How We Treat Your Data?
Your privacy and the security of the personal data that you share with us is very important to us at Shady Rays. Below you will find the main information on the processing of your personal data in relation to your browsing of shadyrays.com and the use of the services offered. For detailed information on how we manage your personal data, please read this privacy statement.
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.
When you browse our store, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.
Email marketing (if applicable): With your permission, we may send you emails about our store, new products and other updates.
Who is the Data Controller?
Shady Rays Inc. (“Shadyrays”) with headquarters at 40 Kingbrook Pkwy Suite 1. Simpsonville, KY 40067, USA is the Data Controller, that is, the subject which decides how and why to process your personal data. You can always contact us by writing to the above address or by contacting us at email@example.com for further information.
SECTION 2 – Your Personal Data
HOW DO YOU GET MY CONSENT?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.
HOW DO I WITHDRAW MY CONSENT?
At any time, depending on the specific processing, you may: revoke your consent to the processing, know which of your personal data we have in our possession, its origin and how it is used, request the update, correction or integration and in the cases provided for by the current provisions, the cancellation, the limitation of processing or oppose their processing. If you wish, you can request to receive your personal data in possession of Shady Rays in a format readable by electronic devices and, where technically possible, we can transfer your data directly to a third party indicated by you.
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at firstname.lastname@example.org or by mailing us at:
40 Kingbrook Pkwy Suite 1. Simpsonville, KY 40067
SECTION 3 – What Personal Data We Collect
What data do we process and why?
The personal data that we process is that which you provide to us when you conclude an order and purchase goods, and that we collect as you browse or use the services offered on shadyrays.com. We can then collect data about you, for example, personal details such as name and surname, shipping address and billing address, browsing data and your purchase habits.
Your personal data is processed for the following purposes:
- conclude and execute the purchase contract for goods offered on shadyrays.com;
- provide you with the services of shadyrays.com such as subscription to the newsletter;
- allow registration to the site and use of services reserved for registered users;
- manage your requests forwarded to our Customer Service.
In the aforementioned cases, the processing of your personal data is legitimate as it is necessary to execute an agreement with you or to provide you with the service that you have specifically requested. We also conduct statistical surveys and analyses with data in aggregate form to understand how users interact and use the site, in order to improve our offer and our services.
However, only with your express consent will we process your personal data to:
- carry out commercial and promotional communication activities;
- customise the site and the commercial offers based on your interests.
Who will process your data?
Your personal data is processed by personnel duly authorised by Shady Rays Inc. as data controller. For organisational and functional needs related to the provision of services on shadyrays.com, your data could also be processed by our third party suppliers. The latter have been evaluated and chosen by us for their proven reliability and competence. Some of these subjects may also be based in non-EU countries and, in these cases, the transfer of your personal data in these countries is carried out in compliance with the guarantees provided by law.
Lawfulness of processing?
We will only process your personal data if one of the following conditions envisaged in the current regulations is satisfied: a) to complete and execute a contract with you. When we process your data in order to complete and execute a purchase contract with you, we take care to use solely the minimum information needed for that purpose. This approach renders lawful the processing of your personal data for the following activities: - complete and execute the contract for the purchase of products offered on shadyrays.com; - register with the Website and access the services offered to registered users; - supply the services offered on shadyrays.com; - manage requests made to our Customer Service centre. The provision of your personal data for the above activities is a contractual obligation. You are free to decide whether or not to give us your data but, in the absence of the requested data, we will be unable to complete or execute the contract or your requests.
This means that you will be unable to purchase the products or benefit from the services provided by us, and we will be unable to manage your requests; b) to satisfy a legal obligation. If you complete a contract for the purchase of goods from shadyrays.com, your data will be processed in order to satisfy the legal obligations imposed on Shady Rays, in compliance with the tax and other regulations applicable to us. You are free to decide whether or not to enter into a contract with us and give us your data but, if you do, your data is necessary and will be processed in order to satisfy the legal obligations imposed on us.
SECTION 4 – Third-Party Services
Your personal data will be processed by Shady Rays internal staff who are specifically trained and authorised to process. Your personal data will also be transmitted to third parties that we use to provide our services; these subjects have been adequately selected and offer a guarantee of compliance with the rules on the processing of personal data. These persons have been appointed as data controllers and carry out their activities according to the instructions given by Shady Rays and under its control.
The third parties in question belong to the following categories: banking operators, internet providers, companies specialised in IT and telematic services; couriers; companies that carry out marketing activities; companies specialised in market research and data processing. In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us. However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in place.
Your data may be transmitted to police and judicial and administrative authorities, in accordance with the law, for the detection and prosecution of crimes, the prevention and protection from threats to public security, to allow Shady Rays to ascertain, exercise or defend a right in court, as well as for other reasons related to the protection of the rights and freedoms of others.
SECTION 5 – Shopify
Our online store is hosted on Shopify Inc (https://www.shopify.com). They provide us with the online e-commerce platform that allows us to sell our products and services to you. Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service here or Privacy Statement here; https://www.shopify.com/legal/privacy.
SECTION 6 – How long do we keep your data
We keep your personal data for a limited period of time, which is different depending on the type of activity that involves the processing of your personal data. After this period, your data will be permanently erased or otherwise rendered anonymous in an irreversible way.
Your personal data is stored in compliance with the following terms and criteria:
- data collected to conclude and execute agreements for the purchase of goods on shadyrays.com: until the administrative and accounting formalities have been completed. The billing data will be kept for ten years from the billing date;
- data relating to the payment: up to the certification of the payment and the conclusion of the related administrative and accounting formalities resulting from the expiration of the right of withdrawal and the terms applied for the contestation of the payment;
- data collected in the context of the use of services offered on shadyrays.com to the user: these data are retained until the termination of service or cancellation of the subscription to the service by the user;
- data related to user requests to our Customer Care: the data useful to assist you will be kept until your request is met;
- data provided for commercial communications activities, opinion polls and market research: up to the request by the user to interrupt the activity and in any case within 2 years from the last interaction of any kind of user with Shady Rays;
- data used for carrying out market research and surveys for the detection of satisfaction: as long as the user does not request the termination of the activity.
SECTION 7 – Security
We protect your personal data with specific technical and organisational security measures, aimed at preventing your personal data from being used illegitimately or fraudulently.
We take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed. If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
SECTION 8 – Age of Consent
By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.