Privacy Policy for TwiggyBits.com
1. Introduction
At TwiggyBits.com, we are committed to protecting your privacy and safeguarding your personal data. We understand the importance of maintaining confidentiality and transparency in how we process your data. This Privacy Policy describes how we collect, use, disclose, and protect your information in compliance with applicable data protection regulations, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Our approach is privacy-first, ensuring your data is handled respectfully and securely.
2. Scope of Policy and Data Controller Role
This Privacy Policy applies to all personal data processed via the website TwiggyBits.com (the “Site”), our related services, and communications. TwiggyBits (referred to as “we”, “us”, or “our”) acts as the data controller responsible for the collection and use of your personal information.
For any inquiries regarding this policy or your personal data, please contact us at [email protected].
3. Categories of Data We Process
We collect different types of personal data depending on your interaction with our Site and services:
– Usage Data: Includes browser type and version, IP address, referring sites, pages visited, time spent on pages, and session identifiers collected through analytics tools and server logs.
– Account Data: Information you provide during account registration or correspondence, such as your full name, email address, phone number, and mailing address.
– Profile Data: Includes your saved preferences, past purchases, browsing behavior, shopping cart contents, and interaction patterns across our digital platforms.
– Communication Data: Encompasses emails, support tickets, live chat logs, and all correspondence initiated by you, including contact form submissions.
– Technical Data: Includes information about the device(s) you use to access the Site such as operating system, hardware model, browser settings, language preferences, and device identifiers.
– Transaction Data: Consists of payment details (processed via secure payment gateways), purchased products, delivery information, and billing records.
– Preference Data: Covers your marketing preferences, newsletter subscription choices, and consent to receive promotional content tailored to your interests.
4. Legal Bases for Processing Personal Data
We process your personal data in accordance with the following legal bases as provided under GDPR and CCPA:
– Consent: Where you have provided explicit consent for data processing (e.g., opting into newsletters or accepting cookies).
– Contractual Obligations: When the processing is necessary for the performance of a contract with you, such as fulfilling orders or providing customer support.
– Legitimate Interests: Where processing is necessary for our legitimate business interests, such as improving website functionality, performing analytics, or preventing fraudulent activity, provided such interests are not overridden by your rights and freedoms.
– Legal Compliance: Where processing is required to comply with legal obligations.
5. Your Rights
Under GDPR and CCPA, you are entitled to the following rights regarding your personal data:
– Right of Access: You may request confirmation of whether we process your personal data and obtain a copy of such data.
– Right to Rectification: You have the right to correct incomplete or inaccurate personal data we hold about you.
– Right to Erasure: Also known as the “right to be forgotten,” you may request the deletion of your personal data when there is no legal basis for its continued processing.
– Right to Restriction of Processing: You may ask us to limit the processing of your personal information under certain circumstances.
– Right to Data Portability: You can request a copy of your data in a structured, commonly used, and machine-readable format.
– Right to Object: You reserve the right to object to the processing of your data based on legitimate interests or direct marketing purposes.
To exercise any of these rights, please contact [email protected] and we will respond as required under applicable laws.
6. Security Measures
We implement a range of technical and organizational safeguards to ensure your data’s security and integrity, including but not limited to:
– Data encryption in transit and at rest
– Role-based access controls and secure authentication protocols
– Regular backups and disaster recovery procedures
– Staff training in data protection principles and cybersecurity
– Security audits and vulnerability scanning
Despite our best efforts, no method of transmission or storage is 100% secure. Nevertheless, we strive to uphold the highest standards of data security.
7. International Data Transfers
Personal data stored or processed by TwiggyBits may be transferred to jurisdictions outside the European Economic Area (EEA). These transfers are conducted in accordance with GDPR provisions using appropriate safeguards, including:
– Standard Contractual Clauses (SCCs) approved by the European Commission
– Verification of adequate data protection levels under applicable frameworks
Where required, we engage only with processors and vendors who demonstrate a commitment to compliant data handling practices.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Specific retention periods include:
– Account Data: Retained as long as the user maintains an account and for up to 5 years thereafter to address potential legal claims.
– Transaction Data: Stored for up to 7 years for accounting and compliance purposes.
– Communication Data: Retained for 24 months unless required longer for legal or business purposes.
– Usage and Technical Data: Anonymized and aggregated for analysis; original logs retained for no more than 12 months.
– Marketing and Preference Data: Retained for up to 2 years post last interaction or until consent is withdrawn.
9. Cookie Policy
TwiggyBits.com uses cookies and similar technologies to enhance user experience, provide essential functionality, and analyze site performance. Types of cookies we use include:
– Essential Cookies: Enable core functionalities such as security, account access, and shopping cart features.
– Functional Cookies: Remember user preferences and customize the site experience.
– Performance Cookies: Collect anonymous data to measure website usage and performance.
– Analytics Cookies: Help us improve functionality by understanding how visitors interact with the site.
10. Cookie Management & Compliance
You may manage your cookie preferences at any time by using the cookie consent tool available on our website. This allows you to accept or decline different categories of cookies in compliance with GDPR and CCPA requirements.
Additionally, you may control cookies via your browser settings. Note that disabling some cookies may impact the functionality of certain parts of the site.
We honor Do Not Track (DNT) signals where supported and provide opt-out mechanisms as required by California privacy laws.
11. Special Protections for Children
TwiggyBits.com does not knowingly collect or solicit personal data from children under the age of 13. If we become aware that a child under 13 has provided us with personal data without verifiable parental consent, we will take immediate steps to delete such data from our systems. If you believe your child has submitted data to us, please contact us at [email protected].
12. Policy Updates
We reserve the right to review and update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or Site functionalities. Any significant modifications will be communicated via our website or direct notice where required. Your continued use of the Site following such changes constitutes acknowledgment and acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or wish to exercise your rights under this Privacy Policy, please contact us at:
Email: [email protected]
Website: https://www.twiggybits.com
We are committed to maintaining full compliance with all applicable data protection regulations and are happy to assist with any privacy-related inquiries.