We collect information you provide directly to us, information collected automatically when you use our services, and information from third-party sources. This information falls into two primary categories:
Automatically Collected Data
When you visit our site, we automatically collect certain information using the following technologies:
Information You Provide Directly
- Name, email address, and phone number when you create an account or contact us
- Billing and shipping addresses when you place an order
- Payment information (processed securely through our payment processor โ we do not store full card numbers)
- Communications you send us, including customer support inquiries
- Survey responses, reviews, or other content you submit
We use the information we collect for legitimate business purposes, including providing and improving our services, communicating with you, and complying with our legal obligations.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Process and fulfill your orders | Order Information | Contract performance |
| Send order confirmations and shipping updates | Email, Order data | Contract performance |
| Provide customer support | Contact info, Order data | Legitimate interest |
| Prevent fraud and screen for risk | Device Info, IP address | Legitimate interest |
| Improve site performance and user experience | Device Info, Behavior data | Legitimate interest |
| Send marketing communications (with consent) | Email address | Consent / Opt-in |
| Comply with legal obligations | All applicable data | Legal obligation |
We do not sell your personal information. We may share your information with trusted third-party service providers who assist us in operating our website, conducting our business, and serving you โ subject to confidentiality agreements and only to the extent necessary to perform their services.
Third-Party Service Providers
- E-Commerce Platform (Shopify): Powers our online store. Shopify Privacy Policy โ
- Payment Processors: Securely handle payment transactions. We do not receive or store your full payment card data.
- Shipping Carriers: Receive your name and address to fulfill and deliver your order.
- Analytics Providers (Google Analytics): Help us understand how visitors use our site. Google Privacy Policy โ
- Email Marketing Services: Used to send transactional and promotional communications (only with your consent).
- Customer Support Tools: Used to manage and respond to your inquiries efficiently.
Other Disclosures
We may also disclose your information when required by law, to protect our legal rights, or in connection with a business transfer (such as a merger or acquisition), in which case we will notify you.
We use cookies and similar tracking technologies to enhance your browsing experience, remember your preferences, analyze site traffic, and deliver relevant content.
We may use your information to provide you with targeted advertisements or marketing communications that may be of interest to you. This is accomplished by sharing data with advertising platforms such as Meta (Facebook/Instagram) and Google.
- You can opt out of targeted advertising on Facebook at: facebook.com/settings/?tab=ads
- You can opt out of Google's interest-based ads at: google.com/settings/ads
- You may opt out of many third-party ad networks via: Network Advertising Initiative or Digital Advertising Alliance
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Order records are retained for a minimum of 7 years for tax and accounting purposes.
- Customer account information is retained for the duration of your account and a reasonable period thereafter.
- Marketing data is retained until you opt out or request deletion.
- Device and analytics data is typically retained for 26 months by our analytics providers.
You may request deletion of your personal information at any time by contacting us (see Section 13). Please note that certain records may be retained even after deletion requests where legally required.
Depending on your location, you may have the following rights regarding your personal information. We are committed to honoring these rights and will respond to verified requests within 30 days.
To exercise any of these rights, please contact us using the information in Section 13. We will not discriminate against you for exercising your privacy rights.
If you are a California resident, the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), grant you specific privacy rights in addition to those listed above.
Additional California Rights
- The right to know what personal information has been collected, disclosed, or sold about you in the past 12 months
- The right to request deletion of personal information, subject to certain exceptions
- The right to correct inaccurate personal information
- The right to opt out of the sharing of personal information for cross-context behavioral advertising
- The right to limit the use of sensitive personal information
- The right to non-discrimination for exercising your CCPA rights
To exercise these rights, please submit a verifiable consumer request to privacy@yourbrand.com. We will verify your identity before processing your request and will respond within 45 days as required by law.
Our website and services are not directed to, and we do not knowingly collect personal information from, children under the age of 13 in the United States, or under the applicable age of digital consent in other jurisdictions.
We comply with the Children's Online Privacy Protection Act (COPPA). If we become aware that we have inadvertently collected personal information from a child under the age of 13, we will take immediate steps to delete that information from our records.
We take the security of your personal information seriously and implement a variety of technical and organizational safeguards designed to protect your data from unauthorized access, use, or disclosure.
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. We encourage you to use strong, unique passwords and to contact us immediately if you suspect any unauthorized access to your account.
Our business is operated in the United States. If you are located outside the United States and choose to use our services, your personal information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
If you are a resident of the European Economic Area (EEA), United Kingdom, or other regions with specific data transfer requirements, please be aware that we process your data in accordance with applicable law, including by relying on Standard Contractual Clauses or other lawful transfer mechanisms where required.
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Updating the "Last Updated" date at the top of this page
- Sending an email notification to registered account holders when changes are significant
- Displaying a prominent notice on our website
Your continued use of our website after the effective date of any changes constitutes your acceptance of the revised Privacy Policy. We encourage you to review this page periodically to stay informed about how we protect your information.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to reach out to us. We are committed to addressing your privacy concerns promptly and transparently.
123 Commerce Ave, Suite 200, Your City, ST 00000
We aim to respond to all privacy-related inquiries within 5 business days. For requests involving your legal rights (access, deletion, etc.), we will acknowledge receipt within 10 days and provide a substantive response within 30โ45 days as required by applicable law.