Privacy Policy

This Privacy Policy outlines how The Pony Island (referred to as the "Site" or "we") collects, utilizes, and shares your Personal Information during your visit to the Site or when you make purchases.

Collection of Personal Information

During your visit to the Site, we gather specific details about your device, your interactions with the Site, and information necessary for processing your purchases. Additionally, if you reach out to us for customer support, we may collect further information. In this Privacy Policy, "Personal Information" refers to any data uniquely identifying an individual. Below is a breakdown of the Personal Information we collect and the reasons for its collection:

Device Information

Examples of Personal Information collected: Web browser version, IP address, time zone, cookie data, viewed sites or products, search terms, and interactions with the Site. Purpose of collection: Ensuring accurate loading of the Site and performing analytics to enhance its performance. Source of collection: Automatically collected via cookies, log files, web beacons, tags, or pixels when accessing the Site. Disclosure for business purposes: Shared with our processor Shopify.

Order Information

Examples of Personal Information collected: Name, billing address, shipping address, payment details (including credit card numbers), email address, and phone number. Purpose of collection: Providing products or services, processing payments, arranging shipping, generating invoices and/or order confirmations, communicating with you, identifying potential risks or fraud, and delivering personalized information or advertisements. Source of collection: Directly collected from you. Disclosure for business purposes: Shared with our processor Shopify.

Customer Support Information

Examples of Personal Information collected: Name, billing address, shipping address, payment details (including credit card numbers), email address, and phone number. Purpose of collection: Providing customer support. Source of collection: Directly collected from you. Disclosure for business purposes: Shared with our processor Shopify.

Minors

The Site is not intended for individuals under 13 years of age. We do not knowingly collect Personal Information from children. If you are a parent or guardian and believe your child has provided Personal Information, please contact us at the address provided below for deletion.

Sharing Personal Information

We share your Personal Information with service providers to assist us in delivering our services and fulfilling our contractual obligations. For instance:
We utilize Shopify to operate our online store. For further details on how Shopify handles your Personal Information, please refer to their privacy policy. We may disclose your Personal Information to comply with applicable laws and regulations, respond to legal requests, or safeguard our rights.

Use of Personal Information

We utilize your Personal Information to provide services, including offering products for sale, processing payments, shipping orders, and keeping you informed about new products, services, and promotions.

Legal Basis

As per the General Data Protection Regulation (GDPR), if you reside in the European Economic Area (EEA), we process your Personal Information based on the following lawful grounds:

Your consent; Performance of the contract between you and the Site; Compliance with legal obligations; Protection of vital interests; Performance of tasks carried out in the public interest; Pursuit of legitimate interests that do not override your fundamental rights and freedoms.

Retention

Upon placing an order through the Site, we retain your Personal Information in our records unless you request its deletion. For more information on your right to erasure, refer to the "Your Rights" section below.

Automatic Decision-Making

Residents of the EEA have the right to object to processing solely based on automated decision-making if such processing has legal consequences or significantly affects them.

We do not engage in fully automated decision-making with legal or significant effects on customers' data.

Our processor, Shopify, utilizes limited automated decision-making to prevent fraud, which does not have legal or significant effects on individuals.

Services involving elements of automated decision-making include:
Temporary denial of IP addresses associated with multiple failed transactions. This denial list remains active for a short period. Temporary denial of credit cards linked to denied IP addresses. This denial list remains active for a brief duration.

Your Rights

GDPR

If you reside in the EEA, you have the right to:
Access your Personal Information held by us; Port your Personal Information to another service; Request correction, updating, or deletion of your Personal Information. To exercise these rights, please contact us through the provided contact information.

Your Personal Information will be initially processed in Ireland and then transferred outside Europe for storage and further processing, including to Canada and the United States. For details on GDPR-compliant data transfers, refer to Shopify's GDPR Whitepaper.

CCPA

If you are a California resident, you have the right to:
Access your Personal Information held by us (Right to Know); Port your Personal Information to another service; Request correction, updating, or deletion of your Personal Information. To exercise these rights, contact us via the provided contact information.

If you wish to appoint an authorized agent to make these requests on your behalf, contact us at the address provided.

Cookies

Cookies are small data pieces downloaded to your device when you visit our Site. They enhance your browsing experience by remembering actions and preferences. Cookies also provide insights into website usage.

We use various cookies to optimize your Site experience and deliver our services.

The duration of a cookie on your device depends on whether it's "persistent" or "session" based. Session cookies last until you stop browsing, while persistent cookies expire or are deleted. Most of our cookies are persistent, lasting between 30 minutes and two years.

You can manage cookies in different ways. However, blocking or removing cookies may impact your user experience, affecting Site accessibility.

Most browsers accept cookies by default, but you can control this via browser settings. For detailed instructions, refer to your browser's help file or websites like www.allaboutcookies.org.

Blocking cookies may not completely prevent information sharing with third parties, including advertising partners. To exercise your rights or opt out of certain information uses by these parties, follow instructions in the "Behavioral Advertising" section above.

Do Not Track

We do not modify our data collection or usage practices in response to "Do Not Track" signals from browsers due to inconsistent industry guidelines.

Changes

This Privacy Policy may be updated periodically to reflect changes in our practices or for operational, legal, or regulatory reasons.

Contact

For further details on our privacy practices, questions, or complaints, contact us via email at susan@theponyisland.com.

Last updated: 03/28/24