The short version
- You can browse the whole catalog without an account. Signed out, we do not know who you are — and you will not see prices.
- An account needs an email address, a password and your name. Company, phone and addresses are optional, and we ask for them only because orders and deliveries need them.
- We do not set any cookies. No advertising network, analytics company or social network receives anything about you from us. We do not sell your information.
- Our assistant is powered by Google Gemini. When you are signed in and use it, your account details and recent orders are sent to Google as part of the question.
- You can delete your account at any time. It is disabled the moment you ask and permanently anonymized 7 days later. Completed orders and any liability waiver you signed stay — they are tax and legal records.
Who we are
Venezia Surfaces USA sells natural and engineered stone slabs from two warehouses in the United States. In this policy, “we” and “our” mean Venezia Surfaces USA, and “you” means anyone who uses our website, signs in at one of our warehouses, or installs our app.
- Maryland: 1954 Halethorpe Farms Rd #500, Halethorpe, MD 21227
- Florida: 6850 Lyons Technology Cir, Coconut Creek, FL 33073
- Phone: +1 (833) 836-3942 · Email: info@veneziasurfaces.com
Browsing without an account
The catalog is open. You can search it, filter it, open any slab and look at the photographs without telling us anything about yourself, and without creating an account.
Signed out you will not see prices. Our prices depend on the kind of business you are and are agreed account by account, so the catalog is served to signed-out visitors with prices removed before it leaves our server — they are not hidden in the page.
We still count the visit. What that means precisely is in section 7.
Your account
What we require
An email address, a password, and your name. We email a six-digit code to that address and ask you to type it back, so that an account cannot be opened in someone else’s name. The code is valid for ten minutes.
Passwords must be at least 12 characters. We store only a bcrypt hash of your password — never the password itself. Nobody at Venezia Surfaces can read it, recover it, or tell you what it is; the only thing we can do is send you a link to set a new one.
What is optional
Everything else. Company name and type, phone, mobile, a separate accounting email, your website, a sales-tax or resale ID, a billing address, one or more shipping addresses, a profile picture, your business hours and the window when you can receive a delivery, and your preferences for language, units, catalog layout and which notifications you want. You can leave all of it blank. We ask because a delivery needs an address and an order needs someone to call, not because we want a file on you.
Approval, and why you may not see prices yet
A business account is created in a pending state. Someone on our team reviews it and assigns a price tier before prices appear. A personal (non-business) account is approved automatically but is browse-only: it never shows prices. This is a commercial decision, not a privacy one, but it explains why a brand-new account looks the same as being signed out.
Staying signed in
On the website, signing in stores a signed token in your browser’s local storage, valid for two days. There is no cookie. In the app, your device additionally holds a long-lived sign-in token so you do not have to type your password every time; we store only a hashed copy of it, it slides forward 180 days each time it is used, and it stops working 365 days after it was issued regardless. Every device that is signed in is listed in the app under Devices, and you can revoke any of them — including the one you are holding.
If you turn on two-factor authentication, we store the authenticator secret encrypted, or — for a passkey — a public key and the name you gave the device. A passkey’s private key never leaves your device and we never see it.
When a sign-in fails we record the email address that was tried, the IP address it came from and the time, so that someone cannot guess passwords at your account indefinitely. These records are deleted after 24 hours, and a successful sign-in clears the earlier failures immediately.
Orders and deliveries
An order records what you bought — including the serial number of each individual slab — the price at the moment you bought it, your email address, the shipping address you chose, the delivery date and speed, any delivery instructions you typed, which warehouse it ships from, and the delivery fee.
The address and email are copied onto the order rather than looked up from your profile each time. That is deliberate: years later the record still says what was actually agreed and what was actually charged, even if you have since changed your address. It also means those copies survive the deletion of your account — see section 11, which says so plainly.
Visiting a warehouse, and your signature
Before entering a warehouse you sign in and accept a release of liability. You can do this on your own phone or on a tablet at the door. It does not require an account, and it is not linked to one — a walk-in visitor who has never used this website can complete it.
What the sign-in collects
- Required: your full name, email address, phone number and the company you work for.
- Optional: how you heard about us, which materials interest you, and an emergency contact — their name, their relationship to you and their phone number.
- Whether you took a hard hat and a safety vest.
- Anyone visiting with you, up to twelve people: each one’s name, whether they are a minor, and if so their guardian’s name.
- Which slabs you asked us to set aside, if any.
