Effective Date: January 01, 2026
1. Introduction
The Gilded Rack (“Company,” “we,” “our,” or “us”) is committed to protecting your privacy in compliance with applicable data protection laws, including the General Data Protection
Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
By using our website, you consent to the data practices described in this policy.
2. Information We Collect
We collect personal data necessary to provide our services.
a. Personal Data:
– Name
– Email address
– Phone number
– Billing and shipping address
– Payment information (processed securely via third-party providers)
b. Technical Data:
– IP address
– Browser type
– Device information
– Usage data
c. Cookies & Tracking:
We use cookies for analytics, personalization, and marketing. Users may control cookies via browser settings.
3. Legal Basis for Processing (GDPR)
We process your data under the following legal bases:
– Consent
– Contractual necessity
– Legal obligation
– Legitimate business interests
4. How We Use Your Information
– Order processing and fulfillment
– Customer communication
– Marketing (with consent)
– Fraud prevention and security
– Website optimization
5. Data Sharing
We do not sell personal data.
We may share data with:
– Payment processors (Stripe, Shopify Payments)
– Shipping carriers
– Marketing platforms (e.g., Klaviyo, Mailchimp)
– Analytics providers (e.g., Google Analytics)
All third parties are contractually obligated to protect your data.
6. International Data Transfers
Your data may be transferred and processed outside your jurisdiction. We ensure
appropriate safeguards such as Standard Contractual Clauses (SCCs).
7. Data Retention
We retain personal data only as long as necessary for:
– Legal obligations
– Business operations
– Dispute resolution
8. Your Rights (GDPR)
You have the right to:
– Access your data
– Correct inaccurate data
– Request deletion ("Right to be Forgotten")
– Restrict processing
– Data portability
– Withdraw consent
9. Your Rights (CCPA)
California residents have the right to:
– Know what personal data is collected
– Request deletion
– Opt-out of data selling (we do not sell data)
– Non-discrimination for exercising rights
To exercise rights: [Insert Contact Email]
10. Data Security
We implement industry-standard safeguards including encryption and secure servers.
However, no system is completely secure.
11. Children’s Privacy
We do not knowingly collect data from individuals under 13.
12. Third-Party Links
We are not responsible for third-party privacy practices.
13. Changes to This Policy
We may update this policy periodically. Updates will be posted with a revised effective date.
14. Contact Information
The Gilded Rack