Information I Collect:
In order to complete your order, it's necessary to furnish specific information (which you've authorized Etsy to share with me), including your name, email address, mailing address, payment details, and specifics about the product you intend to purchase. Optionally, you may decide to share extra personal details (such as for a personalized invitation order) by reaching out to me directly.
I employ various lawful grounds to gather, utilize, and disclose your information, including:
•Service Provision: Your information is crucial to deliver my services, like order fulfillment, dispute resolution, and customer assistance.
•Affirmative Consent: When you willingly provide consent, which you can withdraw anytime, for instance, by subscribing to my mailing list.
•Legal Compliance and Obligations: When needed to adhere to legal requirements or court orders, or in association with a legal claim, such as retaining purchase information in line with tax laws.
•Legitimate Interests: To serve my legitimate interests, provided they do not outweigh your rights or interests. This involves 1) enhancing and offering better services based on your needs, and 2) Complying with Etsy Seller Policy and Terms of Use, fulfilling my responsibilities accordingly.
Safeguarding the information about my customers is a priority for my business. I share your personal data under specific and limited circumstances, as outlined below:
•Etsy: Sharing information with Etsy is essential to provide you with my services and uphold my responsibilities as stated in both the Etsy Seller Policy and Etsy Terms of Use.
•Service Providers: Trusted third-party service providers are occasionally engaged to carry out specific functions and services for my shop, such as delivery companies. Your personal information will be shared with these third parties only to the extent necessary for them to perform these services.
•Business Transactions: In the event of a sale or merger of my business, I may disclose your information as part of that transaction, complying with the extent allowed by law.
•Legal Compliance: Your information may be collected, used, retained, and shared if there is a genuine belief, in good faith, that it is reasonably necessary to: (a) respond to legal processes or government requests; (b) enforce my agreements, terms, and policies; (c) prevent, investigate, and address fraud, other unlawful activities, security, or technical issues; or (d) protect the rights, property, and safety of my customers or others.
Retention of Data:
I hold onto your personal information only for the duration required to offer my services as outlined in my Privacy Policy. Nevertheless, I may need to retain this data to adhere to legal and regulatory requirements, settle disputes, and enforce agreements. Typically, I maintain your data for a period of 4 years.
Transfers of Personal Information Outside the EU:
I may store and process your information through third-party hosting services in the US and other jurisdictions. As a result, I may transfer your personal information to a jurisdiction with different data protection and government surveillance laws than your jurisdiction. If I am deemed to transfer information about you outside of the EU, I rely on Privacy Shield as the legal basis for the transfer, as Google Cloud is Privacy Shield certified.
Your Entitled Rights:
For individuals residing in specific regions, including the EU, various rights pertain to your personal information. While some of these rights are applicable universally, certain rights are limited and apply in specific circumstances. I outline these rights below:
•Access: You possess the right to access and obtain a copy of the personal information I have on record about you. Feel free to reach out to me using the contact details provided below to exercise this right.
•Modify, Limit, Erase: You also have the right to modify, limit my use of, or request the deletion of your personal information. Unless there are exceptional circumstances, such as legal data retention requirements, I will typically erase your personal information upon request.
•Objection: You can voice your objection to (i) my processing of certain aspects of your information based on my legitimate interests and (ii) receiving marketing communications from me after granting explicit consent to receive them. In such instances, I will delete your personal information unless I have compelling and legitimate reasons to continue using it, or if legal obligations necessitate its retention.
•Lodge a Complaint: If you reside in the EU and wish to express concerns about how I handle your information (without affecting any other rights you may have), you have the right to lodge a complaint with your local data protection authority.
For purposes of EU data protection law, I, Simply Smitten Designs, am the data controller of your personal information. If you have any questions or concerns, you may contact me at simplysmittendesigns@gmail.com. Thank you.