Privacy policy
Privacy Policy
This Privacy Policy explains how donuma shop. (“the Site,” “we,” or “our”) gathers, uses, and shares your personal details when you browse, interact with, or make a purchase through our online store.
1. Collecting Personal Information
When you visit our Site, we automatically collect certain details about your device and activity, as well as the information required to complete your orders. Additional information may also be collected if you reach out to us for support. In this policy, the term “Personal Information” refers to any data that can be used to identify you as an individual.
Below is an overview of what we collect and why:
a) Device Information
-
Examples collected: browser version, IP address, time zone, cookie data, pages or products viewed, search terms, and how you interact with our Site.
-
Why we collect it: to ensure the Site loads properly for you and to conduct analytics that help us improve your shopping experience.
-
How it’s collected: automatically through cookies, log files, pixels, tags, and other tracking technologies.
-
Disclosure: shared with Shopify (our e-commerce platform provider) and possibly other analytics or performance partners.
b) Order Information
-
Examples collected: full name, billing and shipping addresses, payment details (such as credit card info or other accepted payment types), email, and phone number.
-
Why we collect it: to process and fulfill your purchase, handle payments, arrange deliveries, confirm orders, communicate with you, check for fraudulent activity, and—if you have opted in—send promotional updates.
-
How it’s collected: directly from you when placing an order.
-
Disclosure: shared with Shopify, payment processors, shipping providers, and other relevant partners who help us fulfill your purchase.
c) Customer Support Information
-
Examples collected: details you provide when contacting us for help (this may include order details or additional contact information).
-
Why we collect it: to resolve your inquiries and provide better support.
-
How it’s collected: directly from you.
-
Disclosure: may be shared with third-party customer service tools or platforms we use.
2. Minors
Our Site is not directed toward individuals under the age of [insert age requirement]. We do not knowingly gather Personal Information from children. If you are a parent or guardian and believe your child has provided us with personal data, please reach out using the contact details below so we can remove it.
3. Sharing Personal Information
We share your information with third-party service providers strictly to help us run our business and fulfill our obligations to you. Examples include:
-
Shopify – our e-commerce platform. Learn more about Shopify’s privacy practices here: https://www.shopify.com/legal/privacy.
-
Compliance purposes – we may disclose information if required by law, court order, subpoena, or to protect our legal rights.
-
Other vendors – such as marketing, payment, logistics, or fulfillment partners (where applicable).
4. Behavioural & Targeted Advertising
We may use your Personal Information to deliver tailored ads or marketing communications that match your interests.
For instance:
-
If we use Google Analytics, it helps us understand how customers use our Site. Learn more here: Google Privacy Policy. To opt out, visit: Google Analytics Opt-out.
-
If we use third-party advertising platforms, we may share limited purchase or browsing data with them (sometimes collected via cookies or tags).
You can control targeted advertising preferences through the following links:
Additionally, you may opt out through the Digital Advertising Alliance portal here: http://optout.aboutads.info/.
Using Personal Information
We rely on your Personal Information to deliver our services effectively. This includes making products available for purchase, processing payments securely, arranging shipping and order fulfillment, and keeping you informed about new products, services, and special offers.
Lawful Basis (GDPR – For EEA Customers)
If you live within the European Economic Area (EEA), we process your data under the General Data Protection Regulation (GDPR). Depending on the circumstances, the lawful bases we may rely on include:
-
Your explicit consent;
-
The necessity of fulfilling the contract we have with you;
-
Our obligation to comply with legal requirements;
-
Protecting your vital interests;
-
Carrying out a task in the public interest;
-
Serving our legitimate business interests, provided these do not override your fundamental rights and freedoms.
Retention of Data
When you place an order, we keep your Personal Information on record unless and until you request its deletion. If you wish to exercise your right of erasure, please refer to the “Your Rights” section below.
Automated Decision-Making
EEA residents are entitled to object to processing based solely on automated decision-making (including profiling) when it produces legal or otherwise significant effects.
We do not engage in fully automated decision-making that has a legal or substantial impact on customers. However, Shopify, our service provider, applies limited automated processes to reduce fraud risks. These measures include:
-
Temporary IP address denylist for repeated failed transactions (active for a limited time).
-
Temporary credit card denylist associated with flagged IP addresses (active for a limited time).
These safeguards help prevent fraud but do not create significant or legal consequences for customers.
