How we use your personal information
Our Privacy Promise
To keep your data safe and private.
Not to sell your data.
To give you ways to manage and review your marketing choices at any time.
Our policy complies with UK law, including that required by the EU General Data Protection Regulation (GDPR).
SECTION 1 - The bases on which we process information about you.
The law requires us to determine under which of six defined bases we process different categories of your personal information, and to notify you of the basis for each category.
If a basis on which we process your personal information is no longer relevant then we shall immediately stop processing your data.
If the basis changes then if required by law we shall notify you of the change and of any new basis under which we have determined that we can continue to process your information.
1.1. Information we process because we have a contractual obligation with you.
When you create an account on our website, buy a product from us, or otherwise agree to our terms and conditions, a contract is formed between you and us. As part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.
In order to carry out our obligations under that contract we must process the information you give us.
We may use it in order to:
- verify your identity for security purposes
- sell products to you
- provide you with our services
- provide you with suggestions and advice on products, services and how to obtain the most from using our website
We process this information on the basis there is a contract between us.
When you browse our store, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.
1.2. Information we process with your consent
Through certain actions when you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
When otherwise there is no contractual relationship between us, such as when you browse our website or ask us to provide you more information about our business, products and services, you provide your consent to us to process information that may be personal information.
Sometimes you might give your consent implicitly, such as when you send us a message by e-mail to which you would reasonably expect us to reply.
With your permission, we may send you emails about our store, new products and other updates.
Except where you have consented to our use of your information for a specific purpose, we do not use your information in any way that would identify you personally. We may aggregate it in a general way and use it to provide information, for example to monitor the performance of a particular page on our website.
If you have given us explicit permission to do so, we may from time to time pass your name and contact information to selected associates whom we consider may provide services or products you would find useful.
We continue to process your information on this basis until you withdraw your consent or it can be reasonably assumed that your consent no longer exists.
You may withdraw your consent at any time.
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at email@example.com.
However, if you do so, you may not be able to use our website or our services further.
1.3. Information we process for the purposes of legitimate interests.
We may process information on the basis there is a legitimate interest, either to you or to us, of doing so.
Where we process your information on this basis, we do after having given careful consideration to:
- whether the same objective could be achieved through other means;
- whether processing (or not processing) might cause you harm;
- whether you would expect us to process your data, and whether you would, in the round, consider it reasonable to do so.
For example, we may process your data on this basis for the purposes of:
- record-keeping for the proper and necessary administration of our business;
- responding to unsolicited communication from you to which we believe you would expect a response;
- protecting your interests where we believe we have a duty to do so.
SECTION 2 - Disclosure
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
SECTION 3 - Specific uses of information you provide to us.
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
3.3 Email marketing
SECTION 4 – Sharing your information with third-party services
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
SECTION 5 - Security
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
SECTION 6 - Cookies
Cookies are small text files that are placed on your computer's hard drive by your web browser when you visit any website. They allow information gathered on one web page to be stored, allowing a website to provide you with a personalised experience and the website owner with statistics about how you use the website so that it can be improved.
Some cookies may last for a defined period of time, such as one day or until you close your browser. Others last indefinitely.
Your web browser should allow you to delete any you choose. It also should allow you to prevent or limit their use.
Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
SECTION 7 – Age of Consent
We do not sell products or provide services for purchase by children, nor do we market to children.
If you are under 18, you may use our website only with consent from a parent or guardian.
We collect data about all users of and visitors to these areas regardless of age, and we anticipate that some of those users and visitors will be children.
Such child users and visitors will inevitably visit other parts of the site and will be subject to whatever on-site marketing they find, wherever they visit.
SECTION 8 - Access to your own information
Access to your personal information.
8.1. At any time you may review or update personally identifiable information that we hold about you, by signing in to your account on our website.
8.2. To obtain a copy of any information that is not provided on our website you may send us a request at firstname.lastname@example.org.
8.3. After receiving the request, we will tell you when we expect to provide you with the information, and whether we require any fee for providing it to you.
8.4. Removal of your information.
If you wish us to remove personally identifiable information from our website, you may contact us at email@example.com.
This may limit the service we can provide to you.
8.5. Verification of your information.
When we receive any request to access, edit or delete personal identifiable information we shall first take reasonable steps to verify your identity before granting you access or otherwise taking any action. This is important to safeguard your information.
SECTION 9 - Retention period for personal data
Except as otherwise mentioned in this privacy notice, we keep your personal information only for as long as required by us:
- to provide you with the services you have requested;
- to comply with other law, including for the period demanded by our tax authorities.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
SECTION 11 – Questions and contact information
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at firstname.lastname@example.org or by mail at
Mom's Own Milk Ltd
[Re: Privacy Compliance Officer]