Last updated: January 30, 2020
governs the privacy terms of our website, located at amycater.com
and any subdomains or connected sites we control (dreamtreefineart.com
is and will be treated as part of our Terms of Service
, and is automatically incorporated therein. Please read the Terms of Service
carefully in addition to this Policy
“You” or “Your” refers to you, the user, subscriber, customer and any other using our Website and Services, and who is the subject of personal information.
Personal information (or “personal data”) means information about a living person who can be identified from that data (or from that and other information either in our possession or that may come into our possession).
This Policy does not apply to our Services offline or through any other means, including our Etsy, Spoonflower or other shops. Nor does this Policy apply to the practices of any third party content or services that we do not own or control and that may be linked to or accessed from our Website. You can reference the trusted third party Privacy Policies below to learn more about their individual privacy practices.
Information Collection And Use
We collect personal information that you provide to us, ultimately, so that we can operate, maintain, improve and enhance our Website and Services in order to create content and products that you love.
What Information We Collect
The two different types of information collected when you visit or use our Website are:
This is information that can be used to contact or personally identify you, and is information that you provide to us or that we may ask you to provide based on the type of request you make while visiting our Website or Services. This type of information may include, but is not limited to your name, email address, phone number, etc.
This is information that you manually provide to us, for example, when you fill out our contact form with questions or comments, sign up for our email newsletter, correspond with us by email and third party social media sites, report a problem, fill out a survey, or otherwise communicate with us.
This is information that cannot identify you and is non-identifying, but provides us an idea of how users interact with and use our Website so that we may improve it. This type of information may include, but is not limited to: what time of day/week visitors come to the Website, the pages viewed, what devices are used - mobile vs desktop, how many visitors are new versus returning, how long visitors stay on the site for, etc.
This is usage information that is automatically collected via browser text files called cookies and web beacons, which gather non-sensitive user information when you access our Website or open email newsletters. To learn more, please see our “Usage Information” section and our Cookies Policy below.
Legal Basis for Processing Personal Information
When you have provided your affirmative consent and given us permission to do so for one or more specific purposes, such as by signing up for our mailing list, which you may revoke at any time;
When we need to provide our Services or perform a contractual agreement with you, such as in the near future when we use your information to fulfill and ship your order, to settle disputes, or to provide customer support;
Compliance With Legal Obligations
When necessary to comply with the law, a legal obligation or court order, or in connection with a legal claim, such as retaining information about your purchases if required by tax law once we open our shop;
When necessary for the purpose of our legitimate interests and the expected behaviour of a business when not overridden by your rights or interests, such as for payment processing purposes and to follow up with emails after you’ve placed an order, etc., once we open our shop. We only use your information to provide the product and services you request and to improve our Services.
How We Use the Information We Collect
We use the collected information for various purposes while you are viewing or using our Website and Services in order to provide, maintain and improve our Website and offerings, and operate our business effectively. Following are the various ways in which we collect certain personal information from you and the manner in which we obtain it based on at least one legal basis to process it.
Information Directly Provided
This site collects the following information that you provide to us:
Contact & Communication Information
When you fill out our contact form and otherwise communicate with us, such as via email, you voluntarily provide us your name, email address, and a message with questions, comments or concerns. We will process this information for administrative purposes in order to provide the requested customer service and support by responding to questions and comments. (GDPR Basis: Consent and/or Contractual)
Email Newsletters Subscription Information
When you sign up for our email newsletter from opt-in areas on our Website pages, you voluntarily provide us your name and email address. We collect this information via MailChimp, who will provide analysis about which emails are opened and what links are clicked on.
We will process this information based on your requested communications in order to keep you up to date and provide you with information about our products and services, such as new images, sales, news, and events and/or special offers (once we open our shop) which may be of interest to you. You may opt-out at any time. Please see “How to Exercise Your Rights” below. (GDPR Basis: Consent)
Information Automatically Collected
This site collects the following information automatically:
As you access and use our Website, we may automatically collect usage information that analyzes and provides us an idea about how users (or “visitors”) interact with and behave within our site, such as what pages are visited, for how long, what pages web traffic enters by and leaves from, if users are new visitors or returning, what device is used (mobile vs desktop), the operating system, browser type, etc. Additionally, we collect IP addresses from visitors to our Website, which identify individual computers or devices on the internet and allows us to analyze where visitors are generally coming from in the world. However, we use IP Anonymization to enforce further privacy. We do not personally identify you from this aggregate (a total or sum of all parts) usage data.
We collect this information via Google Analytics and MailChimp, which use technologies, such as cookies and web beacons (or “pixels,” “tags”), etc., that automatically gather analysis information and monitor the usage of our Website and Services, as well as to recognize you or your device so that we can improve the experience for our users. Your world location may be processed for maintenance, troubleshooting and to block disruptive or harmful use.
