Information We Collect From You
In order to fulfil your order, you have authorised Etsy to provide us with certain information, including your name, email address, postal address, payment information, and details relating to the product you are ordering. You may also choose to provide us with additional personal information for custom and personalised orders when you contact us directly.
Why I Need Your Information and How I Use It
We rely on a number of legal bases to collect, use, and share your information, including:
as needed to provide our services, such as when we use your information to fulfil your order, to settle disputes, or to provide customer support
when you provide affirmative consent, such as by signing up to our mailing list - such consent can be revoked at any time
to comply with a legal obligation or court order, where necessary, or in connection with a legal claim, such as retaining information regarding your purchases if required by tax law
as necessary for the purpose of our legitimate interests, if those legitimate interests are not overridden by your rights or interests. For example:
i) We use your information to provide the services you requested and in the legitimate interest of improving our services, and
ii) As necessary, we use your information to comply with our obligations under the Etsy Seller Policy and Terms of Use.
Sharing and Disclosure of Information
Information about our customers is very important to our business. In very limited circumstances we may share your personal information, as follows:
Etsy - we share information with Etsy as necessary to provide you our services and comply with our obligations under both the Etsy Seller Policy and Etsy Terms of Use
Service providers - we may engage certain trusted third parties to perform functions and provide services to our shop, e.g. delivery companies. We may share your personal information with these third parties, but only to the extent necessary to perform such duties
Business transfers - in the unlikely scenario that we sell or merge our business, we may disclose your information as part of that transaction [although only ever to the extent permitted by law]
Compliance with laws - we may collect, use, retain, and share your information if we have good reason to believe that it is necessary to either (i) respond to legal processes or government requests, (ii) enforce agreements, terms or policies, (iii) prevent, investigate, or address fraud or other illegal activity, security, or technical issues, or (d) protect the rights, property, and safety of our customers or others
Data Retention
We retain your personal information only for as long as necessary to provide you with our services and as described in our Privacy Policy. We may, however, also, be required to retain this information to comply with legal and regulatory obligations, to resolve disputes, and to enforce any agreements we may have. As a result of the above, we generally keep your data for a period of 4 years.
Transfers of Personal Information Outside the EU
We may store and process your information through third-party hosting services in the US and other jurisdictions. As a result, we may transfer your personal information to a jurisdiction with different data protection and government surveillance laws than your jurisdiction. If we are deemed to transfer information about you outside of the EU, we rely on Privacy Shield as the legal basis for the transfer, as Dropbox is Privacy Shield certified.
Your Rights
If you reside in certain territories, including the EU, you have a number of rights in relation to your personal information. While some of these rights apply generally, certain rights apply only in certain limited cases. These rights are described below:
Access - You have the right to access and receive a copy of the personal information we hold about you by contacting us using the contact information below.
Change, restrict, delete - you also have the right to change, restrict our use of, or delete your personal information. Outside of exceptional circumstances, (such as where we are required to store data for legal reasons), we will generally delete your personal information upon request.
Object - you can object to (i) us processing certain aspects of your information on the basis of our legitimate interests and (ii) receiving marketing messages from us after providing your express consent to receive them. In such cases, we will delete your personal information unless we have compelling and legitimate grounds to continue using that information, or if it is needed for legal reasons.
Complain - if you reside in the EU and wish to raise a concern about our use of your information you have the right to do so with your local data protection authority (without prejudice to any other rights you may have).
How to Contact Us
For the purposes of EU data protection law, I, Catherine Earles, am the data controller of your personal information. If you have any questions or concerns, you may e-mail or write to me personally at:
Catherine Earles
Strmec pri svetem florijanu 31,
Rogatec, 3252, Slovenija
catherinejenniferearles@gmail.com