Your signature
You sign by drawing your signature with a finger or a mouse. We keep the drawing itself — an image of your handwritten signature — together with your typed name, the date, the version of the waiver you agreed to, the IP address you signed from and your browser’s user-agent string. Everyone in your group who signs is recorded the same way, including a minor’s signature alongside their guardian’s name.
We keep it because the document is a release of liability, and a signature nobody can produce afterwards is not a record of anything. Our staff can view it, and it is included in a PDF or Word copy of the record if one is exported internally.
We do not photograph you, do not scan any identity document, and do not ask for a date of birth, a home address or a vehicle.
How long a waiver is kept
Indefinitely. A signed waiver is a legal record and nothing deletes it automatically. Because it is not attached to any account, deleting your account does not remove it either. If you want a waiver you signed removed, ask us (section 15) and we will do so unless we are required to keep it — for example while a related claim is open.
Slabs held for you
If you ask us to set slabs aside, we copy your name, email, phone and company onto the reservation so our warehouse team knows whose it is. Approved holds last 5 days and then release automatically. The reservation record is kept on the same basis as the waiver.
The assistant, photos and voice
The assistant is powered by Google Gemini, a service of Google LLC. Your question is sent to Google to be answered. We do not run our own model.
When you are signed in, this is sent to Google with every message:
- Your name, email address, phone and mobile numbers, company name and company type.
- Your billing and shipping addresses, your price tier and your sales-tax rate.
- What is currently in your cart, and the names of the products in your saved lists.
- Your last ten orders — dates, status, delivery dates, totals and the serial numbers of the slabs on them.
That is what lets it answer “where is my order” and “what does this cost me” without you looking anything up. It is also the reason to treat the assistant as you would any message to an outside company: do not type anything into it that you would not want Google to process.
Voice and photos
In the app you can record a voice message for the assistant. It is recorded into the app’s own private storage — not into your gallery — and sent to Google with that one message so the model can hear the question. We do not store the audio, and on this path we do not keep a transcript of it either. What is saved in the conversation is whatever text you typed alongside it, which for a voice-only message is nothing: the record shows that a question was answered, not what you said out loud. The recording on your phone is deleted the moment the message is sent, and the moment you discard it. It stops when you press stop, when it reaches two minutes, or when you leave the screen.
The spoken conversation on this website is a different thing and behaves differently, so it is worth knowing which one you are using. There your microphone is streamed to Google live and Google transcribes both sides as you speak. The audio is still not stored — but that transcript is. It is written into the conversation on your account exactly as a typed chat would be, and kept on the same 30-day basis. Where nothing was recognized, the record simply reads “[Voice]”.
A photograph you attach is sent to Google too. Choosing one from your phone uses Android’s own photo picker, which gives the app the single image you picked and no access to any of the others. A photograph you take with the camera from inside the assistant is saved into your own gallery, in an album called Venezia, and it stays there afterwards — the app does not quietly delete it, and you can. A shot you cancel is not kept.
What is kept, and for how long
Conversations you have while signed in are saved to your account and deleted automatically after 30 days. You can delete any conversation sooner from the app or the website. Conversations you have while signed out are never saved.
Signed out, the assistant is limited to 50 messages a day. That limit is counted against your IP address and a random identifier stored in your browser. Neither is written to our database — they are held briefly in memory and discarded.
If you ask to speak to a person, the conversation so far plus the name and email you give us are passed to our team so they can pick it up. Those conversations are retired 90 days after they are closed.
The assistant at a warehouse sign-in is different
The assistant on the visit screen is deliberately given nothing about you. It receives the warehouse you are at, your visit reference number, and the slabs shown on screen. Your name, email and phone are not sent to Google from that screen — even though you have just typed them in on the same device.
At the end of a visit you can have a summary emailed to you. It covers the visit itself — who signed in, and any slabs you asked us to set aside. It does not contain your conversation with the assistant, and it could not: a visitor’s conversation is never saved on our servers at all, so there is no transcript of it anywhere for us to attach.
How we measure use of the site and app
We count how the catalog is used so we know which stone to photograph next and which pages are too slow. This measurement is entirely our own and runs on our own servers.
There is no Google Analytics, no advertising or social-network pixel, no tag manager, no session recording and no third-party error-reporting service anywhere on this site or in the app. Nothing about your visit is sent to a measurement company.
