix or its service providers operate or host systems there. Where applicable law requires safeguards for international transfers, Phoenix may use legally recognized transfer mechanisms, contractual protections, or other appropriate safeguards.
Phoenix Operations Hub is a business service and is not intended for children. Accounts may be created or used only by individuals legally capable of entering a binding agreement or otherwise authorized to act for a business or organization, subject to applicable law.
We may update this Policy prospectively as the service, law, providers, risks, or business practices evolve. Updated versions will identify an effective date. When a change materially affects privacy practices or customer rights, Phoenix will provide notice or obtain consent where required by law or contract.
Phoenix Crafted
4616 Beth Rd
Greensboro, NC 27406
United States
Email: phoenix@phoenix-crafted.com
Phone: 336-501-4286
Use the email address above for privacy requests, data-access or deletion requests, security concerns, legal notices, and questions about this Policy. Phoenix may reasonably verify identity, authority, and account relationship before acting on sensitive requests.