Privacy policy

This Privacy Policy describes how giafernandez.co.uk (the “Site” or “we”) collects, uses, and discloses your Personal Information when you visit or make a purchase from the Site.

Collecting Personal Information

When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information that can uniquely identify an individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.

Device information

  • Examples of Personal Information collected: version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.
  • Purpose of collection: to load the Site accurately for you, and to perform analytics on Site usage to optimize our Site.
  • Source of collection: Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels.
  • Disclosure for a business purpose: shared with our processor Shopify and relevant production partners.

Order information

  • Examples of Personal Information collected: name, billing address, shipping address, payment information (including credit card numbers, email address, and phone number.
  • Purpose of collection: to provide products or services to you to fulfill our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
  • Source of collection: collected from you.
  • Disclosure for a business purpose: shared with our processor Shopify.

Enquiry information

  • Examples of Personal Information collected: name, email address and telephone number.
  • Purpose of collection: to provide you with information about our products or services to answer your enquiry.
  • Source of collection: collected from you.

Customer support information

  • Purpose of collection: to provide customer support.
  • Source of collection: collected from you.

Minors

The Site is not intended for individuals under the age of 18. We do not intentionally collect Personal Information from children. If you are the parent or guardian and believe your child has provided us with Personal Information, please contact us at the address below to request deletion.

Sharing Personal Information

We may sometimes contract with third parties to supply products and services to you on our behalf. These may include payment processing, delivery of products, search engine facilities, advertising, and marketing. In some cases, the third parties may require access to some or all of your data. Where any of your data is required for such a purpose, we will take all reasonable steps to ensure that your data will be handled safely, securely, and in accordance with your rights, our obligations, and the obligations of the third party under the law.

We may compile statistics about the use of our Site including data on traffic, usage patterns, user numbers, sales, and other information. All such data will be anonymised and will not include any personally identifying data, or any anonymised data that can be combined with other data and used to identify you. We may from time to time share such data with third parties such as prospective investors, affiliates, partners, and advertisers. Data will only be shared and used within the bounds of the law.

We may sometimes use third party data processors that are located outside of the United Kingdom and European Economic Area (“the EEA”) (The EEA consists of all EU member states, plus Norway, Iceland, and Liechtenstein). Where we transfer any Personal Information outside the EEA, We will take all reasonable steps to ensure that your data is treated as safely and securely as it would be within the UK under the Data Protection Legislation including:

  • Using Standard Contractual Clauses “SCCs” as a mechanism to safely process data outside of the UK and EEA to third countries which have not been granted adequacy; or
  • Is a Country that has been granted adequacy which confirms its data protection legislation is adequate to safeguard data processing.

In certain circumstances, we may be legally required to share certain data held by us, which may include your Personal Information, for example, where we are involved in legal proceedings, where we are complying with legal requirements, a court order, or a governmental authority.

We share your Personal Information with service providers to help us provide our services and fulfill our contracts with you, as described above. For example:

  • We use Shopify to power our online store. You can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy.
  • We may share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.

    Behavioural Advertising

    As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:

    • We use Google Analytics to help us understand how our customers use the Site. You can read more about how Google uses your Personal Information here: https://policies.google.com/privacy?hl=en.You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
    • We share information about your use of the Site, your purchases, and your interaction with our ads on other websites with our advertising partners. We collect and share some of this information directly with our advertising partners, and in some cases through the use of cookies or other similar technologies (which you may consent to, depending on your location).

      For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

      You can opt out of targeted advertising by:

      Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.

      Using Personal Information

      We use your Personal Information to deal with any enquiries from you, provide our products or services to you, which includes: offering products for sale, processing payments, shipping and fulfillment of your order, and keeping you up to date on new products, services, and offers.

      Lawful Basis

      Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the United Kingdom or European Economic Area (“EEA”), we process your personal information under the following lawful bases:

      • Your consent;
      • The performance of the contract between you and the Site;
      • Compliance with our legal obligations;
      • To protect your vital interests;
      • To perform a task carried out in the public interest;
      • For our legitimate interests, which do not override your fundamental rights and freedoms.

      Retention

      We do not keep your Personal Information for any longer than is necessary in light of the reason(s) for which it was first collected. Data will therefore be retained for the following periods (or its retention will be determined on the following bases):

      1. We will retain your contact details for as long as we contract with you and for 72 months thereafter;
      2. We will retain your contact details for 24 months if you have enquired about our products or services and thereafter, they will be deleted;
      3.  We will retain your financial information for as long as we contract with you and, thereafter, for the permitted period of time required by law.

      Automatic decision-making

      If you are a resident of the Uk or EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.

      We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.

      Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.

      Services that include elements of automated decision-making include:

      • Temporary denylist of IP addresses associated with repeated failed transactions. This denylist persists for a small number of hours.
      • Temporary denylist of credit cards associated with denylisted IP addresses. This denylist persists for a small number of days.