What is counted
Which page or screen you opened; whether you are still on it (a signal every 60 seconds while the page is visible); which products you opened; what you typed into the search box; which filters you applied; adding something to the cart; opening the assistant; and how quickly the page loaded.
Search terms are recorded. They are stored as a daily count of each distinct term — “calacatta, 41 times today” — and are not attached to you or to any identifier.
How a visit is identified
Signed in, by your account number. Signed out, by a random value created in your browser the first time you arrive and kept in local storage. It is not derived from anything about you or your device, and clearing your browser’s site data removes it. If your browser cannot store it, we fall back to a short one-way hash that changes every day and cannot be traced back.
We do not store your IP address or your browser’s user-agent string in our usage records. Your IP is used at the moment of the request to group a visit and to block abusive traffic, and is then discarded. What lands in the database is a device category — phone, tablet or desktop — and counters.
We should be straightforward about one thing: there is currently no switch to turn this measurement off. It is on for everyone, signed in or not. It collects no contact details and is never shared, but if that matters to you, please tell us — it is the kind of thing we would add.
The app currently sends one such measurement: an event when you add a slab to the cart.
Cookies and browser storage
We do not set any cookies at all — not our own, not anyone else’s. That is why this site has never shown you a cookie banner. Instead, a small amount of information is kept in your browser’s own local storage, on your device, and is sent to us only when it is needed to answer a request.
| What is stored | Why |
|---|---|
| Your sign-in token and a copy of your own profile | So you stay signed in and the page can show your name without asking us again |
| Your cart, your liked products and your saved lists | So a cart survives a reload, and so a signed-out visitor can keep a list at all |
| A random visitor identifier | Counting visits (section 7), and proving ownership of a list you made while signed out |
| Language, catalog width, selected warehouse | Your display preferences |
| A random device token for the feedback widget | Limiting how many problem reports one device can file, so the form cannot be flooded |
Clearing site data in your browser removes all of it, signs you out, and empties the cart.
The Android app
Permissions the app asks for
- Camera
- Two features only: reading a slab label or barcode with the scanner, and attaching a photograph to a question for the assistant. Android asks the first time you open one of them, and the app works without it.
- Microphone
- Voice messages to the assistant, and nothing else. Android asks the first time you press the microphone in the chat — never when the app starts, and never on the first screen. Refusing costs you that one button: typing and photographs carry on working exactly as before. The app never records in the background. The microphone opens when you press record and is closed when you press stop, when the recording reaches two minutes, or when you leave the screen, whichever comes first.
- Approximate location
- One button on the registration form, which fills in your city, state and ZIP for you. It asks for your approximate location only — the coarse permission, which locates a neighbourhood rather than a doorstep — and only at the moment you press it. Because Android deliberately blurs an approximate position, the app never fills the street line from it: a wrong house number in an address we would later deliver to is the mistake this button exists to prevent, so the street stays yours to type. The coordinates go to our server, which asks OpenStreetMap what address is there and hands the text back. We do not write them to your account, to any record, or even to the app’s own diagnostic log; the only trace is a one-hour cache on our server, which exists so we do not ask OpenStreetMap the same question twice. If you refuse, you type the address as you always could.
- Notifications
- Order updates and stock alerts. We ask once, after the catalog has loaded rather than on the first screen. Declining changes nothing else.
- Internet and network state
- To reach our servers, to tell you when you are offline, and to count data used on Wi-Fi separately from mobile data.
- Biometrics
- Only if you turn on the optional app lock. Android performs the check; your fingerprint or face never reaches the app or us.
The app does not ask for your precise location, your contacts, your photo library or an advertising ID, and there is no advertising or tracking software in it at all. Choosing a picture uses Android’s own photo picker, which hands over the one image you chose and grants nothing else — the app is never given a list of your photographs.
Four further permissions are present in the installed app that we never ask you for and that Android never shows you, because Google’s own libraries add them when the app is built: WAKE_LOCK and the Cloud Messaging receive permission come with push notifications and let a message wake the phone, USE_FINGERPRINT is the retired name of the biometric permission and arrives with the biometric library, and one permission named after the app itself keeps an internal message private to it. None of them gives access to anything about you, and none of them produces a prompt. We list them because a permission list is only useful if it is the whole list.
What stays on your phone
The data counter, the diagnostic log, the offline catalog and the image cache are stored on the device and are not transmitted anywhere.
