PERSONAL INFORMATION WE COLLECT
When you visit the Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically-collected information as “Device Information”.
We collect Device Information using the following technologies:
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org.
- “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons,” “tags,” and “pixels” are electronic files used to record information about how you browse the Site.
Additionally when you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, including your name, billing address, shipping address, payment information (including credit card numbers, Shopify Payments, Amazon Pay, Apple Pay, Visa / Mastercard / American Express Credit Cards, Google Pay, PayPal), email address, and phone number. We refer to this information as “Order Information”.
We do not collect any “Special Categories of Personal Data” about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
HOW DO WE USE YOUR PERSONAL INFORMATION?
We will only use your Personal Information when the law allows us to.
Generally, we do not rely on consent as a legal basis for processing your Personal Information although we will get your consent before sending direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting us.
We use the Order Information that we collect generally to fulfil any orders placed through the Site (including processing your payment information, arranging for shipping, and providing you with invoices and/or order confirmations). Additionally, we use this Order Information to:
- communicate with you, for example to deal with your requests, complaints or enquiries;
- screen our orders for potential risk or fraud;
- when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services;
- to update you on any changes to our practices and terms and conditions of business;
- to invite you to take part in surveys, competitions / games or provide feedback about our services, which are always voluntary; or
- where we need to comply with a legal obligation.
We use the Device Information that we collect to help us screen for potential risk and fraud (in particular, your IP address), and more generally to improve and optimize our Site (for example, by generating analytics about how our customers browse and interact with the Site, and to assess the success of our marketing and advertising campaigns).
We will only use your Personal Information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your Personal Information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your Personal Information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
SHARING YOUR PERSONAL INFORMATION
We share your Personal Information with third parties to help us use your Personal Information, as described above. For example, we use Shopify to power our online store. You can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy. In addition, share your Personal Information with our service providers who provide the following services to us:
- IT and system administration services, to assist us with the development and maintenance of our IT system and the Site;
- manufacturing and delivery services, in respect of the goods sold and delivered to you;
- referral programme services;
- provision of warehouse/stock storage facilities, to store the goods sold to you before delivery;
- shopping site services;
- advertising and marketing services, to assist us with the preparation and distribution of our marketing material to you (where you have consented to receive such material);
- social media services, to assist us with our social media accounts; and
- business assistance services, to assist us with the operation of our business generally, to include facilitating communications between you and us;
- online chat services.
We also use Google Analytics to help us understand how our customers use the Site. You can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/.
You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
We may also share your Personal Information with professional advisers including business advisors, lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services to us.
Finally, we may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
Some of the external third parties referred to above are based outside the EEA so their processing of your Personal Information will involve a transfer of data outside the EEA.
Whenever we transfer your Personal Information out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your Personal Information to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
- Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe.
- Where we use providers based in the US, we may transfer Personal Information to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between Europe and the US.
Please contact us if you want further information on the specific mechanism used by us when transferring your Personal Information out of the EEA.
As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.
You will receive marketing communications from us if you have requested information from us or purchased goods from us and you have not opted out of receiving that marketing.
We will get your express opt-in consent before we share your Personal Information with any third party for marketing purposes.
You can opt out of targeted advertising or receiving marketing messages at any time by contacting us.
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.
DO NOT TRACK
Please note that we do not alter our Site’s data collection and use practices when we see a Do Not Track signal from your browser.
Under certain circumstances, you have rights under data protection laws in relation to your Personal Information.
If you are a European resident, you have the right to access the Personal Information we hold about you and to ask that your Personal Information be corrected, updated, or deleted. If you ask for your Personal Information to be deleted where there is no good reason for us to process it, please note we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Other rights include the following:
- to request that we only use your Personal Information for certain purposes;
- to object to the processing of your Personal Information where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. However please note in some cases we may demonstrate that we have compelling legitimate grounds to process your Personal Information which override your rights and freedom;
- to request the transfer of your Personal Information to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Information in a structured, commonly used, machine-readable format. However please note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you; and
- to withdraw consent at any time where we are relying on consent to process your Personal Information. However please note this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
If you would like to exercise this right, please contact us through the contact information below.
You will not have to pay a fee to access your Personal Information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
When you place an order through the Site, we will maintain your Order Information for our records for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements, unless and until you ask us to delete this information.
We may retain your Personal Information for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for Personal Information, we consider the amount, nature and sensitivity of the Personal Information, the potential risk of harm from unauthorised use or disclosure of your Personal Information, the purposes for which we process your Personal Informationand whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
Details of retention periods for different aspects of your Personal Information are available upon request.
We have put in place appropriate security measures to prevent your Personal Information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your Personal Information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your Personal Information on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
The Site is not intended for individuals under the age of 18 and we do not knowingly collect data relating to children under the age of 18.
THIRD PARTY LINKS
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at: firstname.lastname@example.org or by post to GiftsMegaStore, PO Box 248, Wantage, Oxfordshire, OX12 2ER.
You have the right to make a complaint at any time to the Information Commissioner's Office (“ICO”), the UK supervisory authority for data protection issues (www.ico.org.uk). We would however appreciate the chance to deal with your concerns before you approach the ICO so please Contact Us in the first instance.