Privacy policy
1. What personal data I collect:
In order for me to process your order, you must provide me with certain information (which you have authorized Shopify to provide to me). This includes your name, email address, mailing address, payment information, and details about the product you are ordering. You also have the option to provide me with other personal information (for example, for customizing acrylic tools) by contacting me directly.
2. What legal bases I use to collect, use and share personal data
I rely on a number of legal bases to collect, use and share your information.
Namely:
• to the extent that I need your information to provide my services, for example to process your order, resolve disputes or provide customer support;
• if it is necessary to comply with a legal obligation or court order, or in connection with legal claims, such as the need to retain information about your purchases due to tax legislation; and
• as necessary for the purposes of my legitimate interests – provided that these legitimate interests are not overridden by your rights or interests – for example to provide and improve my services.
I use your information to provide the services you have requested from me and in my legitimate interest to improve my services
3. To which third parties I pass on personal data
sharing and disclosure of information
Customer data is important to my business. I only share your personal information for specific reasons and under specific circumstances, as follows:
• Shopify: I share information with Shopify as necessary to fulfill my obligations under the Seller Policy and Terms of Service.
• Service providers: I commission certain trusted third parties to carry out tasks and provide services for my shop, such as parcel services. I pass on your personal data to these third parties, but only to the extent that it is necessary to carry out these services.
• Business Transfers: If I sell my business or merge with another, I may disclose your information as part of that transaction, to the extent permitted by law.
• Compliance with Laws: I may collect, use, retain and disclose your information if I have a good faith belief that doing so is appropriate and necessary to:
(a) to respond to legal process or regulatory requests;
b) enforce my agreements, terms and policies;
c) prevent, investigate and address fraud and other unlawful activities, security or technical issues, or
d) protect the rights, property and safety of my customers or others.
4. How long I store personal data
data retention
I will only retain your personal information for as long as necessary to provide you with my services and as described in my Privacy Policy. However, I may need to retain this information to comply with legal obligations and regulations, resolve disputes, and enforce my agreements.
In general, I keep your data for the following period: 4 years.
5. If I transfer personal data to countries outside Europe: how this transfer is carried out
Transfer of personal data to countries outside the EU
I may store and process your information through third-party hosting services in the United States and other countries. As a result, I may transfer your personal information to countries that have laws regarding data protection and regulatory oversight that differ from the corresponding laws in your country. If I am likely to transfer information about you outside the EU, I rely on the EU-US Privacy Shield as the legal basis for the transfer, as Google Cloud is EU-US Privacy Shield certified.
6. What rights my buyers have regarding the use of their personal data, as well as my contact details
Your rights:
If you live in certain regions, including the EU, you have a number of rights in relation to your personal data. Some of these rights apply generally, and others apply only in specific cases. These rights are described below:
• Access: You may have the right to access and obtain a copy of the personal information I hold about you by contacting me using the contact information below.
• Modification, restriction, deletion: You may also have the right to modify your personal data, restrict my use of that data, or delete it. Except in exceptional circumstances (such as when I need to retain data for legal reasons), I will generally delete your personal data upon request.
• Objection: You can object to this,
1. that I process some of your data in view of my legitimate interests and
2. that you receive marketing messages from me after you have expressly consented to this beforehand. In such cases, I will delete your personal data unless I can demonstrate compelling legitimate grounds for its continued use or it is required for legal reasons.
• Complaint: If you reside in the EU and have concerns about my use of your data – without prejudice to any other rights you may have – you have the right to contact your local data protection authority with these concerns.
How to contact me
For purposes of EU data protection law, I, Mira Stadler, am the data controller of your personal data. If you have any questions or concerns, you can contact me here.
In order for me to process your order, you must provide me with certain information (which you have authorized Shopify to provide to me). This includes your name, email address, mailing address, payment information, and details about the product you are ordering. You also have the option to provide me with other personal information (for example, for customizing acrylic tools) by contacting me directly.
2. What legal bases I use to collect, use and share personal data
I rely on a number of legal bases to collect, use and share your information.
Namely:
• to the extent that I need your information to provide my services, for example to process your order, resolve disputes or provide customer support;
• if it is necessary to comply with a legal obligation or court order, or in connection with legal claims, such as the need to retain information about your purchases due to tax legislation; and
• as necessary for the purposes of my legitimate interests – provided that these legitimate interests are not overridden by your rights or interests – for example to provide and improve my services.
I use your information to provide the services you have requested from me and in my legitimate interest to improve my services
3. To which third parties I pass on personal data
sharing and disclosure of information
Customer data is important to my business. I only share your personal information for specific reasons and under specific circumstances, as follows:
• Shopify: I share information with Shopify as necessary to fulfill my obligations under the Seller Policy and Terms of Service.
• Service providers: I commission certain trusted third parties to carry out tasks and provide services for my shop, such as parcel services. I pass on your personal data to these third parties, but only to the extent that it is necessary to carry out these services.
• Business Transfers: If I sell my business or merge with another, I may disclose your information as part of that transaction, to the extent permitted by law.
• Compliance with Laws: I may collect, use, retain and disclose your information if I have a good faith belief that doing so is appropriate and necessary to:
(a) to respond to legal process or regulatory requests;
b) enforce my agreements, terms and policies;
c) prevent, investigate and address fraud and other unlawful activities, security or technical issues, or
d) protect the rights, property and safety of my customers or others.
4. How long I store personal data
data retention
I will only retain your personal information for as long as necessary to provide you with my services and as described in my Privacy Policy. However, I may need to retain this information to comply with legal obligations and regulations, resolve disputes, and enforce my agreements.
In general, I keep your data for the following period: 4 years.
5. If I transfer personal data to countries outside Europe: how this transfer is carried out
Transfer of personal data to countries outside the EU
I may store and process your information through third-party hosting services in the United States and other countries. As a result, I may transfer your personal information to countries that have laws regarding data protection and regulatory oversight that differ from the corresponding laws in your country. If I am likely to transfer information about you outside the EU, I rely on the EU-US Privacy Shield as the legal basis for the transfer, as Google Cloud is EU-US Privacy Shield certified.
6. What rights my buyers have regarding the use of their personal data, as well as my contact details
Your rights:
If you live in certain regions, including the EU, you have a number of rights in relation to your personal data. Some of these rights apply generally, and others apply only in specific cases. These rights are described below:
• Access: You may have the right to access and obtain a copy of the personal information I hold about you by contacting me using the contact information below.
• Modification, restriction, deletion: You may also have the right to modify your personal data, restrict my use of that data, or delete it. Except in exceptional circumstances (such as when I need to retain data for legal reasons), I will generally delete your personal data upon request.
• Objection: You can object to this,
1. that I process some of your data in view of my legitimate interests and
2. that you receive marketing messages from me after you have expressly consented to this beforehand. In such cases, I will delete your personal data unless I can demonstrate compelling legitimate grounds for its continued use or it is required for legal reasons.
• Complaint: If you reside in the EU and have concerns about my use of your data – without prejudice to any other rights you may have – you have the right to contact your local data protection authority with these concerns.
How to contact me
For purposes of EU data protection law, I, Mira Stadler, am the data controller of your personal data. If you have any questions or concerns, you can contact me here.