- The data counter records how many bytes the app has sent and received, split by area (photos, catalog, scanner, assistant, other) and by network (Wi-Fi, mobile, roaming). It is counted from the size of requests, never their contents, and it is categorized by the path of a request and never by its query — so serial numbers and search terms are not involved. It never leaves the phone. You can reset it.
- The diagnostic log holds the most recent 2,000 entries in memory. It records the screen you moved to, and the path and status code of a request that failed. It never records a query string, a request or response body, your sign-in token, or your email address. A released build keeps errors only. It leaves your phone only when you choose to share it, or when you attach it to a support report.
- The offline catalog is a copy of the catalog saved on the device so it works without a signal. If you are signed in it contains your tier prices, so it is deleted when you sign out — otherwise the next person to pick up the phone would see prices they are not entitled to. Saved prices are hidden once they are more than 24 hours old.
App data is excluded from Google Drive backup and from device-to-device transfer, so none of it is copied off the phone by Android itself. Your sign-in tokens are held in Android’s encrypted storage, with the key in the device’s hardware keystore.
Support reports
If you report a problem, we receive what you typed, optionally your name and email, a screenshot of the screen you were on — which the app takes for you and shows you before anything is sent — the last 200 lines of the diagnostic log, and information about the device and app: manufacturer, model, Android version, app version, language, time zone, screen size and whether dark mode is on.
Push notifications
Notifications are delivered through Firebase Cloud Messaging, a Google service. Your device is issued a push token, which we store alongside that device’s sign-in record together with the device name and platform, so we know where to send an order update. It is cleared when Google tells us the token is dead, and removed with the device record — revoked device records are purged 30 days after revocation. Notifications are shown privately on the lock screen so an order total is not readable from a locked phone.
How long we keep things
| Record | Kept for |
|---|---|
| Your account profile | Until you delete the account — see section 11 |
| Orders | Indefinitely, as business and tax records |
| Signed waivers and slab reservations | Indefinitely, as legal records |
| Assistant conversations | 30 days, deleted automatically |
| Conversations handed to a person | 90 days after they are closed |
| Saved lists | 365 days from last use signed in; 30 days signed out |
| Device sign-ins | 180 days from last use, 365 days maximum; purged 30 days after being revoked |
| Failed sign-in attempts | 24 hours |
| Email verification and two-factor codes | 10 minutes |
| Password reset links | 1 hour, and single use |
| Site and app usage counts | Indefinitely, as daily totals with no identity attached |
| Support reports | Until reviewed and resolved; not deleted automatically |
Deleting your account, and what survives
In the app, open Account → Delete account. You can also simply ask us (section 15). You will be asked for your password, because this cannot be undone after the grace period.
Straight away
Your account is disabled the moment you ask — not at the end of the grace period. You are signed out everywhere, every device sign-in is revoked, and you cannot sign back in.
For 7 days you can change your mind
We email you a confirmation with a link that cancels the deletion and restores the account exactly as it was. After 7 days the link stops working and nothing can be restored.
After 7 days, permanently
The account record itself is kept, but emptied. What is left of it is an internal number and the fact that an account once existed. Your email address, name, company name, phone, mobile, accounting email, website, sales-tax ID, profile picture and every saved address are removed from it.
Removed outright: your passkeys, your two-factor recovery codes and your authenticator secret, every signed-in device together with its push token, any unused verification or two-factor code, and your sign-in history — including the IP addresses in it. Deleted with them: your saved assistant conversations, your liked products, saved-for-later items, draft orders and lists.
Your past orders are kept, because we are required to keep them for tax and accounting — but they are cleaned by the same sweep. The delivery address and any delivery instructions are erased from them, and you are replaced by an internal marker. What remains is the commercial record: the items, their serial numbers, the prices, the dates, the warehouse and the delivery fees.
What stays, and why
- Completed orders, as the commercial record only. The items, their serial numbers, the prices, the dates, the warehouse and the delivery fees. An order is a record of a real transaction and we are required to keep it. The delivery address, the delivery instructions and the link to you are not part of what is kept.
- Signed liability waivers and slab reservations. These are legal records of who entered a warehouse and on what terms. They are never linked to an account in the first place, so account deletion has no effect on them at all.
- Your account type, price tier and home warehouse. A business classification with nothing personal in it, kept so historical orders still make sense.
- The records this process does not reach. Support tickets and the messages on them, the history of notifications we sent you, back-in-stock alerts, anything left sitting in a cart, and any conversation that was handed to a member of our team. They are not part of the deletion sweep, so they are retained. Ask us and we will remove them.
