Privacy Policy
PRIVACY POLICY
This Privacy Policy describes how Ciara Galway collects, uses, and discloses your personal information when you visit our site, use our services, or make a purchase on ciaragalway.com, or interact with us in connection with the Site. For the purposes of this Policy, "you" and "your" refer to the user of the Services, whether you are a customer, a site visitor, or any other person whose information we collect under this Policy.
Please read this Privacy Policy carefully.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time, particularly to reflect changes in our practices or for operational, legal, or regulatory reasons. We will post the revised Policy on the Site, update the "Last updated" date, and take any other steps required by applicable law.
How we collect and use your personal information
To provide the Services, we collect (and have collected over the past 12 months) personal information about you from various sources, as described below. The information we collect and use depends on how you interact with us.
In addition to the specific uses described below, we may use your information to communicate with you, provide or improve the Services, comply with our legal obligations, enforce our terms of use, and protect the Services as well as our rights or those of others.
What personal information we collect
The type of personal information we collect about you depends on how you use the Site. By "personal information," we mean information that identifies you, describes you, or can be associated with you.
Information you provide directly
These may include:
- Contact details: name, address, telephone number, and email address.
- Order information: billing and delivery address, payment confirmation.
- Account information: username, password, security questions.
- Purchase information: products viewed, added to basket, reviews, loyalty points, gift cards.
- Customer service information: anything you choose to share during your communications with us.
Some features may require you to provide certain information. If you choose not to do so, you may not have access to these features.
Information collected automatically
We may automatically collect certain usage data through cookies, pixels, and similar technologies. This data may include information about your device, your browser, your IP address, and your interaction with the Services.
Information from third parties
We may obtain information about you from third parties, such as:
- Website and service providers (e.g., Shopify).
- Payment providers (banking details, credit card, billing address).
- Tracking technologies (such as pixels, SDKs, third-party cookies).
We will process this information in accordance with this Policy. Please also see the section on Third-party sites and links.
How we use your personal information
Providing the Services and products
To process payments, manage accounts, send notifications, handle returns, etc. Shopify may link your account to other services, in accordance with its own privacy policy.
Marketing and advertising
We may send you promotions by email, SMS, or post, and display personalised advertisements to you. For EEA residents, the legal basis is legitimate interest (Art. 6(1)(f) of the GDPR).
Security and fraud prevention
To detect fraudulent or illegal activities and respond to them. For EEA residents, the legal basis is our legitimate interest (Art. 6(1)(f) of the GDPR).
Communication and service improvement
Includes customer support and service optimisation (also under legitimate interest, Art. 6(1)(f) of the GDPR).
Cookies
We use cookies to operate and improve our Site and Services (e.g., remembering preferences, analytics, advertising display). They may also be used by third parties.
You can configure your browser to block cookies, but this may affect site functionality.
We respect the Global Privacy Control (GPC) signal. For more information, visit: https://globalprivacycontrol.org/. We do not currently recognise other "Do Not Track" signals.
Disclosure of personal information
We may share your information with:
- Service providers (e.g., payments, customer service, analytics).
- Commercial and marketing partners, according to their own policies.
- With your consent or through social media integrations.
- With affiliated companies, for legitimate business interests.
- In the case of corporate transactions, legal compliance, or rights protection.
Disclosures over the past 12 months
Identifiers (name, email, etc.) — Providers, marketing partners, affiliates
Customer data (billing/delivery) — Same
Commercial information (purchases, support) — Same
Internet activity (usage data) — Same
Geolocation data — Same
We do not use or disclose sensitive personal data without your consent and do not use it to infer characteristics.
With your consent, we have "sold" or "shared" personal information (in the legal sense of the term) for advertising purposes:
- Identifiers — Marketing/commercial partners
- Commercial information — Same
- Usage data — Same
Third-party sites and links
Our Site may contain links to third-party sites. Please consult their privacy policies. We are not responsible for how they manage your personal data.
Children's data
Our Services are not intended for children. We do not knowingly collect data from children. If you believe your child has provided us with data, please contact us to have it deleted.
To our knowledge, we have not "sold" or "shared" data from persons under the age of 16.
Security and retention
No system is completely secure. Avoid sending sensitive data through unencrypted channels.
We retain personal data for as long as necessary to maintain your account, provide the Services, comply with our legal obligations, or resolve disputes.
Your rights
Depending on where you live, you may have the following rights:
- Access to your data.
- Deletion of data.
- Rectification of inaccurate data.
- Portability of your data.
- Opposition to use for advertising purposes.
- Restriction of processing.
- Withdrawal of consent.
- Complaint to an authority.
- Communication management (you can unsubscribe from promotional emails).
You can exercise these rights through the Site or by contacting us. We may verify your identity. You can designate an authorised representative.
We will not discriminate against you for exercising your rights.
Complaints
If you have a complaint regarding the processing of your data, please contact us. If it is not resolved, you can contact your local data protection authority. Irish residents may contact the Data Protection Commission (DPC) at https://www.dataprotection.ie/. For EEA residents, you may also consult this list:
https://edpb.europa.eu/about-edpb/board/members_en
International users
We may transfer your data outside your country, including outside the EEA, using legal mechanisms such as the European Commission's Standard Contractual Clauses.
Contact
If you have any questions or wish to exercise your rights, please contact us at:
Unless otherwise stated, we are the controller of your personal data in accordance with applicable law.