Privacy Policy
This Privacy Policy describes how niqolasbassano.com (the “Site” or “we”) collects, uses, and discloses your Personal Information when you visit or make a purchase from the Site.
PERSONAL INFORMATION WE COLLECT
When you visit the Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically-collected information as “Device Information”.
We collect Device Information using the following technologies:
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org.
- “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons”, “tags”, and “pixels” are electronic files used to record information about how you browse the Site.
Additionally when you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, including your name, billing address, shipping address, payment information (including credit card numbers and other payment types accepted such as Visa, Mastercard and Apple Pay), email address, and phone number. We refer to this information as “Order Information”.
When we talk about “Personal Information” in this Privacy Policy, we are talking both about Device Information and Order Information.
HOW DO WE USE YOUR PERSONAL INFORMATION?
We use the Order Information that we collect generally to fulfil any orders placed through the Site (including processing your payment information, arranging for shipping, and providing you with invoices and/or order confirmations).
Additionally, we use this Order Information to:
- Communicate with you;
- Screen our orders for potential risk or fraud; and
- When in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
We use the Device Information that we collect to help us screen for potential risk and fraud (in particular, your IP address), and more generally to improve and optimise our Site (for example, by generating analytics about how our customers browse and interact with the Site, and to assess the success of our marketing and advertising campaigns).
SHARING YOUR PERSONAL INFORMATION
We share your Personal Information with third parties to help us use your Personal Information, as described above. For example:
- We use Shopify to power our online store. You can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy.
- We may share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
We also use Google Analytics to help us understand how our customers use the Site -- you can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
Finally, we may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
BEHAVIOURAL ADVERTISING
As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:
- We use Google Analytics which sets cookies to collect information about how our visitors use our website. See our Cookie Policy at https://niqolasbassano.com/pages/cookie-policy We use the information to compile reports and to help us improve the website. The cookies collect information in an anonymous form, including the number of visitors to the website and blog, where visitors have come to the website from and the pages they visited. You can read more about how Google uses your Personal Information here: https://policies.google.com/privacy?hl=en. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
- We share information about your use of the Site, your purchases, and your interaction with our ads on other websites with our advertising partners. We collect and share some of this information directly with our advertising partners, and in some cases through the use of cookies or other similar technologies (which you may consent to, depending on your location).
For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.
You can opt out of targeted advertising by using the links below:
- Facebook: https://www.facebook.com/settings/?tab=ads
- Google: https://www.google.com/settings/ads/anonymous
- Bing: https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.
We do not disclose personal information to anyone else except as set out above unless we are legally entitled to do so. We may provide third parties with aggregate statistical information and analytics about users of our products and services but we will make sure no one can be identified from this information before we disclose it.
INTERNATIONAL TRANSFERS
It is sometimes necessary to share your personal information outside of the UK and the European Economic Area (the EEA) or it will be collected outside of the UK and the EEA. This will typically occur when service providers to our business are located outside the EEA or if you are based outside the EEA. These transfers are subject to special rules under applicable data protection laws.
The same applies to any transfer of personal information to another part of our group of companies based outside of the UK and the EEA. We also apply the same standards to any transfer of personal information between members of our group, regardless of where the group company is based.
If we transfer your personal information outside of the UK and/or the EEA, we will ensure that the transfer will be compliant with applicable data protection laws and all personal information will be secure. Our standard practice is to assess the laws and practices of the destination country and relevant service provider and the security measures that are to be taken as regards the personal Information in the overseas location; alternatively, we use standard data protection/contractual clauses. This means that when a transfer such as this takes place, you can expect a similar degree of protection in respect of your personal information.
Our directors and other key staff working for us may in limited circumstances access personal information from outside of the UK and/or the EEA if they are outside of the UK or EEA. If they do so they will be using our security measures and the same legal protections will apply that would apply to accessing personal information from our premises.
In limited circumstances, the people to whom we may disclose personal information may be located outside of the UK and/or the EEA and we will not have an existing relationship with them, for example a foreign police force outside of the UK and/or the EEA. In these cases we will impose any legally required protections to the personal information as required by law before it is disclosed.
