Privacy Policy
Effective Date: March 11, 2026
Brand: ARTMOONS
This Privacy Policy (“Policy”) explains how ARTMOONS (“we,” “us,” or “our”) collects, uses, stores, and protects your personal information when you access or use our website (the “Site”), products, or services (collectively, the “Services”). We comply with the General Data Protection Regulation (GDPR) for users in the European Union (EU)/European Economic Area (EEA) and the California Consumer Privacy Act (CCPA) for users in California, as well as other applicable data protection laws in the United States and Europe. By using the Services, you consent to our data practices as described in this Policy.
1. Information We Collect
We collect personal information you voluntarily provide, as well as automatic data from your use of the Services—all to improve your experience and deliver our products.
1.1 Personal Information You Provide
- Contact Details: Name, email address, phone number, shipping/billing address.
- Payment Information: Credit/debit card details, billing address (processed securely via third-party payment providers like Shopify Payments, Stripe—we do not store full payment card data).
- Account Information: Username, password (encrypted), and preferences (e.g., size, style preferences, communication opt-ins).
- Other: Information you share via contact forms, customer support chats, social media interactions, or feedback (e.g., product reviews, fit photos, collection ideas).
1.2 Automatically Collected Information
- Device & Usage Data: Browser type (e.g., Microsoft Edge, Google Chrome), device model, operating system, IP address, referring URL, pages visited, time spent on the Site, and click-through patterns.
- Cookies & Similar Technologies: We use cookies (small text files stored on your device) and web beacons to enhance functionality (e.g., remembering your cart), analyze traffic, and personalize content. You can manage cookie preferences via your browser settings (see Section 6 for details).
- Location Data: Approximate geographic location derived from your IP address (used only to optimize shipping, currency, and regional content).
2. How We Use Your Information
We use your personal information for legitimate business purposes, always aligned with your expectations and legal requirements:
- Fulfill Orders: Process, package, and ship your purchases; send order confirmations, tracking updates, and delivery notifications.
- Provide Customer Support: Respond to your questions, resolve issues, and assist with returns/exchanges.
- Improve the Services: Analyze usage trends, test website features (compatible with major browsers like Edge and Chrome), and enhance product design, functionality, and user experience.
- Personalize Your Experience: Recommend products based on your preferences, display content in your preferred language/currency, and remember your account settings.
- Communicate With You: Send marketing emails (e.g., new collections, exclusive offers) if you opt in; notify you of policy updates or service changes.
- Prevent Fraud & Ensure Security: Verify payment information, detect unauthorized access, and protect against fraudulent activities.
- Comply With Legal Obligations: Fulfill tax, shipping, and regulatory requirements in the U.S. and EU/EEA.
3. Legal Basis for Processing (GDPR Compliance)
For EU/EEA users, we process your personal information only when we have a valid legal basis under the GDPR:
- Consent: When you opt in to marketing communications or share information voluntarily (e.g., feedback).
- Performance of a Contract: To fulfill your orders or provide services you request.
- Legitimate Interest: To improve the Services, prevent fraud, or communicate with you about your account (we ensure your interests do not override ours).
- Legal Obligation: To comply with tax, customs, or other regulatory requirements.
4. How We Share Your Information
We never sell your personal information to third parties for marketing purposes. We may share your data only in the following limited circumstances:
- Third-Party Service Providers: Vendors who help us operate the Services (e.g., payment processors, shipping carriers like DHL/UPS, email marketing platforms, analytics tools like Google Analytics). These providers are bound by contracts to protect your data and use it only to perform services for us.
- Legal Compliance: If required by law, court order, or government request (e.g., to respond to a subpoena or prevent harm).
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new owner (we will notify you of such a transfer and ensure compliance with this Policy).
- With Your Consent: When you explicitly agree to share (e.g., posting a public product review with your name).
5. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Policy, or as required by law:
- Order & Account Data: Retained for 7 years to comply with tax and legal obligations, and to handle future returns/exchanges.
- Marketing Data: Retained until you opt out of communications (you can unsubscribe anytime via email links or your account settings).
- Automatically Collected Data: Retained for 12 months for analytics purposes, then anonymized (no longer linked to your identity).
Once retention periods expire, we securely delete or anonymize your data to prevent reconstruction.
6. Cookies & Browser Compatibility
We use cookies to ensure the Site works seamlessly across major browsers (Microsoft Edge, Google Chrome, Safari, Firefox) and to enhance your experience. You can manage cookie preferences through your browser settings:
6.1 Types of Cookies We Use
- Necessary Cookies: Essential for the Site to function (e.g., remembering your cart, enabling checkout). These cannot be disabled without breaking core features.
- Analytics Cookies: Track usage patterns (e.g., Google Analytics) to improve the Site’s performance and compatibility with browsers.
- Functional Cookies: Remember your preferences (e.g., language, currency) for a personalized experience.
- Marketing Cookies: Used to deliver targeted ads (if you opt in) on the Site or third-party platforms (e.g., Instagram, Facebook).
6.2 Managing Cookies
- Microsoft Edge: Go to Settings > Cookies and site permissions > Manage and delete cookies and site data.
- Google Chrome: Go to Settings > Privacy and security > Cookies and other site data.
- Other Browsers: Refer to your browser’s help center for cookie management instructions.
Disabling non-necessary cookies may limit some features (e.g., personalized recommendations) but will not prevent you from purchasing products.
7. Your Data Rights
7.1 Rights for EU/EEA Users (GDPR)
You have the following rights, which you can exercise by contacting us (see Section 10):
- Right to Access: Request a copy of the personal information we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your data (if no legal obligation to retain it).
- Right to Restriction of Processing: Ask us to limit how we use your data (e.g., if you dispute its accuracy).
- Right to Data Portability: Receive your data in a structured, machine-readable format (to transfer to another provider).
- Right to Object: Opt out of processing based on legitimate interests (e.g., marketing communications).
- Right to Withdraw Consent: Revoke consent for marketing or other optional data uses (without affecting prior processing).
7.2 Rights for U.S. Users (CCPA & State Laws)
California residents have the following rights under the CCPA:
- Right to Know: Request details about the personal information we collect, use, or disclose.
- Right to Delete: Request deletion of your personal information (subject to exceptions like legal retention).
- Right to Opt-Out of Sale/Sharing: We do not sell your data, but you can opt out of any future data sharing (if applicable) via your account.
- Right to Non-Discrimination: We will not treat you differently for exercising your privacy rights.
Other U.S. states (e.g., Virginia, Colorado) may have similar rights—contact us for state-specific requests.
8. Data Security
We implement industry-standard security measures to protect your data from unauthorized access, disclosure, or misuse:
- Encryption of data in transit (SSL/TLS) and at rest.
- Secure storage via Shopify’s compliant servers (ISO 27001 certified).
- Regular security audits and updates to protect against browser-related vulnerabilities.
- Restricted access to personal information (only authorized staff can access data for business purposes).
While we strive to protect your data, no online transmission is 100% secure—we cannot guarantee absolute security. You are responsible for keeping your account password confidential.
9. Third-Party Links
The Site may contain links to third-party websites (e.g., social media, payment providers). This Policy does not apply to their practices—we recommend reviewing the privacy policies of any third-party sites you visit.
10. Policy Updates
We may update this Policy from time to time to reflect legal changes or business updates. We will notify you of material changes by:
- Posting the revised Policy on the Site with a new effective date.
- Sending an email to your registered address (for significant changes).
Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.