PRIVACY POLICY Complies with the European General Data Protection Regulation (GDPR)
The GDPR changes how personal data can be used, and also allows individuals to be able to find out what information organisations have about them, and to have that data deleted in certain circumstances.
This Privacy Policy describes how and when I collect, use, and share information when you purchase an item from me, contact me, or otherwise use my services through Etsy.com or its related sites and services.
This Privacy Policy does not apply to the practices of third parties that I do not own or control, including Etsy or any third party services you access through Etsy. You can reference the Etsy Privacy Policy to learn more about its privacy practices.
Information I Collect:
If you want place an order, purchase an item from my shop you have to provide certain information to me, and to do that, you must permit Etsy to gather your info, and then to pass it to me.
Because I do mail order sales to fulfil your order, you must provide me with certain information (which you authorised Etsy to provide to me), such as your name, postal address, email address, phone number and the details of the product that you’re ordering.
Your postal address and payment info are shared via e.g. the Etsy payment platform. You may also choose to provide me with additional personal information (for a custom order for example), by contacting me through a direct communication e.g. on Etsy.
Why I Need Your Information and How I Use It:
I rely on a number of legal bases to collect, use, and share your information, including:
- as required to provide my services, such as when I use your information to fulfil your order, to settle any dispute, or to provide your customer support
- if necessary to comply with any legal requirement or court order or in connection with a legal claim, like keeping information about your purchases if this is dictated by tax law in my country
- and as required for my legitimate interests, if those legitimate interests are not overridden by your rights or interests, like
a) providing and improving my services. I use your information to provide the services you requested and in my legitimate interest to improve my services.
b) compulsory conforming with e.g. the Etsy Seller Policy and Terms of Use, where your info is used as needed to comply with my responsibilities under the Etsy Seller Policy and Terms of Use.
Check also Etsy privacy policies, and their terms and conditions:
Etsy:
Privacy Policy: https://www.etsy.com/legal/privacy/
Terms Of Use: https://www.etsy.com/legal/terms-of-use
Information Sharing and Disclosure:
Information about my customers is super-precious and its security is an absolute priority in my business. I share your personal information for very few, limited reasons and only in limited circumstances, as follows:
- Etsy. I share information with Etsy as necessary to provide you my services and comply with my obligations under both the Etsy Seller Policy and Etsy Terms of Use.
- Service providers. I engage certain trusted third parties to carry out services for my Etsy shop, such as:
- post office / delivery companies. I will share your personal information (e.g. your postal address with phone number) with these third parties, but only as needed to perform the services that you have requested, and with the knowing that they are reliable business folks.
- professional accountants to fulfil my tax obligations. I will share your personal information with these third parties, but only to the extent necessary to perform these services.
- Closing of my business: If I ever give up working and close any or all of my businesses, I may disclose your info to government bodies (e.g. for taxing purposes), but only in the limited capacity that the law (in Great Britain) demands.
- Compliance with laws. I may collect, use, retain, and share your information if I have a good faith belief that it is reasonably necessary to:
a) respond to legal process or to government requests;
b) enforce my agreements, terms and policies;
c) prevent, investigate, and address fraud and other illegal activity, security, or technical issues; or
d) protect the rights, property, and safety of my customers, or others.
Data Retention:
I retain your personal information only for as long as it’s absolutely necessary to provide you with my services and as described in my Privacy Policy. However, I may also be obligated to retain this information to comply with my legal and regulatory requirements, to resolve disputes, and to enforce my contracts or agreements. I generally keep your data for up to 7 years (as required by UK tax law), after which your data is erased or otherwise destroyed.
Transfers of Personal Information Outside the EU:
I may store and process your information through third-party hosting services in the US and other jurisdictions. As a result, I may transfer your personal information to a jurisdiction with different data protection and government surveillance laws than your jurisdiction. If I am deemed to transfer information about you outside of the EU, I rely on Privacy Shield as the legal basis for the transfer, as Google Cloud is Privacy Shield certified.
Your Rights:
If you reside in certain territories, including European Union, you have a number of rights in relation to your personal information. Some of the rights are general, but certain rights apply only in a very few specific situations, like in these outlined below:
a) Access: You have the right to access and ask for a copy of the personal information that I have of yours, by contacting me directly using the contact information below .
b Change, restrict, delete: You also have rights to change and/ or restrict my use of and/ or to have your personal info fully deleted. Apart from exceptional circumstances (such as where I am required to store data for legal reasons). I will generally delete your personal information fully, as per your request.
c) Objections: You might object to (i) my processing of some of your information based on my legitimate interests and (ii) receiving marketing messages from me, even after giving me your clear consent to be given them. In such cases, I’ll delete your personal data, unless I have compelling and legitimate grounds to keep using the data, or if it’s required of my to keep it for legal reasons.
d) Complain. If you reside in the EU and want to raise a genuine issue about my use of your information (and without prejudice to any other rights you may have), you absolutely have the right to do this with your local data protection authority.
HOW TO CONTACT ME:
For purposes of EU data protection law, I, HaBe, am the data controller of your personal information. If you have any questions or concerns, please contact me at: blazej.wojtasik [!at] gmail.com. You are welcome also to write to me at this address: HaBe LTD, Suite 18 Equity Chambers, 249 High Street North, Poole BH15 1DX, Great Britain