Privacy Policy

At Oregon Girl Gardens (https://oregongirlgardens.com), we are deeply committed to safeguarding your privacy and upholding the highest standards of data protection. This Privacy Policy explains how we collect, use, disclose, and secure your personal data, and outlines your rights in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.

1. Introduction

Oregon Girl Gardens values your privacy and is committed to protecting your personal information through transparent data practices and a privacy-conscious design philosophy. This policy provides detailed information on how we process your data when you interact with our website and services.

2. Scope of Policy and Data Controller Role

This Privacy Policy applies to all interactions you may have with the website oregongirlgardens.com, including access, browsing, purchasing, contacting customer support, or signing up for newsletters. Oregon Girl Gardens is the data controller for all processing of personal data described herein. For any questions or concerns regarding our data practices, please contact us at [email protected].

3. Categories of Data Processed

We collect and process the following categories of personal information depending on your interaction with our services:

a. Usage Data
Includes information about how you interact with our website, including your IP address, browser type and version, pages viewed, referring website addresses, time and date of your visit, and session duration.

b. Account Data
Collected when you create an account or make a purchase, including your full name, billing and shipping addresses, email address, and phone number.

c. Profile Data
Includes details related to your preferences, purchase history, interests, and behavioral patterns on the website.

d. Communication Data
Encompasses records of your interactions with us, such as emails to support, chat correspondence, or contact form submissions, as well as your communication preferences.

e. Technical Data
Includes device identifiers, operating system details, browser configurations, and settings necessary for ensuring secure and optimal functionality of the website.

f. Transaction Data
Captured when purchases are made, covering order information, billing/shipping details, payment status, and fulfillment logistics. Please note that payment information is processed securely via third-party payment providers and not stored by Oregon Girl Gardens.

g. Preference Data
Includes your expressed choices regarding marketing communications, product categories of interest, cookie preferences, and survey responses.

4. Legal Bases for Data Processing

We only process your personal data when we have a valid legal basis under applicable law, including:

– Contract: When processing is required to fulfill a contractual obligation or to take pre-contractual steps at your request.
– Consent: When you have freely given informed and specific consent to the processing of your personal data, which you may withdraw at any time.
– Legitimate Interest: When processing is necessary for purposes such as improving services, fraud prevention, and marketing (subject to your rights and interests).
– Legal Obligation: When required to comply with legal and regulatory requirements.

5. Your Rights

As a data subject under GDPR and/or a California resident under CCPA, you have the following rights:

– Right to Access: You may request confirmation and a copy of the personal data we hold about you.
– Right to Rectification: You may request correction of inaccurate or incomplete data.
– Right to Erasure (“Right to be Forgotten”): You may request deletion of your personal data under certain circumstances.
– Right to Restriction: You may request that we limit the processing of your personal data under specific conditions.
– Right to Data Portability: You may request the export of your personal data in a machine-readable format.
– Right to Object: You may object to processing conducted based on legitimate interest or for direct marketing purposes.
– Right to Opt-Out of Sale of Information (CCPA applicable): You may instruct us not to sell your personal information.

To exercise any of these rights, please contact us at [email protected]. We will respond promptly and in accordance with applicable law.

6. Security Measures

We implement appropriate technical and organizational safeguards to protect your data, including:

– HTTPS encryption for data in transit
– Secure storage and access restriction protocols for sensitive information
– Tiered access controls and staff training on secure data handling
– Regular system audits and backups to ensure data integrity

7. International Data Transfers

If personal data is transferred to jurisdictions outside the European Economic Area (EEA) or the United States, appropriate safeguards are implemented, such as the use of Standard Contractual Clauses approved by the European Commission or compliance with regional data frameworks, to ensure your data is handled with adequate protection.

8. Data Retention

We retain your personal data only as necessary for the purposes for which it was collected:

– Usage Data: Retained for up to 12 months, used for analytics and performance clarity
– Account, Profile, and Transaction Data: Retained while your account is active and for a maximum of 7 years thereafter for legal and financial compliance
– Communication Data: Retained for up to 5 years for customer service reference
– Marketing Consent Information: Retained until you withdraw your consent
– Technical Data: Retained temporarily for diagnostics and operational integrity

Data is securely deleted or anonymized after retention deadlines are reached.

9. Cookie Policy

We use cookies and similar tracking technologies to provide a better user experience. These include:

– Essential Cookies: Required for core website functions, such as checkout and account access.
– Functional Cookies: Enable personalization, language settings, and saved preferences.
– Performance Cookies: Collect aggregated information on website usage to improve performance.
– Analytics Cookies: Help us understand user behavior through third-party services such as Google Analytics.
– Marketing Cookies: May be used to deliver relevant advertisements and measure campaign effectiveness.

10. Cookie Management and Compliance

In accordance with GDPR and CCPA, we request your consent before setting non-essential cookies on your device. You may change or withdraw your cookie preferences at any time via our cookie banner or browser settings. Users may opt out of behavioral tracking or data sharing by managing their preferences in accordance with relevant legal frameworks.

11. Children’s Privacy

Our website and services are not directed to or intended for children under the age of 13. Oregon Girl Gardens does not knowingly collect personal information from individuals under 13. If we become aware that we have inadvertently collected data from a child, we will take prompt action to delete such information. Parents or guardians who believe their child has provided us with personal information may contact us at [email protected].

12. Policy Updates and Notifications

This Privacy Policy may be revised from time to time to reflect changes in laws, technologies, or our data processing practices. We will notify users of material changes either via the website or through direct communication when appropriate. Continued use of our services constitutes acknowledgment and acceptance of the updated policy.

13. Contact Information

For any inquiries, to exercise your privacy rights, or to raise a concern regarding this Privacy Policy or our data handling practices, please contact:

Oregon Girl Gardens
Email: [email protected]
Website: https://oregongirlgardens.com

At Oregon Girl Gardens, we prioritize transparency, accountability, and privacy in every aspect of our operations. We remain fully committed to compliance with GDPR, CCPA, and applicable data protection regulations. Please reach out to us at any time with questions or concerns related to your personal information.