      Where we Store your Personal Information

      We only keep your Personal Information for as long as we need to in order to use it as described above, and/or for as long as we have your permission to keep it.

      We will store some of your Personal Information in the UK. This means that it will be fully protected under the UK’s Data Protection Legislation.

      We will store some of your Personal Information within the European Economic Area (the “EEA”). The EEA consists of all EU member states, plus Norway, Iceland, and Liechtenstein. This means that your Personal Information will be fully protected under the EU GDPR and/or to equivalent standards by law. Transfers of Personal Information to the EEA from the UK are permitted without additional safeguards.

      We may store some or all of your Personal Information in countries outside of the UK and EEA. These are known as “third countries”. We will take additional steps in order to ensure that your Personal Information is treated just as safely and securely as it would be within the UK and under the Data Protection Legislation Data security is very important to Us, and to protect your data We have taken suitable measures to safeguard and secure data collected through Our Site.

      Your Rights

      GDPR

      As a data subject, you have the following rights under the data protection legislation, which this policy and our use of Personal Information have been designed to uphold:

      i. The right to be informed about our collection and use of Personal Information;

      ii. The right of access to the Personal Information we hold about you;

      iii. The right to rectification if any Personal Information we hold about you is inaccurate or incomplete (please contact us);

      iv. The right to be forgotten – i.e., the right to ask us to delete any Personal Information we hold about you (we only hold your Personal Information for a limited time, as explained in the Retention section, but if you would like us to delete it sooner, please contact us;

      v. The right to restrict (i.e., prevent) the processing of your Personal Information;

      vi. The right to data portability (obtaining a copy of your Personal Information to re-use with another service or organisation);

      vii. The right to object to us using your Personal Information for particular purposes; and

      viii. Rights with respect to automated decision making and profiling.

      ix. If you have any cause for complaint about our use of your Personal Information, please contact us using the details provided and we will do our best to solve the problem for you. If we are unable to help, you also have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office.

      x. For further information about your rights, please contact the Information Commissioner’s Office or your local Citizens Advice Bureau

      Your Personal Information will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Shopify’s GDPR Whitepaper: https://help.shopify.com/en/manual/your-account/privacy/GDPR.

      CCPA

      If you are a resident of California, you have the right to access the Personal Information we hold about you (also known as the ‘Right to Know’), to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the contact information below.

      If you would like to designate an authorized agent to submit these requests on your behalf, please contact us at the address below.

      Cookies

      A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.

      We use the following cookies to optimize your experience on our Site and to provide our services.

      Facebook Pixel - fbevents.js - This Cookie is placed by Facebook. It enables Gia Fernandez to measure, optimize and build audiences for advertising campaigns served on Facebook. In particular it enables Gia Fernandez to see how our users move between devices when accessing the Gia Fernandez web site and Facebook, to ensure that Gia Fernandez Facebook advertising is seen by our users most likely to be interested in such advertising by analysing which content a user has viewed and interacted with on the Gia Fernandez web site. To opt-out please see https://www.facebook.com/ads/preferences

      Cookies Necessary for the Functioning of the Store

      Name Function
      _ab Used in connection with access to admin.
      _secure_session_id Used in connection with navigation through a storefront.
      cart Used in connection with shopping cart.
      cart_sig Used in connection with checkout.
      cart_ts Used in connection with checkout.
      checkout_token Used in connection with checkout.
      secret Used in connection with checkout.
      secure_customer_sig Used in connection with customer login.
      storefront_digest Used in connection with customer login.
      _shopify_u Used to facilitate updating customer account information.

      Reporting and Analytics

      Name Function
      _tracking_consent Tracking preferences.
      _landing_page Track landing pages
      _orig_referrer Track landing pages
      _s Shopify analytics.
      _shopify_fs Shopify analytics.
      _shopify_s Shopify analytics.
      _shopify_sa_p Shopify analytics relating to marketing & referrals.
      _shopify_sa_t Shopify analytics relating to marketing & referrals.
      _shopify_y Shopify analytics.
      _y Shopify analytics.


      The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.

      You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.

      Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as www.allaboutcookies.org.

      Additionally, please note that blocking cookies may not completely prevent how we share information with third parties such as our advertising partners. To exercise your rights or opt-out of certain uses of your information by these parties, please follow the instructions in the “Behavioural Advertising” section above.

      Do Not Track

      Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.

      Changes

      We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.

      Contact

      For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at info@giafernandez.co.uk or by mail using the details provided below:

      PO BOX 281, Stowmarket IP14 9DY, United Kingdom

      Data Protection Registration Reference: ZB244897

      Last updated: 20 January 2024

       

      If you are not satisfied with our response to your complaint, you have the right to lodge your complaint with the relevant data protection authority. You can contact your local data protection authority, or our supervisory authority here: https://ico.org.uk/make-a-complaint/]