Security & Data Handling
Last reviewed 20 August 2026. Costumes-R-Us is operated by IDM Marketing LLC, Houston, Texas.
This page describes how we collect, process, store, use, share and dispose of the data we handle — including data obtained from the sales channels we sell on. It is written to be checked, not skimmed.
What we collect, and from where
We collect order data only from the sales channels we sell on and from our own website: the buyer's name and delivery address, what they ordered, and the financial record of the sale. Data from Amazon comes directly from Amazon's Selling Partner API for our own seller account. We do not buy, scrape, or obtain that data from any other source.
What we use it for
Fulfilling the order and nothing else — buying the shipping label, printing the packing slip, sending the confirmation and shipping emails, handling returns, and reconciling what we were paid. We do not use it for advertising, we do not build profiles from it, and we do not sell or rent it to anybody.
Who else receives it
Only the parties needed to get the parcel to the door:
- Our hosting provider (Linode / Akamai) — the servers our systems run on.
- The carrier (UPS) — the buyer's name and delivery address, so a label can be produced for that shipment.
- Our own mail server — the name, address and order contents, so we can send the order confirmation and the shipping notice.
That is the complete list. Nothing is shared for any purpose beyond fulfilling the order it belongs to.
How it is stored
- Encrypted in transit with TLS 1.2 or better.
- Encrypted at rest: the server's disks are encrypted, and database backups are encrypted with GPG AES-256.
- Held in a private database that is not reachable from the internet. Only the web application port is exposed, behind a firewall that denies everything else by default.
Who can see it
- Every member of staff has their own named account. There are no shared logins.
- Access is granted by role, limited to what the job needs.
- Passwords must be at least 12 characters with mixed case, a number and a symbol, and are rotated every 90 days.
- Two-factor authentication is available on every account.
- Administrative access to the server itself is by SSH key only — password logins are disabled.
- Sign-ins, failed sign-ins, permission denials and administrative changes are recorded to an audit trail and reviewed regularly. That trail holds no customer names or addresses.
How long we keep it
Personal data is kept only as long as needed to fulfil the order and to meet our legal and tax obligations, and is then deleted. Security logs are kept for 13 months.
Testing
Development and automated testing use invented data against a separate database. Real customer data is never copied into a development or test environment.
If something goes wrong
We keep a written incident response plan: contain, assess the scope, remove the cause, restore from clean encrypted backups, notify those affected and the relevant channel within 24 hours of detection, and review afterwards to stop it recurring.
Contact
Questions about this page, or about data we hold, go to info@costumes-r-us.com.