If you would like any more details about how we protect your personal information in relation to international transfers then please contact our DPO at support@niqolasbassano.com
HOW DO WE PROTECT YOUR PERSONAL INFORMATION?
We are committed to keeping your personal information safe and secure and so we have numerous security measures in place to protect against the loss, misuse, and alteration of information under our control. We will always aim to use best in class security systems implemented across our networks and hardware to ensure access and information are protected. Our security measures include:
-
Encryption of personal information where appropriate.
-
Regular cyber security assessments of all service providers who may handle your personal information.
-
Regular planning and assessments to ensure we are ready to respond to cyber security attacks and data security incidents.
-
Regular penetration testing of systems.
-
Security controls which protect our information technology systems infrastructure and our premises from external attack and unauthorised access.
-
Regular backups of information technology systems data with functionality to correct errors or accidental deletion/modification to data.
-
Internal policies setting out our information security rules for our staff.
-
Regular training for our staff to ensure staff understand the appropriate use and processing of personal information.
-
Where we engage third parties to process personal information on our behalf, they do so on the basis of our written instructions, they are under a duty of confidentiality and are obliged to implement appropriate technical and organisational measures to ensure the security of personal information.
We take information security very seriously and will use all reasonable endeavours to protect the integrity and security of the personal information we collect about you.
FOR HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION?
We will hold your personal information for the duration of your relationship with us and then usually for a further period. Where you are a customer, this will usually be for a period of up to 6 years after you last purchased or ordered any products or services from us or last used our apps. If you have only signed up to receive online marketing communications from us, and you have never ordered or purchased anything from us, then we will only retain your personal information for 2 years after you last used any account you have with us or from when you last consented to receive direct marketing from us. In certain, limited cases, it may be necessary to keep your personal information for longer, for example if the information is relevant to a dispute or legal case or claim.
We will not retain your personal information for longer than necessary for the purposes for which it was collected and is being used..
For more information, please contact our DPO at support@niqolasbassano.com to request a copy of our Data Retention Policy.
DO NOT TRACK
Please note that we do not alter our Site’s data collection and use practices when we see a Do Not Track signal from your browser.
DATA RETENTION
When you place an order through the Site, we will maintain your Order Information for our records unless and until you ask us to delete this information.
CHANGES
We may update this privacy policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons.
MINORS
The Site is not intended for individuals under the age of 18.
COLLECTING PERSONAL INFORMATION
When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information that can uniquely identify an individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.
Device information
- Examples of Personal Information collected: version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.
- Purpose of collection: to load the Site accurately for you, and to perform analytics on Site usage to optimise our Site.
- Source of collection: Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels.
- Disclosure for a business purpose: shared with our processor Shopify.
Order information
- Examples of Personal Information collected: name, billing address, shipping address, payment information (including credit card numbers and other payment types accepted such as Visa, Mastercard and Apple Pay), email address, and phone number.
- Purpose of collection: to provide products or services to you to fulfil our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
- Source of collection: collected from you.
- Disclosure for a business purpose: shared with our processor Shopify, shipping and fulfilment app Royal Mail and/or sales channels that include but not limited to Facebook Shop and Instagram Shop.
Customer support information
- Examples of Personal Information collected: name, billing address, shipping address, email address, and phone number.
- Purpose of collection: to provide customer support.
- Source of collection: collected from you.
- Disclosure for a business purpose: shared with our processor Shopify and with our customer service software provider Zendesk.
WE AIM NOT TO COLLECT PERSONAL INFORMATION ABOUT CHILDREN
The Site is not intended for individuals under the age of 18. We do not intentionally collect Personal Information from children. If you are the parent or guardian and believe your child has provided us with Personal Information, please contact us at the email address below to request deletion.
Our supply of products or services, our website, events, promotions, social media, content, blogs, materials and other services we provide are not intended for use by anyone under the age of 18 years and generally we do not knowingly collect personal information relating to anyone under the age of 18 years old unless for some reason you provide it to us.
