Effective date: May 13 2024
The purpose of this document, the "Privacy Policy", is to inform users of the site on the following:
The personal data we will collect;
Use of collected data;
Who has access to the data collected; and
The rights of Site users.
This Privacy Policy applies in addition to the Terms of Service of our Site. By using our Site users agree that they consent to the conditions set out in this Privacy Policy.
www.oncuff.ca (the "Site") is owned and operated by Kaitlyn Hollander and can be contacted at:
oncuffwebsites@gmail.com
kaitlynhollanderart@gmail.com
When you use our site, purchases a template, or contacts Oncuff Websites directly via email, direct message, or otherwise, Oncuff Websites collects data like location, contact information, and content viewed (not necessarily together though). Any names or information shared with Oncuff Websites through any mode of communication is confidential and will not be distributed without the user’s consent. Data collected for Analytics is strictly used for statistics purposes and other data is necessary for making purchases on site or communicating with customers.
Data Privacy Policy on our site is subject to the policies of the services we use to deliver our digital products. We use [to be determined payment processor] for processing payments and they collect information with your transaction. Data collected here adheres to [to be determined payment processor]’s Privacy Policy. We use Google Analytics to gather information about our users and thus data collected there is also subject to Google Analytics Privacy Policy as well as Google's Privacy and Terms. We are required to disclose what information we use Google Analytics for.
For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.
We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to
appoint a Data Protection Officer under Article 37 of the GDPR.
We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.
We rely on the following legal basis to collect and process the personal data of users in the EU:
1. Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party.
If a user does not provide the the personal data necessary to perform a contract the consequences are that users are unable to
purchase services through digital payment processing.
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below.
When you visit and use our Site, we may automatically collect and store the following information:
1. Location;
2. Age, and
3. Content viewed.
If you communicate with us through email, direct message, or other means and / or make a purchase through our website, we collect and store the following information:
1. Name
2. Address
3. Email, Social Media Handle, or other electronic contact
We do not store credit card information. This would be kept by our payment processor, [to be determined processor] and thus their Privacy Policy applies to that data.
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.
The data we collect automatically is used for the following purposes:
1. Statistics.
The data voluntary given is used for the following purposes:
1. Communication
2. Sale of Products and Services
Employees
We may disclose user data to any member of our organization who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.
Third Parties
Due to the use of their services in delivering our digital products, we may share user data with the following Third Parties:
1. Google
2. Insert Payment Processor Here
Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.
We will not sell or share your data with other third parties, except in the following cases:
1. If the law requires it;
2. If it is required for any legal proceeding;
3. To prove or protect our legal rights; and
4. To buyers or potential buyers of this company in the event that we seek to sell the company. If you follow hyperlinks from our Site to another site, please note that we are not responsible for and have no control over their privacy policies and practices.
User data will be stored until the purpose the data was collected for has been achieved. You will be notified if your data is kept for longer than this period.
Data is encrypted and only certain employees have access to data regarding the business. We have confidentiality agreements in place to protect data and a breach of this agreement would result in the employee's termination.
While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.
Under the GDPR, you have the following rights:
1. Right to be informed;
2. Right of access;
3. Right to rectification;
4. Right to erasure;
5. Right to restrict processing;
6. Right to data portability; and
7. Right to object.
We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our privacy officer.
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact Oncuff Websites at oncuffwebsites@gmail.com
Do Not Track ("DNT") is a privacy preference that you can set in certain web browsers. We do not track the users of our Site over time and across third party websites and therefore do not respond to browser-initiated DNT signals. We are not responsible for and cannot guarantee how any third parties who interact with our Site and your data will respond to DNT signals.
This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates.
If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. You can lodge a complaint with a supervisory authority by contacting the Office of the Privacy Commissioner of Canada.