Privacy Policy
Who we are
This Privacy Policy explains how [Business name] ("we", "us", "our") collects, uses and shares personal information when you use [Website or app name] (the "website"), available at [website URL]. For the purposes of the EU and UK General Data Protection Regulation, [Business name] is the controller of your personal data.
If you have any questions about this policy or your information, contact us:
- Email: [contact email]
- Postal address: [Business address]
Information we collect
Depending on how you use the website, we collect the following categories of personal information:
- Contact details: name, email address, phone number.
- Account login: username and password (stored hashed).
- Purchase & billing: billing and shipping address, order history; card numbers are handled by our payment processor.
- Usage data: pages or screens viewed, features used, clicks, referring page, time and date of visits.
- Device & log data: IP address, browser type, operating system, device identifiers, crash logs.
- Cookies & similar tech: cookies, local storage, pixels and SDK identifiers.
- Support messages: the content of emails, chat and support requests you send us.
- Marketing preferences: newsletter subscription status and email engagement (opens, clicks).
We collect this information directly from you (when you fill in a form, create an account, buy something or contact us), automatically from your device when you use the website, and from the service providers listed below.
How we use your information
- To provide, operate and maintain the website.
- To create and manage your account.
- To process orders and payments, prevent fraud and send transaction receipts.
- To answer your questions and provide customer support.
- To understand how the website is used and improve it.
- To send newsletters or marketing emails you have signed up for. You can unsubscribe at any time using the link in each email.
- To show and measure advertising.
- To keep the website secure and to comply with our legal obligations.
Legal bases for processing (EEA and UK visitors)
We rely on the following legal bases under Article 6 of the GDPR:
- Contract: to provide the services you have asked for, such as your account or an order.
- Legitimate interests: to run, secure and improve the website, where these interests are not overridden by your rights. [Describe each legitimate interest you rely on.]
- Consent: for non-essential cookies, marketing emails and precise location. You can withdraw consent at any time without affecting processing that happened before.
- Legal obligation: to keep records required by tax, accounting or other laws.
How we share information
We do not share your personal information except as described here. We share it with service providers who process it on our behalf and only as needed to provide their services:
- Google Analytics, for website and app analytics (privacy policy: https://policies.google.com/privacy).
- Meta Pixel, for advertising measurement and retargeting (privacy policy: https://www.facebook.com/privacy/policy/).
- Stripe, for payment processing (privacy policy: https://stripe.com/privacy).
- PayPal, for payment processing (privacy policy: https://www.paypal.com/us/legalhub/privacy-full).
- Shopify, for online store hosting and checkout (privacy policy: https://www.shopify.com/legal/privacy).
- Mailchimp, for email newsletters (privacy policy: https://www.intuit.com/privacy/statement/).
We may also disclose information if required by law, to protect our rights or the safety of others, or as part of a merger, acquisition or sale of assets, in which case we will tell you before your information becomes subject to a different privacy policy.
Cookies and tracking technologies
We and our partners use cookies and similar technologies on the website. Some third parties, such as analytics and advertising providers, may collect information about your online activities over time and across different websites when you use the website. See our Cookie Policy for details and for how to change your choices.
Do Not Track and opt-out preference signals
We treat a Global Privacy Control (GPC) signal from your browser as a valid request to opt out of the sale or sharing of your personal information for that browser. There is no common industry standard for older "Do Not Track" (DNT) browser signals, and we [do / do not] respond to them. [Confirm how your site actually behaves.]
California privacy rights (CCPA / CPRA)
This section applies to California residents. In the preceding 12 months we have collected the following categories of personal information, as defined in the California Consumer Privacy Act:
| Category (CCPA) | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | name, email address, phone number | Service providers listed above |
| Identifiers; account log-in credentials (sensitive personal information) | username and password (stored hashed) | Service providers listed above |
| Commercial information | billing and shipping address, order history; card numbers are handled by our payment processor | Service providers listed above |
| Internet or other electronic network activity | pages or screens viewed, features used, clicks, referring page, time and date of visits | Service providers listed above |
| Identifiers; internet or network activity | IP address, browser type, operating system, device identifiers, crash logs | Service providers listed above |
| Internet or other electronic network activity | cookies, local storage, pixels and SDK identifiers | Service providers listed above |
| Identifiers; electronic information | the content of emails, chat and support requests you send us | Service providers listed above |
| Internet or other electronic network activity; inferences | newsletter subscription status and email engagement (opens, clicks) | Service providers listed above |
We do not sell your personal information and do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA.
You have the right to:
- Know what personal information we have collected about you, including the categories, sources, purposes and the categories of third parties we disclose it to, and to receive a copy of specific pieces of information.
- Delete personal information we collected from you, subject to certain exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information.
- Limit the use of sensitive personal information, where we use it for purposes beyond those allowed by the regulations.
- Not receive discriminatory treatment for exercising any of these rights.
To make a request, email [contact email]. We will verify your request by matching information you give us with information we hold. You may use an authorised agent to make a request on your behalf; we may ask for proof of the agent's authority.
We keep each category of personal information only as long as described under "How long we keep information".
Your rights under the GDPR (EEA and UK)
If you are in the European Economic Area or the United Kingdom, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to our processing, including processing based on legitimate interests and direct marketing;
- receive your data in a portable format;
- withdraw consent at any time, where we rely on consent.
To exercise these rights, contact [contact email]. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work, or where you believe an infringement occurred.
International transfers: our service providers may process data outside your country, including in the United States. Where we transfer personal data out of the EEA or UK, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses. [Confirm the transfer mechanism for each provider.]
Automated decisions: we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. [Edit if you do.]
Reviewing and changing your information
You can review and update the information in your account at any time from your account settings, or ask us to do it for you by email.
How long we keep information
We keep personal information as long as your account is active, and afterwards only as long as we need it for the purposes above or to meet legal, tax or accounting obligations.
How we protect information
We use reasonable administrative, technical and physical safeguards appropriate to the sensitivity of the information, including encryption in transit (HTTPS). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Children
The website is not directed to children under 13 (or under the age of digital consent in your country, which is between 13 and 16 in the EU), and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the "Effective date" below, and if the changes are significant we will notify you by email or by a notice on the website before they take effect.
Effective date
This Privacy Policy is effective as of [Effective date].