Selling Personal Information (CCPA)
Under the California Consumer Privacy Act (CCPA), businesses must disclose if they sell personal data. Our Site may sell Personal Information as defined by the CCPA.
If applicable, we will disclose:
-
The categories of information sold;
-
How you can opt-out of such sales;
-
Whether information of minors under 16 is sold, and if affirmative authorization is obtained;
-
Any financial incentives provided in exchange for not selling information.
Your Rights
GDPR – For EEA Residents
If you are based in the EEA, you have the right to:
-
Access the Personal Information we store about you;
-
Request corrections, updates, or deletion;
-
Transfer (port) your data to another service provider.
Requests can be submitted through the contact information provided at the bottom of this policy. Please note, your information may first be processed in Ireland before being transferred outside of Europe (such as to Canada or the United States). For details on compliance with GDPR data transfers, see Shopify’s GDPR Whitepaper: https://help.shopify.com/en/manual/your-account/privacy/GDPR.
CCPA – For California Residents
If you are a California resident, you are entitled to:
-
Know what Personal Information we hold about you (“Right to Know”);
-
Request corrections, updates, or deletion;
-
Transfer (port) your data to another service provider.
You may also appoint an authorized agent to submit these requests on your behalf by contacting us at the address provided below.
Cookies
Cookies are small data files stored on your device when you visit our Site. We use cookies to make your browsing experience smoother, such as remembering login details, region preferences, and shopping cart contents. They also help us understand how visitors use our Site—whether it’s their first time or they are returning customers.
We use several categories of cookies, including:
-
Essential cookies – required for the Site to function;
-
Performance cookies – to improve functionality and speed;
-
Advertising cookies – to deliver targeted promotions;
-
Social media/content cookies – to enable social features and embedded content.
These tools allow us to personalize your experience and continuously improve our services.
Cookies Essential to Store Functionality
Name – Purpose
-
_ab – Used for admin access.
-
_secure_session_id – Maintains navigation through the storefront.
-
cart – Keeps track of shopping cart contents.
-
cart_sig – Supports the checkout process.
-
cart_ts – Used during checkout.
-
checkout_token – Facilitates checkout sessions.
-
secret – Involved in checkout security.
-
secure_customer_sig – Enables secure customer login.
-
storefront_digest – Supports customer authentication.
-
_shopify_u – Helps update customer account details.
Reporting and Analytics Cookies
Name – Purpose
-
_tracking_consent – Stores tracking preferences.
-
_landing_page – Identifies landing pages.
-
_orig_referrer – Tracks original referrals.
-
_s – Shopify analytics.
-
_shopify_fs – Shopify analytics.
-
_shopify_s – Shopify analytics.
-
_shopify_sa_p – Analytics related to marketing and referrals.
-
_shopify_sa_t – Analytics related to marketing and referrals.
-
_shopify_y – Shopify analytics.
-
_y – Shopify analytics.
[Include any additional cookies or tracking tools specific to your business here.]
Cookie Lifespan
How long a cookie remains active depends on whether it is classified as a session cookie or a persistent cookie.
-
Session cookies are erased once you close your browser.
-
Persistent cookies remain until they either expire or are manually deleted.
Most of the cookies we use are persistent, with expiration dates ranging from 30 minutes up to two years.
Managing Cookies
You are in control of your cookie preferences. Keep in mind, however, that disabling or blocking certain cookies may reduce the functionality of the website and some areas may no longer work as intended.
Most browsers are set to accept cookies automatically, but you can change this through your browser’s settings (typically found under “Tools” or “Preferences”). More details on how to manage, block, or filter cookies are available in your browser’s help section or at www.allaboutcookies.org.
Please note that blocking cookies may not fully prevent data sharing with third-party partners, such as advertisers. For guidance on opting out of specific data-sharing practices, see the “Behavioral Advertising” section above.
Do Not Track
Some browsers allow you to send a “Do Not Track” (DNT) signal. Currently, there is no uniform industry standard for responding to such requests, so our data collection practices remain unchanged when we detect a DNT signal.
Updates to This Policy
We may modify this Privacy Policy periodically to reflect operational, legal, or regulatory updates, or to better explain our practices. Any revised version will be posted on this page, and the “Last Updated” date will be adjusted accordingly.
Contact Information
If you have questions about our privacy practices, need more details, or wish to file a complaint, please reach out to us via:
📧 Email: support@donuma.shop.