Purchases can only be made if you are in possession of a personal account or via Guest Checkout. When you create an account or purchase something from our store, as part of the buying and selling process, we collect the following personal information you provide us with:
• First & last name
• Home & invoice address
• Telephone number
• Your gender
• IP address
• E-mail address
• Date of birth
SECTION 1 - WHAT DO WE DO WITH YOUR INFORMATION?
Purpose of data collection
We collect and store account-related data for the following purposes:
a. Carry out our obligations arising from any contracts between you and us, and to provide you with the information, products, and services that you request from us;
b. Set up, manage, and contact you about your account and orders;
c. Carry out market research and analyses;
d. Confirm your age and identity, and to identify and prevent fraud.
This is not auto acceptance -, With your explicit permission, we may send you newsletters about our store, new products, and other updates. We send newsletters based on expressed consent. The following information is collected in context of the newsletter:
• First & last name
• Your gender
• E-mail address
This is not auto acceptance - if after may 25th 2018 you make an order, only orders from people opting in to the marketing will be sent product and service reviews via Trust pilot and Stamped IO view emails
Purpose of data collection
The collected data is used to:
a. personalise our emails, including your name and your gender to provide gender-specific content;
You may withdraw your consent at any time by using the link provided in the newsletter or the contact information provided in section 2.
1.3 Customer service
In order to be able to offer appropriate support, our customer support employees have access to account-related information. Consequently, their support will be highly effective and pleasant.
SECTION 2 - CONSENT
How do you get my consent to be marketed to? We get your consent via a tick box in the checkout procedure before you confirm your order. This is not pre populated with acceptance and you will need to opt in to be marketed to.
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery, or return a purchase, you imply that you consent to our collection of this information to use for that specific reason only. If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.
2.1 If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at any time, by contacting us at firstname.lastname@example.org or mailing us at: Quintessential Tips 14 Kenwyn Street, Truro, Cornwall TR18 5AJ
SECTION 3 - DISCLOSURE
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
SECTION 4 - SHOPIFY
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you. Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
SECTION 5 - THIRD-PARTY SERVICES
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions. For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
SECTION 6 - SECURITY
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered, or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional, generally accepted industry standards. Account-related information is shielded with a hashing method. This method transforms information into a generated hash. As a result, sensitive information is secured, and is even invisible to us. Moreover, our databases are exceptionally protected against unauthorised persons. For example, access to the database is only possible and permitted by approved IP addresses (e.g. at Quintessential's headquarters). Other attempts and addresses are refused at all times.
Additionally, data has been anonymised as much as possible. Thus, the data cannot be directly linked to a specific consumer. With this data, however, we could perform market research and analysis. Furthermore, third-party stakeholders (e.g. mailing service) are screened prior to our collaboration, are GDPR compliant, and are provided with a processor agreement. Within Quintessential Tips, employees are assigned different access permissions. The specific permission provides access only to the strictly needed information required to perform a task.
Digital security measures are subject to changes and must meet high requirements to guarantee the safety of online customers. Therefore we appointed a security manager. Periodical checking and improving of security measures (when necessary) is part of the function
SECTION 7 - COOKIES
Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
store front_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
SECTION 8 - AGE OF CONSENT
By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.
As the nature of the products is used in smoking, we only accept orders from people aged 18 or over, if you use this website under that age, Quintessential Tips ltd will not be liable for any issues arising from you violating our terms of service. Please don't use us if under 18 and respect the laws of your land regarding smoking, paraphernalia and its use. Although our little books are easily used as note books and artist flick books for example we still don't sell them to under 18's.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
QUESTIONS AND CONTACT INFORMATION
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at email@example.com
TERMS OF SERVICE
This website is operated by Quintessential Tips Ltd. Throughout the site, the terms “we”, “us” and “our” refer to Quintessential Tips Ltd. Quintessential Tips Ltd offers this website, including all information, tools and services available from this site to you, the user, conditioned upon your acceptance of all terms, conditions, policies and notices stated here.
By visiting our site and/ or purchasing something from us, you engage in our “Service” and agree to be bound by the following terms and conditions (“Terms of Service”, “Terms”), including those additional terms and conditions and policies referenced herein and/or available by hyperlink. These Terms of Service apply to all users of the site, including without limitation users who are browsers, vendors, customers, merchants, and/ or contributors of content.
Please read these Terms of Service carefully before accessing or using our website. By accessing or using any part of the site, you agree to be bound by these Terms of Service. If you do not agree to all the terms and conditions of this agreement, then you may not access the website or use any services. If these Terms of Service are considered an offer, acceptance is expressly limited to these Terms of Service.
Any new features or tools which are added to the current store shall also be subject to the Terms of Service. You can review the most current version of the Terms of Service at any time on this page. We reserve the right to update, change or replace any part of these Terms of Service by posting updates and/or changes to our website. It is your responsibility to check this page periodically for changes. Your continued use of or access to the website following the posting of any changes constitutes acceptance of those changes.
GDPR Compliance Update May 8th 2018