Privacy Policy
We respect your privacy and are committed to protecting it. This Privacy Policy describes how shop.stephaniesmedbol.com (the “Site” or “we”) collects, uses, maintains, protects, and discloses your Personal Information when you visit or make a purchase from the Site. It also describes the choices available to you regarding our use of your Personal Information and how you can access and update it.
This Policy is a legally binding agreement between you (“User”, “you” or “your”) and Stephanie Smedbol Photography (“Stephanie Smedbol Photography”, “we”, “us” or “our”). If you are entering into this agreement on behalf of a business or other legal entity, you represent that you have the authority to bind such entity to this agreement, in which case the terms “User”, “you” or “your” shall refer to such entity. If you do not have such authority, or if you do not agree with the terms of this agreement, you must not accept this agreement and may not access and use the Site. By accessing and using the Site, you acknowledge that you have read, understood, and agree to be bound by the terms of this Policy. This Policy does not apply to the practices of companies that we do not own or control, or to individuals that we do not employ or manage.
Automated Collection of Information
When you open the Site, information that your browser sends is automatically recorded.
Examples of information collected: your device’s IP address, web browser type and version, operating system type and version, language preferences, time zone, webpage you were visiting before you came to the Site, cookie information, products and other pages of the Site you view, time spent on those pages, information you search for on the Site, access times and dates, and other statistics.
Purpose of collection: to load the Site accurately for you, to perform analytics on Site usage to optimize our Site, and to identify potential cases of abuse. This statistical information is not otherwise aggregated in such a way that would identify any particular User of the system.
Source of collection: Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels.
Disclosure for a business purpose: shared with our processor Shopify.
Collecting Personal Information
You can access and use the Site without telling us who you are or revealing any information by which someone could identify you as a specific, identifiable individual. If, however, you wish to use some of the features offered on the Site (for example, to make a purchase or to contact us for customer support), you may be asked to provide certain information that can uniquely identify an individual (“Personal Information”). We receive and store any information you knowingly provide to us when you create an account, make a purchase, or fill any forms on the Site. When required, this information may include the following:
Examples of Personal Information collected:
- Account details (including user name, unique user ID, password)
- Contact information (including email address, phone number, shipping address)
- Basic personal information (including name, country of residence)
- Payment information (including credit card details, billing address)
- Geolocation data of your device (such as latitude and longitude)
- Any other materials you willingly submit to us (such as articles, images, feedback)
Purpose of collection: to provide products or services to you to fulfill our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, to communicate with you, to provide customer support, to screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information relating to our products or services.
Source of collection: collected from you.
Disclosure for a business purpose: shared with our processor Shopify.
Privacy of Children
We do not knowingly collect any Personal Information from children under the age of 16. If you are under the age of 16, please do not submit any Personal Information through the Website and Services. If you have reason to believe that a child under the age of 16 has provided Personal Information to us through the Website and Services, please contact us to request that we delete that child’s Personal Information from our Services.
We encourage parents and legal guardians to monitor their children’s Internet usage and to help enforce this Policy by instructing their children never to provide Personal Information through the Website and Services without their permission. We also ask that all parents and legal guardians overseeing the care of children take the necessary precautions to ensure that their children are instructed to never give out Personal Information when online without their permission.
Managing Personal Information
You are able to delete certain Personal Information we have about you. The Personal Information you can delete may change as the Site changes. When you delete Personal Information, we may maintain a copy of the unrevised Personal Information in our records for the duration necessary to comply with our obligations to our affiliates and partners, and for the purposes described below. If you would like to delete your Personal Information or permanently delete your account, please contact us through the contact information below.
Sharing Personal Information
We share your Personal Information with service providers to help us provide our services and fulfill our contracts with you, as described above. Service providers are not authorized to use or disclose your information except as necessary to perform services on our behalf or comply with legal requirements. Service providers are given the information they need only in order to perform their designated functions, and we do not authorize them to use or disclose any of the provided information for their own marketing or other purposes.
|
Service Provider |
Description |
Privacy Policy |
|
Shopify |
We use Shopify to power our online store. |
|
| Shopify Payments |
We use the Shopify Payments service to transmit payment information to the Payment Processor, Stripe Payments Canada, Ltd |
We may also disclose any Personal Information we collect, use or receive if required or permitted by law, such as to comply with a subpoena or similar legal process, and when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
We do not sell your Personal Information to third parties for marketing purposes.