Cookies: Most web browsers are set to accept cookies by default. If you prefer, you are able to delete or disable browser cookies by changing your browser settings. Please note that if you choose to remove or reject cookies, this could affect the availability or functionality of our Website and Services. Please read our Cookies Policy below for more information, as well as our “Third Party Service Providers” section below. (GDPR Basis: Legitimate Interest & Consent)
Legal Information and Action
When you access and use our Website and Services, you provide us with information voluntarily and certain non-identifying usage information. We may process that information in order to detect, prevent and address technical and security issues and intellectual property infringements, including copyright infringement, as well as, fraudulent, harmful, and unauthorized illegal activity, including right of privacy violations or defamation issues related to ours and any users’ information posted on our Website.
We may also process any personal information we have on you when required to reveal personal data upon request of public authorities, such as by a court order, legal obligation, or court proceeding. We may also contact you via your email address or other information for legal purposes, such as to meet contract and legal obligations. Your personal information may be used for legal purposes in court or in the stages leading to possible legal action arising from improper use of this Website or the related Services, such as those as noted above. Please read our Terms of Service
carefully for more information. (GDPR Basis: Legal Obligation and Legitimate Basis)
Disclosure and Sharing of Information
Information about our customers is important to our business. We will never rent or sell your information, nor our email lists, to others. However, we may need to disclose your personal information for limited reasons and circumstances, as follows:
Compliance With Laws
Under certain circumstances, we may be required to disclose your personal information if we have a good faith belief that it is reasonably necessary or required to:
❦ Respond to legal process or to government or other public authorities’ requests (e.g. a court)
❦ Meet and enforce our agreements, terms and policies, including invoicing and outstanding payments
❦ Prevent, investigate, and address fraud and other illegal activity, security, or technical issues
❦ Protect the rights, property, and safety of us, our visitors, customers or others
Non-Personally Identifiable Information
We may disclose anonymous, aggregate data as it pertains to our Website, as long as it remains unidentifiable to individual users.
Third Party Service Providers
We may engage or employ certain trusted third party service providers or partners (or “data processors”) only when necessary to serve you, such as to facilitate our Services, to provide the service on our behalf, or to assist us in analyzing how our Services are used. These service providers may have access to your personal information, but only to the extent necessary to perform these tasks or functions on our behalf and to deliver the products and/or services that you have requested. These providers are subject to strict contractual restrictions to ensure that your information is protected and confidential.
Email Newsletters & Promotional Mailing Lists
Your Use of Personally Identifiable Information
Please read our Terms of Service
for more detailed information regarding your use of our Website and Services, especially when it comes to your use of any other person's identifiable information other than your own.
You are responsible for any third party’s personal information and/or intellectual property content obtained, published or shared through our Service, and you agree that you have obtained all necessary and explicit consents from the third party to make such information public, and that doing so will not violate any laws.
Retention of Data
We may also retain usage data for internal analysis purposes, where each visit data may be generally retained up to three years, except when this data is used to strengthen the security or improve the functionality of our Website, or we are legally obligated to retain this data for longer time periods. However, we will only keep email newsletter opt-in information for as long as you subscribe. While, other information may be kept for variable time periods based on their nature, such as communications based on severity of the content and comments on the Website.
Storage and International Transfer of Information
Our studio and office are located in Canada, and we are governed by Canadian law and the Personal Information Protection and Electronic Documents Act (PIPEDA), while our website provider is located in both the United States and Canada. The information that we collect from you may, thereby, be transferred to, and stored at, a location outside of the European Economic Area, Switzerland and the United Kingdom (collectively the “EEA”). In addition, our other third party service providers are based in the United States, and are outside of our direct control, and may be subject to the United States legislation and Patriot Act. Therefore, these service providers may maintain facilities or be located in a different country than you or us, and these countries may not necessarily have data protection laws as comprehensive or protective as those in your country. Therefore, if you decide to proceed with our Services and submit your personal information, you consent to this transfer, storage or use, and do so knowing it may involve the use of third party service providers from countries other than your own, and this may result in transferring your personal information across international borders. Your information may then become subject to the laws of our country and those of our third party service providers.
No transfer of personal information will take place unless there are adequate security and controls in place by us or with any third party service provider. Our collection, storage and transfer of your personal information will, at all times, be governed by this Policy.
How We Protect Your Information
We are concerned with protecting your privacy and sensitive data. We and our third party service providers have implemented security technology measures to guard your information from accidental or inappropriate use, access, disclosure, alteration or destruction while using our Website. We do this by ensuring that whenever you enter sensitive information on our Website, such as the contact forms, email opt-ins, etc., we encrypt that information using secure socket layer technology (SSL) installed on our Website and additional security measures.
