Privacy Policy
Effective Date: 2025-09-011
At Prettygarden (prettygarden.store), we respect your privacy and are committed to protecting your personal data. This policy explains how we collect, use, and safeguard your information when you use our website, make purchases, or interact with our services, in compliance with the California Consumer Privacy Act (CCPA) and the EU General Data Protection Regulation (GDPR) for U.S. customers.
1. Data Controller
- Contact: support@prettygarden.store
2. Information We Collect
2.1 Personal Data You Provide
- Account Information: When creating an account, we collect your full name, email address, phone number, password (encrypted), and shipping/billing addresses (including ZIP codes for tax calculations).
- Purchase Data: For orders, we collect payment details (e.g., credit card number, expiry date, billing address), order history (e.g., “Faux Suede Bomber Jacket – Size M”), and size preferences (e.g., “prefers oversized fit”).
- Communications: Emails, contact form submissions, or chat messages, including your inquiries (e.g., “Does the knit sweater shrink?”) and our responses.
- Marketing Consent: If you opt in to emails/SMS, we store your consent to send promotions (e.g., “20% off faux leather jackets”) and new product alerts.
2.2 Automatically Collected Data
When you visit our website, we collect data via cookies, server logs, and tracking tools:
- Technical Data: IP address, browser type (e.g., Chrome, Safari), device model (e.g., iPhone 15, Windows laptop), operating system, screen resolution, and internet service provider.
- Usage Data: Pages visited (e.g., “Women’s Jackets,” “Knit Sweaters”), time spent on each page, links clicked (e.g., “Add to Cart” for a turtleneck), search queries (e.g., “waterproof faux leather jacket”), and the date/time of your visit.
- Location Data: City and state derived from your IP address (used to tailor delivery estimates and regional promotions, e.g., highlighting warm sweaters for colder states).
3. How We Use Your Data
We process your personal data for the following purposes, based on legal grounds (CCPA and GDPR):
| Purpose | Legal Basis |
|---|---|
| Process orders (shipping, payment, returns) | Performance of a contract (GDPR Art. 6(1)(b); CCPA “service provision”) |
| Manage your account (order tracking, saved sizes) | Performance of a contract (GDPR Art. 6(1)(b); CCPA “service provision”) |
| Send marketing communications (emails/SMS) | Your explicit consent (GDPR Art. 6(1)(a); CCPA “opt-in required”) |
| Improve website experience (e.g., optimizing “New Arrivals” page) | Legitimate business interest (GDPR Art. 6(1)(f); CCPA “business purposes”) |
| Detect fraud (e.g., unauthorized purchases of high-value jackets) | Legitimate business interest (GDPR Art. 6(1)(f); CCPA “fraud prevention”) |
| Comply with legal obligations (e.g., tax filings, consumer protection laws) | Legal obligation (GDPR Art. 6(1)(c); CCPA “legal compliance”) |
4. Sharing Your Data
We do not sell your personal data to third parties. We may share it with:
4.1 Service Providers
- Payment Processors: Stripe and PayPal, which handle payment processing. They receive only your payment details (e.g., card number) and are contractually required to protect your data.
- Shipping Partners: USPS and FedEx, which receive your name, address, and order details to deliver packages. Their privacy policies are available at USPS Privacy and FedEx Privacy.
- Analytics Tools: Google Analytics (tracks website usage) and Hotjar (records user interactions to improve UX). Google’s privacy practices are detailed here; Hotjar’s policy is here.
- Customer Service Platforms: Zendesk, which stores chat/email communications to resolve inquiries. Their privacy policy is here.
4.2 Legal Disclosures
We may share your data if required by law (e.g., subpoenas, tax audits) or to protect our rights (e.g., investigating fraudulent returns of $200+ jackets).
5. Cookies & Tracking
We use cookies to enhance your experience. You can manage preferences via our cookie banner (on the homepage) or browser settings:
- Strictly Necessary Cookies: Essential for checkout, account access, and cart functionality (cannot be disabled).
- Functional Cookies: Remember your preferences (e.g., saved shipping address, size filters) to personalize your experience.
- Analytics Cookies: Track website usage (e.g., which jackets are viewed most) to improve content and navigation.
- Marketing Cookies: Show you relevant ads (e.g., retargeting for a sweater you viewed) on social media or other sites. These require your consent and can be disabled via the cookie banner.
6. Data Retention
- Account Data: Retained while your account is active. You can delete your account via the “Account Settings” page, after which we erase your data (except order history required for tax purposes).
- Order Data: Retained for 7 years to comply with IRS and state tax laws.
- Marketing Data: Retained until you unsubscribe from emails/SMS (via the “Unsubscribe” link in messages).
7. Your Rights
Under CCPA :
- Right to Know: Request details about the personal data we collect, use, or disclose.
- Right to Delete: Request deletion of your data (subject to legal exceptions).
- Right to Opt-Out of Sales: While we do not sell data, you can submit a request via our CCPA Opt-Out Form.
Under GDPR :
- Right to access, rectify, or erase your data.
- Right to restrict processing or object to marketing.
To exercise these rights, email support@prettygarden.store with “Privacy Request” in the subject line. We’ll respond within 45 days (extendable by 45 days for complex requests).
8. Data Security
We use industry-standard measures to protect your data:
- Encryption of data in transit (SSL/TLS 1.3) and at rest (AES-256 encryption).
- Secure payment processing (PCI DSS compliance for credit card data).
- Regular security audits and employee training on data protection.
While no system is 100% secure, we take all reasonable steps to prevent breaches.
9. Changes to This Policy
We may update this policy annually or as needed to reflect legal changes. Updates will be posted here with a new effective date. Your continued use of the website constitutes acceptance of the revised policy.
For privacy inquiries, contact our Data Protection Officer at support@prettygarden.store.