However we may in some cases collect limited personal information related to children if they are connected to someone who is 18 or older whom we have a relationship with, for example a child who may attend an event or our premises when accompanied by a responsible adult who has won a competition or who is entitled to attend one of our events.
USING PERSONAL INFORMATION
We use your personal Information to provide our services to you, which includes: offering products for sale, processing payments, shipping and fulfilment of your order, and keeping you up to date on new products, services, and offers.
LAWFUL BASIS
Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the European Economic Area (“EEA”), we process your personal information under the following lawful bases:
- Your consent;
- The performance of the contract between you and the Site;
- Compliance with our legal obligations;
- To protect your vital interests;
- To perform a task carried out in the public interest;
- For our legitimate interests, which do not override your fundamental rights and freedoms.
RETENTION
When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. For more information on your right of erasure, please see the ‘Your rights’ section below.
AUTOMATIC DECISION-MAKING
Automated decision-making takes place when an electronic system uses personal information to make a decision about that person without any human intervention which produces legal effects concerning them or similarly significantly affects them. We do not currently use this type of automated decision making in our business in relation to you.
You will not be subject to decisions that will have a significant impact on you based solely on automated decision making unless we have a lawful basis for doing so and we have notified you.
However we do use automated processing so that we can show you personalised advertisements whilst browsing our website or those of other companies and to build a customer profile for you. Any advertisements you see may relate to your browsing activity on our website from your computer or other devices.
These advertisements are provided by us via external market leading specialist providers using techniques such as pixels, web beacons, ad tags, mobile identifiers and ‘cookies’ placed on your computer or other devices. For further information on the use of cookies, or for details of how you can remove or disable cookies at any time - see our Cookie Policy - https://niqolasbassano.com/pages/cookie-policy .
We may analyse your browsing and purchasing activity online and your responses to marketing communications. The results of this analysis, together with other demographic data, allow us to decide what advertisements are suitable for you and to ensure that we draw to your attention products, services, events and offers that are tailored and relevant to you. To do so, we use software and other technology for automated processing. This allows us to provide a more personalised services and experience.
We may review personal information held about you by external social media platform providers, such as the personal information available on social media platforms such as TikTok, Instagram, YouTube, Snapchat, Twitter and Facebook.
We aim to update you about products and services which are of interest and relevance to you as an individual. To help us do this, we process personal data by profiling and segmenting, identifying what our customers like and ensuring advertisements we show you are more relevant based on demographics, interests, purchase behaviour, online web browsing activity and engagement with previous communications.
If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.
We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.
Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.
Services that include elements of automated decision-making include:
- Temporary denylist of IP addresses associated with repeated failed transactions. This denylist persists for a small number of hours.
- Temporary denylist of credit cards associated with denylisted IP addresses. This denylist persists for a small number of days.
WHO HAS INTERNAL ACCESS TO YOUR PERSONAL INFORMATION?
Your personal information may be shared internally with our staff, including with our customer support, order fulfilment, loyalty and retention, customer relationship management, media, insights, events, campaign, technical and legal teams where access to your personal information is necessary for the performance of their roles. We only provide access to your personal information to those of our staff who need to have access to your personal information.
YOUR RIGHTS
As an individual whose personal information we collect and process, you have a number of rights. You may:
-
Withdraw any consent you have given to us, although this will only be relevant where we are relying on your consent as a lawful basis to use your personal information, but it is an absolute right. Once we have received notification that you have withdrawn your consent, we will no longer process your personal information for the purpose or purposes for which you originally gave your consent, unless we have another lawful basis for doing so.
-
Request details about how your personal information is being used. This right is linked with the right of access mentioned below.
-
Request access and obtain details of your personal information that we hold (this is commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
-
Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
-
Request erasure of your personal information. This means that you can ask us to delete or stop processing your personal information, for example where we no longer have a reason to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (set out below). The right to have data erased does not apply in all circumstances.
-
Object to the processing of your personal information where we are relying on a legitimate interest (ours or that of a third party) and there is something about your particular situation which makes you want to object to processing on this ground.