Unfortunately, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use industry prescribed means to protect your information, we cannot ensure or warrant the absolute security of any information you transmit to our Website or Service, nor guarantee that your information may not become subject to accidental loss, unauthorized accessed or disclosure, alteration or unlawful destruction by breach of any of our industry standard physical, technical or managerial safeguards. We are not responsible for breach of any protective measures or settings used on this Website, nor any delays or delivery failures, including those due to any third party service provider, or any other loss or damages from the transfer of data over the networks and the Internet. You acknowledge that we also cannot guarantee fully guarding against cyberattacks, such as hacking, ransomware, spyware and viruses. You will also not hold us liable for any unauthorized disclosure, loss, harm or destruction of your personal information arising from such risks.
You provide and transfer personal information at your own risk, and help to maintain the security for your information on this Website. We will never send unsolicited communications asking your information.
In the event we become aware of a security breach of the Website that directly compromises the personal information of our users by unauthorized or unrelated third parties as a result of external activity, including, but not limited to, security attacks or fraud, we reserve the right to take reasonably appropriate measures, including, but not limited to, investigation, reporting and notification to and cooperation with data protection and law enforcement authorities.
Leaving Our Website To Other Sites
and Terms of Service
By using this Website, you acknowledge that you are over the age of 18 (“minor”) or of the age of majority in your country. If you are under 18, please do not attempt to provide any information about yourself to us. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected personal data from minors without verification of parental/guardian consent, we take steps to fully remove that information from our records as quickly as possible. If you believe that we might have any information from or about a minor, please contact us immediately.
Your Privacy Rights
We respect your privacy rights and provides you with reasonable access to the personal information that you may have provided through your use of our Website and Services. If you reside in the EEA or certain other territories, you have a number of certain data protection rights in relation to your personal information. While some of these rights apply generally, certain rights apply only in certain limited cases. We describe these rights below:
The Right to Access
You have the right to access your personal information we hold about you.
The Right to Change and Rectification
You have right to change your personal information, and to have your information corrected if that information is inaccurate or incomplete.
The Right to Objection
You have the right to object to our collection or processing of your information for certain purposes at any time, except in cases where we are otherwise permitted by applicable law or legitimate grounds to continue to do so.
The Right to Restriction
You have the right to request that we restrict further processing of or limit the use of your personal information.
The Right to Deletion
You have the right to request that we delete some or all of your personal information. At your request, we will generally delete or block any reference to your personal information. Please note that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain information you submit for prevention of fraud and abuse, satisfaction of legal obligations and income tax regulations, backups, archiving, or where we otherwise have a legitimate reason to do so.
The Right to Withdraw Consent
You have the right to withdraw your consent at any time where we relied on your provided consent in order to collect or process your personal information.
The Right to Portability
You have the right to request a copy of the personal information we hold about you which you have provided us.
If necessary, you also have the right to raise a concern to a Data Protection Authority about our processing of your personal information. For more information, please contact your local data protection authority in the EEA.
If you restrict, delete or decline to share certain personal information with us, which is certainly your right, some or all of the features and functionality of this Website and Service may no longer work or may become inaccessible. Additionally, once the retention periods expire, personal information shall be deleted and rights cannot be enforced.
How to Exercise Your Rights
Any requests to exercise your rights can be directed to us through the “How to Contact Us” section below. Requests may be subject to a reasonable administration fee.
Please note that we will ask you to verify your identity before responding to such requests in order to confirm the legitimacy of the request and that it does in fact originate from you. This verification may require you to provide us with additional personal information or further details about your request. If you do not cooperate in this, or we cannot verify legitimacy, we may not release such information in a timely manner, so as to prevent a breach of privacy. In addition, if your request requires disclosure of information relating to or identifying another person, we may need to obtain the consent of that person, if possible, otherwise provide you the request with all but that information. As such, you shall provide full cooperation in these regards, so that any requests on our part to verify your request will be undertaken solely to protect against breach of your personal information.
Requests will be addressed by us within one month, unless the request is overly complex or unfounded, in which case we may refuse the request on such grounds or we will notify you after one month’s time about requiring a two months extension and/or a further reasonable administration fee.
To Opt-out of Cookies and Tracking Technologies
To Update Email Subscriber Information
You may update or correct your subscriber information at any time by clicking on the "Manage Your Preferences" option at the bottom of email newsletters.
To Opt-out of Email Newsletters
You are able to withdraw consent and opt-out of our email newsletters at any time by clicking on the "Unsubscribe" link at the bottom of any subscription email we send you. Please note that opting out will not affect emails received for product orders and shipping notices from any of our external shops, such as Etsy, nor the information you provided to us for such purposes. Please see our Policies for any external shop and the applicable third party store's Policies directly for more information. This Policy does not apply to external shops.
We will give notice on this page, so it is strongly recommended that you check this page periodically. Refer to the “Last Updated” date listed at the top of this Policy.
How to Contact Us
If you have any questions or concerns about this policy, you may contact us at dreamtreefineart+privacy [at] pm [dot] me. Please note that we are not responsible for any transfer of sensitive information by you over the Internet.
This Website and its Content are owned and operated by Amy Cater and Dream Tree Fine Art.