1. Information We Collect
We do our best to protect your sensitive personal information. We protect it by having SSL security installed on our website and by partnering with Shopify to process your credit card payments. Tiebreakerbowties.com collects information on you in two ways:
- The information that you manually provide when you place your order, such as your name, email address, postal address, payment information, and the details of the product that you’re ordering. You may also choose to provide us with additional personal information (for a custom order, for example), if you contact us directly. You may also provide your email when you complete a contact form or opt into our email newsletter list. This information can be tied directly to you because of the information you’ve provided.
- The information that’s automatically collected via our third-party partners: Shopify, Google Analytics, Mailchimp, Facebook, Instagram, Pinterest. The types of information collected here include things like what pages are visited on our website, where in the world you are located, the type of device you are using (desktop or mobile), what email campaigns you open, and how you opt-in. Generally, our third-party partners only give us this information in the aggregate (e.g. it’s not identifiable to you) but sometimes this information can be directly tied to you. For example, when you sign up for our email list, Mailchimp lets us know which emails you open and which links you click on.
We partner with Shopify to process your credit card payments, and therefore we never know your credit card number. Shopify encrypts your credit card data through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored with AES-256 encryption only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted. For more insight, you may also want to read Shopify’s Terms of Service or Privacy Statement.
2. Why We Need Your Information & How We Use It
We rely on a number of legal bases to collect, use, and share your information, including:
- as needed to provide our services, such as when we use your information to fulfil your order, to settle disputes, or to provide customer support;
- when you have provided your affirmative consent, which you may revoke at any time, such as by signing up for our mailing list;
- if necessary to comply with a legal obligation or court order or in connection with a legal claim, such as retaining information about your purchases if required by tax law; and
3. Information Sharing & Disclosure
Information about our customers is important to our business. We share your personal information for very limited reasons and in limited circumstances, as follows:
- Service providers. We engage certain trusted third parties to perform functions and provide services to our shop, such as delivery companies like USPS. We will share your personal information with these third parties, but only to the extent necessary to deliver the products or services you have requested.
- Business transfers. If we sell or merge our business, we may disclose your information as part of that transaction, only to the extent permitted by law.
- Compliance with laws. We may collect, use, retain, and share your information if we have a good faith belief that it is reasonably necessary to: (a) respond to legal process or to government requests; (b) enforce our agreements, terms and policies; (c) prevent, investigate, and address fraud and other illegal activity, security, or technical issues; or (d) protect the rights, property, and safety of our customers, or others.
4. Data Retention
5. Transfers of Personal Information Outside of the EU
As a US-based business, we store and process your information in the US. As a result, we transfer your personal information to the US, which may have different data protection and government surveillance laws than your jurisdiction. If you choose to use our services or order our products you recognize that we can’t provide these to you without moving your personal information to our business’s location.
6. Your Rights
If you reside in certain territories, including the EU, you have a number of rights in relation to your personal information. While some of these rights apply generally, certain rights apply only in certain limited cases. We describe these rights below:
- Access. You may have the right to access and receive a copy of the personal information we hold about you by contacting us using the contact information below.
- Change, restrict, delete. You may also have rights to change, restrict our use of, or delete your personal information. Absent exceptional circumstances (like where we are required to store data for legal reasons) we will generally delete your personal information upon request.
- Object. You can object to (i) our processing of some of your information based on our legitimate interests and (ii) receiving marketing messages from us after providing your express consent to receive them. In such cases, we will delete your personal information unless we have compelling and legitimate grounds to continue using that information or if it is needed for legal reasons.
- Complain. If you reside in the EU and wish to raise a concern about our use of your information (and without prejudice to any other rights you may have), you have the right to do so with your local data protection authority.
How to Contact Us
For purposes of EU data protection law, I, Katie Gloede, am the data controller of your personal information. If you have any questions or concerns, you may contact me at firstname.lastname@example.org. Alternately, you may mail me at:
15 Wainwright Cir. E, South Portland, ME 04106