If we delete the account for you, it works differently
An administrator can also delete an account permanently, and the result is not the same thing. Neither path is simply a stronger version of the other, so it is worth setting both out. On this one the account record is destroyed rather than emptied, and everything filed against it goes with it: saved assistant conversations, liked products, saved-for-later items, lists and any list you shared, draft orders, your cart and your back-in-stock alerts, along with your passkeys and two-factor recovery codes.
But because that destruction follows the account number, records keyed to your email address rather than to the account are left standing — and they still carry it: signed-in device records, unused verification and two-factor codes, your sign-in history, support tickets, the history of notifications we sent you, and conversations handed to our team. Past orders are kept as before, but on this path the delivery address and the delivery instructions stay on them.
Put plainly, because it is the question that matters: the deletion you can run yourself removes more about you as a person. It clears the delivery address and instructions off your past orders and wipes the records tied to your email address. An administrator’s deletion removes more of the account — the record stops existing — but leaves those addresses on past orders and leaves your email address in the device, verification, sign-in, support and notification records. If what you want is your personal information gone, the one in the app is the one to use.
If you want something that survives removed as well — a delivery address left on a past order, a waiver you signed, a support ticket — ask us and we will do it wherever we are not required by law to keep the record. We would rather you asked than assumed.
Who else sees your information
We do not sell your information, and we do not share it with advertising networks, data brokers or social networks. These are the only outside companies involved, and this is exactly what each of them receives.
| Company | What they receive |
|---|---|
| Google LLC — Gemini | Assistant questions and answers, voice audio, photographs you attach, and — when you are signed in — your profile, cart, saved lists and last ten orders |
| Google LLC — Firebase Cloud Messaging | Your device’s push token and the text of a notification, in order to deliver it |
| Google LLC — Google Drive | Original photographs of slabs taken by our warehouse staff. A staff tool; it carries no customer information |
| Brevo | Your email address and the contents of the message: verification codes, password resets, order and reservation notices, shared-list invitations, visit summaries and support reports |
| OpenStreetMap Foundation (Nominatim) | The address text you type into an address field, to suggest completions — and, if you use the app’s fill-my-address button, the approximate coordinates it read from your phone. Our server makes the request, so your IP address is not passed on |
| jsDelivr and unpkg | A text-recognition library loaded on the staff scanner page only. No customer page loads anything from an outside server |
Our fonts, icons and scripts are served from our own servers rather than a public network, so simply loading a page on this site does not tell any other company that you were here.
We may also disclose information where the law requires it, or where it is necessary to establish or defend a legal claim.
How we protect it
- Everything is served over HTTPS, and browsers are instructed to refuse an unencrypted connection to us.
- Passwords are stored as bcrypt hashes. Two-factor secrets are encrypted at rest. Backup codes are hashed.
- Two-factor authentication and passkeys are available to every account, and required for administrators.
- Repeated failed sign-ins are rate-limited and then locked out for a period.
- Access to customer records is limited to staff accounts that have been granted that permission explicitly, and every device that is signed in can be revoked.
- In the app, sign-in tokens live in Android’s encrypted storage with the key held in the device’s hardware keystore.
No system is perfect. If you believe your account has been accessed by someone else, change your password — which immediately signs out every device — and tell us.
Children
This is a trade business and its website, app and accounts are meant for adults acting for a business. We do not knowingly collect information from children under 13, and if we learn that we have, we delete it.
There is one deliberate exception, and it is worth stating plainly: the warehouse sign-in has a place for the name of a minor who is entering with an adult, together with their guardian’s name and, if they sign, their signature. That information is provided by the accompanying adult, who is also the person accepting the waiver on the minor’s behalf.
Your choices, and how to reach us
You can ask us what we hold about you, ask us to correct it, and ask us to delete it. Most of it you can also see and change yourself, in your profile or in the app. Depending on where you live you may have further rights under state law; ask and we will honour them.
- Email: info@veneziasurfaces.com
- Phone: +1 (833) 836-3942
- Post: Venezia Surfaces USA, 1954 Halethorpe Farms Rd #500, Halethorpe, MD 21227
Please say which account or which visit you mean, so we can find the right records. We may need to confirm who you are before acting on a request about someone’s personal information — including your own.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects what we collect or who receives it, we will say so on the site and in the app rather than relying on you to notice a date.