Using Personal Information
We may need to collect and use certain Personal Information in order to make the Site and services available to you or to meet a legal obligation. Any of the information we collect from you may be used for the following purposes:
- Create and manage user accounts
- Fulfill and manage orders
- Deliver products or services
- Improve products and services
- Respond to inquiries and offer support
- Request user feedback
- Improve user experience
- Enforce terms and conditions and policies
- Protect from abuse and malicious users
- Respond to legal requests and prevent harm
-
Run and operate the Site
GDPR Lawful Bases
Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the European Economic Area (“EEA”), we collect and process your Personal Information under the following lawful bases:
- Your consent;
- Performance of a contract between you and the Site;
- Compliance with our legal obligations;
- To protect your vital interests;
- To perform a task carried out in the public interest
Retention of Personal Information
When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. We may use any aggregated data derived from or incorporating your Personal Information after you update or delete it, but not in a manner that would identify you personally. For more information on your right of erasure, please see the ‘Your Rights’ section below.
Automated Decision-Making
If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.
We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.
Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.
Services that include elements of automated decision-making include:
- Temporary denylist of IP addresses associated with repeated failed transactions. This denylist persists for a small number of hours.
- Temporary denylist of credit cards associated with denylisted IP addresses. This denylist persists for a small number of days.
Your Rights
European Economic Area (“EEA”) Rights - GDPR
Consumers residing in the European Economic Area (“EEA”) are afforded certain data protection rights under the General Data Protection Regulation (“GDPR”), If you are an EEA resident, this section applies to you.
Data Protection Rights
We take steps to allow you to correct, amend, delete, or limit the use of your Personal Information. As a resident of the EEA, you have the following rights:
- the right to object to processing of your Personal Information and/or to withdraw consent you have previously given;
- the right to restrict the processing of your Personal Information under certain circumstances;
- the right to ask us to update and correct any inaccurate Personal Information that we hold about you;
- the right to prevent processing that is likely to cause damage or distress to you or anyone else;
- certain rights in relation to automated decision-making, including profiling;
- the right to request that we erase your Personal Information in certain circumstances ('Right to be Forgotten'), for example when data are no longer necessary for the purpose for which we collected them;
- the right to receive your Personal Information in a structured, commonly used, and machine-readable format and to have it transmitted to another data controller. This is known as 'Right to Data Portability'.
- the right to lodge a complaint with a data protection authority about our collection and use of your Personal Information, if you are not satisfied with the outcome of your complaint directly with us.
Transfer of Information
If you are a resident of the EEA, your Personal Information will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Shopify’s GDPR Whitepaper: https://help.shopify.com/en/manual/your-account/privacy/GDPR.
California Privacy Rights - CCPA
Consumers residing in California are afforded certain additional rights with respect to their Personal Information under the California Consumer Privacy Act (“CCPA”). If you are a California resident, this section applies to you.
California residents who provide Personal Information to obtain Services for personal, family, or household use are entitled to request and obtain from us, once a calendar year, information about the categories and specific pieces of Personal Information we hold about you (also known as the ‘Right to Know’). You have the right to to port your Personal Information to a new service and to ask that your Personal Information be corrected, updated, or erased.
How to Exercise Your Rights
Any requests to exercise your rights can be directed to us through the contact details provided in this document. Please note that we may ask you to verify your identity before responding to such requests. Your request must provide sufficient information that allows us to verify that you are the person you are claiming to be or that you are the authorized representative of such person.
Cookies
Our Site use “cookies” to help personalize your online experience. A cookie is a small amount of information that is downloaded to your computer or device when you visit our Site. Cookies cannot be used to run programs or deliver viruses to your computer. Cookies are uniquely assigned to you, and can only be read by a web server in the domain that issued the cookie to you. If you choose to decline cookies, you may not be able to fully experience the features of the Site.
We use a number of different cookies, including functional, performance, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.
We use the following cookies to optimize your experience on our Site and to provide our services.
Cookies Necessary for the Functioning of the Store
|
Name |
Function |
|
_ab |
Used in connection with access to admin |
|
_secure_session_id |
Used in connection with navigation through a storefront |
|
cart |
Used in connection with shopping cart |
|
cart_sig |
Used in connection with checkout |
|
cart_ts |
Used in connection with checkout |
|
checkout_token |
Used in connection with checkout |
|
secret |
Used in connection with checkout |
|
secure_customer_sig |
Used in connection with customer login |
|
storefront_digest |
Used in connection with customer login |
|
_shopify_u |
Used to facilitate updating customer account information |
Reporting and Analytics
|
Name |
Function |
|
_tracking_consent |
Tracking preferences |
|
_landing_page |
Track landing pages |
|
_orig_referrer |
Track landing pages |
|
_s |
Shopify analytics |
|
_shopify_s |
Shopify analytics |
|
_shopify_sa_p |
Shopify analytics relating to marketing & referrals |
|
_shopify_sa_t |
Shopify analytics relating to marketing & referrals |
|
_shopify_y |
Shopify analytics |
|
_y |
Shopify analytics |
The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.