-
Object to direct marketing where we are processing your personal information for direct marketing purposes, for example contacting you about products that might interest you. This is an absolute right.
-
Request the restriction of processing of your personal information. This enables you to ask us to stop processing your personal information for a period if data is inaccurate or there is a dispute about whether or not your interests override our legitimate grounds for processing data.
-
Request the transfer of your personal information to another party in certain circumstances.
-
Object to certain automated decision-making processes using your personal information.
You should note that some of these rights, for example the right to require us to transfer your personal information to another service provider or the right to object to automated decision making, may not always apply as they have specific requirements and exemptions which apply to them, and they may not apply to personal information recorded and stored by us. Also, for example we do not use automated decision making in relation to your personal information which has legal or other significant effects for you, but we do use automated processing to show you relevant advertisements. However, some of your rights have no conditions attached, so your right to withdraw consent or object to processing for direct marketing are absolute rights.
If you would like to exercise any of these rights, please contact our DPO at support@niqolasbassano.com.
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person or dealt with by a person who has no right to do so.
Whilst this privacy notice sets out a general summary of your legal rights in respect of personal information, this is a complex area of law. More information about your legal rights can be found on the ICO’s website at https://ico.org.uk/for-the-public/.
If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information below.
Additionally, if you are a European resident we note that we are processing your information in order to fulfil contracts we might have with you (for example if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above. Additionally, please note that your information will be transferred outside of Europe, including to Canada and the United States.
GDPR
If you are a resident of the EEA, you have the right to access the Personal Information we hold about you, to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us at support@niqolasbassano.com
Your Personal Information will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Shopify’s GDPR Whitepaper: https://help.shopify.com/en/manual/your-account/privacy/GDPR.
COOKIES
A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.
We use the following cookies to optimise your experience on our Site and to provide our services.
COOKIES NECESSARY FOR THE FUNCTIONING OF THE STORE
Name | Function |
---|---|
_ab | Used in connection with access to admin. |
_secure_session_id | Used in connection with navigation through a storefront. |
cart | Used in connection with shopping cart. |
cart_sig | Used in connection with checkout. |
cart_ts | Used in connection with checkout. |
checkout_token | Used in connection with checkout. |
secret | Used in connection with checkout. |
secure_customer_sig | Used in connection with customer login. |
storefront_digest | Used in connection with customer login. |
_shopify_u | Used to facilitate updating customer account information. |
REPORTING AND ANALYTICS
Name | Function |
---|---|
_tracking_consent | Tracking preferences. |
_landing_page | Track landing pages |
_orig_referrer | Track landing pages |
_s | Shopify analytics. |
_shopify_fs | Shopify analytics. |
_shopify_s | Shopify analytics. |
_shopify_sa_p | Shopify analytics relating to marketing & referrals. |
_shopify_sa_t | Shopify analytics relating to marketing & referrals. |
_shopify_y | Shopify analytics. |
_y | Shopify analytics. |
The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.
You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.
Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as www.allaboutcookies.org.
Additionally, please note that blocking cookies may not completely prevent how we share information with third parties such as our advertising partners. To exercise your rights or opt-out of certain uses of your information by these parties, please follow the instructions in the “Behavioural Advertising” section above.
DO NOT TRACK
Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.
CHANGES
We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.
COMPLAINTS
We hope you don’t have any reason to complain, and we will always try to resolve any issues you have, but you always have the right to make a complaint at any time to the ICO if you are based in the UK about how we deal with your personal information or your rights in relation to your personal information. If you are based outside of the UK you may have the right to complain to your local data protection regulator. You can make a compliant in writing to the ICO, Wycliffe House, Water Lane, Wilmslow, SK9 5AF, United Kingdom or you can go to https://ico.org.uk/make-a-complaint/.
CONTACTING US
If you have any queries regarding our use of your personal information or this privacy policy then please contact us at support@niqolasbassano.com or write to DPO, NBHQ, Niqolas Bassano, 1 George Street, Wolverhampton, WV2 4DG.
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at support@niqolasbassano.com
Dated: September 2023