Privacy Policy

By using this site, you declare that you are at least the age of majority in your province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.

How do you get my consent?

When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.

If we ask for your personal information for a secondary reason, like marketing, we will ask you directly for your expressed consent. Consent is usually in the form of an affirmative checkbox, or if you’ve met us in-person, we’ll have your verbal consent.

How do I withdraw my consent?

If after you opt-in you change your mind, you may withdraw your consent for us to contact you, or for us to store any of your information, at anytime, by contacting us.

If it’s just related to our marketing emails, you can opt-out using the link provided at the bottom of every marketing email we send you.

Right to data portability:

You have the right to have a full copy of all the data that we, and our partners hold on you. You just need to contact us for a copy. It may take a while to compile all the information due to the fragmented nature of our data-storage practices.

While you visit our site, we’ll track:

  • Products you’ve viewed: we’ll use this to, for example, show you products you’ve recently viewed
  • Location, IP address and browser type: we’ll use this for purposes like estimating taxes and shipping
  • Shipping address: we’ll ask you to enter this so we can, for instance, estimate shipping before you place an order, and send you the order!

We’ll also use cookies to keep track of cart contents while you’re browsing our site.

When you purchase from us, we’ll ask you to provide information including your name, billing address, shipping address, email address, phone number, credit card/payment details and optional account information like username and password. We’ll use this information for purposes, such as, to:

  • Send you information about your account and order
  • Respond to your requests, including refunds and complaints
  • Process payments and prevent fraud
  • Set up your account for our store
  • Comply with any legal obligations we have, such as calculating taxes
  • Improve our store offerings
  • Send you marketing messages, if you choose to receive them

If you create an account, we will store your name, address, email and phone number, which will be used to populate the checkout for future orders.

We generally store information about you for as long as we need the information for the purposes for which we collect and use it, and we are not legally required to continue to keep it. For example, we will store order information for 5 years for tax and accounting purposes. This includes your name, email address and billing and shipping addresses.

We will also store comments or reviews indefinitely, if you choose to leave them.

Even if you’ve opted out of receiving marketing emails from us, you still might receive essential service messages from us. Service messages include emails relating to your order, or if you’ve contacted one of the team about something, and we need your feedback.

In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.

However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.

For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.

In particular, remember that certain providers may be located in or have facilities that are located in a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.

We use Stripe for payment, analytics, and other business services. Stripe collects identifying information about the devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection. You can learn more about Stripe and read its privacy policy here.

We also send your personal (not financial) information to The Rocket Science Group LLC d/b/a MailChimp, a State of Georgia limited liability company. This means your information will be transmitted outside of the EU for the purpose of processing and storage, but we are still the Data Controller.

We also use Google Analytics in order to track your progress throughout our website. We anonymise your IP address, and take steps to remove any personally identifiable information from the service as soon as we are aware of its collection.

Security Logs

The IP address of visitors, user ID of logged in users, and username of login attempts are conditionally logged to check for malicious activity and to protect the site from specific kinds of attacks. Examples of conditions when logging occurs include login attempts, log out requests, requests for suspicious URLs, changes to site content, and password updates. This information is retained for 14 days.

Who we share your data with

This site is scanned for potential malware and vulnerabilities by Sucuri’s SiteCheck. We do not send personal information to Sucuri; however, Sucuri could find personal information posted publicly (such as in comments) during their scan. For more details, please see Sucuri’s privacy policy.

Where we send your data

This site is part of a network of sites that protect against distributed brute force attacks. To enable this protection, the IP address of visitors attempting to log into the site is shared with a service provided by ithemes.com. For privacy policy details, please see the iThemes Privacy Policy.

Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms of Service.

To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.

If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.

Who on our team has access?

Members of our team have access to the information you provide us. For example, both Administrators and Shop Managers can access:

  • Order information like what was purchased, when it was purchased and where it should be sent, and
  • Customer information like your name, email address, and billing and shipping information.

Our team members have access to this information to help fulfill orders, process refunds and support you. Access to this information is governed by our Data Access Policy, which is designed to protect your personal information.

We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.

If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.

21/7/17 – V1.0. Initial release.

17/08/17 – V1.1. Added a new payment provider, with outline of what services we use from them.

3/04/18 – V1.2. Added provisional GDPR language, including the right to be forgotten, and right to data portability. Customer data is processed outside of the EU.

17/04/18 – V1.2.1. Further GDPR rights added, language simplified.

24/04/18 – V2.0. Re-format of the privacy policy. Added section about service messages.

5/07/18 – V2.1. Clarified what information we collect and store.

18/11/18 – V2.1.1 Removed references to Crisp.

21/01/19 – V2.1.2 Added the usage of security network that protects site robustness.