You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.
Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as www.allaboutcookies.org
Data Analytics
We use Google Analytics to help us understand how our customers use the Site. The information gathered is used to compile statistical reports on User activity including how often Users visit our Site, what pages they visit and for how long. We use the information obtained from these analytics tools to monitor the performance and improve our Site. We do not use third-party analytics tools to track or to collect any personally identifiable information of our Users and we will not associate any information gathered from the statistical reports with any individual User.
You can read more about how Google uses your Personal Information here: https://policies.google.com/privacy?hl=en.You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
“Do Not Track” Signals
Some browsers incorporate a Do Not Track feature that signals to websites that you do not want to have your online activity tracked. Tracking is not the same as using or collecting information in connection with a website. For these purposes, tracking refers to collecting personally identifiable information from consumers who use or visit a website or online service as they move across different websites over time. How browsers communicate the Do Not Track signal is not yet uniform. As a result, the Site is not yet set up to interpret or respond to Do Not Track signals communicated by your browser.
Social Media Features
Our Site may include social media features, such as the Instagram and Twitter buttons or Share This buttons (collectively, “Social Media Features”). These Social Media Features may collect your IP address, what page you are visiting on our Site, and may set a cookie to enable Social Media Features to function properly. Social Media Features are hosted either by their respective providers or directly on our Site. Your interactions with these Social Media Features are governed by the privacy policy of their respective providers.
Links to Other Resources
The Site contains links to other resources that are not owned or controlled by us. Please be aware that we are not responsible for the privacy practices of such other resources or third parties. We encourage you to be aware when you leave the Site and to read the privacy statements of each resource that may collect Personal Information.
Information Security
We secure information you provide on computer servers in a controlled, secure environment, protected from unauthorized access, use, or disclosure. We maintain reasonable administrative, technical, and physical safeguards in an effort to protect against unauthorized access, use, modification, and disclosure of Personal Information in our control and custody. However, no data transmission over the Internet or wireless network can be guaranteed.
Therefore, while we strive to protect your Personal Information, you acknowledge that (i) there are security and privacy limitations of the Internet which are beyond our control; (ii) the security, integrity, and privacy of any and all information and data exchanged between you and the Site cannot be guaranteed; and (iii) any such information and data may be viewed or tampered with in transit by a third party, despite best efforts.
As the security of Personal Information depends in part on the security of the device you use to communicate with us and the security you use to protect your credentials, please take appropriate measures to protect this information.
Data Breach
In the event we become aware that the security of the Website and Services has been compromised or Users’ Personal Information has been disclosed to unrelated third parties as a result of external activity, including, but not limited to, security attacks or fraud, we reserve the right to take reasonably appropriate measures, including, but not limited to, investigation and reporting, as well as notification to and cooperation with law enforcement authorities. In the event of a data breach, we will make reasonable efforts to notify affected individuals if we believe that there is a reasonable risk of harm to the User as a result of the breach or if notice is otherwise required by law.
Acceptance of This Policy
You acknowledge that you have read this Policy and agree to all its terms and conditions. By accessing and using the Site and submitting your information you agree to be bound by this Policy. If you do not agree to abide by the terms of this Policy, you are not authorized to access or use the Site.
Changes and Amendments
We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons. When we do, we will revise the updated date at the bottom of this page. We may also provide notice to you in other ways, such as through the contact information you have provided.
An updated version of this Privacy Policy will be effective immediately upon the posting of the revised Policy unless otherwise specified. Your continued use of the Site after the effective date of the revised Policy will constitute your consent to those changes. We will not, without your consent, use your Personal Information in a manner materially different than what was stated at the time your Personal Information was collected.
Contact
For more information about our privacy practices, if you have any questions, or would like to make a complaint, please contact us by email using the Contact Form on the Site or by mail using the details provided below:
Stephanie Smedbol Photography, 74 Thistle Street, Dartmouth NS B3A2V8, Canada
This document was last updated on September 3, 2021